Quick Answer: What should a foreign company review for LGPD compliance?
A useful LGPD compliance checklist should test more than whether the company has a privacy policy. Start with territorial scope and data mapping, then document controller/operator roles, purposes and legal bases, notices, consent where used, sensitive and children's data, cookies and marketing, processing records, vendors, international transfers, data-subject rights, automated decisions, retention, security, incident response, the encarregado, impact assessments, training, and governance evidence. The objective is to connect the law to the company's actual systems and workflows.
Key Takeaways
- Do not begin with documents. Begin with scope, systems, data flows, people, purposes, and vendors.
- Consent is not the universal answer. Article 7 contains multiple legal bases for ordinary personal data.
- Accountability requires evidence. The LGPD expressly includes accountability and demonstration of effective measures among its principles.
- Cross-border access matters. Transfers and remote access can require a separate international-transfer review.
- Incident readiness must be operational. Current ANPD rules generally set a three-business-day communication period for incidents that meet the relevant-risk or damage threshold.
This checklist is designed for a foreign business that needs to answer a practical question: “If the LGPD applies to us, what should we review next?”
If you have not yet assessed territorial scope, start with our guide Does Brazil's LGPD Apply to U.S. Companies?. The Article 3 analysis is relevant far beyond U.S. companies because the LGPD can apply regardless of the country where an organization is headquartered or where the data is located when a statutory territorial trigger is present.
How to Use This 25-Point Checklist
For each item, assign one of three statuses and record evidence. Avoid scoring based only on what a policy says. Score the control based on what the organization can actually demonstrate.
Article 6 of the LGPD includes accountability and demonstration among the law's core principles: the organization should be able to demonstrate effective measures capable of showing compliance with data-protection rules.
1–5. Confirm Scope and Build the Data Picture
Confirm whether the LGPD applies to each Brazil-facing activity
Test the organization against Article 3 instead of relying on the location of the corporate headquarters. Review processing performed in Brazil, processing aimed at goods/services or individuals located in Brazil, and personal data collected while the individual is in Brazil.
Identify what counts as personal and sensitive personal data
Inventory information linked to identified or identifiable natural persons. Separate ordinary personal data from sensitive categories because Article 11 applies a different legal-basis framework to sensitive personal data.
- Customer and prospect records
- Account and device identifiers
- Support and communications data
- Employee or contractor information
- Health, biometric, religious, political, union, sexual-life, genetic, and other sensitive categories defined by the LGPD
Map the complete data lifecycle
Identify where data is collected, transmitted, enriched, analyzed, stored, accessed, shared, backed up, archived, and deleted. Include both customer-facing systems and internal tools.
Identify controller and operator roles by processing activity
Do not classify an entire company as “the processor” or “the controller” without looking at the specific activity. Under the LGPD, the controller makes decisions regarding processing, while an operator processes personal data on behalf of the controller.
Maintain a record of processing activities
Article 37 requires controllers and operators to maintain records of the personal-data processing operations they perform, especially when processing is based on legitimate interest.
A useful processing inventory should connect the activity to purpose, categories of data, data subjects, systems, recipients, roles, legal basis, retention, transfers, security, and ownership.
6–10. Document Why You Process Data and What You Tell People
Define a specific purpose for every material processing activity
Article 6 requires processing for legitimate, specific, explicit, and informed purposes and limits incompatible later processing. “Business purposes” or “improving services” may be too vague to function as useful internal records.
Assign the correct legal basis instead of defaulting to consent
Article 7 provides multiple legal bases for ordinary personal data, including consent, legal or regulatory obligation, contract-related processing, exercise of rights, protection of life, legitimate interest, and credit protection, among others.
Select the basis based on the actual purpose and facts. Then record why that basis fits.
If you rely on legitimate interest, document the assessment
Article 10 requires a concrete analysis of legitimate purposes and the rights and freedoms of the data subject. It also requires strict necessity and transparency for processing based on legitimate interest.
Review consent collection and withdrawal where consent is actually used
Consent must relate to determined purposes, and the controller bears the burden of proving that valid consent was obtained. The law also requires a free and facilitated withdrawal process.
Make privacy notices match operational reality
Article 9 calls for clear, adequate, and prominent information about matters such as processing purposes, duration, controller identity/contact, data sharing, responsibilities, and data-subject rights.
Compare the notice line by line against the actual data map. A polished notice that omits material systems, recipients, or purposes is still an operational gap.
11–15. Review the Technology Stack Around the Core Business
Inventory cookies, analytics, pixels, SDKs, and other trackers
List the technologies actually deployed, the identifiers they collect, their purposes, default behavior, duration, recipients, and how user choices are applied. Do not rely only on what a cookie banner says.
Map CRM, email, WhatsApp, lead generation, and advertising workflows
Marketing often creates some of the most fragmented data flows in a global business. Review forms, purchased or partner leads, enrichment, CRM, outbound email, WhatsApp, remarketing, customer lists uploaded to advertising platforms, suppression lists, and lead handoffs.
Perform vendor and subprocessor due diligence
Identify vendors that host, analyze, transmit, secure, enrich, or otherwise process personal data. Review their role, instructions, security commitments, subprocessors, incident escalation, deletion, assistance with rights, and cross-border processing.
Review international data transfers separately from vendor contracting
Article 33 and the ANPD's International Data Transfer Regulation create a specific transfer framework. Resolution CD/ANPD No. 19/2024 regulates mechanisms including adequacy decisions, Brazilian standard contractual clauses, equivalent clauses, specific contractual clauses, and binding corporate rules.
Map not only storage location but also remote access by global support, engineering, security, parent companies, affiliates, and subprocessors.
Identify processing involving children, adolescents, or other higher-risk contexts
Article 14 requires processing of children's and adolescents' personal data to be carried out in their best interest. Children's data has specific consent requirements in the statute, subject to the law's detailed rules and exceptions.
Also flag large-scale sensitive data, biometrics, profiling, emerging technologies, or other activities that can increase privacy risk.
This is where a short checklist starts becoming a real audit.
The Brazil LGPD Compliance Playbook expands this 25-point screening into a structured 100-point compliance audit plus 16 implementation worksheets.
See the full Brazil LGPD Compliance Playbook →16–20. Test Whether Your Compliance Process Actually Works
Build and test a data-subject request workflow
Article 18 provides rights including confirmation, access, correction, anonymization/blocking/deletion in applicable circumstances, portability, information about sharing, information about consent, and withdrawal of consent.
Article 19 provides for simplified confirmation/access immediately or a clear and complete access statement within up to 15 days, subject to the law and applicable regulation.
Review automated decision-making and profiling
Article 20 gives data subjects the right to request review of decisions made solely on automated processing that affect their interests, including certain profiling decisions. Controllers must also provide clear and adequate information about the criteria and procedures used when requested, subject to commercial and industrial secrecy.
Create a retention and deletion schedule
Articles 15 and 16 address termination of processing and permitted retention after processing ends. Retention should therefore be connected to specific purposes, legal obligations, claims/rights, research where applicable, anonymization, and actual deletion capabilities.
Implement technical and administrative security measures
Article 46 requires agents to adopt technical and administrative measures capable of protecting personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication, or other improper processing.
The LGPD also states that security measures should be considered from the design phase of products and services through execution.
Create a security-incident response and notification process
Not every security incident must be reported. The controller must assess whether an incident can cause relevant risk or damage to data subjects. Under current ANPD rules, where the reporting threshold is met, the controller generally must communicate the incident to the ANPD and affected data subjects within three business days, subject to a specific deadline in another applicable law.
Operators should inform the controller without unjustified delay and provide the information needed for the controller's assessment and notification.
21–25. Build the Evidence That Keeps the Program Alive
Assess the current encarregado / DPO requirement
Article 41 addresses the appointment of an encarregado and requires public disclosure of the encarregado's identity and contact information in a clear and objective manner, preferably on the controller's website.
The ANPD's current rules include Resolution CD/ANPD No. 18/2024 on the role of the encarregado. Qualifying small processing agents can have an exemption under Resolution No. 2/2022, but the exemption is conditional and does not remove the rest of the LGPD's obligations.
Determine when a Data Protection Impact Report (RIPD) is needed
Article 38 allows the ANPD to require the controller to prepare a Data Protection Impact Report. The LGPD defines the report as documentation describing processing that may create risks to civil liberties and fundamental rights, along with risk-mitigation measures and safeguards.
Even where a report has not been formally demanded, a structured impact assessment can be useful for higher-risk processing decisions.
Train people according to their role
Privacy training should reflect what people actually do. Marketing, customer support, HR, engineering, security, procurement, sales, product, and leadership face different privacy decisions.
Article 50 expressly contemplates educational actions as part of good-practice and governance rules.
Create a remediation tracker with owners and deadlines
A compliance assessment without ownership becomes a document archive. Convert every material gap into an action with an owner, priority, due date, dependency, evidence requirement, and closure test.
Establish continuous privacy governance
Article 50 contemplates governance programs, internal oversight, incident and remediation plans, systematic risk evaluation, and continuous monitoring and periodic evaluation.
Revisit the program when products, vendors, tracking, countries, acquisition channels, data categories, AI use, business models, or ANPD rules change.
High-Risk Red Flags That Deserve Faster Review
The checklist above is broad. Certain signals should move an activity toward the front of the review queue because the potential impact, complexity, or regulatory exposure can be higher.
| Red flag | Why it matters | What to verify |
|---|---|---|
| Sensitive or biometric data | Different legal-basis rules and potentially higher impact on individuals. | Purpose, Article 11 basis, necessity, access controls, security, retention. |
| Children or adolescents | Article 14 introduces best-interest and child-specific requirements. | Age handling, consent where applicable, transparency, minimization, design. |
| Large-scale profiling | Can affect rights, expectations, discrimination risk, and automated decisions. | Purpose, basis, Article 20 process, transparency, safeguards, impact assessment. |
| International transfer chains | Multiple importers/subprocessors can make the transfer mechanism and onward flows difficult to evidence. | Exporter/importer roles, mechanism, clauses, onward transfer, access locations. |
| Weak incident escalation | Current ANPD reporting rules can require rapid action after a qualifying incident. | Detection, ownership, controller/operator escalation, three-business-day process, documentation. |
| “Consent to everything” | Consent has validity, proof, purpose, and withdrawal requirements and is not the only legal basis. | Activity-by-activity legal basis and consent evidence where consent is actually used. |
How to Turn This Checklist Into a 30-Day Remediation Plan
Do not try to fix all 25 items at once. A practical first month can be organized around four weekly outcomes:
- Week 1 — Discover and scope: Article 3 analysis, systems, vendors, data flows, sensitive data, current notices and policies.
- Week 2 — Decide and document: processing inventory, roles, legal bases, legitimate interest, transfers, retention, rights workflow.
- Week 3 — Implement controls: notices, forms, tracking behavior, marketing preferences, vendor issues, security, deletion/export, incident channels.
- Week 4 — Test and govern: mock rights requests, incident exercise, cookie tests, vendor escalation, training, evidence review, governance calendar.
This does not mean a company can guarantee “full LGPD compliance in 30 days.” The objective is to create a structured implementation cycle, surface the highest-priority gaps, produce evidence, and identify issues that need qualified legal, security, or technical review.
Ready to Go Beyond the 25-Point Checklist?
The Brazil LGPD Compliance Playbook — 2026 Edition expands this screening into a 100-point LGPD Compliance Audit, a 30-day implementation roadmap, real business scenarios, and 16 practical worksheets for documenting the work.
Frequently Asked Questions
What should a foreign company include in an LGPD compliance checklist?
At minimum, review territorial scope, data mapping, roles, purposes and legal bases, transparency, consent where used, sensitive and children's data, tracking and marketing, processing records, vendors, international transfers, rights, automated decisions, retention, security, incidents, the encarregado, impact assessments, training, remediation, and governance.
Does a foreign company need a Brazilian office for the LGPD to apply?
No. Article 3 can apply regardless of the country where the organization is headquartered or where the data is located when one of the law's territorial triggers is present.
Does every company have to use consent under the LGPD?
No. Consent is only one legal basis. Article 7 contains multiple legal bases for ordinary personal data, and Article 11 contains the framework for sensitive personal data. The correct basis depends on the purpose and facts of the processing.
Do controllers and operators need records of processing?
Article 37 states that controllers and operators must maintain records of the personal-data processing operations they perform, especially when the processing is based on legitimate interest. Small processing agents may have access to a simplified format under ANPD rules if they qualify.
How quickly must a relevant security incident be communicated?
Under current ANPD Resolution CD/ANPD No. 15/2024, when an incident can cause relevant risk or damage to data subjects, the controller generally must communicate it to the ANPD and affected data subjects within three business days, except where another specific law provides a different deadline.
Does every foreign company need an encarregado / DPO?
The answer depends on the organization's role and whether a valid exemption applies. Article 41 and the ANPD's current encarregado rules should be reviewed against the company's actual processing. Qualifying small processing agents can have an exemption, but that exemption is conditional and does not remove the remaining LGPD obligations.
Is this 25-point checklist a complete legal audit?
No. This is a management-level screening tool. A complete assessment depends on the organization's business model, sector, processing purposes, data, systems, vendors, contracts, locations, risks, and other applicable laws.
Official Sources Used for This Checklist
- Law No. 13,709/2018 — LGPD, current compiled text (Planalto) Primary source for territorial scope, principles, legal bases, transparency, rights, transfers, records, encarregado, security, incidents, governance, and sanctions.
- ANPD — Current Regulations Official regulatory index, including current rules on security incidents, the encarregado, international transfers, and small processing agents.
- ANPD — International Data Transfers Official overview of Resolution CD/ANPD No. 19/2024 and transfer mechanisms.
- ANPD — Security Incident Communication Current ANPD guidance on risk assessment, controller/operator roles, and the three-business-day communication period for qualifying incidents.
- ANPD Resolution CD/ANPD No. 2/2022 — Small Processing Agents Rules on simplified records, encarregado exemption, security, deadlines, and the limits of small-agent flexibility.
- ANPD — Data Protection Impact Report (RIPD) Official guidance concerning the impact-report process and organizational participation.