Everything you need to know about LGPD compliance, data security requirements, and secure data disposal.
Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD), or General Personal Data Protection Law, is South America's most comprehensive data protection framework and a law explicitly modeled on the EU's GDPR. Enacted in 2018 and fully effective since 2020, LGPD applies to virtually any organization that processes the personal data of individuals in Brazil.
Background
LGPD was signed into law in August 2018, following years of fragmented sector-specific data protection rules in Brazil. It took effect in September 2020, with sanctions provisions becoming enforceable in August 2021. The law established the Autoridade Nacional de Proteção de Dados (ANPD) — Brazil's National Data Protection Authority — as the body responsible for enforcement, guidance, and regulation.
Who Must Comply
LGPD applies broadly to any natural person or legal entity, public or private, that processes personal data where:
- The processing operation is carried out in Brazil, or
- The purpose of the processing activity is to offer or supply goods or services to individuals located in Brazil, or
- The personal data being processed was collected in Brazil
This means foreign companies with no physical presence in Brazil can still be subject to LGPD if they target Brazilian consumers or process data collected within the country.
Legal Bases for Processing
LGPD sets out ten legal bases for lawful processing, echoing GDPR's approach but tailored to Brazilian legal tradition. These include consent, compliance with a legal or regulatory obligation, execution of a contract, legitimate interests of the controller, protection of credit, and processing necessary for the regular exercise of rights in judicial, administrative, or arbitration proceedings.
Sensitive Personal Data
LGPD defines sensitive personal data to include racial or ethnic origin, religious belief, political opinion, trade union membership, data related to health or sex life, and genetic or biometric data. Processing this category generally requires specific consent or reliance on one of a narrower set of legal bases than for ordinary personal data.
Individual Rights
LGPD grants Brazilian data subjects rights including:
- Confirmation of the existence of processing
- Access to their data
- Correction of incomplete, inaccurate, or outdated data
- Anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in non-compliance with the law
- Data portability to another service or product provider
- Deletion of personal data processed with consent, upon request
- Information about public and private entities with which the controller has shared data
- The right to revoke consent
Data Protection Officer Requirement
LGPD requires controllers to appoint a Data Protection Officer (Encarregado), responsible for accepting complaints from data subjects, communicating with the ANPD, and orienting employees and contractors on data protection practices — a requirement that applies more broadly than GDPR's, which limits mandatory DPO appointment to specific circumstances.
Enforcement and Penalties
The ANPD enforces LGPD and can impose penalties including warnings, public disclosure of violations, blocking or deletion of the personal data involved in the infringement, and fines of up to 2% of the company's, group's, or conglomerate's revenue in Brazil in its prior fiscal year, limited to R$50 million per infraction. While lower in absolute terms than GDPR's maximum fines, penalties can still be substantial for large organizations, and the ANPD has continued to increase its enforcement activity since gaining full sanctioning authority.
Secure Data Disposal Under LGPD
LGPD explicitly recognizes the right to deletion and requires that personal data be eliminated once the purpose of processing has been achieved, once the data is no longer necessary or relevant, or upon a valid request from the data subject — except where retention is required for legal or regulatory compliance. As with other GDPR-inspired laws, this obligation extends beyond databases to any physical media storing the data. Organizations retiring computers, servers, or mobile devices that processed personal data governed by LGPD should use compliant, standards-based erasure methods and retain documented proof of destruction, since the ANPD's enforcement approach increasingly expects organizations to demonstrate — not just assert — that data has been properly eliminated.
Official Regulatory Reference
For the most accurate, authentic, and up-to-date legal text, we highly recommend consulting the official legislative documentation provided by the respective regional government or data protection authority. Relying on the official source of truth is the best way to ensure full compliance.
Streamlining Compliance with D-Secure Solutions
Meeting strict data sanitization requirements doesn't have to be a manual, error-prone process. Our enterprise data sanitization solutions are purpose-built to help organizations seamlessly meet these strict regulatory mandates.
By utilizing D-Secure Drive Eraser, your organization can permanently wipe sensitive data and automatically generate tamper-evident erasure certificates. This creates a rigorous, verifiable audit trail that satisfies regulatory bodies and eliminates the risk of data leaks.
Conclusion
LGPD brought Brazil in line with the global shift toward comprehensive data protection regulation, giving Brazilian residents meaningful rights and giving the ANPD real enforcement authority. For organizations doing business with or in Brazil, compliance requires the same rigor around consent, data subject rights, and verifiable data disposal that GDPR compliance demands.
No comments yet. Be the first to comment.