Jurisdiction Guides / Americas
Brazil Privacy & Data Protection Laws
Every regime below can apply to a business handling Brazil residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.
Comprehensive Privacy Law · 1
Art. 3 gives LGPD explicit, GDPR-style extraterritorial reach: it applies to processing carried out in Brazilian territory (regardless of the controller's HQ or where data is stored), OR where the processing activity is aimed at offering/supplying goods or services to, or processing data of, individuals located in Brazil — broader than GDPR's 'monitoring' prong, sweeping in essentially any processing of Brazil-located individuals' data. Art. 4 exempts purely private/non-economic processing by a natural person, exclusively journalistic/artistic/academic purposes, and exclusively public-safety/national-defense/security/criminal-investigation purposes. No general nonprofit, government, small-business, or health/financial-sector exemption — those are instead treated as sensitive/regulated data categories under the general law. The ANPD has since issued binding regulations on data-subject rights, international transfers (including Brazilian standard contractual clauses), and simplified compliance for small processing agents, so LGPD obligations are now materially more concrete than the statute alone suggests. The regulator itself has been upgraded: Lei no 15.352, de 25 de fevereiro de 2026 converted the ANPD into a regulatory agency with reinforced functional, technical and decision-making autonomy, and it now also enforces the Digital ECA (see the children's entry for Brazil).
Sector-Specific Law · 1
Predates the LGPD by four years and still governs internet-specific duties the LGPD does not touch. The provisions with the sharpest operational edge are the mandatory retention rules, which cut against data-minimisation instincts: Art. 13 requires internet connection providers to retain connection logs — date, start and end time, and IP address — for one year, and Art. 15 requires FOR-PROFIT internet application providers to retain application access logs for six months. Art. 15's duty applies without needing the user's consent, and non-profit sites, blogs and applications are outside it. Both articles allow the retention period to be extended in defined circumstances. The framework also carries Brazil's net-neutrality rules and its intermediary-liability regime, under which a provider is generally liable for third-party content only after failing to comply with a specific court order. Marked 'verified' on structure; the primary text is Portuguese-language, so confirm the current wording if a retention period is load-bearing for a design decision.
Children & Minors Protections · 1
Now in force, and the more demanding of Brazil's two children's instruments. Brazil already required that children's data be processed in their best interest, with specific and prominent consent from a parent or guardian, under LGPD Art. 14. The Digital ECA goes considerably further for anyone running a consumer service. It requires effective and reliable age verification across services likely to be accessed by minors — social networks, games, app stores, operating systems — and expressly rules out self-declaration; it requires parental consent and account linking for under-16s; it bans targeted advertising and profiling of minors; it bans paid loot boxes for under-18s; and it imposes 24-hour notice-and-takedown for criminal content. Penalties run to BRL 50 million per violation or up to 10% of Brazilian revenue. Implementation is settled enough to plan against: Decreto no 12.622/2025 made the ANPD the enforcement authority, Decreto no 12.880 of March 18, 2026 supplies the implementing detail on age verification, unsuitable content, parental supervision and advertising and establishes a national policy for children in the digital environment, and Lei no 15.352 of February 25, 2026 converted the ANPD itself into a regulatory agency. Sequencing matters for anyone triaging work: the obligations bind now, but the ANPD's published implementation schedule treats 2026 as adaptation and monitoring, puts the updated inspection and administrative-sanction regulations from November 2026, and expects effective inspection to consolidate in 2027 — so the exposure is real but the penalty machinery is still being assembled.
Cross-Border Data Transfer · 1
Arts. 33-36 set out the permitted routes — an ANPD adequacy decision, specific or standard contractual clauses, binding corporate rules, seals and certificates, or one of the statutory exceptions — but for four years the mechanisms did not exist in usable form. Resolution CD/ANPD No. 19/2024 supplied them, publishing Brazilian standard contractual clauses and the rules for equivalent clauses, specific clauses, BCRs, and adequacy. The transition period for retrofitting the ANPD-approved SCCs into existing transfer agreements ended August 23, 2025, so contracts still running on generic or EU-only clauses are now out of time. Both exporter and importer bear the burden of proving compliance, and a foreign processor receiving Brazilian data as importer is itself responsible for documenting the transfer.
Data Security & Breach Notification · 1
Art. 48 required communicating security incidents that may create relevant risk or damage to data subjects, but left 'reasonable time' undefined until ANPD's Resolution No. 15/2024 fixed it: three business days from becoming aware, to both the ANPD and the affected data subjects. That is one of the shortest windows in this dataset — shorter in practice than GDPR's 72 hours, because business days exclude weekends only on the running side while the assessment burden is the same, and because Brazil requires notifying individuals on the same clock as the regulator rather than on a separate high-risk trigger. Failure to notify is itself a standalone infraction, sanctionable without proof of damage. The Resolution also supplies the definitions and content requirements Art. 48 lacked.
Other Americas jurisdictions