Quick Answer: How should a company handle an LGPD data-subject request?
Start by identifying the requester, the right being exercised, the controller responsible for the relevant processing, and the systems and vendors that may contain the person's data. Article 18 gives data subjects rights including confirmation, access, correction, anonymization/blocking/deletion in qualifying situations, portability subject to regulation, deletion of consent-based data subject to Article 16 exceptions, information about sharing and consent, and withdrawal of consent. Article 20 adds rights related to certain solely automated decisions. For confirmation/access, Article 19 provides either an immediate simplified response or a clear and complete statement within up to 15 days. Other response deadlines remain subject to ANPD regulation, and the Agency's July 2026 regulatory agenda says that broader regulation of Articles 9, 18, 19 and 20 is still in progress.
Key Takeaways
- LGPD rights are operational, not decorative. The company needs systems, ownership, verification, search and response procedures behind the privacy notice.
- There is no single universal “15-day deadline” for every LGPD right. The 15-day statutory period specifically applies to the clear and complete confirmation/access statement under Article 19.
- Other Article 18 deadlines are still being regulated. As of July 16, 2026, ANPD says the broader rights regulation remains in progress.
- Deletion is not absolute. Article 16 permits retention in specified situations even after processing would otherwise end.
- Corrections can propagate downstream. Article 18 requires the responsible party to notify agents with whom data was shared of correction, deletion, anonymization or blocking, except where impossible or disproportionately burdensome.
- Requests must be free. Article 18 prohibits charging the data subject for exercising these rights.
- ANPD escalation generally follows a prior attempt with the controller. The Agency asks for evidence that the specific controller was first contacted and the issue remained unresolved.
Many global privacy teams use the term DSAR—data subject access request—as a general label for privacy-rights requests. Under the LGPD, however, a request can involve much more than access. It can ask for correction, deletion, information about sharing, consent withdrawal, portability, opposition, or review of a solely automated decision.
The safest operational model is therefore not to create one “download my data” button and assume the problem is solved. Build a rights-request process that can classify the request, apply the correct legal rule, search the right systems, protect other people and confidential information, coordinate with vendors, and document the final decision.
LGPD Data Subject Rights Explained
Confirmation of Processing
A data subject can ask whether the controller processes personal data relating to that individual. This is often the first step before requesting more detailed access.
Access to Personal Data
The data subject can request access to personal data processed by the controller. Article 19 creates two response formats: an immediate simplified response or a clear and complete statement within up to 15 days.
Correction
Incomplete, inaccurate or outdated personal data can be corrected. ANPD's public rights page explains that correction can include updating information and, where needed, adding information to make the record accurate.
Anonymization, Blocking or Deletion of Unnecessary, Excessive or Non-Compliant Data
Article 18 permits the data subject to request anonymization, blocking or deletion when personal data is unnecessary, excessive or processed in violation of the LGPD.
This right is different from the separate Article 18 right to deletion of data processed on the basis of consent.
Portability
A data subject can request portability to another service or product provider, subject to ANPD regulation and commercial/industrial secrecy. Article 18 also says portability does not include data already anonymized by the controller.
Deletion of Consent-Based Data
Article 18 gives the data subject a right to request deletion of personal data processed on the basis of consent, except where Article 16 permits lawful retention.
Information About Sharing
The data subject can ask which public and private entities received personal data through shared use. A generic privacy notice describing “service providers” does not eliminate the need for an internal recipient/vendor record.
Information About Consent and the Consequences of Refusal
Where consent is requested, the data subject has a right to information about the possibility of not providing it and the consequences of refusal. This connects Article 18 to the transparency obligations in Article 9.
Withdrawal of Consent
Consent can be withdrawn by an express manifestation through a free and facilitated procedure. Withdrawal should stop future processing that depends on that consent, subject to the legal treatment of prior processing and any separate lawful basis or retention rule.
Opposition in Certain No-Consent Processing
Article 18 allows the data subject to oppose processing based on a legal ground that does not require consent when the processing violates the LGPD. This is not a blanket veto over every non-consent legal basis; the statutory condition matters.
Review of Certain Solely Automated Decisions
Article 20 gives the data subject the right to request review of decisions made solely on automated processing that affect the person's interests, including decisions defining personal, professional, consumer or credit profiles or aspects of personality.
Explanation of Automated Decision Criteria and Procedures
When requested, the controller must provide clear and adequate information about the criteria and procedures used for the automated decision, subject to commercial and industrial secrecy. If information is withheld on that basis, ANPD may audit for discriminatory aspects.
How Long Does a Company Have to Respond?
This is one of the most misunderstood LGPD topics. There is not one universal 15-day deadline for every data-subject right.
Article 18 says rights are exercised by an express request of the data subject or legally constituted representative to a processing agent. If the requested action cannot be taken immediately, the controller should respond either that it is not the relevant processing agent and, where possible, indicate the responsible agent, or explain the factual or legal reasons preventing immediate action.
Article 18 also says the request must be handled without cost to the data subject, under deadlines and terms established by regulation.
2026 Regulatory Status: The Broader Rights Regulation Is Still in Progress
ANPD's regulatory agenda, updated July 16, 2026, lists “Rights of data subjects” as an action still in progress. The Agency specifically says Articles 9, 18, 19 and 20 still contain points requiring regulation and that the action is in the internal drafting phase.
This matters for published compliance content: do not invent a universal deadline for correction, deletion, portability, opposition or every other Article 18 request when ANPD itself says the broader regulatory work is not yet complete.
Qualifying small processing agents
Resolution CD/ANPD No. 2/2022 gives qualifying small processing agents differentiated deadlines. Article 14 expressly provides double time in specified situations, including:
- requests under Article 18, subject to the specific regulation;
- the clear and complete Article 19 statement; and
- certain other ANPD deadlines.
Article 15 of the same regulation allows qualifying small agents to provide the simplified Article 19 statement within up to 15 days, rather than immediately.
How to Handle an LGPD Access Request
An access request should begin with scope. The company needs to understand what the individual is asking for, what personal data it actually controls, and whether the request concerns one account, multiple products, historical records, marketing systems or customer data processed on behalf of another controller.
Article 19's clear and complete statement should indicate:
- the origin of the data;
- the absence of a record where applicable;
- the criteria used; and
- the purpose of the processing, subject to commercial and industrial secrecy.
The law also says personal data should be stored in a format that favors the exercise of access rights. Information can be supplied electronically through a secure and suitable method or in printed form, at the data subject's choice.
What about data processed as an operator?
A SaaS provider or service provider may receive a request from a person whose personal data it processes only on behalf of a customer-controller. The request should be routed according to the actual controller/operator roles and contractual instructions.
The provider should not automatically ignore the person, but it also should not make controller-level decisions outside its authority. Build a routing rule that identifies requests relating to provider-controlled data versus customer-controlled data.
See our LGPD for SaaS Companies guide for a deeper role-by-purpose framework.
How to Handle an LGPD Deletion Request
“Delete everything you have about me” requires legal and technical classification. The LGPD contains different deletion-related rights, and some data can lawfully remain after the request.
Deletion because data is unnecessary, excessive or non-compliant
Article 18 permits anonymization, blocking or deletion of personal data that is unnecessary, excessive or processed in violation of the law. The company should examine whether the specific data or processing fails the necessity, purpose or other LGPD requirements.
Deletion of consent-based data
Article 18 separately allows deletion of personal data processed with the data subject's consent, except for the retention situations in Article 16.
Article 16 retention exceptions
After processing ends, the LGPD permits retention for specified purposes including:
- compliance with a legal or regulatory obligation;
- research by a research body, with anonymization whenever possible;
- transfer to a third party where the LGPD requirements are respected; or
- exclusive use by the controller, with access by third parties prohibited and the data anonymized.
Backups
The LGPD does not create a magical requirement that every backup bit be instantly erased on demand. The organization should align its retention and deletion architecture with the legal purpose, technical lifecycle and security model. If deleted production data remains temporarily in immutable backups, document the backup retention, access restrictions, restoration controls and how the data returns to the deletion workflow if a backup is restored.
Correction Requests and Downstream Updates
Correction creates an operational duty that many companies miss. Article 18 says the responsible party must inform agents with whom personal data was shared of correction, deletion, anonymization or blocking so they can repeat the same procedure.
The exception is where that communication is demonstrably impossible or would require disproportionate effort.
This means a correction workflow should ask:
- which internal systems hold the outdated data;
- which vendors or recipients received the old value;
- whether those recipients can update the record;
- whether the correction should propagate to derived profiles or accounts; and
- how the company will document completion.
| System | Typical action | Evidence |
|---|---|---|
| CRM | Correct name, email, phone or profile field. | Audit trail / updated record. |
| Billing | Update customer profile where legally and operationally appropriate. | Billing change log. |
| Support | Correct structured account metadata; preserve historical correspondence appropriately. | Ticket/account audit history. |
| Marketing | Update contact data and preference/suppression records. | CRM/email platform history. |
| Vendor / recipient | Notify downstream party when Article 18 requires propagation. | Vendor ticket, API update or written confirmation. |
How Should a Company Verify the Requester's Identity?
The rights process itself can become a privacy incident if a company sends personal data to the wrong person. Identity verification should therefore be strong enough to protect the data but proportionate enough not to become a barrier to rights.
The LGPD does not prescribe one universal identity-verification method for every private-sector request. A risk-based process can use existing authenticated accounts, confirmation through previously verified contact channels, transaction/account information, or additional documentation where genuinely necessary.
A practical verification rule should consider:
- sensitivity of the data requested;
- risk of impersonation or account takeover;
- whether the requester is already authenticated;
- which identifiers the company already holds;
- whether a legally constituted representative is acting for the person; and
- how verification data itself will be retained and protected.
A 12-Step LGPD Data Subject Request Workflow
What Should Be in a Data Subject Request Log?
| Field | Why it matters |
|---|---|
| Request ID | Creates a stable reference without exposing the requester's full identity in every workflow. |
| Date received | Starts the applicable deadline analysis. |
| Requester / representative | Shows who exercised the right and whether representation was used. |
| Verification status | Documents the security control used before disclosing or changing data. |
| Right exercised | Determines the applicable legal analysis and response format. |
| Systems searched | Demonstrates scope and reduces the risk of incomplete responses. |
| Vendors / recipients | Supports downstream correction/deletion and sharing-information requests. |
| Decision | Granted, partially granted, denied, routed or awaiting clarification. |
| Legal / factual reason | Supports Article 18 responses where immediate action is not possible. |
| Response date | Demonstrates deadline performance. |
| Completion evidence | Links export, deletion, correction, vendor tickets or other proof. |
Common LGPD Rights-Request Mistakes
“Every LGPD request has a 15-day deadline.”
Incorrect. Article 19's 15-day period is for the clear and complete confirmation/access statement. ANPD's broader rights regulation is still in progress.
“Deletion means delete absolutely everything immediately.”
Incorrect. Article 16 provides lawful retention situations, and the company should separate retained data from data that can be deleted or anonymized.
“The request came to the wrong email, so we can ignore it.”
Risky. Rights are not created by one magic mailbox. Staff should know how to route privacy requests that arrive through support, sales, WhatsApp or other business channels.
“We only search the CRM.”
A meaningful request can involve support, billing, cloud, analytics, marketing, security logs and other systems. The data map determines search scope.
“We corrected our database, so the request is complete.”
Not always. Article 18 contains a downstream notification rule for correction, deletion, anonymization and blocking where data was shared.
“We require a passport from every requester.”
That can create unnecessary data collection and risk. Use proportionate identity verification based on the data and context.
Rights requests become much easier when the data map already exists.
Use our 25-point LGPD Compliance Checklist to connect request handling with data mapping, vendors, legal bases, retention, security, transfers and governance.
What Happens If the Company Does Not Resolve the Request?
Article 18 gives the data subject the right to petition ANPD in relation to personal data against the controller. The right can also be exercised before consumer-protection bodies where applicable.
ANPD's current FAQ explains an important practical step: a data-subject petition about a specific controller should be accompanied by evidence that the matter was first submitted to the controller and was not resolved within the applicable period. ANPD says self-declaration can be accepted when other proof is unavailable.
Examples given by ANPD include a controller failing to respond to a request for correction, deletion or withdrawal of consent.
Automated Decisions and AI: Build a Separate Escalation Path
Article 20 is increasingly important for credit, fraud, employment, insurance, marketplaces, personalization and AI-enabled products. If a decision is made solely on automated processing and affects the person's interests, the data subject can request review.
When requested, the controller must provide clear and adequate information about the criteria and procedures used, subject to commercial and industrial secrecy. If the controller does not provide information on that basis, ANPD can audit the processing to examine discriminatory aspects.
The Agency's 2025–2026 regulatory agenda also lists artificial intelligence as an ongoing action and specifically highlights interpretation of Article 20 and data-subject rights as part of that work.
Operationally, that means a general support queue should not be the only process for an automated-decision challenge. Create an escalation path to the team that understands the model, decision criteria, data inputs, human-review capability and fairness risks.
A Practical Rights-Request Readiness Test
| Test | Question | Passing evidence |
|---|---|---|
| Discovery | Can staff recognize a privacy-rights request even if the person does not cite the LGPD? | Training, routing procedure and request examples. |
| Ownership | Who owns the request from intake to closure? | Named privacy/operations owner and backup. |
| Verification | Can identity be verified without unnecessary data collection? | Risk-based verification matrix. |
| Search | Can the company find the person's data across relevant systems? | ROPA/data map and system-owner list. |
| Deletion | Can systems distinguish deletion from lawful retention? | Retention schedule and deletion playbook. |
| Correction | Can updates propagate to relevant recipients? | Vendor/recipient map and update process. |
| Access | Can a complete response be produced and delivered securely? | Export procedure, response template and secure channel. |
| Timing | Does the workflow recognize Article 19's 15-day rule and avoid inventing one deadline for all rights? | Deadline matrix tied to current law/regulation. |
| Evidence | Can the company prove what it did? | Data-Subject Request Log and retained completion evidence. |
Turn Data Subject Requests Into a Repeatable LGPD Process
The Brazil LGPD Compliance Playbook — 2026 Edition includes both a Data-Subject Request Intake Form and a Data-Subject Request Log, plus a Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, Retention Schedule, Vendor Review, 100-point compliance audit and a 30-day implementation roadmap.
Frequently Asked Questions
What data subject rights does the LGPD provide?
Rights include confirmation, access, correction, anonymization/blocking/deletion of unnecessary, excessive or non-compliant data, portability subject to regulation, deletion of consent-based data subject to Article 16, information about sharing, information about the consequences of refusing consent, withdrawal of consent, opposition in certain non-compliant no-consent processing, petition to ANPD or consumer-protection bodies, and review/explanation of certain solely automated decisions.
How long does a company have to respond to an LGPD access request?
For confirmation/access, Article 19 permits an immediate simplified response or a clear and complete statement within up to 15 days. Other Article 18 deadlines remain subject to ANPD regulation, and the Agency's July 2026 regulatory agenda says that broader rights regulation is still in progress.
Is 15 days the deadline for every LGPD request?
No. The statutory 15-day rule in Article 19 applies to the clear and complete confirmation/access statement. ANPD has not finalized one universal 15-day rule for every Article 18 right.
Can a company refuse an LGPD deletion request?
Sometimes. The legal result depends on why deletion is requested and whether Article 16 or another lawful requirement permits retention. If immediate action cannot be taken, Article 18 requires the controller to explain the factual or legal reason.
Are LGPD rights requests free?
Yes. Article 18 says the request must be handled without cost to the data subject under the applicable terms and deadlines.
Do corrections have to be sent to vendors?
Article 18 requires the responsible party to immediately inform processing agents with whom data was shared about correction, deletion, anonymization or blocking so they can repeat the procedure, except where that communication is demonstrably impossible or would require disproportionate effort.
Can a data subject complain to ANPD?
Yes. ANPD says a petition concerning a specific controller should generally include evidence that the issue was first presented to that controller and remained unresolved within the applicable period. Self-declaration may be accepted where other evidence is unavailable.
Do qualifying small processing agents get more time?
Resolution 2/2022 provides differentiated deadlines for qualifying small agents. It expressly gives double time for the clear and complete Article 19 statement and allows up to 15 days for the simplified Article 19 statement. Other request timing remains subject to the applicable regulation.
Can a person ask for review of an AI decision under LGPD?
Article 20 applies when a decision is made solely on automated processing of personal data and affects the person's interests. The data subject can request review and can request clear and adequate information about the criteria and procedures used, subject to commercial and industrial secrecy.
Should every requester have to upload an ID document?
Not necessarily. The company should verify identity securely and proportionately. Where an authenticated account or previously verified contact channel provides sufficient assurance, demanding additional identity documents can create unnecessary data collection and security risk.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary source for Articles 17–22, including rights, request handling, access timing, automated decisions, downstream updates and retention exceptions.
- ANPD — Data Subject Rights Current official overview of information, confirmation/access, correction, blocking/deletion/portability, consent withdrawal, sharing information and automated-decision rights.
- ANPD — Frequently Asked Questions Current ANPD explanations of Article 18 request handling, Article 19 timing, small-agent rules and petitioning the Agency after an unresolved controller request.
- ANPD — 2025–2026 Regulatory Agenda Current status of the broader data-subject-rights regulation, listed as in progress and in internal drafting as of July 16, 2026.
- ANPD Resolution CD/ANPD No. 2/2022 — Small Processing Agents Primary regulatory source for differentiated rights-request deadlines applicable to qualifying small processing agents.