LGPD in practice: what your company must actually do (and what is myth)
Compliance is not buying a badge: it is organising what the company already does with data.
Brazil’s LGPD (Law 13,709/2018) applies to virtually every company processing personal data — including employees and suppliers, not just customers. Compliance is not buying a certificate: it is mapping the data you collect, defining the legal basis for each processing activity, adjusting contracts with processors, having an incident response plan and being able to answer data subjects. The ANPD may fine up to 2% of revenue, capped at R$ 50 million per infringement — alongside contractual and reputational risks.
Need help with your case? Talk to our business law team in São Paulo.
“Does the LGPD apply to my company? It is small and does not sell online.” It does. If the company has employees, keeps CVs, maintains a customer database or handles supplier data, it processes personal data — and falls within the law. Size is not a criterion for application; it is a criterion for proportionality of the measures.
LGPD compliance attracts both unnecessarily complex solutions and companies that have yet to adopt basic measures. The starting point should be actual risk, not a generic package. This article separates legal obligations from common misconceptions.
Who the LGPD applies to (and what counts as personal data)
Within its scope, the LGPD covers collection, storage, use, sharing and deletion of personal data, digitally or on paper. Article 3’s territorial criteria and article 4’s exceptions must be considered, including processing by individuals solely for private, non-economic purposes. Personal data identifies or makes a natural person identifiable: names, CPF numbers, email, telephone, IP addresses, location or images, depending on context.
One category deserves extra care: sensitive data — health, biometrics, genetic data, racial or ethnic origin, religious belief, political opinion, union membership, sex life. Processing it follows stricter rules. Employee medical certificates, for instance, are sensitive data — and many companies keep them in shared folders with no controls.
What almost everyone gets wrong: consent is not the rule
A common myth is that every activity requires consent. Article 7 provides ten legal bases for ordinary personal data. Consent is one, can be withdrawn and is not a universal solution. Sensitive data requires separate analysis under article 11.
- Compliance with a legal obligation: keeping employment and tax records required by law.
- Performance of a contract: using the customer’s address to deliver the product ordered.
- Legitimate interest: fraud prevention, security, some relationship activities — requires a balancing test and transparency.
- Exercise of rights in judicial, administrative or arbitral proceedings.
- Credit protection, among other statutory grounds.
The correct reading is this: asking for consent where a legal obligation or contract performance already applies does not protect the company — it hinders it. The real work is choosing and documenting the right legal basis for each processing activity.
What the company actually needs
- Data mapping: what data is collected, from whom, why, where it sits, who accesses it and how long it is kept.
- Records of processing operations (article 37): documentation explaining processing that may be required during an inspection.
- A defined legal basis for each activity, with the rationale recorded.
- A clear, truthful privacy policy (describing what the company actually does).
- Adjusted contracts with vendors processing data for you — systems, accounting, marketing, cloud — setting out roles and responsibilities.
- Proportionate security controls: passwords, access profiles, backups, encryption where appropriate.
- A data subject channel and a process for handling access, correction and deletion requests.
- An incident response plan, stating who escalates to whom and within what time.
- A data protection officer (encarregado/DPO) where required. ANPD Resolution 2/2022 allows an exemption for eligible small-scale entities meeting its conditions, not every small company. Eligible exempt entities must retain a data-subject communication channel.
Data breach: what to do in the first hours
Incidents may arise from attacks or human error, such as exposed email recipients. Where an incident may cause relevant risk or harm to data subjects, the controller must notify the ANPD and affected people. The general rule under ANPD Resolution 15/2024 is three business days from awareness that personal data was affected, subject to special statutory deadlines and any applicable differentiated regime. Do not wait for the entire investigation to finish before assessing notification.
Contain the incident, record what happened and when, identify affected data and people, assess risk and notify when required. Transparent, documented action helps manage risk but does not automatically eliminate liability.
Sanctions: what the ANPD may impose
- Warning, with a deadline to remedy.
- A simple fine of up to 2% of the private legal entity’s, group’s or conglomerate’s Brazilian revenue in the previous financial year, excluding taxes, capped at R$50 million per infringement.
- Daily fine, subject to the same cap.
- Publicising the infringement — often the most painful effect.
- Blocking or deletion of the data involved.
- Suspension or prohibition of processing activities under the statutory conditions; these are not automatic penalties.
Beyond ANPD proceedings, there may be civil liability for harm, client contractual requirements and action by prosecutors or consumer authorities. Compliance gaps can hinder business opportunities, without automatically ending every contract.
Where to start without overspending
Smart compliance is proportionate to risk. A company handling sensitive data at scale is not comparable to a ten-person office with a client list. A realistic roadmap:
- 1) Map the processing activities (an honest spreadsheet gets you started).
- 2) Define the legal basis for each and eliminate unnecessary collection — data you do not collect is risk you do not run.
- 3) Adjust vendor contracts and review internal access.
- 4) Publish a truthful privacy policy and create the data subject channel.
- 5) Write and test the incident plan and train staff, including prevention of and response to human error.
Hypothetical example: compliance to meet client requirements
Imagine a services company with 40 employees undergoing a large client’s vendor approval process. The client requires data-protection clauses and compliance evidence. Processing is not mapped, CVs sit in an open folder and the HR system contract does not address data.
A corrective plan might include mapping, restricted access, addenda with three vendors, a privacy policy and an incident plan. It also identifies CVs from 2015 that no longer need to be retained. These measures may help preserve the contract, but approval depends on the client’s requirements. This is a hypothetical example, not a firm result or timing promise. The reason to comply is not always a fine: it may also be a business requirement.
Frequently asked questions
Does the LGPD apply to small companies?
Yes. Small size does not provide a general exemption. ANPD Resolution 2/2022 permits simplifications for entities meeting its conditions and outside exclusions, including high-risk processing. Legal bases, security and data-subject assistance remain necessary; an exemption from appointing a DPO does not remove the communication channel.
Do I need consent for everything?
No. Consent is one of article 7’s ten bases for ordinary data; legal obligations, contract performance and justified legitimate interests are alternatives. The choice depends on purpose and data type, not indiscriminate consent collection. Sensitive data requires the specific bases in article 11.
What are the LGPD fines?
The LGPD provides warnings, simple fines of up to 2% of the private legal entity’s, group’s or conglomerate’s Brazilian revenue in the previous financial year, excluding taxes, capped at R$50 million per infringement, daily fines, publicity, blocking or deletion and suspension or prohibition under statutory conditions. Civil, contractual and reputational consequences may also arise.
We had a data breach. Must we notify the ANPD?
The controller must notify the ANPD and affected data subjects where relevant risk or harm may arise. ANPD Resolution 15/2024 generally requires notification within three business days of awareness that personal data was affected, subject to special deadlines and any applicable differentiated regime. Contain, record, assess risk and document action. Do not wait for the entire investigation before assessing notification.
Where should we start with LGPD compliance?
Start with mapping: what data the company collects, from whom, why, where it sits, who accesses it and for how long. Then define the legal basis for each activity and eliminate unnecessary collection — data you do not collect is risk you do not run. Next, adjust contracts with vendors processing data for you, publish a truthful privacy policy, create the data subject channel and write an incident response plan.
Good LGPD compliance is not a purchased badge: it means organising processing and continuously reviewing proportionate measures. At Falchet e Marques Sociedade de Advogados, in São Paulo on Avenida Paulista, we handle mapping, contracts and incident response in stages, with priorities suited to the operation.
Talk to our team on WhatsApp: +55 11 95901-1854 — does your company need to comply, or has a client imposed LGPD requirements? Tell us the scenario so we can map the most objective path.
