What LGPD actually requires
Brazil's general data protection law, broadly inspired by the GDPR. The LGPD requires a lawful basis for any processing of personal data — and for non-essential cookies, that lawful basis is usually the user's free and specific consent. The law is enforced by the ANPD (Autoridade Nacional de Proteção de Dados).
Key requirements
- Obtain free, specific and informed consent before setting non-essential cookies
- Publish a clear privacy notice in Portuguese explaining what you collect and why
- Let data subjects access, correct, delete and port their data
- Appoint a data protection officer (Encarregado) and publish their contact details
- Notify the ANPD and affected users of qualifying data breaches
- Keep a record of consents and processing activities you can show on request
At a glance
Full name
Lei Geral de Proteção de Dados Pessoais
Region
Brazil
Status
In force since September 2020
Who it affects
Any organisation that processes personal data of individuals located in Brazil, regardless of where the organisation is based or where the processing happens.
Penalties
Fines up to 2% of an entity's revenue in Brazil per infraction, capped at R$50 million (~USD 10M). The ANPD has been actively issuing sanctions and corrective notices since enforcement began.
How GrantCookie covers it
Compliant defaults
Opt-in by default, granular categories, and a reject button as prominent as accept — the configuration regulators expect.
Provable records
Every consent is timestamped and stored with the banner version, so you can show exactly what was agreed to.
Easy withdrawal
A persistent re-open control lets visitors change their mind at any time, exactly as the law requires.
This page is general guidance, not legal advice. Check your specific obligations with a qualified adviser.
