Loading
Please wait...
Please wait...
Brazil’s General Data Protection Law: Privacy for personal data.
Enforced
18 September 2020
Admin sanctions since 1 Aug 2021
Who this affects
Organisations processing personal data in Brazil
Also those offering goods/services to people in Brazil or collecting data in Brazil - regardless of location.
Penalty ceiling
Up to 2% of Brazilian revenue
Capped at R$50M per infraction
Adopt and maintain technical and organisational measures proportionate to your risks to protect personal data in daily operations (Art. 46).
Maintain a formal register of processing operations - purpose, data categories, recipients, retention, and safeguards - available to the ANPD upon request (Art. 37).
Produce a RIPD for high-risk processing when required by the ANPD or per guidance (e.g., legitimate-interest scenarios), documenting risks and mitigations (Arts. 10 §3, 38).
Define controller instructions, use compliant contracts, and oversee operators and sub-operators to ensure adherence (Art. 39).
Designate a DPO (unless exempted by ANPD rules), provide a public contact channel, and handle rights requests within LGPD timelines (Art. 41; Art. 18).
Process only what is necessary for specific, legitimate purposes; embed minimisation into systems and workflows (Art. 6, items I & III).
Programmes are tailored end-to-end and may depend on earlier phases (e.g., deletion protocols require prior identification of personal-data flows and systems).
We act as your DPO: advise management, monitor compliance, train staff, oversee RIPDs, liaise with the ANPD, and report risks with practical remediation paths.
Be contract-ready for Brazilian customers: lawful bases, privacy notices, transfer mechanisms, operator clauses, and evidence packs that pass procurement and due diligence.
We establish your register of processing operations - what you process, why, with whom, where, retention, and safeguards - and set a lightweight routine to keep it current.
A thorough, personalised RIPD for high-risk processing: scope, stakeholder interviews, risk analysis tailored to your systems and business model, mitigation design, and sign-off documentation.
Design and embed a 72-hour response playbook with roles, decision trees, and notification templates (ANPD and data subjects). We train teams and set up the evidence you’ll need if an incident occurs.
Define lawful retention by data category, implement deletion routines in systems, and set up audit logs to prove execution.
Practical onboarding and periodic review of operators: requirement baselines, contractual clauses, transfer mechanisms, and an oversight cadence that fits your supplier portfolio.
Align AI features and workflows with LGPD: controller/operator role mapping, legal bases, transparency to users, records updates, RIPD triggers, and acceptable-use guidance for teams.
Active enforcement
The ANPD is issuing guidance, opening procedures, and can impose fines, public notices, and processing restrictions.
Pre-launch duties
High-risk processing may require a RIPD and controls before go-live. Planning these steps avoids delays and non-compliance.
Transfers scrutiny
International transfers require valid mechanisms (adequacy, clauses, or seals). Clients increasingly ask for proof during due diligence.
Focused discovery across product features, data flows, and vendors to baseline actual practice.
Co-create bespoke controls and workflows (minimisation, RIPD cadence, operator intake, breach playbooks) aligned to your reality.
Embed changes with your teams and produce evidence packs that stand up in audits and client reviews.
Quarterly tune-ups: records updates, transfer reassessments, spot checks, and change logs that prove control over time.
Share one RIPD, incident, transfer or operator question. We will show how Governance School would turn it into a practical decision record before you consider a wider engagement.
Bring one privacy case