LGPD compliance for companies: Brazil's data protection law in practice
If you are asking what the LGPD is, you are not alone: Brazil's General Data Protection Law (Lei Geral de Proteção de Dados) has been in force for years, the National Data Protection Authority already imposes fines, and yet many companies still live with the same nagging doubt about what LGPD compliance actually requires in practice. Often compared with the European GDPR, the LGPD carries its own rules. This text translates the law into the language of management, shows whom it applies to, what it demands, what happens on breach and how a company, including a software company, can reach the minimum needed to operate in conformity.
Key points
- The LGPD applies to virtually every company that processes the personal data of natural persons, of any size. You do not have to be a large corporation to be subject to it.
- In practice, LGPD compliance comes down to knowing what data the company processes, on what legal basis, with what security and with what transparency, plus someone responsible for overseeing it.
- A breach exposes the company to sanctions from the National Authority, ranging from a warning to a fine, and to the duty to repair the harm caused to data subjects.
Whom the LGPD applies to, and the myth of the company registration number
The LGPD applies to any person or entity that processes the personal data of natural persons in Brazil, or whose processing is connected to the country. Processing is almost anything done with data: collecting, storing, using, sharing, deleting. This means a company does not need to be large to be subject to the law; it is enough that it handles the data of clients, employees or suppliers, which, in practice, reaches almost every business.
Here lies a common confusion worth dispelling: the LGPD protects the data of natural persons, not of legal entities. A company's registration number, on its own, is not personal data. But note, the data of the individuals behind a company, a partner, a contact, a representative, remain protected. So the honest answer to whether the LGPD reaches a company number is: the number itself no, the people behind it yes.
What the LGPD requires of companies, in practice
Reduced to the essentials, the law requires five things of a company. First, to know what data it processes, mapping what it collects, from whom, for what and for how long it keeps it. Second, to have a legal basis for each processing, because processing data without a justification provided by the law is irregular. Third, to be transparent with the data subject, through a privacy policy and clear notices. Fourth, to ensure security, with technical and administrative measures proportional to the risk, and to have a plan to respond to incidents. Fifth, to honor the rights of the data subject, such as access, correction and deletion of their data, and to designate someone responsible for that relationship. These five fronts are the heart of LGPD compliance.
The legal bases: why you process each piece of data
One of the biggest misconceptions about the LGPD is to imagine that everything depends on consent. It does not. The law provides ten legal bases for the processing of personal data, and consent is only one of them. A company may process data to perform a contract with the client, to comply with a legal obligation, for the regular exercise of rights or on the ground of legitimate interest, among other hypotheses. Choosing the correct basis for each processing is a substantive legal decision, because it is the basis that defines what the company may or may not do with the data, and what it needs to ask of the data subject.
The principles that guide processing
Above the specific rules, the LGPD sets out principles that must guide any processing: purpose, which requires a legitimate and informed aim; necessity, which limits collection to the indispensable minimum; transparency, security, prevention and non-discrimination; and accountability, by which the company must be able to demonstrate that it complies with the law. In practice, these principles work as a test: faced with any use of data, the company should be able to explain why it does it, within what limit and with what care.
Who is responsible for the LGPD in the company
The law organizes the roles around two figures, the controller, who decides how and why the data is processed, and the processor, who processes it on the controller's behalf. In addition, the company must designate a data protection officer, the DPO, who is the channel of communication between the company, the data subjects and the National Authority. In smaller companies, the DPO function may be exercised proportionally, including with external support, provided it is genuinely effective. Defining who occupies each role is one of the first steps of compliance.
What happens on breach: sanctions and article 42
A breach has two orders of consequence. On one side, the administrative sanctions applied by the National Data Protection Authority, which range from a warning to a fine, the latter reaching a percentage of the company's revenue within the limits set by law, besides measures such as making the infraction public and blocking the data. On the other, civil liability: article 42 of the LGPD obliges the controller or the processor to repair the harm, material or moral, caused to data subjects by reason of irregular processing. LGPD compliance, therefore, protects the company on two fronts, the sanctioning and the compensatory.
LGPD for software and SaaS companies
For technology companies, the LGPD has its own contours that deserve special attention. A software company is usually, at the same time, the controller of its own users' data and the processor of the data it handles on behalf of its clients, which calls for well-drafted data processing agreements that delimit responsibilities between the parties. Security has to be thought of from the design of the product, and not added afterwards. And there is the question of the international transfer of data, frequent in solutions hosted abroad or serving clients outside the country, a subject the LGPD governs and that connects to the contractual design between companies of different jurisdictions, including the United States. For those who build software, treating data protection as part of the product, and not as an external formality, is what sets a mature solution apart.
A minimum checklist to begin
For the company that needs to comply and does not know where to start, a minimum roadmap is usually enough for the first steps: map the data the company processes; define the legal basis of each processing; publish a privacy policy and clear notices; adopt security measures and an incident-response plan; designate the DPO; and review the contracts with third parties that process data on the company's behalf. Once the minimum is done, compliance evolves through periodic reviews, in proportion to the risk of each operation.
Frequently asked questions
How the firm works on this subject
The need to comply with the LGPD usually translates into the following areas of legal work:
- LGPD compliance, preventive and consultative: data mapping, definition of legal bases, risk analysis and the design of compliance in proportion to the company.
- Drafting of legal documents: privacy policy, notices, data processing agreements between controller and processor and the incident-response regulation.
- Support in the DPO function: support to the company in its relationship with data subjects and with the National Data Protection Authority.
- Software and international focus: contractual design for SaaS and for the international transfer of data between jurisdictions.
- Litigation: defense of the company in the face of incidents, data-subject complaints or sanctioning proceedings.
It is with this set that Grisostolo Advocacia is concerned in matters of data protection, always sized to the size and the risk of each company.
Is your company already LGPD compliant?
If you process client data and are not sure you are compliant, it is possible to reach the minimum needed in stages. We can talk about the first diagnosis.
This text is informative in nature and does not constitute legal advice. LGPD compliance depends on the analysis of the data processing proper to each company.