Comprehensive omnibus statute in force since 2020 with an increasingly empowered, independent regulator; core scope/authority questions are settled.
Primary frameworkLei Geral de Proteção de Dados Pessoais (LGPD) — Law No. 13.709/2018, as amended by Law No. 13.853/2019 and Provisional Measure No. 1.317/2025
Traffic-light rationale — GreenComprehensive omnibus statute in force since 2020 with an increasingly empowered, independent regulator; core scope/authority questions are settled.
Sub-modules (5)
Regulator And AuthorityGreen
ANPD, created by LGPD Art. 55-A and structured by Decree 10.474/2020, was converted into an independent regulatory agency by Provisional Measure 1.317/2025, aligning it with other Brazilian regulatory agencies and granting police-style enforcement powers.
Claims: CLM-BR-4a1e02f1, CLM-BR-4a1e02f2
Act And InstrumentsGreen
The LGPD (65 articles) is the primary instrument, heavily influenced by GDPR, supplemented by numerous ANPD resolutions (DPO, breach notification, international transfers, dosimetry, small agents) and sector rules.
Claims: CLM-BR-4a1e02f3
Material ScopeGreen
LGPD applies to processing of personal data by any natural or legal person, public or private, online or offline, with limited exceptions (journalistic/artistic/academic purposes, public safety, national defense, criminal investigation).
Claims: CLM-BR-4a1e02f4
Territorial ScopeGreen
Article 3 gives the LGPD extraterritorial reach: any processing carried out in Brazil, or aimed at offering goods/services to individuals in Brazil, triggers applicability regardless of the controller's country of establishment.
Claims: CLM-BR-4a1e02f5
Regulator Registration And FilingAmber
There is no general controller-registration regime, but ANPD Resolution 02/2022 (small-scale agents) and a simplified ROPA template create lighter-touch filing/record obligations for small processing agents.
Claims: CLM-BR-4a1e02f6
Category narrative64 words
Brazil's data protection framework is anchored in the LGPD (Law 13.709/2018, as amended by Law 13.853/2019), enforced by ANPD, which in September 2025 was upgraded from a transitional federal-administration body into an autonomous 'National Data Protection Agency' via Provisional Measure 1.317/2025, gaining functional, technical, decision-making, administrative and financial autonomy. The law applies extraterritorially and covers virtually all sectors and processing operations with narrow carve-outs.
Sources and claims (6)
ConfirmedIAPP — Provisional Measure No. 1.317/2025 transformed ANPD into the National Data Protection Agency, guaranteeing functional, technical, decision-making, administrative and financial autonomy.
ConfirmedIAPP — The provisional measure grants ANPD strengthened enforcement powers, including ordering establishments to cease operations, seizing goods, and requesting police assistance in cases of obstruction.
ConfirmedIAPP — The LGPD comprises 65 articles and was greatly influenced by the EU GDPR, providing legal bases authorizing personal data use across all economic sectors.
ConfirmedIAPP — LGPD applicability is not limited by business size; exceptions apply only to journalistic, artistic, academic, public-safety and national-defense purposes.
ConfirmedIAPP — Under Article 3, a personal data processor is subject to the LGPD when data are collected or processed in Brazil, or processed to offer goods/services to individuals in Brazil, irrespective of where the controller is headquartered.
ProbableOneTrust DataGuidance — ANPD developed a simplified ROPA (record of processing activities) template for small-scale processing agents under the small-agents regulation approved by Resolution CD/ANPD No. 02/2022.
Traffic-light rationale — GreenLegal basis and sensitive-data regimes are well-settled statutory provisions with several years of ANPD/court interpretation.
Sub-modules (4)
Lawful BasesGreen
Ten legal bases exist for general personal data, including consent and legitimate interest; a distinct 'protection of credit' basis (Art. 7 X) is unique to Brazil and important for financial/credit-bureau processing.
Claims: CLM-BR-5b2f13a1, CLM-BR-5b2f13a2
Consent ThresholdsGreen
Consent must be free, informed, unambiguous and given for a specific purpose; written consent clauses must be visually highlighted, and the burden of proof for valid consent rests with the controller.
Claims: CLM-BR-5b2f13a3
Special CategoriesGreen
Sensitive personal data (Art. 5 II) includes racial/ethnic origin, religion, political opinion, union/religious/philosophical organisation membership, health, sex life, and genetic or biometric data; processing is restricted to the enumerated grounds of Article 11.
Claims: CLM-BR-5b2f13a4, CLM-BR-5b2f13a5
Pseudonymisation And AnonymisationAmber
Anonymised data (using reasonable technical/cost means at the time of processing) falls outside LGPD scope, except where the anonymisation is reversible or the data is used to build an identified individual's behavioral profile.
Claims: CLM-BR-5b2f13a6
Category narrative70 words
The LGPD provides ten enumerated legal bases (Art. 7 and 11), including consent, legitimate interest, contract necessity and a distinctive 'protection of credit' basis. Sensitive/special-category data (racial/ethnic origin, religion, political opinion, union membership, health, sex life, genetic and biometric data) is subject to a stricter, separately enumerated set of bases under Article 11. Anonymisation and pseudonymisation are defined but ANPD has flagged that re-identifiable/behavioral-profiling data can fall back within scope.
Sources and claims (6)
ConfirmedIAPP — The LGPD restricts processing of personal data to enumerated legal bases in Article 7, similar to GDPR Article 6, including consent and legitimate interest.
ConfirmedOneTrust DataGuidance — A distinctive 'protection of credit' legal basis (Art. 7 X) allows financial institutions and credit bureaus to process personal data for credit risk analysis and credit-history consultation.
ConfirmedIAPP — Consent must be given for particular purposes and the burden of proof is on the controller to demonstrate valid consent; consent may be revoked at any time free of charge.
ConfirmedIAPP — Sensitive personal data includes racial/ethnic origin, religious belief, political opinion, union/religious/philosophical organisation membership, health or sex life, and genetic or biometric data.
ConfirmedIAPP — Processing of sensitive personal data is restricted to the situations enumerated in Article 11, including specific/distinct consent or, without consent, compliance with a legal obligation, public-policy execution, research (with anonymisation where possible), exercise of rights, life/safety protection, health protection, or fraud prevention.
ProbableOneTrust DataGuidance — Anonymised data can be treated as personal data under the LGPD when it is used to formulate a behavioural profile of a particular natural person who is identified.
Traffic-light rationale — GreenRights catalogue is comprehensive and in force, though some response-timeline specifics are left to case-by-case ANPD regulation.
Sub-modules (5)
Access RightGreen
Data subjects have the right to confirmation of the existence of processing and facilitated access to their data (Arts. 9, 19).
Claims: CLM-BR-6c3g24b1
Rectification And ErasureGreen
Article 18 grants rights to correct incomplete/inaccurate/outdated data and to anonymise, block, or delete unnecessary, excessive, or unlawfully processed data.
Claims: CLM-BR-6c3g24b2
Restriction And ObjectionGreen
Data subjects may petition against the controller before ANPD, and may oppose processing carried out under a consent-waiver ground if the LGPD is not being complied with.
Claims: CLM-BR-6c3g24b3
Data PortabilityAmber
Article 18(V) grants a right to data portability; sectoral implementation (e.g., Central Bank open-banking/open-finance rules) has been used to operationalise portability in the financial sector ahead of general ANPD guidance.
Claims: CLM-BR-6c3g24b4
Deadlines And Response WindowsAmber
Where immediate compliance with a rights request is impossible, the controller must respond indicating either that it is not the processing agent or the factual/legal reasons preventing immediate action (Art. 19 §4); a fixed 15-day deadline applies specifically to requests for the text of international-transfer contractual instruments.
Claims: CLM-BR-6c3g24b5
Category narrative42 words
Article 18 grants a GDPR-like bundle of rights (confirmation/access, correction, anonymisation/blocking/deletion, portability, information about sharing and about consequences of refusing consent, and review of automated decisions under Article 20). Rights must first be exercised directly against the controller before escalation to ANPD.
Sources and claims (5)
ConfirmedDataGuidance — Data subjects have the right to facilitated access to information about the processing of their data, to be made available in a clear, adequate and ostensible manner.
ConfirmedIAPP — Article 18 rights include correcting incomplete, inaccurate or out-of-date data, and anonymising, blocking or deleting unnecessary or excessive data or data processed in noncompliance with the law.
ConfirmedIAPP — The data subject has the right to petition regarding her/his data against the controller before the national authority, and may oppose processing carried out under a consent-waiver ground if there is noncompliance with the LGPD.
ProbableOneTrust DataGuidance — The Central Bank and Monetary Council's open banking regulation implemented consent-based data portability among financial institutions ahead of general ANPD portability guidance.
ConfirmedIAPP — Upon a data subject's request for the full text of contractual instruments used in an international transfer, controllers have 15 days to provide it, excluding trade secrets.
Core duties are legislated and increasingly detailed by ANPD resolutions (DPO, breach, dosimetry), but explicit statutory retention/disposal timelines remain unresolved and enforcement of Art. 48/49 duties shows continuing public-sector immaturity.
Traffic-light rationale — AmberCore duties are legislated and increasingly detailed by ANPD resolutions (DPO, breach, dosimetry), but explicit statutory retention/disposal timelines remain unresolved and enforcement of Art. 48/49 duties shows continuing public-sector immaturity.
Sub-modules (7)
Accountability And DpiaGreen
DPIAs ('relatório de impacto') are expressly contemplated when processing relies on legitimate interest (Art. 10 §3) or involves sensitive data (Art. 38); the Digital Government Secretariat (SGD) guideline also recommends DPIAs for location tracking, profiling, automated decision-making with legal effects, and processing involving children/teenagers.
Claims: CLM-BR-7d4h35c1
Dpo RequirementsGreen
Resolution CD/ANPD No. 18/2024 requires all controllers to designate a DPO via a formal written act, grant technical autonomy, and ensure Portuguese-language communication; small-scale controllers are exempt but must maintain a data-subject communication channel; processors are not required to appoint a DPO.
Claims: CLM-BR-7d4h35c2, CLM-BR-7d4h35c3
Ropa RequirementsAmber
A simplified ROPA template for small processing agents was developed under Resolution CD/ANPD 02/2022 following public consultation.
Claims: CLM-BR-7d4h35c4
Joint Controller ArrangementsGreen
Controllers and processors can be jointly and severally liable for security incidents and unauthorized/improper data use; a processor's liability may be limited to its contractual and security obligations if it does not itself violate LGPD rules.
Claims: CLM-BR-7d4h35c5
Security MeasuresAmber
Article 49 requires security in systems operationalising personal data processing; three of ANPD's early sanctioning decisions concerned Article 49 security violations.
Claims: CLM-BR-7d4h35c6
Breach NotificationGreen
Article 48 requires notification of security incidents to ANPD within a reasonable timeframe depending on severity, potentially triggering data-subject notification and public disclosure; Resolution CD/ANPD 15/2024 (April 2024) defines incidents and clarifies criteria, timeline and methods for notification.
Claims: CLM-BR-7d4h35c7, CLM-BR-7d4h35c8
Retention And DisposalRed
No specific statutory retention-period schedule was identified in this research pass beyond the general purpose-limitation principle; ANPD has not published a dedicated retention/disposal regulation comparable to its DPO or breach-notification resolutions.
Category narrative57 words
Controllers must appoint a DPO (Resolution CD/ANPD 18/2024) unless qualifying as a small-scale controller; ROPA obligations apply with a simplified template for small agents; DPIAs are recommended/required for legitimate-interest and sensitive-data processing and for profiling/tracking/children's-data scenarios; breach notification to ANPD is mandatory within a reasonable timeframe under Resolution CD/ANPD 15/2024; joint controller/processor liability follows a GDPR-like split.
Sources and claims (8)
ConfirmedIAPP — The LGPD expressly contemplates DPIAs where processing is based on legitimate interest or involves sensitive data, and ANPD may at any time request a DPIA from the controller in those instances.
ConfirmedIAPP — Under ANPD Resolution CD/ANPD No. 18/2024, all organisations acting as a controller must designate a DPO through a formal written, dated and signed act; exemptions are granted only for small-scale controllers, which must instead maintain a channel for data-subject requests.
ConfirmedIAPP — The DPO must be able to communicate with ANPD and data subjects in Portuguese and is not personally liable for the controller's processing of personal information.
ProbableOneTrust DataGuidance — ANPD developed a draft simplified ROPA (record of processing activities) template specifically for small processing agents under Resolution CD/ANPD No. 02/2022.
ConfirmedIAPP — Controllers and processors can be jointly and severally liable for information-security incidents and improper/unauthorized data use, though a processor's liability may be limited to its contractual and security obligations.
ConfirmedIAPP — Three of ANPD's published sanctioning decisions to date have dealt with Article 49 violations relating to ensuring security in systems operationalising personal data processing.
ConfirmedIAPP — Article 48 of the LGPD requires mandatory data-breach notification to ANPD within a reasonable timeframe, which may, depending on severity, require notifying affected data subjects and public disclosure of the incident.
ConfirmedIAPP — ANPD Resolution CD/ANPD No. 15 of 24 April 2024 defines security incidents and clarifies the criteria, timeline and methods for breach notification.
A full transfer-mechanism toolkit is now operative and the landmark 2026 mutual adequacy determination substantially de-risks EU-Brazil data flows, though SCC/BCR implementation details remain partly unresolved.
Primary frameworkLGPD Arts. 33–36; ANPD International Data Transfer Regulation (Aug. 2024); Resolution No. 32/2026
Traffic-light rationale — GreenA full transfer-mechanism toolkit is now operative and the landmark 2026 mutual adequacy determination substantially de-risks EU-Brazil data flows, though SCC/BCR implementation details remain partly unresolved.
Sub-modules (6)
Transfer MechanismsGreen
Article 33 lists exhaustive grounds for international transfers: adequacy, contractual/BCR guarantees, international cooperation agreements, life/safety protection, ANPD prior authorization, public-policy execution, consent, legal/regulatory compliance, contractual necessity, and exercise of rights.
Claims: CLM-BR-8e5i46d1
Adequacy ReceivedGreen
The European Commission's Implementing Decision 2026/179 (January 2026) recognises that Brazil ensures an adequate level of protection for personal data transferred from the EU under GDPR Article 45.
Claims: CLM-BR-8e5i46d2
Adequacy GrantedGreen
ANPD's Resolution No. 32/2026 reciprocally recognised the EU as an international organisation providing an adequate level of protection for international transfers under the LGPD.
Claims: CLM-BR-8e5i46d3
Sccs And BcrsAmber
ANPD introduced a rigid standard-contractual-clause model (inspired by EU, UK, New Zealand and Singapore frameworks) divided into general information, mandatory clauses, security measures, and additional clauses/annexes; BCRs require prior ANPD assessment and evidence of a data-privacy governance program.
Claims: CLM-BR-8e5i46d4, CLM-BR-8e5i46d5
Transfer Impact AssessmentAmber
The LGPD does not impose a discrete, Schrems-II-style per-transfer impact assessment; adequacy equivalence is instead assessed by ANPD at the country level, though commentators note open questions about whether additional safeguards for SCCs may eventually be required.
Claims: CLM-BR-8e5i46d6
Data LocalisationAmber
Brazil does not impose a general data-localisation mandate; however, discussions of a 'sovereign cloud' as part of Brazil's Artificial Intelligence Plan aim to keep government data stored within national borders.
Claims: CLM-BR-8e5i46d7
Category narrative72 words
Article 33 provides an exhaustive list of transfer mechanisms (adequacy, standard contractual clauses, BCRs, consent, legal-obligation, contract necessity, and other named grounds). ANPD published its long-awaited International Data Transfer Regulation (August 2024) and, in January 2026, mutual EU-Brazil adequacy was achieved: the European Commission adopted Implementing Decision 2026/179 recognising Brazil as adequate under GDPR Art. 45, and ANPD's Resolution No. 32/2026 reciprocally recognised the EU as providing adequate protection under the LGPD.
Sources and claims (7)
ConfirmedIAPP — Article 33 of the LGPD provides an exhaustive list of grounds authorising international data transfers, including adequacy, contractual instruments, ANPD-authorised specific clauses, international cooperation agreements, and data-subject consent.
ConfirmedEUR-Lex — For the purpose of Article 45 of Regulation (EU) 2016/679, Brazil ensures an adequate level of protection for personal data transferred from the European Union to controllers and processors in Brazil subject to the LGPD.
ConfirmedIAPP — In Resolution No. 32/2026, ANPD recognized the EU as an international organization providing an adequate level of protection for purposes of international data transfers under the LGPD.
ConfirmedIAPP — ANPD's SCCs can form a stand-alone contract or be attached to a broader agreement, are divided into general information, mandatory clauses, security measures, and additional clauses/annexes, and unlike EU clauses do not feature modules but customizable fields.
ConfirmedIAPP — Use of BCRs for intragroup international transfers requires prior ANPD assessment, with data controllers demonstrating compliance including implementation of a data privacy governance program.
UncertainIAPP — There will inevitably be discussions about the adequacy of SCCs and whether additional measures are necessary, mirroring concerns raised in the EU under Schrems II.
UncertainIAPP — Publication of the ANPD international-transfer regulation coincided with discussions of creating a 'sovereign cloud' under Brazil's Artificial Intelligence Plan, aiming to keep government data stored within national borders.
Financial and health overlays are documented and active; telecoms/ePrivacy, education and insurance sub-areas lack dedicated sectoral DP instruments in the sources reviewed.
Primary frameworkLGPD (general) plus BACEN/CMN Open Finance regulation and FEBRABAN self-regulation (financial sector)
Traffic-light rationale — AmberFinancial and health overlays are documented and active; telecoms/ePrivacy, education and insurance sub-areas lack dedicated sectoral DP instruments in the sources reviewed.
Sub-modules (7)
Financial Sector OverlayGreen
BACEN and the Monetary Council's Open Finance regulation establishes consent as the sole legal ground for data transfers within open banking; FEBRABAN's CARB Standard 21/2022 reiterates and supplements LGPD requirements for banks.
Claims: CLM-BR-9f6j57e1, CLM-BR-9f6j57e2
Health Sector OverlayAmber
ANPD sanctioned the Instituto de Assistência Médica ao Servidor Público Estadual (IAMSPE) for failing to safeguard public employees' health data and for an untimely Article 48 breach notification.
Claims: CLM-BR-9f6j57e3
Telecoms And EprivacyRed
No dedicated telecoms/ePrivacy-specific data-protection overlay (comparable to the EU ePrivacy Directive) was identified for Brazil in this research pass; cookie-specific guidance exists as ANPD soft-law rather than a distinct statute.
Claims: CLM-BR-9f6j57e4
Employment DataAmber
Employment-related sensitive health data has been subject to ANPD enforcement in the public sector (IAMSPE case involving public employees' health data), but no dedicated private-sector employment-data statute was identified.
Claims: CLM-BR-9f6j57e3
Credit And ScoringAmber
The 'protection of credit' legal basis (Art. 7 X) underpins credit-bureau and scoring activity; Brazilian courts have restricted processing of data such as voter registration number, mother's name, lifestyle, social class, schooling, marginal propensity to consume and georeferencing for credit-protection purposes as not necessary.
Claims: CLM-BR-9f6j57e5
EducationRed
No education-sector-specific data-protection instrument was identified in this research pass beyond general LGPD applicability and DPIA guidance touching on children's data in digital products.
InsuranceRed
No insurance-sector-specific data-protection instrument was identified in this research pass beyond general LGPD applicability.
Category narrative92 words
Financial-sector data flows are shaped by BACEN/Monetary Council open-banking (Open Finance) rules layered atop the LGPD, plus bank self-regulation (FEBRABAN's CARB Standard 21/2022). Health-sector enforcement so far centres on ANPD sanctions against a public health-insurance entity for failing to safeguard employees' health data and for a late Article 48 breach notification. Credit/scoring processing is governed by a bespoke 'protection of credit' legal basis, with courts restricting non-necessary data (e.g., voter registration, marginal propensity to consume) in credit-protection scoring. No comprehensive telecoms/ePrivacy-specific overlay, education-sector, or insurance-sector regime was identified in this research pass.
Sources and claims (5)
ConfirmedOneTrust DataGuidance — The Central Bank and Monetary Council's open banking regulation establishes consent as the unique legal ground for data transfers within the scope of open banking, excluding sensitive data, credit scores/ratings and login/access credentials from the transferable dataset.
ProbableOneTrust DataGuidance — FEBRABAN's CARB Standard 21/2022 reiterates and adds to LGPD requirements, prompting financial institutions toward international standards and better data-protection governance.
ConfirmedIAPP — ANPD determined that the government health system IAMSPE violated the LGPD by failing to safeguard public employees' personal health data and by not producing a data-breach notification within a reasonable period.
UncertainEUR-Lex — No distinct telecoms/ePrivacy statute analogous to the EU ePrivacy Directive was located for Brazil; ANPD has issued a Guide on Cookies and Data Protection as soft-law guidance rather than binding sector legislation.
ProbableEUR-Lex — Brazilian courts have restricted the processing of data such as voter registration number, mother's name, lifestyle, social class, schooling, marginal propensity to consume and georeferencing for credit-protection purposes as not necessary.
One concrete enforcement precedent (Meta AI-training suspension) exists, but most adtech sub-areas lack dedicated Brazilian instruments identified in this pass.
Primary frameworkLGPD general provisions (Arts. 7, 18, 20) plus ANPD enforcement practice; no dedicated adtech statute identified
Traffic-light rationale — AmberOne concrete enforcement precedent (Meta AI-training suspension) exists, but most adtech sub-areas lack dedicated Brazilian instruments identified in this pass.
Sub-modules (6)
Cookies And TrackersAmber
ANPD has published a Guide on Cookies and Data Protection referenced in the EU's adequacy assessment, but this is soft-law guidance rather than a binding ePrivacy-style cookie consent statute.
Claims: CLM-BR-ag7k68f1
Dark PatternsRed
No Brazil-specific dark-pattern prohibition distinct from general LGPD transparency/consent principles was identified in this research pass.
Opt Out SignalsRed
No evidence was found of Brazil recognising standardized opt-out signals (e.g., Global Privacy Control) analogous to US state regimes.
Clean Rooms And DcrRed
No clean-room or data-collaboration-room-specific guidance was identified for Brazil in this research pass.
Cross Context AdvertisingAmber
ANPD ordered Meta to suspend processing of personal data for AI-model training under penalty of a daily fine of BRL50,000; the order was later suspended conditional on Meta's compliance with a monitored plan facilitating the right to object.
Claims: CLM-BR-ag7k68f2, CLM-BR-ag7k68f3
Direct MarketingRed
No Brazil-specific direct-marketing suppression/consent regime distinct from general LGPD consent and objection rights was identified in this research pass.
Category narrative80 words
Commercial/adtech-specific DP rules in Brazil remain comparatively underdeveloped relative to cookie/consent regimes seen in the EU or certain US states. The clearest enforcement data point is ANPD's order suspending Meta's processing of personal data for AI-model training (subject to a daily fine), conditioned on facilitating the right to object. ANPD has referenced a Guide on Cookies and Data Protection, but dark-pattern-specific prohibitions, opt-out signal recognition (e.g., GPC), clean-room/data-collaboration rules, and direct-marketing-specific suppression regimes were not located in this research pass.
Sources and claims (3)
ProbableEUR-Lex — ANPD has issued a Guide on Cookies and Data Protection, referenced as an official ANPD guidance document in the European Commission's Brazil adequacy assessment.
ConfirmedIAPP — The ANPD ordered Meta to suspend the processing of personal data for AI training, under penalty of a daily fine of BRL 50,000.
ConfirmedIAPP — The Meta suspension order was lifted conditional on compliance with a plan monitored by ANPD, including facilitating the exercise of the right to object.
ADM transparency right is in force but implementation guidance is nascent; the horizontal AI statute remains unconfirmed as fully enacted; state-surveillance carve-outs are statutorily defined but ANPD's practical oversight role there is limited.
Primary frameworkLGPD Art. 20 (ADM); LGPD Art. 4 §3 (state-surveillance carve-out); Brazilian AI Bill (PL 2338/2023, status uncertain)
Traffic-light rationale — AmberADM transparency right is in force but implementation guidance is nascent; the horizontal AI statute remains unconfirmed as fully enacted; state-surveillance carve-outs are statutorily defined but ANPD's practical oversight role there is limited.
Sub-modules (6)
Profiling RestrictionsAmber
The SGD's DPIA guideline recommends impact assessments where processing involves location tracking, behavioral profiling, or automated decision-making with legal effects on a person's personal, professional, consumer or credit profile.
Claims: CLM-BR-bh8l79g1
Automated Decision Making TransparencyAmber
Article 20 of the LGPD guarantees individuals the right to request review of decisions made solely through automated processing of personal data; ANPD's Technical Note 12/2025 (May 2025) summarised public input on AI/ADM to inform future regulation.
Claims: CLM-BR-bh8l79g2
Ai Risk AssessmentsAmber
The Brazilian AI Bill (PL 2338/2023), a risk-based framework drawing on the EU AI Act, passed the Senate in December 2024 and was under Chamber of Deputies discussion; separate sector-specific AI bills (e.g., AI-based domestic-violence-offender monitoring, Bill 750/2026) are also in progress. Final enactment status of PL 2338/2023 could not be confirmed as of this research pass.
Claims: CLM-BR-bh8l79g3, CLM-BR-bh8l79g4
Biometric RegimeAmber
Biometric data is classified as sensitive personal data under Art. 5 II and subject to Art. 11 processing restrictions; age-verification mechanisms under the Digital ECA increasingly rely on soft-biometric signals (e.g., typing patterns, device position), raising fresh biometric-processing questions.
Claims: CLM-BR-bh8l79g5
Genetic DataGreen
Genetic data is expressly listed among sensitive personal data categories under Art. 5 II, subject to the same Art. 11 restrictions as other special categories.
Claims: CLM-BR-bh8l79g6
State Surveillance CarveoutsAmber
The LGPD does not apply to processing for public security, national defense, state security, or investigation/prosecution of criminal offenses, but ANPD retains authority to issue technical opinions, recommendations, and to request a DPIA from controllers even in these carve-out scenarios.
Claims: CLM-BR-bh8l79g7
Category narrative109 words
Article 20 gives data subjects the right to request review of decisions made solely through automated processing; ANPD's Technical Note 12/2025 explores implementation as AI use grows. A dedicated Brazilian AI Bill (PL 2338/2023), risk-based and modeled on the EU AI Act, passed the Senate in December 2024 but its enactment status in the Chamber of Deputies could not be confirmed as final in this research pass. Biometric and genetic data are protected as sensitive categories under Art. 5 II/Art. 11. Public-security, national-defense, state-security and criminal-investigation processing fall outside LGPD's substantive scope, though ANPD retains power to issue technical opinions, recommendations, and request DPIAs even in those carve-out cases.
Sources and claims (7)
ProbableIAPP — The SGD DPIA guideline suggests a DPIA where processing involves tracking data subjects' location, formation of a behavioral profile, or automated decision-making with legal effects on personal, professional, consumer or credit profiles, or involving children and teenagers.
ConfirmedIAPP — Article 20 of the LGPD guarantees individuals the right to request a review of decisions made solely through automated processing of personal data.
UncertainOneTrust DataGuidance — The Brazilian Artificial Intelligence Bill (PL 2338/2023) had its wording approved by the Senate in December 2024 and draws parallels with the EU AI Act's risk-based approach.
ConfirmedIAPP — Bill No. 750/2026, before the Chamber of Deputies, would establish a National Program for Monitoring Aggressors Using Artificial Intelligence, combining electronic monitoring, behavioral analytics and real-time alerts.
ProbableIAPP — Age-verification approaches evolving under Brazil's Digital ECA framework increasingly draw on soft biometrics such as typing patterns and device position to assess probable user age.
ConfirmedIAPP — Genetic and biometric data are expressly included within the LGPD's definition of sensitive personal data under Article 5 II.
ConfirmedIAPP — For public security, national defense, state security, or investigation/prosecution of criminal offenses, the LGPD is not applicable, but ANPD retains the attribution of issuing technical opinions, recommendations and requesting a DPIA from controllers (Art. 4 §3).
Statutory protection is strong and rapidly maturing (Digital ECA now in force), but implementing age-verification technical standards remain under active public consultation as of mid-2026.
Primary frameworkLGPD Art. 14; Digital Child and Adolescent Statute (Law No. 15.211/2025) and Decree No. 12.881/2026
Traffic-light rationale — AmberStatutory protection is strong and rapidly maturing (Digital ECA now in force), but implementing age-verification technical standards remain under active public consultation as of mid-2026.
Sub-modules (5)
Age VerificationAmber
The Digital ECA (Law 15.211/2025), in force since 17 March 2026, requires providers of digital products/services directed at or likely accessed by children/adolescents to implement robust age-verification mechanisms; ANPD's Radar Tecnológico and 2026 public consultations are developing detailed technical guidance.
Article 14 requires specific and highlighted parental/guardian consent as the general rule for processing children's data, with statutory exceptions for contacting parents or protecting the child; ANPD's Statement 1/2023 clarified that other LGPD legal bases can apply provided the best interest of the child prevails.
Claims: CLM-BR-ci9m8ah4, CLM-BR-ci9m8ah5
Minor Profiling BansAmber
The SGD DPIA guideline recommends a DPIA whenever processing involves children and teenagers, reflecting heightened scrutiny of profiling activities affecting minors rather than an outright statutory profiling ban.
Claims: CLM-BR-ci9m8ah6
Education SettingsRed
No education-sector-specific children's-data provision distinct from the general Digital ECA/LGPD children's-data framework was identified in this research pass.
Dependent AdultsRed
No Brazil-specific statutory provisions for dependent/incapacitated adults distinct from general Civil Code representation rules were identified in this research pass.
Category narrative131 words
The LGPD (Art. 14) requires specific/highlighted parental or guardian consent for children's data processing as the general rule, subject to exceptions (contacting parents, protection, one-time non-stored use), while ANPD's Statement 1/2023 clarified that other legal bases may apply provided the child's best interest is observed. This framework has been substantially overlaid by the new Digital Child and Adolescent Statute ('Digital ECA', Law 15.211/2025, in force since March 2026 with Decree 12.881/2026), which mandates robust age verification, content restrictions, parental-supervision tools, and anti-exploitation measures for any digital product/service directed at or accessible to children (under 12) and adolescents (12-18). ANPD is the enforcing authority for the Digital ECA and has been running public consultations (its 2025-26 Regulatory Agenda, Radar Tecnológico #5, and a May 2026 call for contributions) on age-verification mechanism guidance.
Sources and claims (6)
ConfirmedIAPP — Law No. 15.211/2025, the Digital Child and Adolescent Statute ('Digital ECA'), establishes a substantive framework for protecting children and adolescents in digital environments, with Decree No. 12.881/2026 operationalising preventive measures, risk management and accountability requirements.
ConfirmedIAPP — The Digital ECA applies to any product, service, or platform directed to, or likely to be accessed by, children (under 12) and adolescents (12-18) in Brazil.
ConfirmedIAPP — ANPD's Radar Tecnológico #5 and a May 2026 call for contributions are developing an Age Verification Mechanisms Guide to implement the Digital ECA, updating preliminary guidelines first published in March 2026.
ConfirmedDataGuidance — Children's personal data may only be processed with specific and highlighted consent from a parent or legal representative, except where collection is necessary to contact the parents/representative, is used a single time without storage, or is for the child's protection.
ConfirmedIAPP — ANPD's Statement No. 1/2023 clarified that processing of children's data may rely on any legal basis under the LGPD, provided the best interests of the child prevail in the specific case, moving away from consent as the sole compliance anchor.
ProbableIAPP — The SGD's DPIA guideline recommends a data protection impact assessment whenever processing involves children and teenagers.
Statutory penalty and powers framework is robust and has just been substantially strengthened, but actual enforcement volume remains modest and concentrated in the public sector, and ANPD's historic capacity constraints are only now being addressed.
Primary frameworkLGPD Arts. 52, 55-A to 55-L; Provisional Measure No. 1.317/2025; ANPD Dosimetry Regulation (Resolution of 27 Feb. 2023)
Traffic-light rationale — AmberStatutory penalty and powers framework is robust and has just been substantially strengthened, but actual enforcement volume remains modest and concentrated in the public sector, and ANPD's historic capacity constraints are only now being addressed.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
ANPD has sole responsibility for LGPD sanctions (Art. 55-K), which include warnings, fines up to 2% of Brazilian revenue capped at BRL 50 million per infraction, daily fines, publicization, data blocking/deletion, and processing/database suspension up to 12 months; the 2025 reform added cease-operation, seizure and police-assistance powers.
Claims: CLM-BR-dj0n9bi1, CLM-BR-dj0n9bi2
Enforcement Activity IndexAmber
Of ANPD's seven to eight published sanctioning decisions, most target the public sector; five concerned Article 48 breach-notification violations and three concerned Article 49 security violations, alongside the Meta AI-training suspension order (BRL 50,000 daily fine).
Claims: CLM-BR-dj0n9bi3, CLM-BR-dj0n9bi4
Regulator Funding And CapacityAmber
ANPD historically operated with a small technical and administrative staff limiting its scope of action; the September 2025 transformation into an autonomous agency (with tenured technical staff positions) is expected to substantially increase structural and budgetary capacity.
Claims: CLM-BR-dj0n9bi5, CLM-BR-dj0n9bi6
Collective Redress And Class ActionsGreen
Individual and class suits are possible independent of ANPD's administrative process, and fines collected by ANPD are allocated to Diffuse Rights Defense Funds.
Claims: CLM-BR-dj0n9bi7
Private Right Of ActionGreen
Brazil's Constitution gives all citizens both a private right of action and a public right of action via the Public Prosecutors' Office, enabling enforcement by individuals, consumer-protection organisations, and prosecutors independent of ANPD sanctions.
Claims: CLM-BR-dj0n9bi8
Recent Developments 180DGreen
Within the last 180 days (Feb.-Aug. 2026): the EU-Brazil mutual adequacy regime took effect (EU Implementing Decision 2026/179 and ANPD Resolution 32/2026, Jan. 2026); the Digital ECA Decree 12.881/2026 operationalised the Digital ECA which took force 17 March 2026; and ANPD opened a May 2026 public consultation to update its Age Verification Mechanisms Guide.
ANPD has sole administrative sanctioning authority under Article 55-K, with penalties (Art. 52) ranging from warnings to fines of up to 2% of Brazil-derived revenue (capped at BRL 50 million per infraction), daily fines, public disclosure, data blocking/deletion, and processing/database suspension of up to twelve months. The September 2025 transformation into an autonomous agency added cease-operation, seizure, and police-assistance powers. To date, ANPD's sanctioning track record (seven to eight published decisions) skews heavily toward public-sector entities, mostly for Article 48 (breach notification) and Article 49 (security) violations, alongside the high-profile Meta AI-training suspension order. Independent of ANPD, individuals, public prosecutors, and consumer-protection bodies retain constitutional rights of private and collective action.
Sources and claims (11)
ConfirmedIAPP — ANPD has sole responsibility for applying LGPD sanctions (Art. 55-K), including fines of up to 2% of a company's Brazil-derived revenue for the prior fiscal year, excluding taxes, capped at BRL 50 million per infraction, plus daily fines subject to the same cap.
ConfirmedIAPP — Provisional Measure 1.317/2025 makes clear that ANPD can now order establishments to cease operations, seize goods, and request police assistance in cases of obstruction of its functions.
ConfirmedIAPP — Of ANPD's seven sanctioning decisions published to date, most target the public sector, with five dealing with Article 48 breach-communication violations.
ConfirmedIAPP — Among ANPD's first eight sanctioning procedures, seven were issued against public entities.
ConfirmedIAPP — ANPD's actions in relation to public entities have historically been predominantly pedagogical and limited in scope, aggravated by the authority's small technical and administrative staff.
ProbableIAPP — ANPD's transformation into a regulatory agency is expected to bring greater structural and budgetary robustness, with increased staff and technical resources and enhanced operational independence.
ConfirmedIAPP — The sum of fines collected by ANPD is allocated to the Diffuse Rights Defense Funds referred to in Law No. 7.347/1985 and Law No. 9.008/1995.
ConfirmedIAPP — Brazil's Constitution gives all citizens a private right of action and a public right of action to the Brazil Public Prosecutors' Office, enabling individual and class suits regardless of ANPD's administrative sanction status.
ConfirmedIAPP — In January 2026, the European Commission recognized that Brazil ensures an adequate level of protection for personal data transferred from the EU under the GDPR.
ConfirmedIAPP — Brazil's Digital ECA (Law 15.211/2025) took effect 17 March 2026, alongside Decree 12.881/2026 operationalizing its preventive-measures and accountability requirements, with ANPD empowered as enforcer.
ConfirmedIAPP — On 22 May 2026, ANPD opened a call for contributions on its Age Verification Mechanisms Guide, updating preliminary guidelines published in March 2026 to implement the Digital ECA.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Brazil
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 64 claim(s), 32 source(s) in the cumulative register.