WorldPrivacyAtlas
Laws by country

Jurisdiction Guides / Americas

Brazil Privacy & Data Protection Laws

Every regime below can apply to a business handling Brazil residents' data, depending on whether you have an established presence there, actively offer goods or services to residents, or monitor their behavior. This is a general reference, not a determination for your specific business — run the full questionnaire to see which of these actually apply to you.

Comprehensive Privacy Law · 1

September 18, 2020 (administrative sanctions delayed to August 1, 2021)
Lei Geral de Protecao de Dados Pessoais (General Personal Data Protection Law)
LGPD
Verify details

Art. 3 gives LGPD explicit, GDPR-style extraterritorial reach: it applies to processing carried out in Brazilian territory (regardless of the controller's HQ or where data is stored), OR where the processing activity is aimed at offering/supplying goods or services to, or processing data of, individuals located in Brazil — broader than GDPR's 'monitoring' prong, sweeping in essentially any processing of Brazil-located individuals' data. Art. 4 exempts purely private/non-economic processing by a natural person, exclusively journalistic/artistic/academic purposes, and exclusively public-safety/national-defense/security/criminal-investigation purposes. No general nonprofit, government, small-business, or health/financial-sector exemption — those are instead treated as sensitive/regulated data categories under the general law. The ANPD has since issued binding regulations on data-subject rights, international transfers (including Brazilian standard contractual clauses), and simplified compliance for small processing agents, so LGPD obligations are now materially more concrete than the statute alone suggests. The regulator itself has been upgraded: Lei no 15.352, de 25 de fevereiro de 2026 converted the ANPD into a regulatory agency with reinforced functional, technical and decision-making autonomy, and it now also enforces the Digital ECA (see the children's entry for Brazil).

Lei no 13.709, de 14 de agosto de 2018, Arts. 3-4 (amended by Lei no 13.853/2019)Read regulation →

Sector-Specific Law · 1

Predates the LGPD by four years and still governs internet-specific duties the LGPD does not touch. The provisions with the sharpest operational edge are the mandatory retention rules, which cut against data-minimisation instincts: Art. 13 requires internet connection providers to retain connection logs — date, start and end time, and IP address — for one year, and Art. 15 requires FOR-PROFIT internet application providers to retain application access logs for six months. Art. 15's duty applies without needing the user's consent, and non-profit sites, blogs and applications are outside it. Both articles allow the retention period to be extended in defined circumstances. The framework also carries Brazil's net-neutrality rules and its intermediary-liability regime, under which a provider is generally liable for third-party content only after failing to comply with a specific court order. Marked 'verified' on structure; the primary text is Portuguese-language, so confirm the current wording if a retention period is load-bearing for a design decision.

Lei no 12.965, de 23 de abril de 2014, esp. Arts. 13 and 15Read regulation →

Children & Minors Protections · 1

March 17, 2026 (six months after publication of Lei no 15.211 on September 17, 2025)
Digital Statute for Children and Adolescents (Estatuto Digital da Crianca e do Adolescente)
Brazil Digital ECA (Lei 15.211/2025)

Now in force, and the more demanding of Brazil's two children's instruments. Brazil already required that children's data be processed in their best interest, with specific and prominent consent from a parent or guardian, under LGPD Art. 14. The Digital ECA goes considerably further for anyone running a consumer service. It requires effective and reliable age verification across services likely to be accessed by minors — social networks, games, app stores, operating systems — and expressly rules out self-declaration; it requires parental consent and account linking for under-16s; it bans targeted advertising and profiling of minors; it bans paid loot boxes for under-18s; and it imposes 24-hour notice-and-takedown for criminal content. Penalties run to BRL 50 million per violation or up to 10% of Brazilian revenue. Implementation is settled enough to plan against: Decreto no 12.622/2025 made the ANPD the enforcement authority, Decreto no 12.880 of March 18, 2026 supplies the implementing detail on age verification, unsuitable content, parental supervision and advertising and establishes a national policy for children in the digital environment, and Lei no 15.352 of February 25, 2026 converted the ANPD itself into a regulatory agency. Sequencing matters for anyone triaging work: the obligations bind now, but the ANPD's published implementation schedule treats 2026 as adaptation and monitoring, puts the updated inspection and administrative-sanction regulations from November 2026, and expects effective inspection to consolidate in 2027 — so the exposure is real but the penalty machinery is still being assembled.

Lei no 15.211, de 17 de setembro de 2025 (in force March 17, 2026); Decreto no 12.622/2025 (designating the ANPD); Decreto no 12.880, de 18 de marco de 2026 (implementing regulation); Lei no 13.709/2018 (LGPD), Art. 14Read regulation →

Cross-Border Data Transfer · 1

September 18, 2020 (Arts. 33-36); Resolution CD/ANPD No. 19/2024 in force from publication, with a transition period that ended August 23, 2025
Lei Geral de Protecao de Dados Pessoais — international transfer of personal data
LGPD Arts. 33-36

Arts. 33-36 set out the permitted routes — an ANPD adequacy decision, specific or standard contractual clauses, binding corporate rules, seals and certificates, or one of the statutory exceptions — but for four years the mechanisms did not exist in usable form. Resolution CD/ANPD No. 19/2024 supplied them, publishing Brazilian standard contractual clauses and the rules for equivalent clauses, specific clauses, BCRs, and adequacy. The transition period for retrofitting the ANPD-approved SCCs into existing transfer agreements ended August 23, 2025, so contracts still running on generic or EU-only clauses are now out of time. Both exporter and importer bear the burden of proving compliance, and a foreign processor receiving Brazilian data as importer is itself responsible for documenting the transfer.

Lei no 13.709/2018, Arts. 33-36; Resolution CD/ANPD No. 19 of August 23, 2024Read regulation →

Data Security & Breach Notification · 1

September 18, 2020 (Art. 48); Resolution CD/ANPD No. 15 published April 26, 2024
Lei Geral de Protecao de Dados Pessoais — communication of security incidents
LGPD Art. 48

Art. 48 required communicating security incidents that may create relevant risk or damage to data subjects, but left 'reasonable time' undefined until ANPD's Resolution No. 15/2024 fixed it: three business days from becoming aware, to both the ANPD and the affected data subjects. That is one of the shortest windows in this dataset — shorter in practice than GDPR's 72 hours, because business days exclude weekends only on the running side while the assessment burden is the same, and because Brazil requires notifying individuals on the same clock as the regulator rather than on a separate high-risk trigger. Failure to notify is itself a standalone infraction, sanctionable without proof of damage. The Resolution also supplies the definitions and content requirements Art. 48 lacked.

Lei no 13.709/2018, Art. 48; Resolution CD/ANPD No. 15 of April 24, 2024Read regulation →

Other Americas jurisdictions