Comprehensive Privacy Law
Lei Geral de Protecao de Dados Pessoais (General Personal Data Protection Law)
Brazil · September 18, 2020 (administrative sanctions delayed to August 1, 2021)
Verify detailsArt. 3 gives LGPD explicit, GDPR-style extraterritorial reach: it applies to processing carried out in Brazilian territory (regardless of the controller's HQ or where data is stored), OR where the processing activity is aimed at offering/supplying goods or services to, or processing data of, individuals located in Brazil — broader than GDPR's 'monitoring' prong, sweeping in essentially any processing of Brazil-located individuals' data. Art. 4 exempts purely private/non-economic processing by a natural person, exclusively journalistic/artistic/academic purposes, and exclusively public-safety/national-defense/security/criminal-investigation purposes. No general nonprofit, government, small-business, or health/financial-sector exemption — those are instead treated as sensitive/regulated data categories under the general law. The ANPD has since issued binding regulations on data-subject rights, international transfers (including Brazilian standard contractual clauses), and simplified compliance for small processing agents, so LGPD obligations are now materially more concrete than the statute alone suggests. The regulator itself has been upgraded: Lei no 15.352, de 25 de fevereiro de 2026 converted the ANPD into a regulatory agency with reinforced functional, technical and decision-making autonomy, and it now also enforces the Digital ECA (see the children's entry for Brazil).
This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.