Key Takeaways
- LGPD's general provisions took effect September 18, 2020; its administrative-sanctions provisions (the fines) took effect separately, on August 1, 2021. Guides citing a single "May 2021" or "August 2020" date are working from a superseded timeline.
- Fines are capped at 2% of the violating entity's revenue in Brazil, up to R$50 million per infraction, a hard ceiling, not an alternative to a flat figure the way GDPR's "whichever is higher" structure works.
- Since April 2024, businesses must report a data breach to Brazil's ANPD and to affected individuals within 3 business days (6 for small-scale processing agents), replacing the original statute's vague "reasonable timeframe" standard.
- Small businesses (Brazil revenue under R$4.8 million/year, or R$16 million for startups) have been exempt from mandatory DPO appointment since January 2022, provided the processing isn't high-risk and a communication channel still exists for data subjects.
- Data subjects get a 15-day deadline for a full access request under Article 19, not an open-ended timeline some older guides describe.
- Transferring data outside Brazil requires ANPD's own standard contractual clauses, not GDPR's. The deadline to adopt them, August 22, 2025, has already passed.
Brazil's LGPD (Lei Geral de Proteção de Dados) took effect in two stages, general provisions in September 2020 and administrative sanctions in August 2021, and violations are capped at 2% of a company's Brazil revenue up to R$50 million per infraction. Several of the specific rules have changed since the law was first passed: breach-notification timelines tightened in 2024, and a small-business DPO exemption has existed since 2022. Below: who has to comply, what rights Brazilian data subjects actually have, and the enforcement actions that show how ANPD is applying the law today.
Secure Privacy is a cookie and consent management platform that generates LGPD-compliant consent flows alongside GDPR, CCPA, and 55+ other privacy laws.
What Is LGPD, and Who Does It Apply To?
LGPD (Law 13.709/2018) is Brazil's comprehensive data protection law, signed August 14, 2018, and modeled closely on GDPR's structure while diverging on specific mechanics that matter for compliance. It applies to any organization processing personal data of individuals located in Brazil, regardless of where the organization itself is headquartered, and to any processing carried out in Brazil, mirroring GDPR's extraterritorial reach.
A narrow set of processing activities sit outside LGPD's scope under Article 4: data processed for exclusively personal and non-economic purposes, processing for journalistic, artistic, or academic purposes, processing for public safety, national defense, state security, or the investigation of criminal offenses, and data originating outside Brazil that isn't shared with a Brazilian processing agent. Content claiming "family" use or general "B2B data exchanges" fall under a separate exemption is describing a category that doesn't exist in the statute.
When Did LGPD Actually Take Effect?
In two separate stages, which is where a lot of guides blend the timeline into one wrong date. LGPD's general, substantive provisions, the actual data-processing obligations, took effect September 18, 2020, under Law 14.010/2020, which overrode an earlier May 2021 effective date that a since-superseded provisional measure had set. The administrative-sanctions provisions, the part that lets ANPD actually issue fines, took effect separately, roughly a year later, on August 1, 2021.
That two-stage history matters for one practical reason: an organization only in scope since 2021 has had less runway to build compliance than one that's been technically obligated since 2020, and any content citing a single blended date is working from an incomplete picture of the rollout.
What Rights Do Data Subjects Have, and How Fast Do You Have to Respond?
LGPD grants data subjects rights to confirmation of processing, access, correction, anonymization or deletion of unnecessary or excessive data, portability, and information about who their data has been shared with. Article 19 sets a specific response structure: a simplified confirmation of whether processing is taking place has to be provided immediately, while a full, detailed response has a 15-day deadline. Content describing this as an open-ended or undefined timeline is incorrect; the statute is specific on this point.
What Are the Legal Bases for Processing Under LGPD?
LGPD lists 10 legal bases under Article 7 for lawful processing, consent being only one of them alongside compliance with a legal obligation, contract performance, legitimate interest, protection of life, and health protection, among others. Cookie-specific consent mechanics, including what a compliant banner actually needs to present, are covered in more depth separately, since that's a narrower, more technical topic than a general compliance overview needs to carry here.
Can You Transfer Data Outside Brazil?
Only through one of LGPD's specific permitted mechanisms, per Article 33: a transfer to a country or international body ANPD has recognized as providing adequate protection, ANPD-approved standard contractual clauses, ANPD-approved binding corporate rules, the data subject's specific and highlighted consent to that particular transfer, or a narrow set of situational bases like international legal cooperation or contract performance. There's no default "adequate country" list to lean on the way GDPR's works in practice; ANPD's own standard contractual clauses (adopted in full, without modification) are the mechanism most businesses actually use.
One detail that trips up multinational compliance programs specifically: GDPR's own standard contractual clauses don't satisfy LGPD's transfer requirement. They're separate legal instruments under separate laws, and a business already using GDPR SCCs for its EU data flows still needs ANPD's own version, in its own contracts, for any personal data leaving Brazil. The deadline to have these incorporated was August 22, 2025, which has already passed, so this isn't a future to-do item; it's a current compliance gap for any business that hasn't done it yet.
What Security Measures Does LGPD Actually Require?
LGPD requires "technical and administrative measures" adequate to protect personal data from unauthorized access and from accidental or unlawful destruction, loss, alteration, communication, or disclosure. That's a deliberately general standard rather than a fixed checklist, which means what counts as adequate scales with the sensitivity and volume of data actually being processed. For high-risk processing specifically, ANPD can require a Data Protection Impact Assessment, a documented evaluation of the processing's risks to data subjects and the safeguards in place to address them, similar in function to a DPIA under GDPR though LGPD doesn't mandate one as broadly as a fixed pre-condition for every processing activity.
What Happens If You Have a Data Breach?
Since April 2024, ANPD Resolution CD/ANPD No. 15/2024 requires notifying both ANPD and affected data subjects within 3 business days of becoming aware of a breach, extended to 6 business days for small-scale processing agents. This replaced the original statute's vaguer "reasonable timeframe" standard, and it's a common gap in older compliance content that hasn't been updated to reflect the 2024 resolution.
Do You Need a Data Protection Officer?
Generally yes, but a real exemption exists that a lot of guides miss. Since ANPD Resolution CD/ANPD No. 2/2022 (effective January 27, 2022), small processing agents, defined as businesses with Brazil revenue at or under R$4.8 million per year (R$16 million for eligible startups), are exempt from mandatory DPO appointment, provided the processing isn't high-risk and the organization still maintains a communication channel for data subjects to reach. A DPO's actual responsibilities under LGPD, for organizations that do need one, are covered in a separate, dedicated post.
How Big Are the Fines, and What Has ANPD Actually Enforced?
LGPD fines are capped, not open-ended: up to 2% of the violating entity's revenue in Brazil, limited to R$50 million per infraction. That's a hard ceiling, not a "whichever is higher" structure the way GDPR's percentage-or-flat-figure calculation works; content describing it that way is describing GDPR's mechanism, not LGPD's.
ANPD's actual enforcement record shows the range in practice. In July 2024, ANPD issued a preventive measure suspending Meta's AI training on Brazilian user data pending further review. In December 2024, ANPD ordered a 5-business-day suspension of X Corp's Grok AI over how it handled minors' data. On the smaller end, Telekall received the country's first published LGPD sanction in July 2023, a total fine of R$14,400, showing enforcement scales down to genuinely small violations, not just headline-making tech-company cases.
How Do You Actually Build an LGPD Compliance Program?
Knowing the rules and having a working program are different things. In practice, building one runs through the same sequence regardless of company size:
- Map every place personal data of individuals in Brazil enters, moves through, and leaves your systems, including any vendor or processor that touches it.
- Identify the legal basis for each processing activity from LGPD's 10 options under Article 7, not just default to consent for everything.
- Appoint a DPO if you don't qualify for the small-processing-agent exemption, and publish how to reach them.
- Put technical and administrative security measures in place sized to the sensitivity and volume of what you actually process, and document a DPIA for anything high-risk.
- Build a rights-request process that can confirm processing immediately and deliver a full response within 15 days.
- Put ANPD-approved standard contractual clauses (not GDPR's) in place for any data leaving Brazil, and a breach-response process that can notify ANPD and affected individuals within 3 business days.
A Brief Legislative Timeline
LGPD's legal status has shifted since 2018 in ways worth knowing if you're tracking the law's trajectory rather than just its current text. Constitutional Amendment 115/2022, which took effect February 10, 2022 (originating from proposed amendment PEC 17/2019), elevated data protection to a fundamental right under Brazil's constitution, giving LGPD's underlying protections a stronger legal foundation than statute alone. Separately, Provisional Measure 1124/2022, signed June 13, 2022, converted ANPD from a body with more limited standing into an "autarquia de natureza especial," a special-nature autonomous agency with greater independence to investigate and enforce.
Building an actual compliance program against this framework means treating it as a moving target on specific mechanics (the 2024 breach-notification tightening being the clearest recent example) even though the law's core obligations have stayed stable since 2020. A consent management platform that tracks LGPD alongside GDPR, CCPA, and other frameworks from one system means a regulatory update like the 2024 breach-notification change gets reflected once, not re-implemented separately for each jurisdiction a business operates in. Secure Privacy covers LGPD alongside 55+ other privacy laws from a single consent record.
FAQ
When did LGPD actually take effect?
In two stages: general provisions on September 18, 2020, and administrative sanctions separately on August 1, 2021. Content citing a single date, especially "May 2021," is working from a superseded timeline.
How much is the maximum LGPD fine?
Up to 2% of the violating entity's revenue in Brazil, capped at R$50 million per infraction. This is a hard ceiling, not an alternative-to-a-flat-figure structure like GDPR uses.
Do all businesses need a Data Protection Officer under LGPD?
No. Small processing agents with Brazil revenue at or under R$4.8 million a year (R$16 million for eligible startups) have been exempt since January 2022, as long as the processing isn't high-risk and a data-subject communication channel still exists.
How fast do you have to report a data breach under LGPD?
Since April 2024, within 3 business days to both ANPD and affected individuals, or 6 business days for small-scale processing agents. This replaced the original statute's less specific "reasonable timeframe" standard.
How fast do you have to respond to a data access request?
Immediately for a simplified confirmation of whether processing is occurring, and within 15 days for a full, detailed response, per Article 19.
Can GDPR standard contractual clauses be used to satisfy LGPD's transfer requirements?
No. They're separate legal instruments under separate laws. A business transferring data out of Brazil needs ANPD's own standard contractual clauses in its contracts, even if it already uses GDPR's SCCs for its EU data flows.
Is LGPD enforcement mostly focused on large tech companies?
No. While ANPD's highest-profile actions have involved companies like Meta and X Corp, its first published sanction (Telekall, 2023) was a R$14,400 fine, showing enforcement reaches well below headline-making cases.
Sources
- Lei Geral de Proteção de Dados (LGPD), Law 13.709/2018
- ANPD Resolution CD/ANPD No. 15/2024, breach-notification requirements
- ANPD Resolution CD/ANPD No. 2/2022, small processing agent DPO exemption
- Article 33, LGPD, international data transfer mechanisms, and ANPD's standard contractual clauses, mandatory since August 22, 2025




