2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD Data Subject Rights

LGPD Data Subject Rights: How Companies Should Handle Access, Deletion and Correction Requests

A privacy notice can list rights in a few lines. Actually fulfilling those rights is harder. A single request may require identity verification, searches across CRM, support, billing, cloud and marketing systems, legal review of deletion exceptions, coordination with vendors, correction of shared records, and an auditable response trail. This guide turns Articles 18–20 of Brazil's LGPD into a practical request-handling workflow.

Published: Last reviewed: Reading time: ~21 minutes By LGPD Brazil Editorial Team

Quick Answer: How should a company handle an LGPD data-subject request?

Start by identifying the requester, the right being exercised, the controller responsible for the relevant processing, and the systems and vendors that may contain the person's data. Article 18 gives data subjects rights including confirmation, access, correction, anonymization/blocking/deletion in qualifying situations, portability subject to regulation, deletion of consent-based data subject to Article 16 exceptions, information about sharing and consent, and withdrawal of consent. Article 20 adds rights related to certain solely automated decisions. For confirmation/access, Article 19 provides either an immediate simplified response or a clear and complete statement within up to 15 days. Other response deadlines remain subject to ANPD regulation, and the Agency's July 2026 regulatory agenda says that broader regulation of Articles 9, 18, 19 and 20 is still in progress.

Key Takeaways

  • LGPD rights are operational, not decorative. The company needs systems, ownership, verification, search and response procedures behind the privacy notice.
  • There is no single universal “15-day deadline” for every LGPD right. The 15-day statutory period specifically applies to the clear and complete confirmation/access statement under Article 19.
  • Other Article 18 deadlines are still being regulated. As of July 16, 2026, ANPD says the broader rights regulation remains in progress.
  • Deletion is not absolute. Article 16 permits retention in specified situations even after processing would otherwise end.
  • Corrections can propagate downstream. Article 18 requires the responsible party to notify agents with whom data was shared of correction, deletion, anonymization or blocking, except where impossible or disproportionately burdensome.
  • Requests must be free. Article 18 prohibits charging the data subject for exercising these rights.
  • ANPD escalation generally follows a prior attempt with the controller. The Agency asks for evidence that the specific controller was first contacted and the issue remained unresolved.

Many global privacy teams use the term DSAR—data subject access request—as a general label for privacy-rights requests. Under the LGPD, however, a request can involve much more than access. It can ask for correction, deletion, information about sharing, consent withdrawal, portability, opposition, or review of a solely automated decision.

The safest operational model is therefore not to create one “download my data” button and assume the problem is solved. Build a rights-request process that can classify the request, apply the correct legal rule, search the right systems, protect other people and confidential information, coordinate with vendors, and document the final decision.

LGPD Data Subject Rights Explained

1

Confirmation of Processing

A data subject can ask whether the controller processes personal data relating to that individual. This is often the first step before requesting more detailed access.

Operational evidence: intake date, identity verification, systems searched, confirmation response and delivery record.
2

Access to Personal Data

The data subject can request access to personal data processed by the controller. Article 19 creates two response formats: an immediate simplified response or a clear and complete statement within up to 15 days.

Operational evidence: source systems, export/search scope, data origin, criteria, purpose, secure delivery and access-response log.
3

Correction

Incomplete, inaccurate or outdated personal data can be corrected. ANPD's public rights page explains that correction can include updating information and, where needed, adding information to make the record accurate.

Operational evidence: original value, corrected value, source of correction, systems updated and downstream recipients notified where required.
4

Anonymization, Blocking or Deletion of Unnecessary, Excessive or Non-Compliant Data

Article 18 permits the data subject to request anonymization, blocking or deletion when personal data is unnecessary, excessive or processed in violation of the LGPD.

This right is different from the separate Article 18 right to deletion of data processed on the basis of consent.

Operational evidence: necessity/compliance assessment, decision, systems affected, implementation evidence and downstream action.
5

Portability

A data subject can request portability to another service or product provider, subject to ANPD regulation and commercial/industrial secrecy. Article 18 also says portability does not include data already anonymized by the controller.

Operational evidence: portability request, scope, applicable format/rule, excluded anonymized data and secure transfer process.
6

Deletion of Consent-Based Data

Article 18 gives the data subject a right to request deletion of personal data processed on the basis of consent, except where Article 16 permits lawful retention.

Operational evidence: original legal basis, consent record, deletion scope, Article 16 exception analysis and deletion confirmation.
7

Information About Sharing

The data subject can ask which public and private entities received personal data through shared use. A generic privacy notice describing “service providers” does not eliminate the need for an internal recipient/vendor record.

Operational evidence: vendor/recipient register, data shared, purpose, role, transfer location and relevant date range.
8

Information About Consent and the Consequences of Refusal

Where consent is requested, the data subject has a right to information about the possibility of not providing it and the consequences of refusal. This connects Article 18 to the transparency obligations in Article 9.

Operational evidence: consent language, optional/required distinction, product consequence and version history.
9

Withdrawal of Consent

Consent can be withdrawn by an express manifestation through a free and facilitated procedure. Withdrawal should stop future processing that depends on that consent, subject to the legal treatment of prior processing and any separate lawful basis or retention rule.

Operational evidence: withdrawal event, systems updated, marketing suppression, consent ledger and resulting retention/deletion assessment.
10

Opposition in Certain No-Consent Processing

Article 18 allows the data subject to oppose processing based on a legal ground that does not require consent when the processing violates the LGPD. This is not a blanket veto over every non-consent legal basis; the statutory condition matters.

Operational evidence: legal basis, alleged non-compliance, investigation, decision and remediation if needed.
11

Review of Certain Solely Automated Decisions

Article 20 gives the data subject the right to request review of decisions made solely on automated processing that affect the person's interests, including decisions defining personal, professional, consumer or credit profiles or aspects of personality.

Operational evidence: automated decision inventory, decision logic owner, review process, outcome and explanation record.
12

Explanation of Automated Decision Criteria and Procedures

When requested, the controller must provide clear and adequate information about the criteria and procedures used for the automated decision, subject to commercial and industrial secrecy. If information is withheld on that basis, ANPD may audit for discriminatory aspects.

Operational evidence: explanation template, criteria summary, secrecy assessment, fairness/discrimination review and escalation route.

How Long Does a Company Have to Respond?

This is one of the most misunderstood LGPD topics. There is not one universal 15-day deadline for every data-subject right.

Immediately Article 19 simplified confirmation/access response.
Up to 15 days Article 19 clear and complete confirmation/access statement.
Immediate action where possible ANPD FAQ says the controller should take immediate action on Article 18 requests; if impossible, explain why or indicate the responsible agent.
Other deadlines Remain subject to specific ANPD regulation. The broader rights regulation is still in progress in 2026.

Article 18 says rights are exercised by an express request of the data subject or legally constituted representative to a processing agent. If the requested action cannot be taken immediately, the controller should respond either that it is not the relevant processing agent and, where possible, indicate the responsible agent, or explain the factual or legal reasons preventing immediate action.

Article 18 also says the request must be handled without cost to the data subject, under deadlines and terms established by regulation.

2026 Regulatory Status: The Broader Rights Regulation Is Still in Progress

ANPD's regulatory agenda, updated July 16, 2026, lists “Rights of data subjects” as an action still in progress. The Agency specifically says Articles 9, 18, 19 and 20 still contain points requiring regulation and that the action is in the internal drafting phase.

This matters for published compliance content: do not invent a universal deadline for correction, deletion, portability, opposition or every other Article 18 request when ANPD itself says the broader regulatory work is not yet complete.

Check ANPD's current regulatory agenda .

Qualifying small processing agents

Resolution CD/ANPD No. 2/2022 gives qualifying small processing agents differentiated deadlines. Article 14 expressly provides double time in specified situations, including:

  • requests under Article 18, subject to the specific regulation;
  • the clear and complete Article 19 statement; and
  • certain other ANPD deadlines.

Article 15 of the same regulation allows qualifying small agents to provide the simplified Article 19 statement within up to 15 days, rather than immediately.

Do not rely on small-agent extensions without checking eligibility. The differentiated regime has conditions and exclusions. “Small startup” or “small foreign business” is not itself a legal conclusion under Resolution 2/2022.

How to Handle an LGPD Access Request

An access request should begin with scope. The company needs to understand what the individual is asking for, what personal data it actually controls, and whether the request concerns one account, multiple products, historical records, marketing systems or customer data processed on behalf of another controller.

Article 19's clear and complete statement should indicate:

  • the origin of the data;
  • the absence of a record where applicable;
  • the criteria used; and
  • the purpose of the processing, subject to commercial and industrial secrecy.

The law also says personal data should be stored in a format that favors the exercise of access rights. Information can be supplied electronically through a secure and suitable method or in printed form, at the data subject's choice.

An access request is not simply “export the database row.” The organization should search the relevant systems, explain the processing context, protect third-party information, use a secure delivery method and preserve evidence of what was disclosed.

What about data processed as an operator?

A SaaS provider or service provider may receive a request from a person whose personal data it processes only on behalf of a customer-controller. The request should be routed according to the actual controller/operator roles and contractual instructions.

The provider should not automatically ignore the person, but it also should not make controller-level decisions outside its authority. Build a routing rule that identifies requests relating to provider-controlled data versus customer-controlled data.

See our LGPD for SaaS Companies guide for a deeper role-by-purpose framework.

How to Handle an LGPD Deletion Request

“Delete everything you have about me” requires legal and technical classification. The LGPD contains different deletion-related rights, and some data can lawfully remain after the request.

Deletion because data is unnecessary, excessive or non-compliant

Article 18 permits anonymization, blocking or deletion of personal data that is unnecessary, excessive or processed in violation of the law. The company should examine whether the specific data or processing fails the necessity, purpose or other LGPD requirements.

Deletion of consent-based data

Article 18 separately allows deletion of personal data processed with the data subject's consent, except for the retention situations in Article 16.

Article 16 retention exceptions

After processing ends, the LGPD permits retention for specified purposes including:

  • compliance with a legal or regulatory obligation;
  • research by a research body, with anonymization whenever possible;
  • transfer to a third party where the LGPD requirements are respected; or
  • exclusive use by the controller, with access by third parties prohibited and the data anonymized.
Good response design: distinguish data that will be deleted, data that will be anonymized, data that must be retained for a specific lawful reason, and data that the organization does not control. Give the data subject an understandable explanation instead of a generic “request denied.”

Backups

The LGPD does not create a magical requirement that every backup bit be instantly erased on demand. The organization should align its retention and deletion architecture with the legal purpose, technical lifecycle and security model. If deleted production data remains temporarily in immutable backups, document the backup retention, access restrictions, restoration controls and how the data returns to the deletion workflow if a backup is restored.

Correction Requests and Downstream Updates

Correction creates an operational duty that many companies miss. Article 18 says the responsible party must inform agents with whom personal data was shared of correction, deletion, anonymization or blocking so they can repeat the same procedure.

The exception is where that communication is demonstrably impossible or would require disproportionate effort.

This means a correction workflow should ask:

  • which internal systems hold the outdated data;
  • which vendors or recipients received the old value;
  • whether those recipients can update the record;
  • whether the correction should propagate to derived profiles or accounts; and
  • how the company will document completion.
System Typical action Evidence
CRMCorrect name, email, phone or profile field.Audit trail / updated record.
BillingUpdate customer profile where legally and operationally appropriate.Billing change log.
SupportCorrect structured account metadata; preserve historical correspondence appropriately.Ticket/account audit history.
MarketingUpdate contact data and preference/suppression records.CRM/email platform history.
Vendor / recipientNotify downstream party when Article 18 requires propagation.Vendor ticket, API update or written confirmation.

How Should a Company Verify the Requester's Identity?

The rights process itself can become a privacy incident if a company sends personal data to the wrong person. Identity verification should therefore be strong enough to protect the data but proportionate enough not to become a barrier to rights.

The LGPD does not prescribe one universal identity-verification method for every private-sector request. A risk-based process can use existing authenticated accounts, confirmation through previously verified contact channels, transaction/account information, or additional documentation where genuinely necessary.

Avoid over-collection. Asking every requester to upload a passport or national ID can create a new sensitive security risk when the request could have been verified through an authenticated account or existing verified channel.

A practical verification rule should consider:

  • sensitivity of the data requested;
  • risk of impersonation or account takeover;
  • whether the requester is already authenticated;
  • which identifiers the company already holds;
  • whether a legally constituted representative is acting for the person; and
  • how verification data itself will be retained and protected.

A 12-Step LGPD Data Subject Request Workflow

1. Receive and timestamp the requestRecord the date, channel, requester, request type and original wording.
2. Identify the controller / processing roleDetermine whether your organization is the controller for the data involved or must route an operator-held request.
3. Classify the rightConfirmation, access, correction, deletion, sharing information, consent withdrawal, portability, opposition or automated-decision review.
4. Start the applicable deadline clockApply the Article 19 timing where relevant and track any applicable small-agent rule or future ANPD regulation.
5. Verify identity proportionatelyUse the least intrusive method that provides reasonable assurance for the sensitivity and risk involved.
6. Search the processing mapUse the ROPA/data map to identify systems, vendors, recipients, backups and relevant business owners.
7. Gather and validate the dataConfirm the result belongs to the requester, remove unrelated third-party information and identify data gaps.
8. Apply legal exceptions and retention rulesFor deletion or restriction-type requests, document what can be changed and what lawfully must remain.
9. Coordinate downstream actionsWhere Article 18 requires it, notify recipients of correction, deletion, anonymization or blocking.
10. Prepare a clear responseExplain what was done, what could not be done, why, and any relevant next steps.
11. Deliver securelyUse a secure electronic or appropriate alternative channel, particularly for access responses containing personal data.
12. Close and log the requestPreserve request date, verification, systems searched, decision, exceptions, response, completion date and downstream actions.

What Should Be in a Data Subject Request Log?

Field Why it matters
Request IDCreates a stable reference without exposing the requester's full identity in every workflow.
Date receivedStarts the applicable deadline analysis.
Requester / representativeShows who exercised the right and whether representation was used.
Verification statusDocuments the security control used before disclosing or changing data.
Right exercisedDetermines the applicable legal analysis and response format.
Systems searchedDemonstrates scope and reduces the risk of incomplete responses.
Vendors / recipientsSupports downstream correction/deletion and sharing-information requests.
DecisionGranted, partially granted, denied, routed or awaiting clarification.
Legal / factual reasonSupports Article 18 responses where immediate action is not possible.
Response dateDemonstrates deadline performance.
Completion evidenceLinks export, deletion, correction, vendor tickets or other proof.

Common LGPD Rights-Request Mistakes

“Every LGPD request has a 15-day deadline.”

Incorrect. Article 19's 15-day period is for the clear and complete confirmation/access statement. ANPD's broader rights regulation is still in progress.

“Deletion means delete absolutely everything immediately.”

Incorrect. Article 16 provides lawful retention situations, and the company should separate retained data from data that can be deleted or anonymized.

“The request came to the wrong email, so we can ignore it.”

Risky. Rights are not created by one magic mailbox. Staff should know how to route privacy requests that arrive through support, sales, WhatsApp or other business channels.

“We only search the CRM.”

A meaningful request can involve support, billing, cloud, analytics, marketing, security logs and other systems. The data map determines search scope.

“We corrected our database, so the request is complete.”

Not always. Article 18 contains a downstream notification rule for correction, deletion, anonymization and blocking where data was shared.

“We require a passport from every requester.”

That can create unnecessary data collection and risk. Use proportionate identity verification based on the data and context.

Rights requests become much easier when the data map already exists.

Use our 25-point LGPD Compliance Checklist to connect request handling with data mapping, vendors, legal bases, retention, security, transfers and governance.

What Happens If the Company Does Not Resolve the Request?

Article 18 gives the data subject the right to petition ANPD in relation to personal data against the controller. The right can also be exercised before consumer-protection bodies where applicable.

ANPD's current FAQ explains an important practical step: a data-subject petition about a specific controller should be accompanied by evidence that the matter was first submitted to the controller and was not resolved within the applicable period. ANPD says self-declaration can be accepted when other proof is unavailable.

Examples given by ANPD include a controller failing to respond to a request for correction, deletion or withdrawal of consent.

Your request log is therefore also regulatory evidence. It can show that the company received the request, verified it, investigated it, applied the law, responded within the applicable timing framework and documented any legitimate limitation.

Automated Decisions and AI: Build a Separate Escalation Path

Article 20 is increasingly important for credit, fraud, employment, insurance, marketplaces, personalization and AI-enabled products. If a decision is made solely on automated processing and affects the person's interests, the data subject can request review.

When requested, the controller must provide clear and adequate information about the criteria and procedures used, subject to commercial and industrial secrecy. If the controller does not provide information on that basis, ANPD can audit the processing to examine discriminatory aspects.

The Agency's 2025–2026 regulatory agenda also lists artificial intelligence as an ongoing action and specifically highlights interpretation of Article 20 and data-subject rights as part of that work.

Operationally, that means a general support queue should not be the only process for an automated-decision challenge. Create an escalation path to the team that understands the model, decision criteria, data inputs, human-review capability and fairness risks.

A Practical Rights-Request Readiness Test

Test Question Passing evidence
DiscoveryCan staff recognize a privacy-rights request even if the person does not cite the LGPD?Training, routing procedure and request examples.
OwnershipWho owns the request from intake to closure?Named privacy/operations owner and backup.
VerificationCan identity be verified without unnecessary data collection?Risk-based verification matrix.
SearchCan the company find the person's data across relevant systems?ROPA/data map and system-owner list.
DeletionCan systems distinguish deletion from lawful retention?Retention schedule and deletion playbook.
CorrectionCan updates propagate to relevant recipients?Vendor/recipient map and update process.
AccessCan a complete response be produced and delivered securely?Export procedure, response template and secure channel.
TimingDoes the workflow recognize Article 19's 15-day rule and avoid inventing one deadline for all rights?Deadline matrix tied to current law/regulation.
EvidenceCan the company prove what it did?Data-Subject Request Log and retained completion evidence.

Turn Data Subject Requests Into a Repeatable LGPD Process

The Brazil LGPD Compliance Playbook — 2026 Edition includes both a Data-Subject Request Intake Form and a Data-Subject Request Log, plus a Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, Retention Schedule, Vendor Review, 100-point compliance audit and a 30-day implementation roadmap.

Request Intake Form Request Log Retention Schedule 100-point audit
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

What data subject rights does the LGPD provide?

Rights include confirmation, access, correction, anonymization/blocking/deletion of unnecessary, excessive or non-compliant data, portability subject to regulation, deletion of consent-based data subject to Article 16, information about sharing, information about the consequences of refusing consent, withdrawal of consent, opposition in certain non-compliant no-consent processing, petition to ANPD or consumer-protection bodies, and review/explanation of certain solely automated decisions.

How long does a company have to respond to an LGPD access request?

For confirmation/access, Article 19 permits an immediate simplified response or a clear and complete statement within up to 15 days. Other Article 18 deadlines remain subject to ANPD regulation, and the Agency's July 2026 regulatory agenda says that broader rights regulation is still in progress.

Is 15 days the deadline for every LGPD request?

No. The statutory 15-day rule in Article 19 applies to the clear and complete confirmation/access statement. ANPD has not finalized one universal 15-day rule for every Article 18 right.

Can a company refuse an LGPD deletion request?

Sometimes. The legal result depends on why deletion is requested and whether Article 16 or another lawful requirement permits retention. If immediate action cannot be taken, Article 18 requires the controller to explain the factual or legal reason.

Are LGPD rights requests free?

Yes. Article 18 says the request must be handled without cost to the data subject under the applicable terms and deadlines.

Do corrections have to be sent to vendors?

Article 18 requires the responsible party to immediately inform processing agents with whom data was shared about correction, deletion, anonymization or blocking so they can repeat the procedure, except where that communication is demonstrably impossible or would require disproportionate effort.

Can a data subject complain to ANPD?

Yes. ANPD says a petition concerning a specific controller should generally include evidence that the issue was first presented to that controller and remained unresolved within the applicable period. Self-declaration may be accepted where other evidence is unavailable.

Do qualifying small processing agents get more time?

Resolution 2/2022 provides differentiated deadlines for qualifying small agents. It expressly gives double time for the clear and complete Article 19 statement and allows up to 15 days for the simplified Article 19 statement. Other request timing remains subject to the applicable regulation.

Can a person ask for review of an AI decision under LGPD?

Article 20 applies when a decision is made solely on automated processing of personal data and affects the person's interests. The data subject can request review and can request clear and adequate information about the criteria and procedures used, subject to commercial and industrial secrecy.

Should every requester have to upload an ID document?

Not necessarily. The company should verify identity securely and proportionately. Where an authenticated account or previously verified contact channel provides sufficient assurance, demanding additional identity documents can create unnecessary data collection and security risk.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD and official ANPD materials available on August 19, 2026. ANPD's broader regulation of data-subject rights remains in progress, so request deadlines and procedures beyond rules already established in the LGPD or specific regulations may change. Verify current ANPD sources before relying on timing or procedural details, and obtain qualified Brazilian legal advice for complex or disputed requests.