LGPD · Data Privacy & Law
LGPD in 2026: ANPD, lawful bases, and why a GDPR clone is not Brazilian compliance
How companies with Brazilian users operationalize LGPD — agents, rights, incidents, and ANPD expectations versus GDPR muscle memory.
6 min read
Brazil's LGPD is a modern privacy law with familiar concepts: lawful bases, controller and operator roles, data subject rights, security, incident response, and regulator oversight by the ANPD. Familiarity, however, is where many programs become careless.
A GDPR program can accelerate LGPD readiness, but it should not be copied without localization. Portuguese notices, Brazilian role terminology, ANPD expectations, lawful-basis differences, incident handling, and the encarregado role all need deliberate treatment.
The paired checklist helps execute the program. This guide helps teams make the harder decisions about localization, governance, and evidence so Brazilian privacy is not reduced to an English notice with a translated footer.
What LGPD actually is
LGPD is Brazil's general data protection law. It applies to many organizations that process personal data in Brazil, offer goods or services to people in Brazil, or process data collected in Brazil. It defines controller and operator roles, provides data subject rights, sets lawful bases, and expects security and incident accountability.
The law has its own vocabulary and regulatory ecosystem. The encarregado is often compared to a DPO, but the role should be designed for Brazilian operations and communication with the ANPD and data subjects. ANPD guidance and sector-specific obligations can shape how the general law is applied.
LGPD readiness should also account for how Brazilian users interact with the business. Support channels, HR workflows, ecommerce journeys, payment providers, marketing campaigns, and local partners may all create evidence outside the global privacy repository. If those front-line teams cannot route requests or incidents, the central privacy policy will not help much. The program should therefore translate accountability into scripts, inbox routing, ticket fields, and ownership that local teams can use during ordinary customer operations.
Decisions the checklist will not make for you
The checklist cannot choose the lawful basis for each processing activity. LGPD bases resemble GDPR in some areas but are not identical in wording, practice, or risk. Teams need to decide and document the Brazilian basis rather than importing an EU label automatically.
It also cannot decide how local the program must be. A company with Brazilian customers, employees, support teams, and vendors needs practical Portuguese workflows, contact routes, and incident procedures. A company with a narrow exposure may need a lighter but still accurate localization.
The checklist will not appoint an effective encarregado. Leadership must decide who owns the function, how reachable they are, how requests are routed, and how they coordinate with global privacy, security, and legal teams.
Where teams actually fail
English-only notices are a visible failure. Brazilian users need clear information they can understand, including rights, controller identity, purposes, sharing, retention, and contact channels. A privacy program that depends on English legal text creates both user friction and regulatory exposure.
Another failure is leaving the encarregado undefined or purely symbolic. If requests, complaints, or ANPD communications arrive, the organization needs a person or function that can respond with authority. A buried privacy inbox managed from another region may not be enough operationally.
Teams also import GDPR lawful bases that do not map cleanly, ignore ANPD incident communication, or assume EU breach playbooks cover Brazil. Incident analysis must address whether communication to the ANPD and affected data subjects is required, what facts are available, and who approves the Brazilian response.
Rights operations often reveal the gap. A Brazilian user asks for confirmation, access, deletion, or information about sharing, and the workflow routes through an EU DSAR template that uses different language, deadlines, and legal assumptions. The user experiences delay, while the business loses the chance to show local accountability.
How to use the paired checklist
Begin by mapping Brazilian data subjects, systems, vendors, purposes, and data flows. Then use the checklist to test whether each processing activity has an LGPD-specific lawful basis, notice language, rights route, retention rule, and accountable owner.
Review the checklist with local counsel or privacy expertise where the exposure is meaningful. The goal is not to rebuild the global program from scratch, but to localize the parts that Brazilian users, regulators, and business partners will actually see.
After implementation, connect the checklist to operations. Rights requests, marketing consent, HR processing, vendor onboarding, and security incidents should all route through workflows that recognize Brazil as its own jurisdiction, not a footnote under EU privacy. Track request outcomes and incident decisions so the ANPD file shows actual performance, not just policy intent, and review those records for recurring process gaps.
What teams get wrong
- LGPD is basically GDPR, so our EU program is enough.
- The laws are related in structure but differ in terminology, bases, regulator practice, incident handling, and localization needs. GDPR materials should be adapted through an LGPD lens rather than translated mechanically.
- Brazilian users can use the English privacy notice.
- Notices and rights routes should be understandable and practical for the audience, which often means Portuguese content and local contact clarity. The test is whether Brazilian users can exercise rights without decoding a foreign privacy program.
- The encarregado is optional because we have a global DPO.
- A global function may support the role, but the organization still needs a clear LGPD contact and operating model. The encarregado function should be reachable, understood internally, and connected to ANPD and data-subject response workflows.
When the checklist is enough — and when it is not
- Brazilian personal data is processed without LGPD-specific lawful-basis mapping.
- No encarregado or Brazilian privacy contact route is operationally defined.
- An incident may require communication to the ANPD or affected data subjects.
- Product, HR, or marketing teams rely on English-only notices for Brazilian users.
Related checklists
Privacy Regulation
GDPR Compliance Checklist for Web Applications
Guide: GDPR for web applications: lawful basis, cookies, and processor chains
PIPEDA
PIPEDA Fair Information Principles Checklist
Guide: PIPEDA: fair information principles, meaningful consent, and breach reporting to the OPC
PDPA
Singapore PDPA Data Protection Checklist
Guide: Singapore PDPA: consent, deemed consent, and PDPC’s 2026 enforcement posture
Related field notes
The checklists and field notes provided on this website are for educational and informational purposes only. They do not constitute legal, financial, or professional advice. Completing a checklist does not guarantee compliance, certification, or immunity from audits. Always consult with a certified auditor or legal counsel for your specific organizational needs. Full disclaimer