Article · Data protection and the LGPD

LGPD compliance for companies: Brazil's data protection law in practice

Gabriel Cordeiro Grisostolo · OAB/PR nº 136.464

If you are asking what the LGPD is, you are not alone: Brazil's General Data Protection Law (Lei Geral de Proteção de Dados) has been in force for years, the National Data Protection Authority already imposes fines, and yet many companies still live with the same nagging doubt about what LGPD compliance actually requires in practice. Often compared with the European GDPR, the LGPD carries its own rules. This text translates the law into the language of management, shows whom it applies to, what it demands, what happens on breach and how a company, including a software company, can reach the minimum needed to operate in conformity.

Key points

  • The LGPD applies to virtually every company that processes the personal data of natural persons, of any size. You do not have to be a large corporation to be subject to it.
  • In practice, LGPD compliance comes down to knowing what data the company processes, on what legal basis, with what security and with what transparency, plus someone responsible for overseeing it.
  • A breach exposes the company to sanctions from the National Authority, ranging from a warning to a fine, and to the duty to repair the harm caused to data subjects.

Whom the LGPD applies to, and the myth of the company registration number

The LGPD applies to any person or entity that processes the personal data of natural persons in Brazil, or whose processing is connected to the country. Processing is almost anything done with data: collecting, storing, using, sharing, deleting. This means a company does not need to be large to be subject to the law; it is enough that it handles the data of clients, employees or suppliers, which, in practice, reaches almost every business.

Here lies a common confusion worth dispelling: the LGPD protects the data of natural persons, not of legal entities. A company's registration number, on its own, is not personal data. But note, the data of the individuals behind a company, a partner, a contact, a representative, remain protected. So the honest answer to whether the LGPD reaches a company number is: the number itself no, the people behind it yes.

What the LGPD requires of companies, in practice

Reduced to the essentials, the law requires five things of a company. First, to know what data it processes, mapping what it collects, from whom, for what and for how long it keeps it. Second, to have a legal basis for each processing, because processing data without a justification provided by the law is irregular. Third, to be transparent with the data subject, through a privacy policy and clear notices. Fourth, to ensure security, with technical and administrative measures proportional to the risk, and to have a plan to respond to incidents. Fifth, to honor the rights of the data subject, such as access, correction and deletion of their data, and to designate someone responsible for that relationship. These five fronts are the heart of LGPD compliance.

The legal bases: why you process each piece of data

One of the biggest misconceptions about the LGPD is to imagine that everything depends on consent. It does not. The law provides ten legal bases for the processing of personal data, and consent is only one of them. A company may process data to perform a contract with the client, to comply with a legal obligation, for the regular exercise of rights or on the ground of legitimate interest, among other hypotheses. Choosing the correct basis for each processing is a substantive legal decision, because it is the basis that defines what the company may or may not do with the data, and what it needs to ask of the data subject.

The principles that guide processing

Above the specific rules, the LGPD sets out principles that must guide any processing: purpose, which requires a legitimate and informed aim; necessity, which limits collection to the indispensable minimum; transparency, security, prevention and non-discrimination; and accountability, by which the company must be able to demonstrate that it complies with the law. In practice, these principles work as a test: faced with any use of data, the company should be able to explain why it does it, within what limit and with what care.

Who is responsible for the LGPD in the company

The law organizes the roles around two figures, the controller, who decides how and why the data is processed, and the processor, who processes it on the controller's behalf. In addition, the company must designate a data protection officer, the DPO, who is the channel of communication between the company, the data subjects and the National Authority. In smaller companies, the DPO function may be exercised proportionally, including with external support, provided it is genuinely effective. Defining who occupies each role is one of the first steps of compliance.

What happens on breach: sanctions and article 42

A breach has two orders of consequence. On one side, the administrative sanctions applied by the National Data Protection Authority, which range from a warning to a fine, the latter reaching a percentage of the company's revenue within the limits set by law, besides measures such as making the infraction public and blocking the data. On the other, civil liability: article 42 of the LGPD obliges the controller or the processor to repair the harm, material or moral, caused to data subjects by reason of irregular processing. LGPD compliance, therefore, protects the company on two fronts, the sanctioning and the compensatory.

LGPD for software and SaaS companies

For technology companies, the LGPD has its own contours that deserve special attention. A software company is usually, at the same time, the controller of its own users' data and the processor of the data it handles on behalf of its clients, which calls for well-drafted data processing agreements that delimit responsibilities between the parties. Security has to be thought of from the design of the product, and not added afterwards. And there is the question of the international transfer of data, frequent in solutions hosted abroad or serving clients outside the country, a subject the LGPD governs and that connects to the contractual design between companies of different jurisdictions, including the United States. For those who build software, treating data protection as part of the product, and not as an external formality, is what sets a mature solution apart.

A minimum checklist to begin

For the company that needs to comply and does not know where to start, a minimum roadmap is usually enough for the first steps: map the data the company processes; define the legal basis of each processing; publish a privacy policy and clear notices; adopt security measures and an incident-response plan; designate the DPO; and review the contracts with third parties that process data on the company's behalf. Once the minimum is done, compliance evolves through periodic reviews, in proportion to the risk of each operation.

Frequently asked questions

What is the LGPD?
The LGPD (Lei Geral de Proteção de Dados) is Brazil's General Data Protection Law, which governs how companies may process the personal data of natural persons, requiring a legal basis, transparency, security and respect for the rights of the data subject, under the oversight of the National Authority. Translating it into policies and routines applicable to the business is a matter of LGPD compliance, one of the preventive advisory areas of Grisostolo Advocacia.
LGPD vs GDPR: what is the difference?
The LGPD is strongly inspired by the European GDPR and shares its logic of legal bases, data-subject rights and accountability, but it is a distinct Brazilian law, with its own authority, its own sanctions and specific rules, so GDPR compliance does not automatically mean LGPD compliance. Mapping how each applies to a company that operates in both markets is part of the firm's work.
What are the five things the LGPD requires of companies?
To know what data it processes, to have a legal basis for each processing, to be transparent with the data subject, to ensure security and an incident plan, and to honor the rights of the data subject with a designated officer. Structuring these five fronts to measure is the object of the compliance work the firm conducts.
Does the LGPD apply to a company outside Brazil?
Yes, when the processing is carried out in Brazil, aims to offer goods or services to individuals in Brazil, or concerns data of people located in the country. That is why a US company dealing with Brazilian clients or users often falls within the LGPD. Assessing that reach, and structuring the international transfer of data, is an analysis the firm carries out.
Who is responsible for the LGPD in the company?
The law speaks of the controller (who decides on the processing) and the processor (who processes on the controller's behalf), plus the DPO, who bridges data subjects and the National Authority. Defining these roles and, when the case calls for it, acting as support in the DPO function is a service the firm provides.
How does a company become LGPD compliant?
Compliance is built in stages: map the personal data the company processes, define a legal basis for each use, review contracts and privacy notices, set security measures and a channel for data-subject requests, and appoint someone accountable for data protection. Structuring this program in the proportion of your risk, so the company reaches a defensible posture without paralyzing the operation, is a front on which the firm works.
How does the LGPD apply to software companies?
A software company is usually the controller of its users' data and the processor of its clients' data, which calls for well-drafted processing agreements, security by design and attention to the international transfer of data. Structuring these agreements and the compliance design for SaaS is a front on which the firm works, including in the context of international operations between Brazil and the United States.

How the firm works on this subject

The need to comply with the LGPD usually translates into the following areas of legal work:

  • LGPD compliance, preventive and consultative: data mapping, definition of legal bases, risk analysis and the design of compliance in proportion to the company.
  • Drafting of legal documents: privacy policy, notices, data processing agreements between controller and processor and the incident-response regulation.
  • Support in the DPO function: support to the company in its relationship with data subjects and with the National Data Protection Authority.
  • Software and international focus: contractual design for SaaS and for the international transfer of data between jurisdictions.
  • Litigation: defense of the company in the face of incidents, data-subject complaints or sanctioning proceedings.

It is with this set that Grisostolo Advocacia is concerned in matters of data protection, always sized to the size and the risk of each company.

Is your company already LGPD compliant?

If you process client data and are not sure you are compliant, it is possible to reach the minimum needed in stages. We can talk about the first diagnosis.

This text is informative in nature and does not constitute legal advice. LGPD compliance depends on the analysis of the data processing proper to each company.

See the practice areas in detail →
FAQ