Published on
· July 10, 2026

LGPD: what it is, data subjects'' rights and company duties

Blog
  • Photo of Henrico Piubello
    Henrico Piubello
    Henrico Piubello
    IT Specialist - Grupo Voitto

    IT Specialist - Grupo Voitto

The LGPD (General Data Protection Law, Law No. 13.709/2018) is the Brazilian legislation that regulates the collection, processing and sharing of personal data by companies and public bodies. It gives the citizen control over their information and imposes duties of transparency and security on those who process it.

What is the LGPD?

The LGPD is Brazil's regulatory framework for privacy, inspired by the European GDPR (the General Data Protection Regulation) and in force since September 18, 2020, according to the Federal Senate. It establishes clear rules for every operation with personal data — from an e-commerce sign-up to a human resources system — with the goal of protecting citizens' privacy and informational self-determination.

The law applies to any organization that processes data of people in Brazil, regardless of where the company is headquartered. Violating its rules exposes the business to sanctions from the ANPD (National Data Protection Authority) and, above all, to the loss of customer trust. Good information security practices have stopped being a differentiator and become a legal obligation.

What are the LGPD's principles?

The LGPD is grounded in ten principles that guide all data processing. They work as a legality test: if a practice violates any of them, it is likely out of compliance with the law.

  • Purpose: the collection must have a specific and legitimate purpose, informed to the data subject.
  • Adequacy: the processing must be compatible with the stated purpose.
  • Necessity: collect only the essential data, avoiding excess.
  • Free access: the data subject can consult their data and how it is used.
  • Data quality: the information must be accurate and up to date.
  • Transparency: clearly inform how the data is processed.
  • Security: adopt technical measures against leaks and improper access.
  • Prevention: anticipate risks before they become incidents.
  • Non-discrimination: data cannot be used for discriminatory purposes.
  • Accountability: demonstrate compliance and assume responsibility for the actions.

Every data processing must rely on at least one of the LGPD's ten legal bases. Consent is the best known, but it is far from the only one — and relying solely on it is usually a compliance mistake.

Legal basisWhen it applies
ConsentFree and informed authorization from the data subject
Legal obligationRequirement of law or regulation
Execution of contractData necessary for a contract with the data subject
Legitimate interestInterest of the controller without harming rights
Protection of lifeCritical physical safety situations
Health careMedical and care contexts

The other bases include the regular exercise of rights, credit protection, research and the execution of public policies. Choosing the correct basis is the first step of any compliance project.

What are the data subjects' rights?

The data subject is the person to whom the information refers, and the LGPD guarantees a series of rights that can be exercised for free. These rights shift power from companies to the citizen.

They include the right of access, rectification of incorrect data, deletion, objection to processing, portability to another provider, not being subjected to solely automated decisions and revoking consent at any time. It is up to the controller to respond to requests within deadlines defined by the ANPD.

What do companies need to do to comply?

Compliance with the LGPD is a continuous process, not a one-off project. Organizations need to map the data they process throughout the entire data pipeline, define the legal basis for each operation and implement technical and organizational controls.

The main obligations include: appointing a Data Protection Officer (DPO) as a point of contact, preparing a Data Protection Impact Report (DPIA/ RIPD) for risky processing, keeping a record of processing activities, adopting security measures, reporting incidents to the ANPD and to data subjects, publishing a clear privacy policy and training teams. Companies that handle authentication and access should review practices such as the use of SSH and access keys and adopt access control mechanisms in the style of a gatekeeper to protect credentials.

What are the LGPD's sanctions?

Enforcement of the LGPD falls to the ANPD, which applies administrative sanctions since August 1, 2021, when articles 52 to 54 of the law came into force. In February 2023, the authority published the Dosimetry Regulation (Resolution CD/ANPD No. 4), which defines the criteria for calculating fines. The goal is to encourage compliance, not just punish.

Penalties range from a warning to a fine of up to 2% of the company's revenue in Brazil, capped at R50millionperinfraction,plusadailyfine,publicizationoftheinfraction,blockinganddeletionofdata,and,inextremecases,partialortotalsuspensionofprocessingactivities.ThefirstfineintheLGPDshistorywasappliedonJuly6,2023,[totalingR 50 million per infraction, plus a daily fine, publicization of the infraction, blocking and deletion of data, and, in extreme cases, partial or total suspension of processing activities. The first fine in the LGPD's history was applied on July 6, 2023, [totaling R 14.4 thousand against the company Telekall Infoservice](https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-aplica-a-primeira-multa-por-descumprimento-a-lgpd) for processing data without a legal basis. Reputational damage, however, usually exceeds the value of the fines.

Conclusion

The LGPD has gone from being an exclusive concern of the legal department to becoming part of the engineering and culture of any company that processes data — that is, practically all of them. At CodeCrush, we treat data protection as a project requirement, not as a final patch: thinking about purpose, necessity and security from the first line of code is what separates real compliance from compliance theater.

📜 Read the full General Data Protection Law and consult the LGPD best practices guide published by the federal government.

## faq

Frequently asked questions

What is the LGPD in a few words?

The LGPD is the General Data Protection Law (Law 13.709/2018), the Brazilian legislation that defines rules for the collection, storage, processing and sharing of personal data. It applies to companies and public bodies and gives the citizen control over their own information.

What are the data subject''s rights under the LGPD?

The data subject can confirm the existence of processing, access their data, correct incomplete information, request anonymization or deletion, request portability to another provider, revoke consent and object to irregular processing. These rights are exercised for free with the data controller.

What is the difference between controller and processor under the LGPD?

The controller is who decides how and why personal data is processed, assuming primary responsibility. The processor performs the processing on behalf of the controller, following their instructions. A company that hires an email marketing service, for example, is the controller, and the hired platform is the processor.

What are the LGPD''s fines?

The ANPD can apply a warning, a fine of up to 2% of the company''s revenue in Brazil (capped at R$ 50 million per infraction), a daily fine, publicization of the infraction and even the suspension or prohibition of data processing activities in the most serious cases.

Is consent always necessary to process data?

No. Consent is only one of the LGPD''s ten legal bases. A company can process data without consent when there is compliance with a legal obligation, execution of a contract, legitimate interest, protection of life or health care, among other hypotheses provided for in the law.

Topics in this article

## continue lendo

Keep browsing

About the author

Photo of Henrico Piubello

Henrico Piubello

IT Specialist - Grupo Voitto · Grupo Voitto

See profile and all articles