2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
Cookies, Tracking & Advertising

LGPD Cookie Consent Requirements: Analytics, Pixels and Advertising

Does Brazil's LGPD require a cookie banner? Can analytics run before consent? What about Meta Pixel, Google Analytics, advertising cookies, remarketing, server-side tracking, and consent management? The useful answer is not “accept all cookies.” It is a purpose-by-purpose legal-basis and control analysis.

Published: Last reviewed: Reading time: ~19 minutes By LGPD Brazil Editorial Team

Quick Answer: Does LGPD require cookie consent?

Not for every cookie and not through one universal rule. The LGPD does not say that every website must obtain consent for every cookie. When a cookie or similar tracker processes personal data, the organization needs an appropriate LGPD legal basis and must comply with principles such as purpose, necessity, transparency, security, and accountability. ANPD guidance says legitimate interest may be appropriate for strictly necessary cookies in suitable contexts and may support limited audience measurement in some cases. For advertising cookies—especially third-party tracking, behavioral profiling, preference prediction, or cross-site tracking—the guide says legitimate interest will generally be harder to justify and that consent may be more appropriate.

Key Takeaways

  • The LGPD does not create a blanket “consent for all cookies” rule. Legal basis depends on purpose and context.
  • ANPD's cookie document is guidance. Its banner recommendations are non-exhaustive good practices for applying the LGPD.
  • Necessary cookies and advertising cookies should not be treated alike. Their privacy impact and legal-basis analysis can be very different.
  • Analytics can sometimes use legitimate interest. ANPD highlights lower-risk audience measurement using aggregated data without additional tracking or profiling as an example.
  • Advertising tracking is more difficult under legitimate interest. Third-party profiling and cross-site tracking are specifically identified as higher-risk contexts where consent may be more appropriate.
  • Consent must be real. No preselected consent, no forced all-or-nothing acceptance, and no assumption that continuing to browse means consent.

Cookie compliance is often implemented backward. A company buys a consent-management platform, installs a banner, creates three categories called “necessary,” “analytics,” and “marketing,” and assumes the legal analysis is finished.

The ANPD's approach points in the opposite direction. Start by understanding which personal data is processed, for which specific purpose, through which technology, for how long, by which parties, and under which legal basis. The banner is then a transparency and control layer built around that analysis—not a substitute for it.

The LGPD itself does not contain a rule that literally says: “Every website must display a cookie banner.” Instead, the statute regulates personal-data processing and requires an appropriate legal basis, transparency, necessity, respect for data-subject rights, security, and other safeguards where the technology processes personal data.

The ANPD's official cookie guide describes banners as widely used mechanisms that can materialize the LGPD principles of transparency and free access. It then provides non-exhaustive good-practice recommendations for designing banners compatibly with the law.

Legal framework vs guidance

Think of the LGPD as the legal framework and ANPD's cookie guide as an official operational interpretation and good-practice resource. The guide does not turn every cookie into a consent cookie and does not say every website needs the same banner configuration.

See ANPD's official cookie guidance page .

In practice, a website that uses non-essential tracking based on consent will usually need a mechanism capable of providing the required information, collecting the user's choice, preventing consent-based trackers from firing before the choice, and allowing the user to change that choice later.

Article 7 of the LGPD contains multiple legal bases for ordinary personal data. Cookies do not sit outside that framework. ANPD explicitly says cookie processing involving personal data must be connected to an applicable legal basis and the specific requirements of that basis.

Often lower risk Strictly necessary

ANPD says legitimate interest may generally be appropriate in suitable cases for cookies essential to providing the service or operating the page.

Context-dependent Audience analytics

Legitimate interest may work in some contexts, especially narrowly scoped measurement using aggregated data without combining trackers or building profiles.

Higher scrutiny Advertising / profiling

ANPD says legitimate interest will generally be difficult where third-party cookies support behavioral profiles, preference prediction, or cross-site tracking.

When consent is used

Under Articles 5, 8, and 9, valid consent must be free, informed, unequivocal, connected to determined purposes, and capable of later withdrawal through a free and facilitated procedure. The controller also bears the burden of proving that consent was validly obtained.

In the cookie context, ANPD translates those principles into very practical expectations: a real choice to accept or reject, clear information about the purpose and retention period, consent-based trackers disabled by default, and a simple way to revoke the consent.

Not recommended by ANPD: inferring consent because the visitor continued browsing, using preselected authorization options, giving the user only an “Accept” button where consent is the basis, or making all-cookie acceptance the condition without an effective alternative.

When legitimate interest is used

Legitimate interest is not “consent without a banner.” Article 10 requires a concrete assessment of legitimate purpose, necessity, the individual's legitimate expectations, fundamental rights and freedoms, and transparency. Only personal data strictly necessary for the intended purpose should be processed.

ANPD's cookie guide says legitimate interest may generally be appropriate for strictly necessary cookies, subject to the facts. It also says audience measurement can sometimes fit legitimate interest where risk is lower—for example, when the processing is limited to identifying aggregate patterns and trends and is not combined with other tracking mechanisms or used to create user profiles.

By contrast, the guide says legitimate interest will often be difficult to justify for advertising cookies, particularly third-party tracking connected with behavioral profiling, preference analysis or prediction, and tracking across different websites.

Necessary Cookies, Analytics and Advertising: Practical Comparison

Category Typical use ANPD guidance signal What to document
Necessary Session, cart, authentication, security, load balancing, essential site preferences. Legitimate interest may generally be appropriate in suitable cases, subject to the concrete assessment. Why essential, data collected, duration, purpose, necessity, access, third parties.
Audience analytics Visits, page views, performance, aggregated trends, product usage measurement. Legitimate interest may be possible in some lower-risk contexts, especially aggregated measurement without combining trackers or profiling. Configuration, identifiability, retention, aggregation, user profile linkage, sharing, transfer, opt-out/opposition process.
Advertising Remarketing, ad personalization, conversion attribution, behavioral audiences, cross-site tracking. Legitimate interest generally harder to justify; consent may be more appropriate, especially with third-party profiling or cross-site tracking. Vendor, identifiers, purpose, profiling, matching, destinations, retention, consent state, withdrawal.
Preference Language, region, display or non-essential personalization choices. Depends on necessity, context, purpose, and whether personal data is processed. User expectation, essentiality, retention, basis, ability to change the preference.
Category names are not legal bases. Calling a tracker “analytics” does not automatically make legitimate interest valid, and calling it “necessary” does not make it necessary. The actual configuration and purpose control the analysis.

What About Meta Pixel, Google Analytics, Ad Tags and Server-Side Tracking?

The ANPD guide is titled “Cookies and Personal Data Protection,” but the LGPD regulates personal-data processing regardless of the technology used. The guide itself emphasizes that indiscriminate personal-data collection and unlimited tracking are incompatible with the LGPD where there is no clear purpose, appropriate legal basis, transparency, or effective control.

Therefore, as an operational inference, the same privacy questions should be asked about technologies that perform similar tracking functions even if they are not technically browser cookies:

  • advertising pixels;
  • SDKs in mobile apps;
  • local storage and similar browser storage;
  • device or browser identifiers;
  • conversion tags;
  • server-side event forwarding;
  • hashed audience uploads;
  • fingerprinting or probabilistic identifiers;
  • cross-device or cross-site identity systems.

Changing the transmission method from browser-side to server-side does not automatically remove the LGPD issue. If personal data is still collected, matched, enriched, profiled, shared, or used for advertising, document the processing based on what actually happens.

Google Analytics

Do not conclude that every analytics implementation can run under legitimate interest merely because ANPD mentions audience measurement as a possible legitimate-interest use case. The guide's lower-risk example is more specific: aggregate pattern and trend identification without combination with other tracking mechanisms or formation of user profiles.

Review your actual configuration: advertising features, user IDs, cross-domain measurement, data retention, integrations, granular events, CRM linkage, geographic processing, and whether the analytics data is used beyond basic audience measurement.

Meta Pixel and advertising tags

Advertising pixels often support attribution, remarketing, audience creation, optimization, behavioral inference, and data matching with third-party platforms. That pattern is much closer to the higher-risk advertising context ANPD describes than to simple aggregated audience measurement.

If consent is the selected legal basis, make sure the pixel or corresponding advertising event does not fire before the necessary consent state is obtained, and make sure withdrawal changes future tracking behavior.

Server-side tracking

Server-side tracking can improve security, performance, and data governance, but it can also make processing less visible to users. Privacy compliance depends on purpose, data, roles, legal basis, transparency, retention, recipients, and controls—not simply whether the event was sent from JavaScript or from a server.

ANPD's guidance uses a layered model: a first-level banner with essential information and high-level choices, followed by a second-level management interface where the user can see categories and more detailed purposes.

ANPD's recommended good practices include:

Easy rejectionProvide an easily visible control to reject all non-essential cookies at both first and second levels.
Second-level managementAllow users to see and control cookie categories and purposes in more detail.
Clear categoriesGroup trackers into understandable categories based on their actual uses and purposes.
Specific informationExplain purposes clearly, precisely, and accessibly instead of relying on vague language such as “improve your experience.”
Consent by purpose where appropriateAllow specific consent according to relevant identified categories/purposes.
Consent-based trackers off by defaultDo not preload optional consent-based cookies and require the user to manually turn them off.
Rights and withdrawalProvide an easy path to learn more, revoke consent, oppose processing where applicable, and exercise other rights.
Browser guidance as a supplementBrowser controls can be explained, but ANPD says they do not replace the site's own direct cookie-management mechanism.

What should you avoid?

ANPD specifically discourages patterns such as:

  • only one first-level “Accept” button where consent is the legal basis;
  • making reject/configure controls difficult to see or understand while emphasizing acceptance;
  • making rejection of non-essential cookies difficult;
  • non-essential cookies enabled by default;
  • no second-level management interface;
  • no direct mechanism for withdrawal or opposition;
  • overly granular information that creates fatigue and prevents meaningful choice; and
  • conditioning consent on full acceptance without effective alternatives.

Do You Need a Separate Cookie Policy?

Not necessarily. ANPD says the essential cookie information can be presented in different legitimate ways: as a dedicated section of the privacy notice, as a separate cookie policy, or through the layered banner itself. What matters is that information about cookies and personal-data collection is clear, precise, and easy to access.

For a site with a larger marketing stack, a separate cookie/tracking policy can still be operationally useful because it provides space to describe categories, vendors, purposes, retention, rights, and preference controls without turning the first-level banner into a wall of text.

How Long Can Cookies Be Kept?

ANPD connects cookie retention to the LGPD principles of purpose and necessity. Its guidance says retention should be compatible with the purpose and limited to what is strictly necessary. Indefinite, excessive, or disproportionate retention periods are described as incompatible with the LGPD.

A useful inventory therefore records duration alongside purpose and legal basis. “Persistent” is not enough. Record the actual lifetime configured by the site or vendor and explain why it is needed.

12-Point LGPD Cookie, Pixel and Tracking Audit

This is a practical screening checklist—not a substitute for a complete legal or technical assessment.

1. Scan the site and appIdentify cookies, pixels, scripts, SDKs, local storage, tags, server-side events and third-party trackers.
2. Map the owner/vendorKnow who places or receives each identifier and which party determines the purpose.
3. Record the exact purposeAvoid generic descriptions. Distinguish security, session, audience measurement, personalization, attribution, remarketing and profiling.
4. Determine whether personal data is processedReview identifiers, IP/device information, account linkage, profiles, matched audiences and re-identification potential.
5. Assign the legal basisDocument why the chosen Article 7 basis fits the actual purpose and configuration.
6. Test legitimate-interest safeguardsWhere used, assess necessity, user expectations, rights/freedoms, minimization, transparency and opposition.
7. Test the banner before consentVerify that consent-based trackers are actually blocked—not merely described as blocked.
8. Test rejectionReject non-essential tracking and confirm optional tags remain disabled.
9. Test withdrawalChange consent later and verify future tracking follows the updated choice.
10. Check retentionRecord and justify cookie/session durations and downstream platform retention.
11. Review third-party and international flowsMap recipients, roles, vendor terms, subprocessors and international-transfer mechanisms.
12. Save evidenceKeep scan results, screenshots, CMP settings, tag configurations, legal-basis decisions, consent logs and review dates.

Tracking is only one part of the website's LGPD exposure.

See our LGPD for E-Commerce guide for the complete journey from advertising and cookies through checkout, payment, shipping, CRM, support and retention.

2026–2027 Regulatory Signal: Targeted Advertising Is on ANPD's Radar

ANPD's published priority map for 2026–2027 includes monitoring the secondary use of personal data for targeted commercial advertising. The same official announcement also highlights privacy-protective design and default settings in its digital-environment priorities.

This does not create a new universal cookie-consent rule by itself. It does mean that advertising, profiling, reuse of data, and privacy-by-default choices are active regulatory concerns rather than theoretical compliance topics.

Read ANPD's 2026–2027 priority announcement .

Practical Examples

Example 1: Necessary session and security cookies

An e-commerce site uses a session cookie to keep products in the cart and a security cookie to detect abusive login attempts. The site documents why the technologies are necessary, limits their duration and use, provides transparency, and performs a legitimate-interest assessment appropriate to the actual facts.

Example 2: Limited audience measurement

A content site uses a privacy-minimized analytics configuration only to understand aggregate page and traffic patterns. It avoids advertising integrations, cross-site tracking, user profiles, CRM linking, and unnecessary identifiers. The controller documents its legitimate-interest assessment, transparency, retention, safeguards and opposition handling.

This fact pattern is closer to the lower-risk analytics scenario ANPD says can sometimes fit legitimate interest. It is not a blanket approval for every configuration of every analytics product.

Example 3: Advertising pixel and remarketing

A store loads a third-party advertising pixel that connects browsing behavior to ad-platform identifiers, builds audiences, optimizes campaigns, measures conversions, and supports remarketing across other sites or apps.

This is much closer to the advertising/profiling scenario for which ANPD says legitimate interest will generally be difficult to justify and consent may be more appropriate. If the store relies on consent, the implementation should prevent consent-based events from firing before valid consent and should respect later withdrawal.

Example 4: “Accept” only banner

A site says, “We use cookies to improve your experience,” and provides only an “Accept” button while advertising trackers are already active. This creates multiple concerns at once: vague purpose, lack of real choice, trackers enabled before consent, and potentially invalid consent if consent is the chosen legal basis.

Turn Your Tracking Inventory Into a Documented LGPD Review

The Brazil LGPD Compliance Playbook — 2026 Edition includes a Cookie and Tracking Inventory, Legal-Basis Decision Record, Legitimate Interest Assessment, Vendor Privacy and Security Review, International Transfer Review, Privacy Notice Framework, 100-point compliance audit, and a 30-day implementation roadmap.

Cookie & Tracking Inventory Legal-Basis Record Legitimate Interest Assessment 100-point audit
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

Does the LGPD require every website to have a cookie banner?

The LGPD does not contain a universal sentence requiring every website to display a cookie banner. When cookies or similar technologies process personal data, the processing must comply with the LGPD. ANPD's cookie guide presents banners as a common transparency/control mechanism and provides non-exhaustive good-practice recommendations.

Do all cookies require consent under the LGPD?

No. ANPD says the legal basis depends on the processing context. It notes that legitimate interest may generally be appropriate for strictly necessary cookies in suitable cases and may support limited audience measurement in some contexts. Advertising tracking, especially third-party profiling and cross-site tracking, is a more difficult legitimate-interest case.

Can analytics cookies rely on legitimate interest?

Sometimes. ANPD specifically notes that audience measurement can in certain contexts rely on legitimate interest, especially where processing is limited to aggregate patterns and trends without combination with other tracking mechanisms or formation of user profiles. A company should document the actual configuration and balancing analysis.

Can advertising pixels rely on legitimate interest?

ANPD says legitimate interest will generally be difficult to justify for advertising cookies, particularly when third-party tracking is associated with behavioral profiles, preference analysis/prediction or tracking across different websites. Consent may be more appropriate in those circumstances, subject to the facts.

Can we assume consent if the user keeps browsing?

ANPD guidance advises against tacit or inferred consent and specifically gives continued browsing as an example that should not be assumed to constitute consent. Where consent is used, a clear positive manifestation should be obtained.

Can non-essential cookies be enabled by default?

Where the cookie is based on consent, ANPD recommends that it be disabled by default. The guide specifically discourages non-essential cookies being pre-enabled and requiring users to turn them off manually.

Does a site need a “Reject non-essential” button?

ANPD's non-exhaustive good-practice recommendations say a clearly visible option to reject all non-essential cookies should be available in first- and second-level banners.

Does server-side tracking avoid LGPD cookie requirements?

Not automatically. The legal analysis follows the personal-data processing, purpose, legal basis, transparency, recipients, retention, transfers and controls. Moving a tracking event from the browser to a server changes the architecture, but does not by itself eliminate LGPD obligations.

Do we need a separate cookie policy?

Not necessarily. ANPD says cookie information can be provided as a dedicated section of the privacy notice, a separate cookie policy, or through the layered banner itself, as long as essential information is clear, precise and easy to access.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD and official ANPD materials available on August 19, 2026. The ANPD cookie guide contains non-exhaustive guidance and good-practice recommendations; application depends on the actual tracker, purpose, data, configuration, legal basis, parties, user expectations, risks, and other applicable law. Product settings and advertising technologies change frequently, so verify both current ANPD guidance and the live configuration of your website or app before making compliance decisions.