Logo GH

LGPD: Brazil's data law

1) Who applies LGPD and who is who

LGPD applies to the processing of personal data (PD) carried out in Brazil, targeting residents of Brazil or related to the offer of goods/services and monitoring of behavior in its territory.

Roles:
  • Controller-Defines the goals and means of processing.
  • Operador-Processes the PD on behalf of the controller.
  • Encarregado (DPO): data protection contact; ANPD may exempt SMEs from mandatory assignment, but for iGaming/fintech is usually assigned.

2) Processing principles (LGPD core)

Goal setting and goal compatibility

Necessity and minimization

Transparency and non-discrimination

Data quality (accuracy, relevance)

Safety and damage prevention

Accountability (prove compliance)

3) Legal bases

Matrix for typical iGaming/fintech scenarios:
PurposeSample dataLGPD base
Registration, transactions, paymentsID, contact, paymentPerformance of the contract
KYC/AML, tax and regulatory responsibilitiesDocuments, logs, biometrics (where permissible)Yur. duty
Antifraud/safetyIP/ASN, device, behaviorLegitimate interest
Marketing, optional analyticsContacts, cookies/IDConsent
Life Safety/Physical SafetyContextual risk signalsProtection of life/physical. integrity
Credit scoring/checksG/L/Payment/HistoryCredit protection (LGPD specifics)
Research/StatisticsPseudo-/anonymous dataStudy (with de-identification measures)
💡 For a legitimate interest, conduct a balance test, fix minimization measures. For consent - free, informed, specific, with convenient feedback.

4) Special categories and children

Sensitive data: health, biometrics, religion, political views, etc. - require a separate foundation and enhanced measures.
Children and adolescents: for <13 - consent of the parent/guardian; processing solely in their best interests, without intrusive profiling.

5) Rights of subjects (standard of operations)

Confirmation of processing and access to data

Correcting inaccuracies

Anonymization/blocking/deletion of redundant/illegally processed data

Tolerability (to another provider)

Information about recipients, goals, and consequences of failure

Withdrawing consent is as easy as providing

Request for review of automated decisions affecting the interests of the subject

Timeline: Respond without undue delay, keep a request log (DSR) and verify the applicant.

6) Security and incidents

Implement organizational and technical measures: encryption, RBAC/ABAC, DLP, logs, WORM archives, recovery tests.
In case of an incident with a risk of damage to the subjects, appropriate notification to the ANPD and the subjects (contains the nature of the incident, data categories, measures taken). Timelines/formats focus on risk and ANPD recommendations.

7) Cross-border transmissions

Allowed if one of the mechanisms is present:
  • Adequacy (ANPD-recognized countries/organizations)
  • Contractual instruments (standard clauses, corporate rules)
  • Conformity Certification/Printing
  • Explicit subject consent when appropriate
  • Other LGPD grounds (contract performance, protection of life, etc.)
  • Practice: encryption before transmission, key separation, pseudonymization and field minimization.

8) RIPD (Brazilian DPIA) and documentation

Relatório de Impacto à Proteção de Dados Pessoais (RIPD) is mandatory for risky treatments (scale profiling, biometrics, new sources/partners). Contains:

1. Description of operations 2) grounds and necessity; 3) risks to rights/freedoms; 4) mitigation measures; 5) residual risk and plan.

Also keep a register of operations, privacy policy, public notifications, register of incidents, register of transfers abroad.

9) Cookies/SDK and marketing

Consent banner with understandable categories (mandatory/functional/analytics/marketing).
Document goals and shelf life; respect rejection/recall and don't profile children.
Server analytics/aggregation is preferable to open pixels; restrict "sharing" with third parties without justification.

10) Contracts with operators and third parties

Contracts shall:
  • Restrict processing strictly to the instructions of the controller;
  • Prohibit reuse and onward transfers without permission;
  • Require security, incident notifications, assistance with DSR and removal;
  • Disclose sub-processors and grant audit rights;
  • Capture processing geography and cross-border transmission mechanisms.

11) Automated solutions and profiling

If the decision has a legal/similar significant effect (for example, anti-fraud scoring, RG limits), the subject has the right to information about logic within reasonable limits and to human revision. It is recommended to store reason codes, version models/rules and conduct bias audits.

12) ANPD sanctions and liability

Warnings and corrective actions

Public announcement of violation

Blocking/deleting personal data

Penalties: up to 2% of revenue in Brazil for the year (last period), up to 50 million BRL per violation (ceiling)

Additionally, civil liability and class actions are possible.

13) Purpose → Basis → Storage Matrix

PurposeBasisSample term
Account/TransactionsContractWhile the contract is valid + N months.
KYC/AML/TaxesYur. dutyUsually ≥5 years after the end of the relationship
Antifraud/safetyLegitimate interest12-24 months with pseudonymization
MarketingConsentAs long as there is agreement or before withdrawal
Credit/ScoringCredit protectionLocal Regulations/Policies

14) Compliance checklist (operational)

Policies and Notifications

  • Current Privacy Policy (goals, PD categories, rights, request channels, transfers abroad).
  • Notice at collection points (cookies/forms/SDK).
  • Procedure for processing children's data.

Entity Rights (DSR)

  • Request channels (web form/mail), verification, SLA and log.
  • Migration, deletion, remediation, de-marketing procedures.

Security

  • Encryption in transit/at rest, KMS/HSM, key rotation.
  • RBAC/ABAC, JIT accesses, logs, DLP, recovery tests.
  • Playbook incident and ANPD/subject notifications.

Vendors

  • DPA with operators/third parties; sub-processor registry.
  • Processing geography and cross-border transmission mechanism.
  • SDK/pixel auditing and control.

RIPD/Register

  • Register of Operations; RIPD for risky treatments.
  • Retention matrix and removal/anonymization pipeline.

15) Metrics and control

DSR SLA (% on time), mean/95th percentile

Consent Coverage и Opt-out Honor Rate

Retention Adherence (deleted on schedule)

Access/Export Violations and Delta by Quarter

Incident MTTD/MTTR and repeatability

Vendor Compliance Rate

RIPD Coverage

16) Implementation Roadmap (6 steps)

1. Data mapping: PD sources, flows, goals, legal grounds, vendors.
2. Policies/notifications: Privacy Policy, consent banner, Notice at collection.
3. DSR processes: channels, verification, templates, log, metrics.
4. Security: encryption, accesses, logs, DLP, IR plan.
5. Vendors and cross-border transfers: DPA, sub-processors, mechanisms, testers.
6. RIPD/retention: high risk reports, retention matrix, deletion/anonymization.

17) Differences between LGPD and GDPR (brief)

Additional grounds "protection of credit," "protection of life" are explicitly highlighted.
RIPD is a functional analogue of DPIA, but with a focus on local ANPD practice.
Penalties - BRL 50m ceiling for breach; the sanctions model is different from that of GDPR.
Children/adolescents: "best interest" controls, strict profiling and marketing policies.

Total

LGPD compliance is not only a cookie banner, but a data lifecycle management system: correct grounds, minimization and security, transparent notifications, working DSR processes, contracts with vendors, RIPD for risk processing and cross-border transmission discipline. By embedding these contours "by default," you will reduce legal and reputational risks, retain partnerships and user trust - without compromising product speed and conversion.

Contact

Get in Touch

Reach out with any questions or support needs.We are always ready to help!

Telegram
@Gamble_GC
Start Integration

Email is required. Telegram or WhatsApp — optional.

Your Name optional
Email optional
Subject optional
Message optional
Telegram optional
@
If you include Telegram — we will reply there as well, in addition to Email.
WhatsApp optional
Format: +country code and number (e.g., +380XXXXXXXXX).

By clicking this button, you agree to data processing.