You run a company outside Brazil. Maybe your headquarters are in Lisbon, New York, or Berlin. You sell to Brazilian customers online, or you just acquired a Brazilian subsidiary. Now you keep hearing about the “LGPD” and wondering: does this Brazilian law really apply to my foreign company? And what happens if I ignore it?
The short answer is yes, it very likely applies to you, and ignoring it can cost up to R$ 50 million per infraction. The LGPD (Lei Geral de Proteção de Dados, Brazil’s General Data Protection Law, Law 13.709/2018) has extraterritorial reach. Your company does not need to be based in Brazil to be bound by it.
If you offer goods or services to people located in Brazil, process data collected in Brazil, or employ staff there, you fall under the law. Your servers can sit in Frankfurt and your CEO in California. What matters is where the data subjects are.
This guide explains, in plain English, exactly what foreign companies must do to comply with the LGPD in 2026: who is covered, what the penalties are, the legal bases you can rely on, how it differs from Europe’s GDPR, and the practical steps to build a compliance program that holds up before Brazilian regulators. This is a satellite of our broader guide on doing business in Brazil as a foreigner.
On this page
Does the LGPD Apply to Your Foreign Company?
Yes, if any of three triggers in Article 3 of Law 13.709/2018 apply. The LGPD covers any processing of personal data when the operation happens in Brazil, when the purpose is to offer goods or services to individuals located in Brazil, or when the data was collected in Brazil, regardless of where your company is headquartered.
The Brazilian Migration Law and other statutes tie residency and business to physical presence. The LGPD is different. It follows the data subject, not the company. This is why a foreign e-commerce site with no office in Brazil can still be fully liable.
Here are practical scenarios where the LGPD applies to a foreign company:
- You run a SaaS platform accessed by Brazilian users who register with their name and email.
- Your online store ships products to customers in Brazil and stores their CPF (individual taxpayer number), address, and payment data.
- You employ remote workers or contractors located in Brazil and process their RG (national ID) and CPF.
- You acquired a Brazilian company that holds a customer database collected locally.
- Your marketing team runs targeted ads at Brazilian audiences and captures leads.
Important: The law explicitly states that the location of your servers and headquarters is irrelevant. If the data was collected from people in Brazilian territory, the LGPD reaches you. You can read the full text of Law 13.709/2018 on the official Planalto government portal.
There are narrow exceptions. The LGPD does not apply to processing done by a natural person for purely personal purposes, nor to processing exclusively for journalistic, artistic, or academic purposes, nor to matters of national security. These exceptions rarely cover a commercial foreign company.
What Are the Penalties for Not Complying With the LGPD?
Under Article 52 of the LGPD, the ANPD (National Data Protection Authority) can impose fines of up to 2% of your company’s revenue in Brazil for the prior fiscal year, capped at R$ 50 million (about USD 9 million) per infraction. It can also block databases, delete data, publicize the violation, and suspend or prohibit your data processing activities.
The ANPD is the enforcement agency created by the law. It has been active in monitoring, guidance, and increasingly in sanctioning. Penalties escalate depending on severity, cooperation, and whether the company adopted corrective measures.
The full list of administrative sanctions available to the ANPD includes:
| Sanction | Detail |
|---|---|
| Warning (advertência) | With a deadline to adopt corrective measures |
| Simple fine | Up to 2% of Brazilian revenue, capped at R$ 50 million per infraction |
| Daily fine | Subject to the same R$ 50 million total cap |
| Publicizing the infraction | Public disclosure after confirmation |
| Blocking of personal data | Until the situation is regularized |
| Deletion of personal data | Full erasure of affected data |
| Suspension of the database | Up to 6 months, extendable |
| Prohibition of processing | The most severe measure |
Example: A foreign company with R$ 60 million in Brazilian revenue that suffers a serious data breach and had no compliance measures could face a simple fine of up to R$ 1.2 million (2% of revenue), plus daily fines and mandatory public disclosure that damages its brand.
Beyond ANPD fines, there is a second layer of exposure many foreigners overlook: civil liability. Data subjects can sue for moral and material damages in Brazilian courts. Consumer protection agencies and the Public Prosecutor’s Office (Ministério Público) can also file collective actions. You can review the ANPD’s activities and official guidance on the gov.br ANPD portal.
Warning: Fines stack per infraction. A single incident touching thousands of records can generate multiple violations. Treating the R$ 50 million figure as a comfortable ceiling is a serious mistake.
What Legal Basis Do You Need to Process Personal Data?
Under Article 7 of the LGPD, you must have a valid legal basis for every processing activity. There are ten legal bases, including consent, contract performance, legal obligation, legitimate interest, and credit protection. Consent is not the only option, and for many business operations it is not the best one.
Foreign companies coming from a GDPR mindset often over-rely on consent. Under Brazilian law, consent must be free, informed, and unambiguous, and it can be withdrawn at any time, which makes it fragile for operational data. The most common legal bases for commercial operations are:
- Consent: best for marketing communications and optional features.
- Performance of a contract: ideal for processing customer data needed to deliver a purchased product or service.
- Legal or regulatory obligation: for tax records, labor filings, and retention duties.
- Legitimate interest: for fraud prevention, network security, and certain analytics, subject to a balancing test.
- Protection of credit: for credit scoring and default prevention.
Sensitive personal data (Article 11) gets stricter treatment. This includes data on racial or ethnic origin, religious belief, political opinion, union membership, health, sex life, and genetic or biometric data. For sensitive data, the legal bases are narrower and consent, when used, must be specific and highlighted.
Tip: Map each processing activity to a single, documented legal basis before you start. Absence of documented legal bases is, according to compliance practitioners, the single most reliable indicator of an immature LGPD program, and the first thing the ANPD asks about.
How Does the LGPD Differ From the GDPR?
The LGPD was modeled on the European GDPR, so they are roughly 80% similar in structure and principles. However, key differences require specific adaptation: the LGPD has ten legal bases (not six), lower maximum fines (R$ 50 million versus 4% of global turnover under GDPR), different data subject rights, and mandatory processing records under Brazilian standards.

Assuming your GDPR compliance automatically covers Brazil is a costly error. The frameworks diverge in important ways. Here is a side-by-side comparison:
| Aspect | LGPD (Brazil) | GDPR (EU) |
|---|---|---|
| Legal bases | 10 bases (Article 7) | 6 bases |
| Maximum fine | 2% of Brazil revenue, cap R$ 50 million per infraction | 4% of global turnover or EUR 20 million |
| Regulator | ANPD | National DPAs |
| DPO requirement | Encarregado, expected but scalable by risk | DPO mandatory in defined cases |
| Language of policies | Portuguese for Brazilian users | Local languages |
| Territorial trigger | Offering goods/services to people in Brazil | Offering goods/services to people in the EU |
The most practical difference for foreign companies is documentation language. A privacy policy written only in English will not satisfy Brazilian regulators or courts when your users are Brazilian consumers. Your policies, consent forms, and data subject request channels should be available in Portuguese.
Another difference is international data transfer. The LGPD regulates transfers of personal data abroad. If your Brazilian subsidiary sends employee or customer data to a parent company overseas, you need an appropriate transfer mechanism, such as standard contractual clauses approved by the ANPD or specific consent.
What Data Subject Rights Must You Honor?
Under Article 18 of the LGPD, data subjects have the right to confirm processing, access their data, correct it, anonymize or delete unnecessary data, obtain portability, revoke consent, and be informed about data sharing. You must respond to these requests, in principle at no cost to the individual, within a reasonable timeframe.
Brazilian users increasingly know these rights and exercise them. If a customer emails asking what data you hold and you cannot answer, or you ignore the request, you expose yourself to complaints filed directly with the ANPD.
The core rights you must be able to satisfy are:
- Confirmation that you process the person’s data.
- Access to the data you hold about them.
- Correction of incomplete or outdated data.
- Anonymization, blocking, or deletion of excessive data.
- Data portability to another provider.
- Deletion of data processed based on consent.
- Information about public and private entities you shared the data with.
- Withdrawal of consent at any time.
Note: You must provide a clear channel for these requests, ideally an email address or web form in Portuguese, and appoint someone responsible for handling them. Silence is treated as non-compliance.
You also carry a duty to report security incidents. If a breach may cause relevant risk or damage to data subjects, you must notify the ANPD and the affected individuals within a reasonable period. Failing to report is itself a violation that aggravates any fine.
What Does a Minimum Viable LGPD Program Look Like?
For a foreign company establishing or acquiring a Brazilian operation, a minimum viable LGPD program has five foundational components: a data mapping inventory, documented legal bases, a privacy policy in Portuguese, an appointed data protection officer (Encarregado), and an incident response procedure. Building these can cost between R$ 15,000 and R$ 80,000 as a one-time adequacy project.
These five pillars turn abstract legal duties into operational reality:
- Data mapping: a current inventory of all processing activities, listing the legal basis, purpose, retention period, and recipients for each.
- Legal bases documentation: a record of processing activities (ROPA) matching each activity to a valid Article 7 basis.
- Privacy policy and terms in Portuguese: transparent, accessible, and specific to your Brazilian operation.
- Encarregado (DPO): a named contact between you, data subjects, and the ANPD. This role can be outsourced, typically for R$ 1,500 to R$ 8,000 per month.
- Incident response plan: a documented procedure to detect, contain, assess, and report breaches.
Example: A mid-sized foreign SaaS company entering Brazil budgeted R$ 45,000 for a one-time adequacy project (mapping, policies, and contracts) plus R$ 3,000 per month for an outsourced Encarregado. That total is trivial next to a potential R$ 50 million exposure.
Note that there is no government registration fee to “comply” with the LGPD. Compliance is a set of ongoing obligations, not a license you buy. Anyone offering you a paid LGPD “certificate” from the government is misinformed.
What Trips Up Foreign Companies the Most?
The most damaging mistake is assuming the LGPD does not apply because the company has no legal entity in Brazil. The second is relying only on English documents and GDPR templates. Both errors surface immediately during an ANPD inquiry or an M&A due diligence, and both are expensive to fix retroactively.
If you are buying a Brazilian company, LGPD exposure is a real deal risk. A structured due diligence should cover eight areas, with data mapping first: does the target maintain a current inventory of its processing activities with documented legal bases? The absence of data mapping is the clearest sign of an immature program and a red flag for hidden liability.
Transaction documents for a Brazilian acquisition should include LGPD-specific representations and warranties from the seller covering:
- Absence of open ANPD investigations or formal notices.
- Absence of pending data subject claims.
- Material compliance with the LGPD across all processing activities.
- Notification of all material security incidents as required by law.
- Validity of the legal bases relied upon for key processing activities.
Other frequent failures include: no channel for data subject rights, indefinite data retention with no deletion schedule, sharing data with third parties (payment processors, marketing tools) without proper contracts, and no incident response plan. Employment data is a particular blind spot, since RG, CPF, payroll, and health data are all processed the moment you hire in Brazil.
Caution: Brazil uses a Civil Law system, not Common Law. Contracts and compliance obligations are interpreted strictly against the written text and statute. Vague or foreign-language documentation carries far less protective weight than in Common Law jurisdictions.
Lgpd compliance foreign companies: What Changed in 2026?
In 2026, the ANPD continues to move from an educational posture toward active enforcement, issuing more regulations and applying sanctions. The maximum fine remains R$ 50 million per infraction or 2% of Brazilian revenue. The ANPD has also matured its rules on international data transfers, making standard contractual clauses the central transfer mechanism.
Several practical developments matter for foreign companies this year:
- International transfer rules are now more concrete, so cross-border flows to a parent company need documented mechanisms rather than informal arrangements.
- The ANPD has issued guidance for small and medium processing agents, allowing scaled-down obligations for lower-risk operations, though foreign companies should not assume they automatically qualify.
- Enforcement activity and public sanctioning have increased, raising reputational stakes.
The direction of travel is clear: less tolerance for companies that treated the LGPD as optional. If you are setting up in Brazil, build compliance in from day one rather than retrofitting it after your first complaint. For the structural side of entering the market, see our guides on how to open an LTDA company in Brazil and choose between company types.
Step-by-Step: How to Get Your Foreign Company LGPD Compliant
Getting compliant follows a logical sequence, from understanding your data to embedding ongoing governance. A realistic timeline for a small or medium foreign company is 60-120 days for a first adequacy project, then continuous maintenance. Build in a buffer, as document translation and internal alignment often take longer than expected.
Step 1: Confirm the LGPD applies and define scope
Identify whether you offer goods or services to people in Brazil, process data collected there, or employ staff locally. Map which parts of your operation touch Brazilian data subjects.
Step 2: Run a data mapping exercise
Inventory every processing activity. For each, document what data you collect, why, on what legal basis, how long you keep it, and who you share it with. This is the backbone of everything else.
Step 3: Assign legal bases and fix gaps
Match each activity to a valid Article 7 basis. Where none applies, stop the activity, obtain proper consent, or restructure it. Give sensitive data special attention under Article 11.

Step 4: Draft policies and contracts in Portuguese
Prepare a privacy policy, terms of use, consent language, and data processing agreements with vendors, all in Portuguese for your Brazilian users. Budget roughly R$ 3,000 upward for professional drafting.
Step 5: Appoint an Encarregado (DPO) and set up request channels
Name a data protection officer and publish a contact channel for data subject rights. Outsourced DPO services typically run R$ 1,500 to R$ 8,000 per month.
Step 6: Handle international transfers and incident response
Put standard contractual clauses in place for any data sent abroad, and document an incident response procedure with clear ANPD notification steps.
Remember: If you are opening a CNPJ (company tax registration) in Brazil, you will also need a registered fiscal address in Brazil before you can incorporate, which is a separate but related step in establishing a compliant local presence.
Frequently Asked Questions About LGPD for Foreign Companies
Does the LGPD apply if my company has no office in Brazil?
Yes. Under Article 3 of Law 13.709/2018, the LGPD applies whenever you offer goods or services to individuals located in Brazil or process data collected in Brazil, regardless of where your company is based. A foreign company with no legal entity, no office, and no servers in Brazil can still be fully liable if it processes Brazilian users’ data. The absence of a local presence does not exempt you. If anything, it makes appointing a local representative or Encarregado more important, so Brazilian authorities and data subjects have a point of contact.
How much can the ANPD fine my company?
Under Article 52, the ANPD can impose a fine of up to 2% of your revenue in Brazil for the prior fiscal year, capped at R$ 50 million (around USD 9 million) per infraction. It can also issue warnings, block or delete data, publicize the violation, and suspend or prohibit your processing activities. Fines stack per infraction, so a single incident affecting many records can generate multiple penalties. On top of ANPD sanctions, data subjects and the Public Prosecutor’s Office can pursue civil damages in Brazilian courts, adding a separate layer of financial exposure.
Is my GDPR compliance enough for Brazil?
No, though it gives you a strong head start. The LGPD and GDPR share about 80% of their structure, but the LGPD has ten legal bases instead of six, different data subject rights, a different regulator (the ANPD), and specific transfer rules. Most critically, your policies and data subject request channels must be available in Portuguese for Brazilian users. You will also need to reassess your legal bases and international transfer mechanisms under Brazilian standards. Treat GDPR compliance as a foundation to adapt, not a finished product to copy.
Do I have to appoint a Data Protection Officer in Brazil?
The LGPD requires appointing an Encarregado (data protection officer) as the contact point between you, data subjects, and the ANPD. The ANPD has allowed scaled obligations for smaller, lower-risk processing agents, but foreign companies handling significant volumes of Brazilian data should appoint one. The role can be outsourced to a specialized firm or lawyer, typically costing R$ 1,500 to R$ 8,000 per month depending on your size and complexity. Publishing the Encarregado’s contact details on your website is part of the transparency obligations under the law.
Can I transfer Brazilian data to my headquarters abroad?
Yes, but only with a valid transfer mechanism. The LGPD regulates international data transfers, and in 2026 the standard contractual clauses approved by the ANPD are the central instrument. You can also rely on specific, highlighted consent from the data subject, or transfers to countries the ANPD recognizes as offering adequate protection. Informal arrangements, such as simply moving data to a parent company without documentation, are non-compliant. If your Brazilian subsidiary shares employee or customer data with an overseas group entity, put the appropriate clauses in place before the data leaves Brazil.
What should I check for LGPD before acquiring a Brazilian company?
Start with data mapping: does the target have a current inventory of processing activities with documented legal bases? Its absence signals an immature program and hidden liability. Then check for open ANPD investigations, pending data subject claims, past security incidents, vendor contracts, and the validity of legal bases. Your purchase agreement should include LGPD representations and warranties from the seller covering compliance, absence of investigations, and incident notifications. LGPD gaps can justify price adjustments or indemnity clauses, so make data protection a formal workstream in your due diligence, not an afterthought.
Make Your Brazilian Operation LGPD Compliant With Confidence
Navigating the LGPD from abroad can feel overwhelming, especially when the penalties reach R$ 50 million and the documents must be in Portuguese under a Civil Law system you did not grow up with. You do not have to figure it out alone. Whether you are launching a product for Brazilian customers, hiring your first local employee, or acquiring a company, getting your data protection program right from the start protects both your budget and your reputation.
Our bilingual legal team at Ribeiro Cavalcante Advocacia helps foreign companies map their data, document legal bases, draft Portuguese-language policies, appoint an Encarregado, structure international transfers, and run LGPD due diligence on Brazilian acquisitions. Every lawyer is registered with the OAB (Brazilian Bar Association) and works directly with you in your language.
Reach out today and tell us about your operation. We will show you exactly what applies to you and what to do next.
Talk to a specialist lawyer now
Talk to a Lawyer on WhatsApp