LGPD
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Cross-Border + Article 33-36 + Mercosur + RIPD
Brazil LGPD Articles 33-36 International Data Transfer (Transferencia Internacional). Transfer of personal data outside Brazil permitted only where: (I) destination jurisdiction provides adequate level of protection (ANPD assessment - automatic recognition pending + ANPD Resolution CD/ANPD No. 19 of 2024 on SCCs + adequacy review for EU + UK + Switzerland + Argentina + Canada + Israel + Japan + Korea + Uruguay + Mexico + Convention 108 parties); (II) safeguards through (a) ANPD-approved Standard Contractual Clauses (Clausulas Contratuais Padrao - issued by ANPD Resolution 19/2024); (b) Binding Corporate Rules (Normas Corporativas Globais - ANPD-approved); (c) Specific contracts; (d) Seals + Certificates + Codes of Conduct ANPD-approved; (e) International Cooperation; (III) Transfer necessary for: international legal cooperation + protection of life + safety + ANPD-authorized + execution
- Cross-border transfer inventory
- Adequacy reliance documentation
- ANPD Resolution 19/2024 SCCs executed copies
- ANPD-approved BCRs
- Transfer Impact Assessment per Schrems II
- Mercosur + RIPD cooperation evidence
- EU-Brazil Working Group engagement
- Transfer without lawful basis
- Old SCCs not ANPD 19/2024
- No TIA
- No BCR approval procedure
- Inadequate Mercosur coordination
Enforcement + Sanctions + ANPD + 2% Turnover
Brazil LGPD Articles 52-58 Sanctions + Enforcement. Article 52 Administrative Sanctions (Sancoes Administrativas) - ANPD-imposed tiered: (I) Warning (Advertencia) with indication of corrective measures + deadline; (II) Simple Fine (Multa Simples) up to 2% of revenue of legal entity + group + conglomerate in Brazil for the preceding financial year excluding taxes UP TO BRAZILIAN REAL (BRL) 50 MILLION PER INFRACTION; (III) Daily Fine (Multa Diaria) for continuing violations + max BRL 50M per infraction; (IV) Publicization of Infraction; (V) Blocking of Personal Data; (VI) Elimination of Personal Data; (VII) Partial Suspension of Database operation up to 6 months extendable; (VIII) Partial Suspension of Processing activities up to 6 months extendable; (IX) Partial or Total Prohibition of Processing activities. Reduced for SMEs + cooperatives + microenterprises. Article 52 paragraph 1 criter
- ANPD investigation response plan
- Sanctions exposure register (2% turnover + BRL 50M cap + ANPD Resolution 4/2023 criteria)
- Cooperation with ANPD audit records
- CDC alignment for class actions
- Public Civil Action exposure analysis
- IDEC + PROCONs engagement
- Federal Court review procedure
- No ANPD response plan
- No sanctions exposure analysis
- No CDC alignment for class actions
- No Public Civil Action exposure analysis
- No Federal Court procedure
Governance + Encarregado + ROPA + DPIA + Articles 46-50
Brazil LGPD Articles 41 + 46-50 Governance and Accountability. Article 41 Data Protection Officer (Encarregado pelo Tratamento de Dados Pessoais - Brazilian-specific term for DPO) - mandatory designation by all controllers (default + exceptions per ANPD Resolution CD/ANPD No. 2 of 27 January 2022 - microenterprises + small enterprises + startups + entities not in high-volume processing may exempt with documented procedures). Encarregado must be made known + accept complaints + provide explanations to data subjects + receive ANPD communications + train + advise controller + ANPD notification. Article 50 Good Practices and Governance (Boas Praticas e Governanca) - controllers and processors can formulate Rules of Governance Practices including: privacy policies + sectoral codes of conduct + privacy seals + technical and administrative security measures + business continuity + impact assess
- Encarregado designation records + ANPD Resolution CD/ANPD 2/2022 compliance
- ROPA per processing operation
- RIPD (Brazilian DPIA) reports
- Privacy by Design + Privacy by Default in SDLC
- Codes of Conduct adoption
- Joint and several liability allocation evidence
- Annual training records
- No Encarregado
- ROPA incomplete
- No RIPD for high-risk
- No PbD in development
- No Codes of Conduct
- Joint liability unallocated
Lawful Basis + 10 Principles + Articles 6-10
Brazil LGPD Article 6 10 Principles (Principios) - Brazilian-specific framing: (I) Purpose (Finalidade); (II) Adequacy (Adequacao); (III) Necessity (Necessidade); (IV) Free Access (Livre Acesso); (V) Data Quality (Qualidade dos Dados); (VI) Transparency (Transparencia); (VII) Security (Seguranca); (VIII) Prevention (Prevencao); (IX) Non-Discrimination (Nao Discriminacao); (X) Accountability and Reporting (Responsabilizacao e Prestacao de Contas). Article 7 10 Lawful Bases (Hipoteses de Tratamento): (I) Consent of data subject; (II) Compliance with legal or regulatory obligation; (III) Public administration execution; (IV) Public interest research with anonymisation where possible; (V) Performance of contract; (VI) Regular exercise of rights in judicial + administrative + arbitration proceedings; (VII) Protection of life or physical safety of data subject or third party; (VIII) Health pro
- Lawful basis register per processing
- Consent records (explicit + verifiable + withdrawable)
- Portuguese privacy notices
- 10 LGPD principles compliance matrix
- Article 7 hypothesis selection documentation
- Direct marketing opt-in evidence
- Article 7.X credit protection documentation
- Bundled consent
- Notices not in Portuguese
- No 10-principle compliance matrix
- No hypothesis selection documentation
- Article 7.X credit gap
Scope + Lei 13.709/2018 + ANPD + Constitution
Brazil Lei Geral de Protecao de Dados Pessoais (LGPD) Law No. 13.709 of 14 August 2018 + Amended by Law No. 13.853 of 8 July 2019 (ANPD establishment + sanctions provisions) + effective 18 September 2020 (administrative sanctions effective 1 August 2021). Foundational Brazilian comprehensive personal data protection statute. Constitutional anchor Brazilian Constitution Article 5 paragraphs X (inviolability of intimacy + private life + honor + image) + XII (inviolability of correspondence and data communication) + XXII (protection of personal data, added by Constitutional Amendment 115/2022) + LXXII (Habeas Data action). 65 articles in 10 chapters: Chapter I Preliminary Provisions + Chapter II Processing of Personal Data + Chapter III Rights of Data Subjects + Chapter IV Processing by Public Authorities + Chapter V International Data Transfer + Chapter VI Processing Agents + Chapter VII S
- Applicability assessment
- Personal data inventory
- ANPD engagement records
- Portuguese privacy notices
- Constitution Article 5 compliance memo
- RIPD coordination evidence
- EU adequacy preparation evidence
- No ANPD engagement
- Notices not in Portuguese
- Treating LGPD same as GDPR without Brazil-specific 10 principles
- No Encarregado designation
Security + Article 46 + Breach Article 48 + ANPD 3 days
Brazil LGPD Articles 46-48 Security + Breach Notification. Article 46 Security of Processing (Seguranca do Tratamento) - controllers and processors must adopt technical and administrative measures to protect personal data against unauthorised access + accidental or unlawful destruction + loss + alteration + communication + diffusion + including: state-of-the-art + ISO 27001/27002 alignment + encryption (at rest and in transit) + pseudonymisation + access control + authentication + logging + monitoring + secure SDLC + vulnerability management + backup + business continuity + incident response. Article 47 Persons Involved in Processing under controller authority obligated to data secrecy and confidentiality + LGPD professional secrecy obligation. Article 48 Personal Data Breach Notification (Comunicacao de Incidente de Seguranca) - controller must notify ANPD and affected data subjects wit
- Encryption + pseudonymisation evidence
- Confidentiality attestations + LGPD professional secrecy
- ANPD breach notification log + 3-working-day evidence (CD/ANPD 15/2024)
- Affected data subject notification
- CGI.br + CTIR Gov + CERT.br coordination records
- Incident response playbook
- Banking Resolution 4.893/2021 alignment (financial sector)
- No encryption
- Late ANPD notification
- No data subject breach notification
- No CGI.br/CTIR Gov liaison
- Banking incident reporting gap
Sensitive Data + Article 11 + Children Article 14 + Public Sector
Brazil LGPD Articles 11-14 + 17 Sensitive Personal Data and Children. Article 5.II Sensitive Personal Data (Dado Pessoal Sensivel) categories: racial or ethnic origin + religious belief + political opinion + trade union or religious/philosophical/political organization membership + health data + sexual life + genetic data + biometric data when linked to natural person. Article 11 Sensitive Data processing prohibited except: (I) consent of data subject for specific purposes (highlighted vs general consent); (II) without consent if indispensable for (a) compliance with legal obligation; (b) public administration shared treatment; (c) anonymised research; (d) regular exercise of rights including contract performance + judicial process; (e) protection of life or physical safety; (f) tutelage of health; (g) fraud prevention by controller; (h) protection of credit. Article 13 Public Health res
- Sensitive data inventory + Article 5.II categories
- Specific consent for sensitive vs general
- Children parental consent (under 12) + age verification
- ECA Law 8.069/1990 best interests
- Marco Civil da Internet compliance evidence
- Public Sector LGPD Chapter IV compliance
- Public Health research ethics committee
- Sensitive without specific consent
- Children without parental consent
- No Marco Civil alignment
- Public Sector not aligned with Chapter IV
- No research ethics for bioethics
Subject Rights + Article 18 + 9 Rights + Article 20 Automated Review
Brazil LGPD Article 18 Data Subject Rights (Direitos do Titular) - 9 enumerated rights (BRAZIL-SPECIFIC LIST): (I) Confirmation of Existence of Processing (Confirmacao da existencia de tratamento) - to know if data is being processed; (II) Right of Access (Acesso) - obtain personal data + purposes + categories + recipients; (III) Correction of Incomplete + Inaccurate + Outdated Data (Correcao); (IV) Anonymization + Blocking + Deletion of unnecessary + excessive data + data processed in non-compliance with LGPD; (V) Right to Data Portability (Portabilidade) - to another service or product provider; (VI) Deletion of Personal Data processed with consent except as authorised by law; (VII) Information about Sharing (Informacao sobre Compartilhamento) - public + private bodies with which data have been shared; (VIII) Information about Non-Consent Possibility and Consequences (when consent is l
- Rights request SLAs (15-day + 25-day complex) + log
- Portuguese response templates
- Confirmation of processing procedure
- Anonymization + blocking + deletion procedures
- Portability format documentation
- Article 20 algorithmic transparency + human review + explanation of criteria
- ANPD appeals procedure
- Slow response
- No anonymization procedure
- No automated decision review
- No algorithmic transparency
- No appeals path
- Inadequate identity verification
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the LGPD framework page.