Skip to content

Evidence request lists

LGPD

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Cross-Border + Article 33-36 + Mercosur + RIPD

LGPD-BR-Cross-Border-International-Transfer-Article-33-Adequacy-SCC-BCR-ANPD-Approval-Mercosur-RIPD
Brazil LGPD Cross-Border + Article 33 + Adequacy + SCC + BCR + Mercosur + RIPD

Brazil LGPD Articles 33-36 International Data Transfer (Transferencia Internacional). Transfer of personal data outside Brazil permitted only where: (I) destination jurisdiction provides adequate level of protection (ANPD assessment - automatic recognition pending + ANPD Resolution CD/ANPD No. 19 of 2024 on SCCs + adequacy review for EU + UK + Switzerland + Argentina + Canada + Israel + Japan + Korea + Uruguay + Mexico + Convention 108 parties); (II) safeguards through (a) ANPD-approved Standard Contractual Clauses (Clausulas Contratuais Padrao - issued by ANPD Resolution 19/2024); (b) Binding Corporate Rules (Normas Corporativas Globais - ANPD-approved); (c) Specific contracts; (d) Seals + Certificates + Codes of Conduct ANPD-approved; (e) International Cooperation; (III) Transfer necessary for: international legal cooperation + protection of life + safety + ANPD-authorized + execution

Artefacts an auditor will ask for
  • Cross-border transfer inventory
  • Adequacy reliance documentation
  • ANPD Resolution 19/2024 SCCs executed copies
  • ANPD-approved BCRs
  • Transfer Impact Assessment per Schrems II
  • Mercosur + RIPD cooperation evidence
  • EU-Brazil Working Group engagement
Where this commonly fails
  • Transfer without lawful basis
  • Old SCCs not ANPD 19/2024
  • No TIA
  • No BCR approval procedure
  • Inadequate Mercosur coordination

Enforcement + Sanctions + ANPD + 2% Turnover

LGPD-BR-Enforcement-Sanctions-ANPD-Article-52-55-Administrative-Sanctions-2-Percent-Turnover-50M-BRL
Brazil LGPD Enforcement + Sanctions + Article 52 + 2% Turnover + 50M BRL + ANPD

Brazil LGPD Articles 52-58 Sanctions + Enforcement. Article 52 Administrative Sanctions (Sancoes Administrativas) - ANPD-imposed tiered: (I) Warning (Advertencia) with indication of corrective measures + deadline; (II) Simple Fine (Multa Simples) up to 2% of revenue of legal entity + group + conglomerate in Brazil for the preceding financial year excluding taxes UP TO BRAZILIAN REAL (BRL) 50 MILLION PER INFRACTION; (III) Daily Fine (Multa Diaria) for continuing violations + max BRL 50M per infraction; (IV) Publicization of Infraction; (V) Blocking of Personal Data; (VI) Elimination of Personal Data; (VII) Partial Suspension of Database operation up to 6 months extendable; (VIII) Partial Suspension of Processing activities up to 6 months extendable; (IX) Partial or Total Prohibition of Processing activities. Reduced for SMEs + cooperatives + microenterprises. Article 52 paragraph 1 criter

Artefacts an auditor will ask for
  • ANPD investigation response plan
  • Sanctions exposure register (2% turnover + BRL 50M cap + ANPD Resolution 4/2023 criteria)
  • Cooperation with ANPD audit records
  • CDC alignment for class actions
  • Public Civil Action exposure analysis
  • IDEC + PROCONs engagement
  • Federal Court review procedure
Where this commonly fails
  • No ANPD response plan
  • No sanctions exposure analysis
  • No CDC alignment for class actions
  • No Public Civil Action exposure analysis
  • No Federal Court procedure

Governance + Encarregado + ROPA + DPIA + Articles 46-50

LGPD-BR-Governance-Encarregado-DPO-ROPA-DPIA-Privacy-by-Design-Article-46-50-Codes-of-Conduct
Brazil LGPD Governance + Encarregado (DPO) + ROPA + DPIA + Articles 46-50

Brazil LGPD Articles 41 + 46-50 Governance and Accountability. Article 41 Data Protection Officer (Encarregado pelo Tratamento de Dados Pessoais - Brazilian-specific term for DPO) - mandatory designation by all controllers (default + exceptions per ANPD Resolution CD/ANPD No. 2 of 27 January 2022 - microenterprises + small enterprises + startups + entities not in high-volume processing may exempt with documented procedures). Encarregado must be made known + accept complaints + provide explanations to data subjects + receive ANPD communications + train + advise controller + ANPD notification. Article 50 Good Practices and Governance (Boas Praticas e Governanca) - controllers and processors can formulate Rules of Governance Practices including: privacy policies + sectoral codes of conduct + privacy seals + technical and administrative security measures + business continuity + impact assess

Artefacts an auditor will ask for
  • Encarregado designation records + ANPD Resolution CD/ANPD 2/2022 compliance
  • ROPA per processing operation
  • RIPD (Brazilian DPIA) reports
  • Privacy by Design + Privacy by Default in SDLC
  • Codes of Conduct adoption
  • Joint and several liability allocation evidence
  • Annual training records
Where this commonly fails
  • No Encarregado
  • ROPA incomplete
  • No RIPD for high-risk
  • No PbD in development
  • No Codes of Conduct
  • Joint liability unallocated

Lawful Basis + 10 Principles + Articles 6-10

LGPD-BR-Lawful-Basis-Consent-Notice-Article-6-10-Principles-Article-7-Hypotheses-Article-9-Transparency
Brazil LGPD Lawful Basis + 10 Principles + Article 6-10 + Hypotheses + Transparency

Brazil LGPD Article 6 10 Principles (Principios) - Brazilian-specific framing: (I) Purpose (Finalidade); (II) Adequacy (Adequacao); (III) Necessity (Necessidade); (IV) Free Access (Livre Acesso); (V) Data Quality (Qualidade dos Dados); (VI) Transparency (Transparencia); (VII) Security (Seguranca); (VIII) Prevention (Prevencao); (IX) Non-Discrimination (Nao Discriminacao); (X) Accountability and Reporting (Responsabilizacao e Prestacao de Contas). Article 7 10 Lawful Bases (Hipoteses de Tratamento): (I) Consent of data subject; (II) Compliance with legal or regulatory obligation; (III) Public administration execution; (IV) Public interest research with anonymisation where possible; (V) Performance of contract; (VI) Regular exercise of rights in judicial + administrative + arbitration proceedings; (VII) Protection of life or physical safety of data subject or third party; (VIII) Health pro

Artefacts an auditor will ask for
  • Lawful basis register per processing
  • Consent records (explicit + verifiable + withdrawable)
  • Portuguese privacy notices
  • 10 LGPD principles compliance matrix
  • Article 7 hypothesis selection documentation
  • Direct marketing opt-in evidence
  • Article 7.X credit protection documentation
Where this commonly fails
  • Bundled consent
  • Notices not in Portuguese
  • No 10-principle compliance matrix
  • No hypothesis selection documentation
  • Article 7.X credit gap

Scope + Lei 13.709/2018 + ANPD + Constitution

LGPD-BR-Scope-Lei-13-709-2018-14-August-2018-Effective-18-September-2020-ANPD-Constitution-Article-5-X-XII
Brazil LGPD Scope + Lei 13.709/2018 + Congresso Nacional + Effective 18 September 2020 + ANPD

Brazil Lei Geral de Protecao de Dados Pessoais (LGPD) Law No. 13.709 of 14 August 2018 + Amended by Law No. 13.853 of 8 July 2019 (ANPD establishment + sanctions provisions) + effective 18 September 2020 (administrative sanctions effective 1 August 2021). Foundational Brazilian comprehensive personal data protection statute. Constitutional anchor Brazilian Constitution Article 5 paragraphs X (inviolability of intimacy + private life + honor + image) + XII (inviolability of correspondence and data communication) + XXII (protection of personal data, added by Constitutional Amendment 115/2022) + LXXII (Habeas Data action). 65 articles in 10 chapters: Chapter I Preliminary Provisions + Chapter II Processing of Personal Data + Chapter III Rights of Data Subjects + Chapter IV Processing by Public Authorities + Chapter V International Data Transfer + Chapter VI Processing Agents + Chapter VII S

Artefacts an auditor will ask for
  • Applicability assessment
  • Personal data inventory
  • ANPD engagement records
  • Portuguese privacy notices
  • Constitution Article 5 compliance memo
  • RIPD coordination evidence
  • EU adequacy preparation evidence
Where this commonly fails
  • No ANPD engagement
  • Notices not in Portuguese
  • Treating LGPD same as GDPR without Brazil-specific 10 principles
  • No Encarregado designation

Security + Article 46 + Breach Article 48 + ANPD 3 days

LGPD-BR-Security-Article-46-48-Breach-Notification-ANPD-Reasonable-Time-Incident-Response-CSIRT
Brazil LGPD Security + Article 46-48 + Breach Notification + ANPD + Incident Response

Brazil LGPD Articles 46-48 Security + Breach Notification. Article 46 Security of Processing (Seguranca do Tratamento) - controllers and processors must adopt technical and administrative measures to protect personal data against unauthorised access + accidental or unlawful destruction + loss + alteration + communication + diffusion + including: state-of-the-art + ISO 27001/27002 alignment + encryption (at rest and in transit) + pseudonymisation + access control + authentication + logging + monitoring + secure SDLC + vulnerability management + backup + business continuity + incident response. Article 47 Persons Involved in Processing under controller authority obligated to data secrecy and confidentiality + LGPD professional secrecy obligation. Article 48 Personal Data Breach Notification (Comunicacao de Incidente de Seguranca) - controller must notify ANPD and affected data subjects wit

Artefacts an auditor will ask for
  • Encryption + pseudonymisation evidence
  • Confidentiality attestations + LGPD professional secrecy
  • ANPD breach notification log + 3-working-day evidence (CD/ANPD 15/2024)
  • Affected data subject notification
  • CGI.br + CTIR Gov + CERT.br coordination records
  • Incident response playbook
  • Banking Resolution 4.893/2021 alignment (financial sector)
Where this commonly fails
  • No encryption
  • Late ANPD notification
  • No data subject breach notification
  • No CGI.br/CTIR Gov liaison
  • Banking incident reporting gap

Sensitive Data + Article 11 + Children Article 14 + Public Sector

LGPD-BR-Sensitive-Personal-Data-Children-Article-11-14-Public-Health-Genetic-Biometric-Article-17-Public-Sector
Brazil LGPD Sensitive Data + Children + Public Sector + Articles 11-14 + 17

Brazil LGPD Articles 11-14 + 17 Sensitive Personal Data and Children. Article 5.II Sensitive Personal Data (Dado Pessoal Sensivel) categories: racial or ethnic origin + religious belief + political opinion + trade union or religious/philosophical/political organization membership + health data + sexual life + genetic data + biometric data when linked to natural person. Article 11 Sensitive Data processing prohibited except: (I) consent of data subject for specific purposes (highlighted vs general consent); (II) without consent if indispensable for (a) compliance with legal obligation; (b) public administration shared treatment; (c) anonymised research; (d) regular exercise of rights including contract performance + judicial process; (e) protection of life or physical safety; (f) tutelage of health; (g) fraud prevention by controller; (h) protection of credit. Article 13 Public Health res

Artefacts an auditor will ask for
  • Sensitive data inventory + Article 5.II categories
  • Specific consent for sensitive vs general
  • Children parental consent (under 12) + age verification
  • ECA Law 8.069/1990 best interests
  • Marco Civil da Internet compliance evidence
  • Public Sector LGPD Chapter IV compliance
  • Public Health research ethics committee
Where this commonly fails
  • Sensitive without specific consent
  • Children without parental consent
  • No Marco Civil alignment
  • Public Sector not aligned with Chapter IV
  • No research ethics for bioethics

Subject Rights + Article 18 + 9 Rights + Article 20 Automated Review

LGPD-BR-Data-Subject-Rights-Article-18-Confirmation-Access-Correction-Anonymization-Portability-Revoke-Sharing
Brazil LGPD Data Subject Rights + Article 18 + 9 Rights + Confirmation + Anonymization

Brazil LGPD Article 18 Data Subject Rights (Direitos do Titular) - 9 enumerated rights (BRAZIL-SPECIFIC LIST): (I) Confirmation of Existence of Processing (Confirmacao da existencia de tratamento) - to know if data is being processed; (II) Right of Access (Acesso) - obtain personal data + purposes + categories + recipients; (III) Correction of Incomplete + Inaccurate + Outdated Data (Correcao); (IV) Anonymization + Blocking + Deletion of unnecessary + excessive data + data processed in non-compliance with LGPD; (V) Right to Data Portability (Portabilidade) - to another service or product provider; (VI) Deletion of Personal Data processed with consent except as authorised by law; (VII) Information about Sharing (Informacao sobre Compartilhamento) - public + private bodies with which data have been shared; (VIII) Information about Non-Consent Possibility and Consequences (when consent is l

Artefacts an auditor will ask for
  • Rights request SLAs (15-day + 25-day complex) + log
  • Portuguese response templates
  • Confirmation of processing procedure
  • Anonymization + blocking + deletion procedures
  • Portability format documentation
  • Article 20 algorithmic transparency + human review + explanation of criteria
  • ANPD appeals procedure
Where this commonly fails
  • Slow response
  • No anonymization procedure
  • No automated decision review
  • No algorithmic transparency
  • No appeals path
  • Inadequate identity verification
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the LGPD framework page.