Lei Geral de Proteção de Dados Pessoais (LGPD)
Lei nº 13.709 de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 18 September 2020.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Establish a lawful basis under article 7 before processing personal data, including data the person has made public.
- Take consent only when it is provided in writing or by another means demonstrating the data subject's free will, in a clause set apart from the other contract terms, and be ready to prove it meets these requirements.
- Keep a record of your processing operations, especially those based on legitimate interest, and name a person in charge (encarregado) whose identity and contact details you publish, preferably on your website.
- Adopt technical and administrative security measures suited to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or improper processing, from the design of the product or service through its execution.
- Delete personal data once processing ends, unless retention is needed to comply with a legal or regulatory obligation, for research with anonymization where possible, for an authorized transfer, or for your own exclusive anonymized use.
- As a public body, publish clear, up to date information about the legal basis, purpose and procedures for any processing you carry out, name a person in charge for it, and do not pass on personal data you hold to a private entity except in the cases the law lists.
What it reaches
Obligation class
Consent, Security, Retention, Governance, DPIA
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The LGPD applies to any operation processing personal data by a natural or legal person, public or private, wherever performed, when the operation happens in Brazil, aims to offer goods or services to a person in Brazil, or processes data collected in Brazil, and article 4 exempts processing for exclusively personal and non-economic purposes, for journalistic, artistic or academic purposes, for public safety, national defense, state security or criminal investigation and enforcement under specific legislation, and data originating outside Brazil that is never shared with a Brazilian controller or transferred onward.
Article 5 defines the personal data, controller, operator and encarregado (data protection officer) roles that anchor the regime, and its most recent redação, given by Lei nº 15.352, de 2026, confirms that the body those roles report to is now the Agência Nacional de Proteção de Dados (ANPD), not the Autoridade Nacional de Proteção de Dados the LGPD originally created.
Article 6 states the purpose limitation, necessity, transparency, security and accountability principles that govern every processing operation, and article 7 lists ten lawful bases for ordinary personal data, from consent to legitimate interest, while article 8 sets consent's formal requirements, including a clause set apart from other contract terms and a burden of proof on the controller.
Article 9 requires clear, adequate and prominent information about the processing, and article 10 conditions a legitimate-interest basis on strictly necessary data and transparency measures. Articles 15 and 16 require personal data to be deleted once processing ends, unless retention is needed for a legal obligation, anonymized research, an authorized transfer, or the controller's own anonymized use.
Articles 23 to 32 require a public body to publish the legal basis, purpose and procedures for any processing it carries out, bar it from transferring personal data to a private entity outside the listed cases, and let the ANPD demand a report or issue guidance where a public body's processing violates the law.
Article 37 requires a record of processing operations, especially those resting on legitimate interest, article 38 lets the ANPD demand a data protection impact report, and article 41 requires the controller to name an encarregado and publish their contact details.
Articles 46, 47 and 49 require technical and administrative security measures against unauthorized access and accidental or unlawful destruction, loss, alteration or improper processing, from a product's design through its operation, and articles 50 and 51 encourage a governance program with internal rules, risk-mitigation mechanisms and complaint channels.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Official compiled text of Lei nº 13.709/2018, Presidência da República
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.