Brazil's LGPD does not include a list of mandatory technologies. What it requires, in Articles 46 to 49 of Law No. 13,709/2018, are technical and administrative security measures "capable" of protecting personal data. The wording is deliberately open, which is why many companies cannot say whether they actually comply. This article translates the legal text into verifiable controls.
What Articles 46 to 49 actually say
Chapter VII of the LGPD, "Security and Good Practices", opens with four short provisions:
- Article 46. Processing agents must adopt technical and administrative security measures capable of protecting personal data from unauthorized access and from accidental or unlawful destruction, loss, alteration, communication or any other improper or unlawful processing. Paragraph 2 adds that these measures must be observed from the design phase of the product or service through its execution, which is commonly called privacy by design.
- Article 47. Processing agents and anyone else involved in any phase of processing are bound to ensure information security, even after processing ends. Suppliers fall within its reach.
- Article 48. The controller must notify the ANPD and the data subject of any security incident that may cause relevant risk or harm to data subjects.
- Article 49. Systems used for processing must be structured to meet security requirements, good practice and governance standards, and the law's principles.
Two points change how this reads. The principle of accountability (Article 6, X) requires the agent to be able to demonstrate that it adopted effective measures. And the sole paragraph of Article 44 states that the controller or processor that causes harm by failing to adopt the measures in Article 46 is liable for damages resulting from the security breach. In practice, personal data security becomes a matter of evidence.
Paragraph 1 of Article 46 also allows the ANPD to set minimum technical standards. It is worth following the authority's regulatory agenda: a rule of that kind would become the reference to meet.
Good practices and governance: Article 50
Article 50 allows controllers and processors to draw up good practice and governance rules. Paragraph 2 describes the minimum content of a privacy governance program, including: policies and safeguards based on systematic assessment of privacy impacts and risks, internal and external oversight mechanisms, incident response and remediation plans, and constant updating based on continuous monitoring and periodic assessments.
The program is optional, but it carries weight when sanctions are calculated, as we explain in LGPD dosimetry and ANPD fines. Here the focus is the technical side.
The ANPD guide for small processing agents
In October 2021, the ANPD published its Guidance on Information Security for Small Processing Agents (version 1.0), prepared with input from CERT.br. Its measures are presented as good practices, to be supplemented as needed. They include:
- Administrative. An information security policy, even a simplified one, reviewed periodically; awareness and training; confidentiality agreements; security clauses in contracts with IT suppliers.
- Technical. Least-privilege access control, with no shared accounts and no default passwords; multi-factor authentication for systems holding personal data; collecting only what is necessary; encryption and pseudonymization of sensitive data; regular backups stored in a separate location and not synchronized in real time, so they survive ransomware; encrypted connections; firewall and WAF; system updates and antivirus.
- Mobile and cloud. The same access controls on mobile devices, remote wipe in case of loss, and cloud contracts that address data security.
Although written for smaller companies, the guide works as a floor for organizations of any size.
Incidents: notification and record-keeping
CD/ANPD Resolution No. 15 of April 24, 2024 approved the Security Incident Reporting Regulation. Notification to the ANPD and to data subjects is required when the incident may significantly affect data subjects' interests and fundamental rights and involves at least one of these criteria: sensitive data; data of children, adolescents or older people; financial data; system authentication data; data protected by confidentiality; or large-scale data.
The deadline is three business days from the moment the controller learns that the incident affected personal data, doubled for small processing agents, with the option to supplement the information within twenty business days. For security teams, the most operational provision is Article 10: every incident must be recorded, including those not reported, and the record kept for at least five years, with the risk assessment, the measures taken and, where applicable, the reasons for not reporting.
Encryption counts in the assessment. Article 48, paragraph 3, of the LGPD provides that, when judging the severity of an incident, the authority will consider evidence of technical measures that render the data unintelligible to unauthorized third parties.
From law to control: a practical mapping
The LGPD does not cite technical standards, but ISO/IEC 27001:2022 is a recognized framework for organizing controls and producing evidence. The mapping below is indicative:
- Data inventory and classification. Which personal data exists, where it lives and who accesses it; it ties into the record of processing operations in Article 37. ISO 27001: 5.9 (asset inventory), 5.12 (classification) and 5.34 (privacy and protection of PII).
- Access control and MFA. Least privilege, periodic review, named accounts and MFA on systems with personal data. ISO 27001: 5.15, 5.18, 8.2 and 8.5. See also privileged access management.
- Encryption. Data in transit and at rest, with key management kept separate from the data. ISO 27001: 8.24; masking and pseudonymization under 8.11.
- Logging and monitoring. A record of who accessed what, and someone watching the alerts; without it, there is no way to determine the scope of an incident. ISO 27001: 8.15 and 8.16.
- Vulnerability management. Remediation prioritized by real-world exploitation. ISO 27001: 8.8. On prioritization, see CVSS, EPSS and KEV.
- Backup. Isolated or immutable copies and tested restores. ISO 27001: 8.13. More in backup and cyber resilience.
- Incident response. Risk criteria aligned with Article 5 of Resolution No. 15, a decision flow that fits within three business days, and a record of every incident. ISO 27001: 5.24 to 5.28.
- Third-party management. Security clauses, instructions to the processor (Article 39) and a duty to report incidents. ISO 27001: 5.19 to 5.23.
- Security by design. Security and privacy requirements from the start of every project (Article 46, paragraph 2). ISO 27001: 5.8 and 8.25.
For organizations that already run a management system, ISO/IEC 27701 extends 27001 to privacy information management, as we cover in 27000, 27001, 27002 and 27701. A gap analysis against these controls, carried out by a GRC team, is usually the fastest starting point.
Frequently asked questions
Does the LGPD require encryption or MFA?
Not by name. The law requires measures capable of protecting the data, considering the nature of the information and the state of technology. But the ANPD guide recommends MFA for systems holding personal data, and encryption is expressly taken into account when assessing the severity of an incident (Article 48, paragraph 3).
Does ISO 27001 certification mean LGPD compliance?
No. Certification helps demonstrate security measures, but the LGPD also covers legal bases, data subject rights, the data protection officer and transparency, which fall outside the scope of 27001.
Do I need to record an incident that was not reported to the ANPD?
Yes. Article 10 of CD/ANPD Resolution No. 15/2024 requires every security incident to be recorded, including unreported ones, for at least five years, with the risk assessment and the reasons for not reporting.
Sources consulted: Law No. 13,709/2018 (LGPD), Articles 6, 37, 39, 44 and 46 to 50, on the Brazilian Presidency's legislation portal; CD/ANPD Resolution No. 15 of April 24, 2024 (Security Incident Reporting Regulation); ANPD, Guia Orientativo sobre Segurança da Informação para Agentes de Tratamento de Pequeno Porte, version 1.0, October 2021; ISO/IEC 27001:2022, Annex A. The mapping to ISO/IEC 27001 is indicative and does not represent an official equivalence. This article is educational and does not constitute legal advice; for specific cases, consult the official texts and a specialized lawyer.
Official references
- Lei nº 13.709/2018 (LGPD), texto compilado — Presidência da República
- Guia Orientativo sobre Segurança da Informação para Agentes de Tratamento de Pequeno Porte — ANPD
- Resolução CD/ANPD nº 15/2024 (Regulamento de Comunicação de Incidente de Segurança) — Biblioteca Digital do Ministério da Justiça
- Comunicação de Incidente de Segurança — ANPD