2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD for Digital Businesses

LGPD for E-Commerce: What Online Stores Selling to Brazil Need to Know

Privacy compliance for an online store is much bigger than a privacy policy. A single Brazilian order can touch advertising pixels, cookies, checkout fields, payment and fraud providers, shipping companies, CRM, email, WhatsApp, customer support, analytics, cloud infrastructure, and international data flows. This guide shows how to map that entire journey.

Published: Last reviewed: Reading time: ~19 minutes By LGPD Brazil Editorial Team

Quick Answer: What does an online store selling to Brazil need to review under LGPD?

An e-commerce business should first test whether its processing falls within Article 3 of the LGPD. If it does, map the entire customer-data lifecycle: website tracking, account creation, checkout, payment, fraud screening, shipping, customer support, CRM, email and WhatsApp marketing, reviews, analytics, vendors, international transfers, retention, data-subject requests, security, and incident response. Each material activity should have a documented purpose, role, legal basis, transparency layer, retention logic, and evidence of the controls actually implemented.

Key Takeaways for E-Commerce Teams

  • A foreign store can fall within LGPD without a Brazilian office. Article 3 looks beyond headquarters location.
  • The privacy journey starts before checkout. Cookies, pixels, analytics, forms, and advertising can process personal data before a purchase occurs.
  • Do not treat payment, fraud, shipping, CRM, and marketing providers as one generic “vendor” category. Map their real roles and data flows.
  • Cookie consent is not a universal answer. ANPD guidance calls for a legal-basis analysis by purpose and warns against indiscriminate tracking.
  • Operational evidence matters. A privacy notice should match what the store and its integrations actually do.

E-commerce creates one of the most visible LGPD use cases because the same customer can generate personal data at every stage of the commercial relationship—from the first ad impression through post-purchase support and repeat marketing.

That makes an online store a useful example of why privacy compliance cannot be reduced to adding a checkbox at checkout. The website, marketing stack, order-management system, payment flow, logistics chain, support tools, and cloud environment all need to be part of the analysis.

The E-Commerce Data Journey

A practical data map can begin with these stages:

1. AcquisitionAds, search, referral links, social media, landing pages.
2. Website VisitCookies, analytics, device and browser data, pixels.
3. Account / LeadName, email, phone, preferences, abandoned-cart identifiers.
4. CheckoutIdentity, contact, billing and delivery information.
5. PaymentTransaction references, payment provider and fraud signals.
6. FulfillmentRecipient, address, phone, order details, shipping provider.
7. SupportTickets, email, WhatsApp, returns, complaints, recordings.
8. Retention / ReuseInvoices, CRM, loyalty, marketing, analytics, deletion.
Useful test: if you cannot draw where customer data travels after someone clicks “Buy,” it is too early to conclude that your privacy policy, cookie banner, retention periods, or vendor contracts are accurate.

Does LGPD Apply to an Online Store Outside Brazil?

It can. Article 3 states that the LGPD can apply independently of the country where the organization is headquartered or where the data is located when one of the law's territorial conditions is met.

For e-commerce, a clear screening scenario is a foreign store that offers products or services to people located in Brazil and processes their information through the commercial journey. Personal data collected while the individual is located in Brazil is also expressly addressed by Article 3.

If you need the deeper territorial analysis, see Does Brazil's LGPD Apply to U.S. Companies?. The same Article 3 framework is relevant to foreign e-commerce businesses from other jurisdictions.

Primary legal source

Article 3 of the current compiled LGPD covers processing regardless of headquarters or data location when the statutory territorial triggers are present. Article 9 also requires clear, adequate, and prominent information about matters such as purpose, processing duration, controller identity/contact, sharing, responsibilities, and data-subject rights.

Read the official compiled LGPD .

12 LGPD Workstreams for an Online Store

1

Map Every Collection Point

List the places where personal data enters the business: cookie technologies, search, account creation, newsletter forms, discount popups, checkout, payment, fraud tools, order notes, support chat, WhatsApp, returns, reviews, surveys, loyalty programs, and customer-service channels.

Evidence: data-flow diagram, form inventory, checkout screenshots, tag-manager export, integration list.
2

Define Purpose and Legal Basis by Activity

Article 7 contains multiple legal bases for ordinary personal data. Do not write “consent” beside every row. The purpose and facts of payment processing, order fulfillment, fraud prevention, marketing, analytics, support, and legal recordkeeping are different and should be assessed separately.

Evidence: purpose/legal-basis register, legitimate-interest assessment where relevant, consent records where consent is actually used.
3

Review the Privacy Notice Against the Real Store

A privacy notice should describe the actual operation. If the store sends order data to a logistics partner, uses fraud screening, uploads audiences to advertising platforms, or transfers support data internationally, those realities should be reflected appropriately in the transparency framework.

Evidence: notice-to-processing map, last-review date, collection notices, vendor/share categories.
4

Separate Checkout Necessity From Optional Marketing

Do not bundle an optional marketing choice into information that is genuinely necessary to process an order. Article 9 requires prominent information when personal-data processing is a condition for providing a product or service. Optional marketing should be assessed and presented according to its own purpose and legal-basis analysis.

Evidence: checkout field map, marketing opt-in design, preference log, legal-basis rationale.
5

Review Payment and Fraud-Prevention Data Flows

Payment service providers, gateways, acquirers, fraud platforms, and identity checks can receive different categories of data and may have different roles in the processing chain.

The store should know what it actually receives and retains. If card details are handled directly by a payment provider, do not falsely state that the store stores full card data.

Evidence: payment-flow diagram, provider contract, fields transmitted, fraud signals, retention, role analysis, security review.
6

Map Shipping and Fulfillment Providers

Delivery often requires sharing recipient name, address, contact information, order identifiers, and sometimes delivery instructions with logistics providers. Dropshipping, fulfillment warehouses, customs workflows, and cross-border carriers can make the chain more complex.

Evidence: recipient-data map, carrier/warehouse register, purpose, role, contract, retention, cross-border location.
7

Control CRM, Email, WhatsApp, and Remarketing

Buying once should not be treated as an unlimited permission to use a customer profile for every future marketing purpose. Review post-purchase campaigns, abandoned-cart reminders, win-back flows, WhatsApp messaging, loyalty programs, audience uploads, suppression lists, and profiling.

When consent is relied upon, the LGPD requires it to be free, informed, unequivocal, connected to determined purposes, and capable of withdrawal through a free and facilitated process.

Evidence: campaign inventory, source/basis, opt-out process, suppression list, preference history, audience-upload register.
8

Review Cookies, Analytics, and Advertising Pixels

The ANPD's cookie guidance rejects indiscriminate personal-data collection without a defined purpose and appropriate legal basis. It also emphasizes clear, precise, easily accessible information and real control for users.

This is especially important in e-commerce because advertising and analytics tags are often added through apps, theme code, tag managers, affiliate scripts, or platform integrations without a central inventory.

Evidence: cookie/tracker inventory, purpose, provider, duration, legal-basis review, consent state, default state, testing results.
9

Build a Data-Subject Rights Workflow

Article 18 provides rights including confirmation, access, correction, deletion/anonymization/blocking in applicable circumstances, portability, sharing information, information about consent, and withdrawal of consent.

The store needs a practical way to locate the same person across commerce platform, CRM, email, support, loyalty, fraud, and other systems before it can reliably execute a request.

Evidence: intake form, identity-verification process, system search map, response log, export/delete procedures.
10

Define Retention by Data Type

Order history, accounting/tax records, support tickets, abandoned-cart records, fraud signals, marketing preferences, analytics identifiers, and backup data should not automatically have the same retention period.

The LGPD's necessity principle limits processing to what is relevant, proportionate, and non-excessive for the stated purpose. The ANPD's cookie guidance likewise warns against indefinite, excessive, or disproportionate cookie retention.

Evidence: retention schedule, purpose/legal rationale, deletion procedure, backup treatment, exceptions.
11

Review Vendors and International Transfers

Commerce platforms, cloud providers, analytics tools, advertising platforms, support systems, fraud services, CRM, email providers, and logistics technologies can process personal data in multiple countries.

Resolution CD/ANPD No. 19/2024 regulates international transfers and provides mechanisms including adequacy decisions, Brazilian standard contractual clauses, recognized equivalent clauses, specific contractual clauses, and binding corporate rules.

Evidence: vendor register, countries, roles, contract/DPA, transfer mechanism, subprocessors, security review.
12

Prepare for Security Incidents Before the Store Has One

Article 46 requires technical and administrative measures to protect personal data. For e-commerce, this should connect privacy to account security, administrator access, credential management, plugins/apps, payment integrations, backups, logging, patching, fraud monitoring, and vendor security.

Under current ANPD rules, when a confirmed incident involving LGPD-covered personal data can cause relevant risk or damage, the controller generally must communicate it to the ANPD and affected data subjects within three business days, subject to a different deadline in specific legislation.

Evidence: response plan, incident contacts, vendor escalation terms, severity/risk matrix, incident log, notification templates, tabletop test.

LGPD Checkout Checklist

The checkout is a high-conversion area, so privacy controls should reduce unnecessary friction while still collecting only what the business actually needs and providing the required transparency.

Field necessityCan you explain why each requested field is needed for purchase, fraud, delivery, tax/legal obligations, or another documented purpose?
Required vs optionalClearly distinguish required order information from optional marketing/profile information.
TransparencyMake the privacy information available at or before collection in an accessible format.
Marketing choiceDo not obscure or preselect consent where consent is the chosen basis.
Payment flowKnow whether payment-card data goes directly to the provider or through your own environment.
Fraud toolsDocument fraud signals, automated scoring, providers, retention, and any meaningful automated-decision implications.
Shipping disclosureMap recipient information shared with carriers, fulfillment partners, or dropshipping suppliers.
Account creationDo not make unnecessary account/profile data a hidden condition of purchase.

Want to audit the entire store instead of only the checkout?

Our 25-point LGPD Compliance Checklist expands the review into scope, data mapping, legal bases, vendors, transfers, rights, security, and governance.

Build an E-Commerce Vendor and Transfer Map

One of the fastest ways to discover privacy gaps is to list every company that receives customer or visitor data. A typical online store may have more processors and recipients than the merchant realizes.

Vendor category Typical data Questions to review
Commerce platformAccount, order, customer, catalog and operational recordsRole, hosting region, subprocessors, security, retention, exports/deletion.
Payment / fraudTransaction, billing, device, risk and identity signalsWhich fields reach the merchant? Independent purposes? Retention? Transfers?
Shipping / fulfillmentName, address, phone, order and delivery dataPurpose, onward sharing, geography, deletion, proof of delivery.
Email / CRMContacts, purchases, preferences, segments, campaign activityPurpose/basis, suppression, retention, profiling, transfer, deletion.
AnalyticsIdentifiers, device/browser, events, pages, conversionsLegal basis, cookie state, retention, linking to account/order data, transfer.
AdvertisingPixels, audiences, conversion events, identifiersConsent/other basis analysis, default state, data matching, audience uploads, controls.
Customer supportIdentity, order history, messages, attachments, recordingsAccess, sensitive data, retention, third-party tools, cross-border support.

If a vendor or team outside Brazil receives or accesses personal data subject to the LGPD, add that flow to the international-transfer review. The current ANPD transfer regulation is Resolution No. 19/2024.

What About Abandoned Carts?

An abandoned-cart workflow is not just a sales automation. It can involve identifiers or contact information collected before the customer completes an order, followed by email, SMS, WhatsApp, or ad remarketing.

Map at least four questions:

  1. At what point is the person's information captured?
  2. What specific purpose is disclosed at collection?
  3. What legal basis supports the reminder or remarketing activity?
  4. How long is an abandoned-cart record kept if no transaction occurs?

The correct answer is context-specific. The important compliance point is not to assume that entering an email during checkout creates unlimited permission for future marketing.

What About Customer Reviews and User-Generated Content?

Reviews can contain a customer's name, profile information, images, purchase information, location references, or other personal data. Decide whether the public display is necessary, which fields are optional, how moderation works, how long the review remains public, and how requests concerning the review are handled.

Avoid publishing more personal information than needed to provide a useful review. This is a direct application of the LGPD's necessity principle: processing should be limited to the minimum relevant, proportionate, and non-excessive data needed for the purpose.

A Practical 30-Day E-Commerce LGPD Roadmap

Week Focus Deliverables
Week 1 Discover & map Article 3 scope, checkout fields, trackers, apps/plugins, vendors, CRM, payment, shipping, support, countries.
Week 2 Decide & document Purposes, legal bases, roles, processing inventory, cookie inventory, vendor/transfer register, retention draft.
Week 3 Implement Privacy/cookie disclosures, banner behavior, marketing preferences, vendor remediation, rights workflow, security changes.
Week 4 Test & govern Cookie tests, mock rights request, customer deletion/export, incident exercise, vendor escalation, evidence review.

This is a structured implementation cycle, not a promise that every e-commerce company can become “fully compliant” in 30 days. Complex transfer, security, contractual, sector, tax, consumer, or legal issues may need specialist review.

Turn Your Online Store Into a Documented LGPD Review

The Brazil LGPD Compliance Playbook — 2026 Edition includes a real-world U.S. Shopify store scenario, a 100-point compliance audit, a 30-day implementation roadmap, and 16 worksheets covering data mapping, legal bases, cookies, vendors, transfers, rights, incidents, privacy notices, retention, and governance.

E-commerce / Shopify scenario 100-point compliance audit 16 implementation worksheets 30-day action plan
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

Does LGPD apply to an online store outside Brazil?

It can. Article 3 can apply regardless of where the store is headquartered or where the data is located when a statutory territorial trigger is present, including Brazil-based processing, processing aimed at goods/services or individuals located in Brazil, or personal data collected in Brazil.

Does an e-commerce store need consent for every cookie under LGPD?

No. The ANPD cookie guide explains that an appropriate legal basis must be identified for cookie-related processing and discusses consent and legitimate interest as common examples without treating the list as exhaustive. Consent can be especially appropriate for non-essential cookies when the user has a genuine choice.

Should non-essential cookies be active before consent?

Where consent is the legal basis, ANPD guidance recommends disabling consent-based cookies by default and providing easy options to reject non-essential cookies and manage categories.

Can the store use “continued browsing” as cookie consent?

The ANPD cookie guide states that consent should be a clear and positive manifestation and does not recommend inferring consent from omission or assuming that continued browsing means consent.

Do payment processors and shipping providers matter for LGPD?

Yes. Map which personal data is shared, the purpose, roles of the parties, contracts, security, retention, onward sharing, and any international transfer involved.

What is the current LGPD security incident notification deadline?

When a confirmed incident involving data subject to the LGPD can cause relevant risk or damage, current ANPD rules generally require the controller to communicate it to the ANPD and affected data subjects within three business days, subject to a specific deadline in another applicable law.

Is a privacy policy enough for an online store?

No. A privacy notice is one transparency control. Effective compliance also depends on the actual data map, purposes and legal bases, tracking behavior, vendor and transfer controls, rights workflows, retention, security, incident response, and evidence.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against official Brazilian sources available on August 19, 2026. E-commerce implementations vary by platform, payment model, logistics chain, advertising stack, countries, industry, and customer profile. Verify current official sources and obtain qualified Brazilian legal and technical advice for decisions involving your organization's specific processing.