Lei Geral de Proteção de Dados Pessoais
The LGPD is Brazil's national data protection law, described as the country's first comprehensive framework regulating how personal data is collected, used, and processed, including in digital environments. It sets guidelines that organizations handling personal data must follow. This entry describes the law's general character and scope and does not cover specific obligations, penalties, cross-border transfer mechanics, or how requirements are enforced.
The Lei Geral de Proteção de Dados Pessoais (LGPD), enacted in Brazil, is described in the evidence as Brazil's first comprehensive data protection regulation governing the processing (tratamento) of personal data, including in digital media, and as broadly aligning with the EU approach to data protection. One stated aim is to unify multiple prior Brazilian laws that regulated the processing of personal data into a single framework. Practitioners should note that alignment with the EU model is described as broad rather than identical; the LGPD is a distinct instrument and should not be treated as interchangeable with the EU GDPR, UK GDPR, or other regimes, and specific definitions of roles, lawful bases, and controller and processor obligations must be assessed against the LGPD's own text and jurisdictional context. This definition addresses the law's identity and general scope only; it does not detail lawful bases for processing, data subject rights, records or impact assessment obligations, retention rules, international transfer mechanisms, or enforcement and penalty provisions, which require separate analysis.
Why it matters
The LGPD represents Brazil's first comprehensive framework regulating how personal data is collected, used, and processed, including in digital environments. For organizations operating in or serving individuals in Brazil, it establishes a national baseline where previously the treatment of personal data was governed by a patchwork of separate laws. Its stated aim of unifying numerous prior Brazilian laws into a single framework means that compliance efforts that once had to reconcile fragmented rules can now be oriented around one primary instrument, though the practical obligations under that instrument still require careful analysis against its own text.
Because the LGPD is described as broadly aligning with the EU approach to data protection, organizations already familiar with EU-style frameworks may recognize some structural similarities. However, this alignment is broad rather than identical, and treating the LGPD as interchangeable with the EU GDPR, the UK GDPR, or any other regime is a common and consequential mistake. Definitions of roles, lawful bases, and controller and processor obligations must be assessed against the LGPD's own provisions and Brazilian jurisdictional context, not assumed from another law. Misapplying assumptions carried over from a different regime can lead organizations to misjudge their responsibilities.
This entry describes the law's general character and scope only. It does not address specific lawful bases, data subject rights, records or impact assessment obligations, retention rules, cross-border transfer mechanics, or enforcement and penalty provisions. Each of those areas requires separate, jurisdiction-specific analysis before an organization can rely on any conclusion about its LGPD posture.
Who it's relevant to
Inside LGPD
Common questions
Answers to the questions practitioners most commonly ask about LGPD.