General Data Protection Law (LGPD)
Brazil's GDPR. The General Data Protection Law (LGPD) governs how organizations handle personal data in Brazil — in force since 2020, modeled on the EU's GDPR, and overseen by a national authority.
- Term
- General Data Protection Law (LGPD)
- Is
- Brazil's comprehensive data-protection law
- In force
- 2020, GDPR-inspired
- Regulator
- National Data Protection Authority (ANPD)
Parts of speech & senses
- The General Data Protection Law (LGPD), Lei Geral de Proteção de Dados, is Brazil's comprehensive, GDPR-inspired data-protection law, in force since 2020 and regulated by the ANPD. "The LGPD reshaped how we collect data in Brazil."
What the LGPD is
The General Data Protection Law (LGPD) — Lei Geral de Proteção de Dados in Portuguese — is Brazil's comprehensive national data-protection law. It governs how organizations collect, use, store, share, and otherwise process the personal data of people in Brazil, and it came into force in 2020. The LGPD is closely modeled on the European Union's General Data Protection Regulation, so its structure will be familiar to anyone who knows the GDPR: it requires a lawful basis for processing personal data, grants people a set of rights over their data, imposes duties on organizations that handle it, and applies broadly, including to companies outside Brazil that process the data of people there. It is overseen by Brazil's National Data Protection Authority, the Autoridade Nacional de Proteção de Dados (ANPD), which regulates, guides, and can penalize organizations that breach the law.
The LGPD matters because Brazil is the largest market in Latin America, and any organization that handles the personal data of people there falls within the law's reach, wherever the organization is based. Before the LGPD, data protection in Brazil was scattered across many separate laws; the LGPD unified them into a single, comprehensive regime with a dedicated regulator. For people, it establishes clear rights over their data; for organizations, it sets clear obligations and real consequences for getting it wrong, with the ANPD able to investigate and impose penalties. For marketers, the practical effect is that collecting and using customer data in Brazil — through sites, apps, CRMs, or ad campaigns — has to rest on a lawful basis and respect people's rights, exactly as the GDPR requires in Europe.
LGPD versus the GDPR and other laws
The LGPD is deliberately GDPR-inspired, so the two share a great deal: lawful bases for processing, data-subject rights, accountability duties, and broad extraterritorial reach. If you have built a GDPR-compliant program, much of it transfers conceptually to the LGPD. But the LGPD is Brazil's own law, not a copy, and the details differ — the specific lawful bases, the rights and how they are exercised, breach and transfer rules, the role and powers of the ANPD, and the penalty framework all follow Brazilian law. It also differs from the other national regimes in this family — Japan's APPI, China's PIPL, South Korea's PIPA — each of which addresses the same goal under its own rules and regulator. The LGPD is the Brazilian member of that family.
The distinction matters because a GDPR program is a strong starting point for the LGPD but not an automatic pass. The lawful basis you rely on, the way you honor rights requests, your breach-notification approach, and your handling of international transfers must be checked against the LGPD and ANPD guidance specifically, not assumed from Europe. At the same time, the conceptual overlap is genuine and useful — purpose limitation, a lawful basis for every processing activity, transparency, security, and honoring data-subject rights are shared principles. The right posture is to treat the LGPD as the governing law for personal data tied to Brazil, map your practices against it, and lean on GDPR-style hygiene as the shared foundation while respecting the points where Brazilian law goes its own way.
Working within the LGPD
Working within the LGPD well means treating it as the law that governs personal data connected to Brazil and building compliance around its requirements — establishing a lawful basis for each processing activity, being transparent about how data is used, securing it, honoring the rights the law gives people, and handling breaches and international transfers as the law directs. It means recognizing that the LGPD applies even to organizations based outside Brazil if they process the data of people there, and that the ANPD is the authority whose guidance and enforcement set the standard. For marketers, consent and data handling for Brazilian audiences should be designed against the LGPD, and a GDPR-aligned program adapted to Brazilian specifics rather than assumed to be sufficient as-is.
The failures are assuming a GDPR program automatically satisfies the LGPD, ignoring the law because the company is based outside Brazil even though it processes Brazilian residents' data, relying on a lawful basis or rights process that does not match the LGPD, and overlooking the ANPD's guidance and enforcement. The discipline is to map personal-data flows tied to Brazil against the LGPD specifically — lawful basis, transparency, security, data-subject rights, breach handling, and transfers — adapt a GDPR foundation to Brazilian rules, and keep current with the ANPD, recognizing that the conceptual overlap with the GDPR is real but the governing details are Brazil's own.
Synonyms & antonyms
Synonyms
Antonyms
Origin & history
General Data Protection Law (LGPD) — Lei Geral de Proteção de Dados — Brazil's comprehensive, GDPR-inspired data-protection law, in force since 2020 and regulated by the National Data Protection Authority (ANPD).
Etymology: source.
Usage trends
Search interest for this term over the last five years:
Common questions
- What is the LGPD?
- The General Data Protection Law — Lei Geral de Proteção de Dados — Brazil's comprehensive, GDPR-inspired data-protection law, in force since 2020, governing how organizations handle personal data in Brazil and regulated by the ANPD.
- Is the LGPD the same as the GDPR?
- No. The LGPD is closely modeled on the GDPR and shares its structure, but it is Brazil's own law with its own lawful bases, rights, transfer rules, regulator, and penalties, so a GDPR program is a strong base but not an automatic pass.
- Who regulates the LGPD?
- Brazil's National Data Protection Authority, the Autoridade Nacional de Proteção de Dados (ANPD), which regulates, issues guidance, and can investigate and penalize organizations that breach the law.
Resources & people to follow
- referenceRGM analysis — definitions, senses, and usage verified per term
Curated, non-competitor resources verified per term.
Related training
Disciplines
Areas of marketing where general data protection law (lgpd) is a core concern:
Related terms
Sources
- trendsGoogle Trends — "lgpd"