LGPD (Brazil, Law 13,709/2018): cited answers and gap reviews
Brazil's Lei Geral de Proteção de Dados governs personal data processing in Brazil, enforced by the ANPD. Compliance Colleague covers legal bases, data subject rights, breach notification, DPO duties and international transfers, including Brazil-EU mutual adequacy.
What it covers
- The legal bases for processing and sensitive data
- Data subject rights and DPO appointment
- Breach notification to the ANPD
- International transfers and Brazil-EU mutual adequacy (January 2026)
- Penalties of up to 2% of revenue, capped at R$50 million per infraction
Questions you can ask
- “Do we still need SCCs for transfers between Brazil and the EU?”
- “Which legal basis fits our employee monitoring?”
- “How quickly must we notify the ANPD of a breach?”
Every answer cites the LGPD requirement, article or control it rests on, so you can check it in seconds.
What you can upload for review
- Your privacy policy for Brazil checked against the LGPD
- A DPIA checked for gaps
- A consent flow screenshot checked for valid consent
Files: PDF, Word, Excel or CSV, Visio (.vsdx), draw.io, or an image such as a screenshot. Choose a full review, a prioritized fix list (each gap with its fix and the evidence an assessor will expect) or a short summary, and download the result as Word or PDF.
Crosswalk LGPD to other standards
With LGPD in your plan you can compare it against any standard in the library and see where they align and exactly where they don’t. Common pairings:
What it’s built from
Compliance Colleague carries the official text and checks its answers against it: Lei nº 13.709/2018, Lei Geral de Proteção de Dados Pessoais (LGPD), consolidated text (texto compilado) (Presidência da República, Casa Civil (Planalto)).
Re-checked every month for new versions, deadlines and penalty changes. Full list on the sources page.
Research aid, not legal or audit advice, and not an audit opinion or certification. Verify findings against the official text before relying on them.