LGPD: Brazil's data law
1) Who applies LGPD and who is who
LGPD applies to the processing of personal data (PD) carried out in Brazil, targeting residents of Brazil or related to the offer of goods/services and monitoring of behavior in its territory.
Roles:- Controller-Defines the goals and means of processing.
- Operador-Processes the PD on behalf of the controller.
- Encarregado (DPO): data protection contact; ANPD may exempt SMEs from mandatory assignment, but for iGaming/fintech is usually assigned.
2) Processing principles (LGPD core)
Goal setting and goal compatibility
Necessity and minimization
Transparency and non-discrimination
Data quality (accuracy, relevance)
Safety and damage prevention
Accountability (prove compliance)
3) Legal bases
Matrix for typical iGaming/fintech scenarios:4) Special categories and children
Sensitive data: health, biometrics, religion, political views, etc. - require a separate foundation and enhanced measures.
Children and adolescents: for <13 - consent of the parent/guardian; processing solely in their best interests, without intrusive profiling.
5) Rights of subjects (standard of operations)
Confirmation of processing and access to data
Correcting inaccuracies
Anonymization/blocking/deletion of redundant/illegally processed data
Tolerability (to another provider)
Information about recipients, goals, and consequences of failure
Withdrawing consent is as easy as providing
Request for review of automated decisions affecting the interests of the subject
Timeline: Respond without undue delay, keep a request log (DSR) and verify the applicant.
6) Security and incidents
Implement organizational and technical measures: encryption, RBAC/ABAC, DLP, logs, WORM archives, recovery tests.
In case of an incident with a risk of damage to the subjects, appropriate notification to the ANPD and the subjects (contains the nature of the incident, data categories, measures taken). Timelines/formats focus on risk and ANPD recommendations.
7) Cross-border transmissions
Allowed if one of the mechanisms is present:- Adequacy (ANPD-recognized countries/organizations)
- Contractual instruments (standard clauses, corporate rules)
- Conformity Certification/Printing
- Explicit subject consent when appropriate
- Other LGPD grounds (contract performance, protection of life, etc.)
- Practice: encryption before transmission, key separation, pseudonymization and field minimization.
8) RIPD (Brazilian DPIA) and documentation
Relatório de Impacto à Proteção de Dados Pessoais (RIPD) is mandatory for risky treatments (scale profiling, biometrics, new sources/partners). Contains:1. Description of operations 2) grounds and necessity; 3) risks to rights/freedoms; 4) mitigation measures; 5) residual risk and plan.
Also keep a register of operations, privacy policy, public notifications, register of incidents, register of transfers abroad.
9) Cookies/SDK and marketing
Consent banner with understandable categories (mandatory/functional/analytics/marketing).
Document goals and shelf life; respect rejection/recall and don't profile children.
Server analytics/aggregation is preferable to open pixels; restrict "sharing" with third parties without justification.
10) Contracts with operators and third parties
Contracts shall:- Restrict processing strictly to the instructions of the controller;
- Prohibit reuse and onward transfers without permission;
- Require security, incident notifications, assistance with DSR and removal;
- Disclose sub-processors and grant audit rights;
- Capture processing geography and cross-border transmission mechanisms.
11) Automated solutions and profiling
If the decision has a legal/similar significant effect (for example, anti-fraud scoring, RG limits), the subject has the right to information about logic within reasonable limits and to human revision. It is recommended to store reason codes, version models/rules and conduct bias audits.
12) ANPD sanctions and liability
Warnings and corrective actions
Public announcement of violation
Blocking/deleting personal data
Penalties: up to 2% of revenue in Brazil for the year (last period), up to 50 million BRL per violation (ceiling)
Additionally, civil liability and class actions are possible.
13) Purpose → Basis → Storage Matrix
14) Compliance checklist (operational)
Policies and Notifications
- Current Privacy Policy (goals, PD categories, rights, request channels, transfers abroad).
- Notice at collection points (cookies/forms/SDK).
- Procedure for processing children's data.
Entity Rights (DSR)
- Request channels (web form/mail), verification, SLA and log.
- Migration, deletion, remediation, de-marketing procedures.
Security
- Encryption in transit/at rest, KMS/HSM, key rotation.
- RBAC/ABAC, JIT accesses, logs, DLP, recovery tests.
- Playbook incident and ANPD/subject notifications.
Vendors
- DPA with operators/third parties; sub-processor registry.
- Processing geography and cross-border transmission mechanism.
- SDK/pixel auditing and control.
RIPD/Register
- Register of Operations; RIPD for risky treatments.
- Retention matrix and removal/anonymization pipeline.
15) Metrics and control
DSR SLA (% on time), mean/95th percentile
Consent Coverage и Opt-out Honor Rate
Retention Adherence (deleted on schedule)
Access/Export Violations and Delta by Quarter
Incident MTTD/MTTR and repeatability
Vendor Compliance Rate
RIPD Coverage
16) Implementation Roadmap (6 steps)
1. Data mapping: PD sources, flows, goals, legal grounds, vendors.
2. Policies/notifications: Privacy Policy, consent banner, Notice at collection.
3. DSR processes: channels, verification, templates, log, metrics.
4. Security: encryption, accesses, logs, DLP, IR plan.
5. Vendors and cross-border transfers: DPA, sub-processors, mechanisms, testers.
6. RIPD/retention: high risk reports, retention matrix, deletion/anonymization.
17) Differences between LGPD and GDPR (brief)
Additional grounds "protection of credit," "protection of life" are explicitly highlighted.
RIPD is a functional analogue of DPIA, but with a focus on local ANPD practice.
Penalties - BRL 50m ceiling for breach; the sanctions model is different from that of GDPR.
Children/adolescents: "best interest" controls, strict profiling and marketing policies.
Total
LGPD compliance is not only a cookie banner, but a data lifecycle management system: correct grounds, minimization and security, transparent notifications, working DSR processes, contracts with vendors, RIPD for risk processing and cross-border transmission discipline. By embedding these contours "by default," you will reduce legal and reputational risks, retain partnerships and user trust - without compromising product speed and conversion.