LGPD: Brazil's Data Privacy Law Explained
The short answer: LGPD stands for Lei Geral de Proteção de Dados ("General Data Protection Law") — Brazil's comprehensive privacy law, in force since 2020 and enforced by the National Data Protection Authority (ANPD). It governs how any organization collects, uses, and shares the personal data of people in Brazil and, like the EU's GDPR, grants rights to access, correct, delete, and port data. Crucially, it's extraterritorial: a US or EU store that sells to Brazilian shoppers must comply even without a physical presence in Brazil.
The LGPD, Brazil's general data protection law (Lei Geral de Proteção de Dados), is the country's comprehensive privacy framework governing how organizations collect, store, and use personal data. If your online store sells to or markets at shoppers in Brazil, the LGPD applies to you even if your business has no physical presence in the country. This guide breaks down LGPD in plain English: who it covers, the rights it grants consumers, the penalties for getting it wrong, and a practical compliance roadmap you can act on. Whether you are a store owner, a marketer, or a privacy lead, understanding the LGPD is now a baseline requirement for selling internationally rather than an optional nice-to-have.
What Is the LGPD?
The Lei Geral de Proteção de Dados (LGPD) is Brazil's general data protection law. It establishes a single, nationwide framework for the collection, storage, processing, and sharing of personal data, replacing a previously fragmented patchwork of sector-specific rules. The law is widely described as Brazil's answer to the European Union's General Data Protection Regulation (GDPR), and it borrows much of GDPR's structure and vocabulary while adapting the details to the Brazilian legal context.
At its core, the LGPD does three things:
- Defines personal data broadly. Any information that can identify a person — names, email addresses, IP addresses, device identifiers, and more — falls within scope. A special category of "sensitive personal data" (such as data revealing racial or ethnic origin, religious belief, health, or biometric data) carries stricter handling requirements.
- Sets out lawful bases for processing. Organizations must have a valid legal basis before processing personal data. Consent is one basis, but the LGPD recognizes several others, so consent is not always required.
- Grants individuals enforceable rights. People whose data you hold (data subjects) can ask to see it, correct it, delete it, and more.
The LGPD also created a dedicated regulator, the National Data Protection Authority (Autoridade Nacional de Proteção de Dados, or ANPD), responsible for guidance, oversight, and enforcement.
For a side-by-side comparison with the U.S. framework most eCommerce teams already know, see our guide on CCPA vs. LGPD: key differences for eCommerce brands.
Who Does the LGPD Apply To?
This is the question most online sellers get wrong. The LGPD's reach is extraterritorial: it applies to any individual or organization that processes the personal data of people in Brazil, regardless of where that organization is based. Three triggers are commonly cited:
- The processing happens in Brazil.
- The processing relates to offering goods or services to people in Brazil.
- The personal data being processed was collected in Brazil.
In practical terms, a Shopify or WooCommerce store headquartered in the United States or Europe can fall under the LGPD the moment it takes orders from, advertises to, or collects data from Brazilian shoppers. This mirrors the extraterritorial logic of GDPR — a pattern we cover in depth in how GDPR affects non-EU companies. If you operate across several jurisdictions, our overview of navigating the global landscape of data privacy laws maps how LGPD fits alongside GDPR, CCPA, and other regimes.
Why LGPD Matters for Online Stores
In an era where data breaches and tracking controversies dominate headlines, LGPD compliance is both a legal obligation and a trust signal. The law mandates transparency and accountability: shoppers gain meaningful control over their data, and businesses that respect that control tend to build stronger customer relationships.
There are three concrete reasons eCommerce teams should treat LGPD seriously:
- Market access. Brazil is one of the largest eCommerce markets in Latin America. Treating LGPD as optional puts that revenue at risk.
- Financial and reputational exposure. Non-compliance can lead to enforcement action and fines, alongside the reputational damage that follows a privacy failure.
- Operational alignment. Because LGPD shares so much DNA with GDPR, building one solid privacy program usually satisfies large parts of both. The work compounds rather than duplicates.
LGPD Data Subject Rights
The LGPD grants individuals a defined set of rights over their personal data. At a high level, data subjects can request to:
- Confirm whether their data is being processed.
- Access the personal data an organization holds about them.
- Correct incomplete, inaccurate, or outdated data.
- Anonymize, block, or delete data that is unnecessary, excessive, or processed unlawfully.
- Port their data to another service provider, on request.
- Delete personal data processed on the basis of consent.
- Obtain information about the entities with which their data has been shared.
- Be informed about the consequences of refusing to give consent.
- Withdraw consent at any time.
Operationally, these rights look a lot like the data subject access requests (DSARs) that GDPR and CCPA teams already handle. If you have a process for those, you are most of the way there. Our guide on navigating data subject access requests for eCommerce walks through how to receive, verify, and fulfill these requests without grinding your operations to a halt.
LGPD vs. GDPR: How They Compare
LGPD was modeled on GDPR, so the two share a common foundation: broad definitions of personal data, lawful bases for processing, strong data subject rights, breach-notification expectations, and an independent regulator. The differences tend to live in the details — the specific legal bases recognized, the structure of penalties, breach-notification timelines, and the role and powers of the supervisory authority.
| LGPD (Brazil) | GDPR (EU) | |
|---|---|---|
| Legal bases for processing | 10 (Article 7) | 6 (Article 6) |
| Regulator | ANPD | Each member state's DPA, coordinated by the EDPB |
| Maximum fine | 2% of Brazil revenue, capped at R$50M per infraction | €20M or 4% of global turnover |
| Breach notification | "Reasonable time" — ~3 business days per ANPD guidance | 72 hours |
| Enumerated data-subject rights | 9 | 8 |
| Extraterritorial reach | Yes | Yes |
For eCommerce teams, the practical takeaway is that a well-built GDPR program is a strong starting point for LGPD, but it is not a drop-in substitute. You still need to map LGPD's specific requirements to your data flows. For a deeper comparison across multiple regimes, our comprehensive guide to data privacy laws for eCommerce lays the frameworks side by side.
How to Implement LGPD Compliance: A Practical Roadmap
LGPD compliance is less about a single project and more about an ongoing operating posture. These steps give online stores a defensible starting framework:
-
Map your data. Run a data inventory: what personal data you collect, where it comes from, why you process it, where it is stored, who can access it, and who you share it with. You cannot protect — or delete — data you cannot see.
-
Establish a lawful basis. For each processing activity, identify which LGPD legal basis applies. Where you rely on consent, make sure it is freely given, specific, informed, and easy to withdraw.
-
Update your privacy notices. Clearly explain what you collect, why, how long you keep it, and how shoppers can exercise their rights. Plain language beats legalese.
-
Build a rights-request workflow. Create a repeatable process to receive, verify the identity of, and respond to data subject requests within the timeframes the law expects.
-
Tighten your consent and cookie practices. Trackers, pixels, and analytics tags frequently process personal data. A clear consent mechanism on your storefront is often the most visible part of compliance.
-
Secure the data. Apply technical and organizational safeguards — encryption, access controls, and regular security reviews — appropriate to the sensitivity of the data you hold.
-
Assign accountability. The LGPD expects organizations to designate a person responsible for data protection who can act as the point of contact for data subjects and the ANPD.
-
Plan for breaches. Know in advance how you will detect, contain, document, and report a security incident, including any notification obligations to the ANPD and affected individuals.
-
Treat compliance as continuous. Re-audit periodically, retrain staff, and adjust as the ANPD issues new guidance.
If most of your shopper data lives in tools like Shopify, your ad platforms, your email service, and your analytics stack, the hardest part is usually visibility and rights fulfillment across all of them at once — exactly the kind of work a privacy automation platform is built to handle.
The LGPD's Ten Legal Bases — and Rules for Sending Data Abroad
Two areas where the LGPD's details diverge most from the GDPR are its legal bases and its cross-border transfer rules.
Ten legal bases, not six. Where the GDPR offers six lawful bases for processing, the LGPD's Article 7 sets out ten — a broader, but still defined, set of grounds. They are: consent; compliance with a legal or regulatory obligation; execution of public policies by the public administration; studies by research bodies (anonymized where possible); performance of a contract or pre-contract steps; the regular exercise of rights in legal proceedings; protection of life or physical safety; protection of health by health professionals; the legitimate interests of the controller or a third party; and credit protection. As with the GDPR, consent is just one option — and where you rely on it, it must be free, informed, and unambiguous. Sensitive personal data (health, biometrics, race, religion, political views, and similar) is narrower: it can generally only be processed with explicit consent or under specific legal exceptions.
Sending data outside Brazil. The LGPD restricts international transfers much as the GDPR does. You can move Brazilian residents' personal data abroad only when a condition is met — for example, the destination country offers an adequate level of protection; you put contractual guarantees (such as standard contractual clauses) in place; the data subject gives specific, informed consent to the transfer; or the transfer is necessary to protect life, for legal cooperation, to execute a public policy, or under an international agreement Brazil is party to. For a typical store using US-based tools, the practical path is usually contractual safeguards plus clear disclosure.
One more deadline to know. If you suffer a security incident affecting personal data, the LGPD expects you to notify the ANPD and affected individuals promptly — generally within three business days of confirming the breach, with a longer window for smaller organizations. Build that timeline into your incident-response plan.
Frequently Asked Questions
What is LGPD?
The LGPD (Lei Geral de Proteção de Dados) is Brazil's general data protection law. It regulates how organizations collect, use, store, and share personal data, and it grants individuals rights such as access, correction, deletion, and the ability to withdraw consent. It is frequently described as Brazil's counterpart to the EU's GDPR.
Does LGPD apply to businesses outside Brazil?
Yes, in many cases. The LGPD is extraterritorial: it can apply to any organization that processes the personal data of people in Brazil, including when the processing relates to offering goods or services to them — regardless of where the business is located. A US or EU online store selling to Brazilian shoppers can fall within scope.
How is LGPD different from GDPR?
LGPD was modeled on GDPR and shares much of its structure, but the two differ in details such as the recognized legal bases for processing, penalty structures, breach-notification rules, and the powers of the supervisory authority. A strong GDPR program is a good foundation for LGPD but not an automatic substitute.
How many legal bases does the LGPD have?
Ten, set out in Article 7 — more than the GDPR's six. They range from consent and contractual necessity to legitimate interests, legal obligations, health protection, and credit protection. Consent is only one of them, so you don't always need it if another basis genuinely applies.
Can I transfer Brazilian customers' data outside Brazil?
Yes, if you meet one of the LGPD's transfer conditions — such as an adequacy finding for the destination country, contractual safeguards like standard contractual clauses, or the data subject's specific informed consent. Most stores using US-based tools rely on contractual safeguards plus clear disclosure.
What are the penalties for LGPD non-compliance?
The LGPD provides for administrative sanctions that can include fines tied to a company's revenue in Brazil (capped per infraction), alongside other corrective measures such as warnings, data deletion, and suspension of processing.
What tools help with LGPD compliance?
Common categories include data-mapping and discovery tools, consent management platforms, privacy impact assessment tools, data subject request automation, and security tooling such as encryption and access controls. Many eCommerce teams consolidate these into a single privacy platform so consent, rights requests, and data visibility live in one place.
Who enforces the LGPD?
Brazil's National Data Protection Authority (ANPD) is responsible for guidance, oversight, and enforcement of the LGPD.