The LGPD, explained: a practical guide for companies and website owners

Brazil's data-protection law in plain English — who it reaches, what it costs to ignore, what your website must actually do, and how to check your exposure in a minute. Leia em português.

The basics

What is the LGPD?

The LGPD (Lei Geral de Proteção de Dados, Law No. 13,709/2018) is Brazil's general data-protection law. It has been in force since September 2020, with administrative sanctions enforceable since August 2021, and it governs how any organization — public or private, inside Brazil or not — collects, uses, stores, and shares the personal data of people in Brazil. It is supervised by a national regulator, the ANPD (Autoridade Nacional de Proteção de Dados). If your website has Brazilian visitors or your company serves Brazilian customers, the LGPD is very likely part of your compliance surface.

Does the LGPD apply to companies outside Brazil?

Usually, yes. The law applies extraterritorially (Article 3): it covers processing carried out in Brazil, data collected in Brazil, and — the broadest trigger — processing whose purpose is to offer goods or services to individuals located in Brazil. A US SaaS company with Brazilian users, a European store shipping to São Paulo, and a remote-first employer hiring Brazilian engineers are all in scope, no office in Brazil required. For the hiring and background-check angle specifically, see our FAQ.

How is the LGPD different from the GDPR?

They are close relatives — a GDPR program covers most of the LGPD — but the differences matter in practice:

A safe mental model: GDPR compliance gets you roughly 80% of the way, and the remaining 20% — legal-basis mapping, the encarregado, Portuguese-language notices, ANPD transfer rules — is real work.

What are the penalties for violating the LGPD?

The ANPD's sanctions menu (Article 52) ranges from warnings with corrective deadlines, through daily fines and simple fines of up to 2% of the company's revenue in Brazil (capped at R$50 million per infraction), to publicizing the violation and, at the top end, suspending or banning the processing activity itself. Enforcement started deliberately — the first fines came in 2023 — and has been expanding since. For most companies the practical near-term risks are corrective orders, the reputational cost of a publicized violation, and the operational shock of a processing ban, more than the headline fine number.

What your website must do

What does the LGPD actually require of a typical website?

For a typical commercial site, the recurring requirements are:

What is an "encarregado" (DPO), and does a small company need one?

The encarregado (Article 41) is the LGPD's counterpart to a DPO: the named person or company that answers to data subjects and to the ANPD. On paper every controller needs one; in practice the ANPD's small-business rule (Resolution CD/ANPD No. 2/2022) exempts micro and small enterprises and startups from appointing one — but they must still offer a working communication channel for privacy matters. Past small-business size, appoint one and publish the contact in your privacy notice.

What rights can Brazilian users exercise against my company?

Article 18 gives data subjects the right to confirmation that you process their data, access to it, correction, anonymization or deletion, portability, information about who you share it with, and revocation of consent — generally free of charge and within defined response windows. Operationally the bar is simple to state: a request arrives by email, and your team can actually find, export, correct, or delete that person's data. If no one at your company could do that today, that gap matters more than any banner.

Checking your exposure

How do I find out if my website is exposed?

The outside-in signals are checkable in seconds, and that is what our free scan does: it loads your site the way a visitor's browser does and reports which trackers fire before any consent, whether a consent banner exists, whether a privacy policy is reachable, whether cookies are set on first load, and whether HTTPS is enforced — scored 0–100, with the relevant LGPD articles cited for each finding. It is free, takes about a minute, and requires no account. Results are in Portuguese.

Does VerifyBR fix the problems its scan finds?

No — and that is deliberate. We are an assessor, not a remediation consultant: the same logic that says a SOC 2 auditor should not sell you the controls it audits. The scan tells you honestly where your site stands and what each finding means under the law; the fixing belongs to your developers or your privacy counsel. That separation is what keeps the assessment worth something.

Where do hiring and background checks fit in?

If your LGPD exposure comes from hiring Brazilians — background checks, credential verification, cross-border candidate data — that is a distinct set of questions: the lawful basis for verification, candidate consent in Portuguese, and international transfer via consent or standard contractual clauses. Start with our FAQ on verifying Brazilian credentials or the guide to why background checks fail in Brazil.

See where your site stands in one minute. The free VerifyBR scan checks trackers, consent, privacy policy, and HTTPS from the outside — scored, with the LGPD article behind every finding. No account, no commitment.

This guide is educational information, not legal advice. For decisions about your company's obligations under the LGPD, consult a lawyer qualified in Brazilian law. Last updated July 14, 2026.