Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

What is the LGPD?

DefinitionThe LGPD (Lei Geral de Proteção de Dados Pessoais, Law No. 13,709/2018) is Brazil's law regulating the processing of personal data by companies and public bodies, setting data subject rights and security obligations, enforced by the ANPD, the national data protection authority.

How it works

The LGPD applies to any processing of personal data, digital or physical, carried out in Brazil, aimed at offering goods or services to people in Brazil, or involving data collected in the country. Every processing activity needs a legal basis, such as consent, compliance with a legal obligation, performance of a contract or legitimate interest. The law defines roles:

  • Data subject: the person the data refers to.
  • Controller: who makes decisions about the processing.
  • Processor: who processes the data on the controller's behalf.
  • Data protection officer (encarregado): the communication channel between controller, data subjects and the ANPD.

Where the LGPD meets cybersecurity

The law requires processing agents to adopt technical and administrative security measures to protect data from unauthorized access and accidental or unlawful situations. It also requires the controller to notify the ANPD and data subjects of any security incident that may cause relevant risk or harm. In practice, this demands the ability to detect, investigate and document incidents: without knowing which data were affected, there is no way to assess the risk or notify correctly.

Sanctions

Article 52 provides sanctions ranging from a warning to a simple fine of up to 2% of revenue in Brazil, capped at BRL 50 million per violation, as well as public disclosure of the violation, blocking and deletion of data, among others. Fines are calculated under the ANPD's sanction calculation regulation.

LGPD vs ISO 27001: the LGPD is a law and deals with personal data; ISO/IEC 27001 is a voluntary standard on information security in general. A well-implemented ISMS helps demonstrate the security measures the law requires.

Network Secure supports GRC and incident response programs that help meet the LGPD's security requirements.

Frequently asked questions

What is the difference between the LGPD and the GDPR?

The LGPD is Brazil's data protection law; the GDPR is the European Union's regulation. They share similar principles but differ on points such as legal bases, deadlines and sanction amounts.

Must every data breach be reported to the ANPD?

The LGPD requires notifying the ANPD and data subjects of incidents that may cause relevant risk or harm. Assessing that risk depends on investigating what was affected.

Go deeper