TerraLex Guide to Data Protection

Welcome to the Terralex cross-border guide to data protection

Data protection continues to be a top issue for companies around the globe. With the ever-changing technology and responding legislation, it is important that businesses be prepared to handle a patchwork of data protection regulations. This guide, prepared by TerraLex members from around the globe, provides initial guidance on some of the key aspects to consider.

How to Use: You can use the tools below to create bespoke reports for the jurisdiction(s) and topic(s) covered. Click into single jurisdiction for one location or use the compare tool to compare multiple jurisdictions. Select the jurisdictions and topics of interest to create your unique report. You also have the option to print or download using the ellipsis button in the top right corner.

Brazil TerraLex Guide to Data Protection Guide

Date posted:
12/04/2021
Last update:
24/02/2025

Legislation and regulations

What national laws regulate the processing of personal data in your jurisdiction?

Brazilian Federal Constitution and Brazilian Civil Code protect privacy as a general principle although they do not contain more specific provisions detailing, for instance, possible situations in which personal data may be used without infringing privacy or conditions to obtain a valid consent to collect and how to process personal data.

The Brazilian Data Protection Law (Law Nº 13,709/2018 known as "LGPD"), enacted in 2018 and effective in September 2020, establishes that personal data must be used only for the specific purposes for which it was collected, and that processing of personal data must be limited to the period necessary to achieve such specific purposes. In addition, LGPD determines (i) that the collection and treatment would be conditioned upon the prior and express consent of the data owners in some cases and that such consent may be revoked at any time; and (ii) establishes specific conditions for international transfer of personal data.

There are also some sectorial laws that contain privacy protection provisions such as:

  • Consumer Code (Law Nº 8,078/1990) establishes rules for the protection and defense of consumer, public order, and social interest.
  • Banking Secrecy Act (Complementary Law Nº 105/2001) provides for the secrecy of the operations of financial institutions.
  • Internet Act (Law Nº 12,965/2014 known as "MCI"), recognized that the fundamental rights to privacy and intimacy protection granted by the Brazilian Federal Constitution must also be applied to activities over the Internet. It expressly establishes, as a general principle and as a specific guaranty for Internet users, the protection of personal data.
  • Information Access Act (Law Nº 12,527/2011) governs the processing of data by public administration and how individuals can obtain access to such data.

To whom do the laws apply?

LGPD applies to any processing operation of personal data carried out by a natural person or by a legal entity under public or private law, regardless of the media, the country of the company’s headquarters or the country where the data is located, provided that: "(i) the processing operation is carried out within the national territory; (ii) the purpose of the processing activity is the offer or the supply of goods or services or the processing of data of individuals located in the national territory; or (iii) the personal data to be processed has been collected in the national territory."

However, according to Resolution No. 2/2022, published by the National Data Protection Authority ("ANPD") on January 2, 2022 ("Resolution No. 2/2022"), small-sized processing agents are exempted from certain obligations determined by LGPD, such as appointing a DPO.

The Federal Constitution and Civil Code apply to all Brazilian individuals and entities, as well as foreigners living in Brazil.

The MCI sets forth that all transactions involving the capture, storage or processing of data that occur within the Brazilian territory or in which one of the terminals is in the Brazilian territory will be subject to the Brazilian laws and regulations regarding privacy and personal data protection. These provisions shall apply even if the activities are performed by companies headquartered outside the Brazilian territory, provided that (i) the companies offer services to the Brazilian public; or (ii) at least one company of the same economic group is established in Brazil.

The Consumer Code applies to consumer relationships and their subjects.

The Banking Secrecy Act applies to financial institutions that operate and provide services in Brazil.

The Information Access Act applies to public administration, as well as to private entities or individuals who have access to confidential or personal information concerning public administration.

Scope of protection

What type of data is covered by the law?

LGPD covers all "Personal Data" which shall be construed as any information related to an identified or identifiable individual, including identification numbers, location data, electronic identifiers, and all sensitive personal data. "Sensitive Personal Data" shall be understood as any personal data that disclose the person's racial or ethnic origin, religious, philosophical, or moral beliefs, political views, affiliation to trade unions or religious, philosophical, or political organizations, data pertaining to the person's health or sexual life, as well as genetic data.

What are the main exemptions (if any)?

LGPD shall not apply to the processing of personal data:

a) carried out by a natural person exclusively for private and non-economic purposes; b) carried out exclusively for: journalistic and artistic purpose or academic purposes; c) carried out for the sole purpose of: public or State security, national defense or investigation and prosecution of criminal offenses' activities; or from outside the national territory and which are not the communication' subject, shared use of data within Brazilian processing agents or international data transfer' subject with a country other than the country of origin, provided that the country of origin grants a degree of protection of personal data consistent with the provisions of the LGPD.

Also, according to Resolution No. 2/2022, small-sized processing agents are exempted from certain obligations determined by LGPD.

What rights do the laws grant to the data owners?

Under LGPD, when the processing of personal data is a condition for the provision of a service, the data owner shall be prominently informed about it and about the means by which he/she may exercise his/her rights, such as: (i) confirmation of the existence of processing; (ii) access to data; (iii) correction of incomplete, inaccurate or outdated data; (iv) anonymization, blocking or elimination of unnecessary, excessive or processed data in disagreement with the provisions of LGPD; (v) portability of the data to another service or product supplier, upon express request, in accordance with the regulation of the national authority, and observing the commercial and industrial secrecy; (vi) deletion of personal data processed with the consent of the data owner, except in some cases provide for in the LGPD; (vii) information of the public and private entities with which the controller performed shared use of data; (viii) information on the possibility of not providing consent and on the consequences of refusal; (ix) revocation of consent, pursuant to LGPD.

The Federal Constitution grants the fundamental rights on privacy and intimacy and guarantees individuals the right to be indemnified in case of infringement of such fundamental rights. Based on such principles, individuals are entitled to adopt judicial measures to protect their personal data and to claim compensation for material and moral damages which may be caused by violation of privacy and intimacy. In addition to the Brazilian Federal Constitution, the Brazilian Civil Code also establishes the inviolability of individuals' privacy and allows them to seek judicial remedies.

Under MCI, the following rights are guaranteed to users: (i) inviolability of intimacy and private life, its protection and indemnity for material or moral damage resulting from its violation; (ii) inviolability and confidentiality of the flow of your communications over the internet, except by court order, as provided by law; (iii) inviolability and confidentiality of your stored private communications, except by court order; (iv) non-suspension of the internet connection, except by direct debit resulting from its use; (v) maintaining the contracted quality of the internet connection; (vi) clear and complete information contained in the service provision contracts, with details on the protection regime for connection records and access records to internet applications, as well as on network management practices that may affect their quality; (vii) failure to provide third parties with your personal data, including connection records, and access to internet applications, except with free, express and informed consent or in the cases provided for by law; (viii) clear and complete information about the collection, use, storage, treatment and protection of your personal data, which can only be used for purposes that: justify their collection; are not prohibited by law; and are specified in the service provision contracts or in terms of using internet applications; (ix) express consent on the collection, use, storage and treatment of personal data, which must occur in a detached manner from the other contractual clauses; (x) definitive exclusion of personal data that you have provided to a particular internet application, at your request, at the end of the relationship between the parties, except for the cases of mandatory record keeping provided for in the MCI; (xi) publicity and clarity of any policies for the use of internet connection providers and internet applications; (xii) accessibility, considering the physical-motor, perceptual, sensory, intellectual and mental characteristics of the user, under the terms of the law; and (xiii) application of consumer protection and defense rules in consumer relations carried out on the internet.

The Consumer Code establishes that consumers shall be notified in writing about their inclusion in a consumer registry or database. They shall also have access to the information existing in registrations, records, records, and personal and consumer data filed about it, as well as about their respective sources and are entitled to access, correct, update or exclude their personal data available in any consumer registry or database.

The Banking Secrecy Act and the Information Access Act guarantee the right to inviolability of information about banking activities and personal and confidential information concerning the public administration, except upon a court decision and only for crime investigations.

Processing requirement and main obligations

What are the lawful grounds for processing personal data or sensitive personal data (if different)?

LGPD set forth the following lawful grounds for processing personal data: (i) upon data owner’s consent; (ii) for compliance of legal or regulatory obligation; (iii) by the public administration, for the processing and shared use of data necessary for public policies compliance, provided for in laws and regulations or supported by contracts, agreements or similar instruments, subject to the provisions of the LGPD; (iv) to carry out studies by a research body, assured, whenever possible, the anonymization of personal data; (v) when necessary for the performance of a contract or preliminary procedures related to a contract to which the data owner is a party, at the request of the data owner; (vi) for the regular exercise of rights in judicial, administrative or arbitration proceedings; (vii) for the protection of the life or physical safety of the data owner or third party; (viii) for the protection of health, exclusively, in a procedure carried out by health professionals or sanitary authority; (iv) when necessary to assure the legitimate interests of the controller or third party, except in the case of the data owner's fundamental rights and freedoms that require the protection of personal data; or (x) for the protection of credit, including as provided in the pertinent legislation.

Regarding sensitive personal data, lawful grounds shall be: (i) when the data owner or the owner legal representative grants specific and highlighted consent, for specific purposes; or (ii) without the consent of the data owner, in cases in which it is necessary for: a) compliance with legal or regulatory obligation by the controller; b) necessary shared data processing for public policies provided for in laws or regulations; c) conducting studies by a research body, guaranteed, whenever possible, the anonymization of sensitive personal data; d) regular exercise of rights, including in contract and in judicial, administrative and arbitration proceedings; e) protection of the life or physical safety of the data owner or third party; f) health protection, in a procedure carried out by health professionals or by health entities; or g) guarantee of fraud prevention and security of the data owner, in the processes of identification and authentication of registration in electronic systems, safeguarding the rights mentioned in art. 9º of this Law and save in case of the fundamental rights and freedoms of the data owner that require the protection of personal data.

What are the main obligations imposed by the law?

LGPD set forth that personal data processing activity shall observe the good faith and the following principles: (i) purpose: to carry out the data processing for legitimate, specific, explicit and informed purposes to the data owner, without possibility of further processing in a way incompatible with such purposes; (ii) adequacy: compatibility of the processing with the purposes informed to the data owner, according to the processing context; (iii) necessity: processing limited to the minimum necessary for fulfill its purposes, including the relevant, proportional and non-excessive data in relation to the purposes of data processing; (iv) free access: guarantee to the data owners of free and easy consultation on the form and duration of the processing, as well as on the integrity of their personal data; (v) data quality: guarantee to the data owners, of accuracy, clarity, relevance and updating of the data, according to the necessity and to the fulfill the purpose of its processing; (vi) transparency: guaranteeing the data owners of clear, precise and easily accessible information on the conduct of the processing and the respective processing agents, subject to commercial and industrial secrecy; (vii) security: use of technical and administrative measures able to protect personal data from unauthorized access and from accidental or unlawful situations of destruction, loss, alteration, communication or diffusion; (viii) prevention: adoption of measures to prevent damages from the processing of personal data; (ix) nondiscrimination: impossibility of carrying out processing for unlawful or abusive discriminatory purposes; (x) accountability and liability: evidence by agent of adoption of effective measures to observe and comply with the rules for the protection of personal data, including the effectiveness of such measures.

Under MCI, in any operation for the collection, storage and processing of records, personal data or communications by connection providers and internet applications in which at least one of these acts occurs in national territory, Brazilian law and rights to privacy, protection of personal data and confidentiality of private communications and records. It applies to data collected in the national territory and the content of communications, provided that at least one of the terminals is in Brazil and even if the activities are performed by companies headquartered abroad, if it offers services to the Brazilian public or at least one member of the same economic group has an establishment in Brazil. There is also the obligation for connection providers to store and keep confidential all connection logs for a period of 12 months and for service providers to store and keep confidential the records of applications usage for the period of 6 months. In both cases, disclosure of such information shall be obtained only with Court order. Connection suppliers are not allowed to keep or store records of applications usage and service providers may not keep records of usage of any third-party application without user's prior consent.

The Consumer Code establishes that consumer records and data must be objective, clear, true and in easy-to-understand language, and must not contain negative information for a period exceeding 5 years. In addition, consumers must be communicated in writing about their inclusion in a consumer registry or database, when not requested by him.

Do the laws establish a data retention period to be observed?

LGPD does not establish a specific period, but provides that the end of the processing of personal data will occur in the following cases: (i) verification that the purpose has been achieved or that the data are no longer necessary or relevant to the achievement of the specific purpose sought; (ii) end of the processing period; (iii) communication from the holder, including in the exercise of his right to revoke the consent as provided for in the LGPD, safeguarding the public interest; or (iv) determination of the national authority, when there is a violation of the provisions of the LGPD. In this sense, LGPD establishes that personal data will be deleted after the end of its processing, within the scope and technical limits of the activities, but conservation is authorized for the following purposes: (i) compliance with legal or regulatory obligations by the controller; (ii) study by a research body, guaranteeing, whenever possible, the anonymization of personal data; (iii) transfer to a third party, provided that the data processing requirements provided for in the LGPD are respected; or (iv) exclusive use of the controller, access by a third party is prohibited, and provided the data is anonymized.

Regarding MCI and Consumer Code, please refer to the answer to the related question above.

Must the data processing activities be recorded under the law?

LGPD provides that the controller and the operator must keep a record of the personal data processing operations that they carry out, especially when based on legitimate interest.

Regarding MCI, please refer to the answer to the related question above.

National authority and DPO

Is there a Data Protection National Authority? If so, what is the National Authority main role?

LGPD created the National Data Protection Authority (ANPD), an entity of the federal public administration. It main role are (i) ensure the protection of personal data; (ii) develop guidelines for the National Policy for the Protection of Personal Data and Privacy; (iii) supervise and apply sanctions in case of data processing carried out in breach of legislation, through an administrative process; (iv) edit regulations and procedures on the protection of personal data and privacy, as well as on reports on the impact of the protection of personal data in cases where the treatment represents a high risk to guarantee the general principles of protection of personal data provided for in the LGPD.

Does the law impose the obligation of designating a data protection officer (DPO)? If so, what is the role of the DPO under the law?

LGPD determines that the DPO must be indicated by the controller of the personal data processing activity, except if the controller is characterized as a small sized processing agent, which according to Resolution No. 2/2022, is exempted from this obligation. The DPO, which acts as a communication channel between the controller, the data owners, and the National Data Protection Authority (ANPD), has among its attributions: (i) to accept complaints and communications from the data owners; (ii) receiving communication from the ANPD and adopting suitable measures; and (iii) advise the entity's employees on appropriate practices in relation to the protection of personal.

Cross-border transfers

What rules regulate the transfer of data outside your jurisdiction?

LGPD defines "international data transfer" as "transfer of personal data to a foreign country or to an international entity of which the country is a member" and establishes that international transfer of personal data is only allowed in specific conditions among which "when the data owner has given his specific and highlighted consent to the transfer, with prior information on the international character of the operation, clearly distinguishing this from other purposes". Furthermore, on August 23, 2024, the ANPD published Resolution No. 19/2024, which approved the Regulations on International Data Transfers Regulations and the content of standard contractual clauses, in accordance with the LGPD.

Is it necessary to notify the National Authority prior to the international transfer?

No, LGPD does not establish such obligation. However, the international transfer of personal data is only allowed in the following cases: (i) to countries or international organizations that provide a degree of protection of personal data adequate to that provided for in the LGPD; (ii) when the controller offers and proves guarantees of compliance with the principles, the rights of the holder and the data protection regime provided for in this Law, in the form of: a) specific contractual clauses for a given transfer; b) standard contractual clauses; c) global corporate standards; d) stamps, certificates and codes of conduct regularly issued; (iii) when the transfer is necessary for international legal cooperation between public intelligence, investigation and prosecution bodies, in accordance with the instruments of international law; (iv) when the transfer is necessary to protect the life or physical safety of the holder or third party; (v) when the national authority authorizes the transfer; (vi) when the transfer results in a commitment made in an international cooperation agreement; (vii) when the transfer is necessary for the execution of public policy or legal attribution of the public service, publicity being given under the terms of the LGPD; (viii) when the holder has provided his specific and highlighted consent for the transfer, with prior information on the international character of the transaction, clearly distinguishing it from other purposes; or (ix) when necessary to meet the hypotheses provided for in the LGPD.

Security standards, data breaches, and sanctions

Do the laws impose any information security standards and/or requirements?

LGPD establishes that processing agents shall adopt technical and administrative security measures to protect personal data from unauthorized access and from accidental or unlawful situations of destruction, loss, alteration, communication, or any form of inappropriate or illicit processing. In 2021, the ANPD published information security guidelines for small-sized processing agents.

The MCI obligates the internet service provider to storage access and connection data, by adopting security and secrecy measures on the data storage. It was regulated by Decree Nº 8,771/2016 which establishes the minimum security and secrecy measures, which are (i) strict control over data access, (ii) authentication measures to access the data, (iii) detailed information on the access to the data; and (iv) use of cryptography measures or similar protection measures.

Do the laws establish any kind of mandatory notification duty?

Under LGPD, the controller shall communicate to the ANPD and to the data owners the occurrence of a security incident that may entail significant risk or damage to the data owners. Such communication shall be made following timeframes, requirements, and criteria established in Resolution No. 15/2024, published by ANPD on April 24, 2024.

Regarding the Consumer Code, please refer to the answer to the related question above.

What are the sanctions for noncompliance with data protection laws?

Data processing agents will be subject to the following administrative sanctions applicable by the ANPD, due to the infractions committed to the provisions established in the LGPD: (i) warning, indicating deadline for corrective measures; (ii) simple fine, up to 2% (two percent) of the private law legal entity, group or conglomerate revenue in Brazil in its last fiscal year, excluding taxes, limited, in total, to R$ 50,000,000.00 (fifty million reais) for infraction; (iii) daily fine, observing the total limit referred to in item ii above; (iv) publication of the infraction after duly verified and confirmed its occurrence; (v) blocking of the personal data to which the infraction relates until its regularization; (vi) deletion of the personal data to which the infraction refers to; (vii) partial suspension of the operation of the database to which the infringement refers for a maximum period of six (6) months, extendable for an equal period, until the controller regulates the processing activity; (viii) suspension of the exercise of the activity of processing personal data to which the infringement refers for a maximum period of 6 (six) months, extendable for the same period; (ix) partial or total prohibition of the exercise of activities related to data processing.

The MCI establishes the following sanctions for improper processing of personal data: (i) warning; (ii) a fine of up to 10% (ten percent) of the economic group's revenue in Brazil in its last year, excluding taxes; and (iii) temporary suspension or prohibition of activities that include data processing.

The Consumer Code also imposes penalties ranging from fines to the withdrawal of the establishment's or activity's license.

Breach of confidentiality provided for in the Banking Secrecy Act, outside of the authorized hypotheses, constitutes a crime and subjects those responsible to imprisonment, from one to four years, and a fine, applying, as appropriate, the Penal Code, without prejudice to other applicable sanctions.

The individual or private entity that holds information due to any link with the public authorities and fails to observe the provisions of the Information Access Act will be subject to the following sanctions: (i) warning; (ii) fine; (iii) termination of the bond with the government; (iv) temporary suspension from participating in bidding and impediment to contract with the public administration for a period not exceeding 2 (two) years; and (v) declaration of unfitness to bid or contract with the public administration, until rehabilitation is promoted before the authority that applied the penalty.

Other comments

Other comments

Despite sparse mentions in some laws and regulations, it is undeniable that Brazilian legal system lacked adequate regulation of personal data. In this sense, the enactment of the LGPD can be considered a real breakthrough, which places Brazil among the countries that really care about data protection.

Other advances that deserve mention is the recognition of the protection of personal data as an autonomous fundamental right by the Supreme Federal Court (Direct Unconstitutionality Action - ADIN 6347) and the publication of guidelines and resolutions by ANPD.

Disclaimer: This guide contains summaries of general principles of law. It is not a substitute for specific legal advice and should not be relied upon in relation to the application of the law or subject matter covered.