Does the LGPD apply to your business?
The LGPD applies in either one of the following two scenarios:
- if your company operates servers in Brazil or has a physical presence there
- if you process the personal data of Brazilians (by accepting payments, email addresses, or monitoring IP addresses)
If you fall within either category, you must take steps to comply with the LGPD.
Learn what's required for LGPD compliance
Here are the critical legal pages you need to get compliant with LGPD.
Features you need to meet LGPD compliance
Build a custom privacy policy, terms of service, cookie consent banner, and Do Not Sell My Personal Information page that complies with the LGPD.
Privacy Policy
Data Subject Access Rights Form
Create a Do Not Sell My Personal Information form to allow customers to opt-out.
Cookie Consent
Easily manage consent through our customizable cookie banner and cookie manager generator.
25+ Languages
Available in English, French, German, Italian, Danish, Japanese, Spanish, EU Portuguese, Dutch and more.
Your privacy policy must be up to date
To ensure compliance with Brazil's LGPD, websites must have specific sections in their privacy policy. This includes third-party data sharing, purposes of storing data, and more.
-
Information must be complete and accessible
-
Accessible on your website or mobile app
-
Automatic updates as laws change
Display a cookie banner and allow users to opt out
LGPD-compliant cookie consent banners must allow users the ability to opt out of tracking. Build yours in minutes, with customizable text, colours, layout and configuration.
-
Set cookie preferences for LGPD compliance
-
Include links to your privacy policy
-
Add analytics tracking integrations from popular services
Allow customers to request access for or to delete their personal data
LGPD data requests must be completed within 30 days, or else businesses can face expensive fines. With Enzuzo's streamlined privacy dashboard, you can track every request from start to finish.
-
Create a "Do Not Sell My Personal Information" page in minutes
-
Customers can opt-out or request personal information
-
Manage and complete data requests in one place
LGPD compliance FAQs
What are LGPD regulations?
The Lei Geral de Proteção de Dados Pessoais (LGPD) is the Brazilian general data protection law, similar to the EU’s General Data Protection Regulation (GDPR). It was introduced in 2020 to give Brazilians greater rights over their personal information, and to place new responsibilities on organizations that collect and process it.
Our guide to LGPD has more information.
Who Does the LGPD Apply To?
The LGPD applies in situations where one or more of the following are involved:
- Data collected within Brazil is processed in any location
- Data is processed within the territory of Brazil
- Data that concerns people located within Brazil is processed in any location
Do I need to keep records of data processing activities?
Under the LGPD, it is mandatory that you keep records of your data processing activities — you can be fined if you don't maintain these actively.
What is the penalty for noncompliance with the LGPD?
The penalties for non-compliance can include fines of up to 2% of your company’s annual turnover or US$9M – per violation.
Is the LGPD the same as the GDPR?
While both laws are meant to guarantee people's privacy of their personal information and ensure there is compliance, the two have several unique differences.
For instance, the LGPD is squarely focused on Brazil while the GDPR focuses on data subjects (any person residing in the European Union who is identifiable, both directly and indirectly). Nevertheless, the two regulations are considered global solutions to data privacy, albeit under somewhat different circumstances.
Do you have a LGPD compliance checklist?
Yes, our LGPD requirements checklist can be found on our data privacy compliance page.
The page includes a LGPD audit checklist and advises you of the necessary legal pages for your business to be compliant.