2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD for Foreign Companies

Does Brazil's LGPD Apply to U.S. Companies? A Practical 2026 Guide

Yes, a U.S. company can fall within Brazil's LGPD even without a Brazilian subsidiary or office. The right starting point is Article 3: where the processing occurs, what the processing is aimed at, where the individual is located, and where the personal data was collected.

Published: Last reviewed: Reading time: ~14 minutes By LGPD Brazil Editorial Team

Quick Answer: Does the LGPD apply to U.S. companies?

It can. Brazil's LGPD is not limited to companies incorporated in Brazil. Article 3 applies regardless of where a company is headquartered or where its databases are located when at least one territorial trigger is present: the processing occurs in Brazil; the processing is aimed at offering or providing goods or services or processing data of individuals located in Brazil; or the personal data was collected in Brazil. Applicability is fact-specific, so a U.S. company should map each Brazil-facing processing activity rather than rely on headquarters location alone.

Key Takeaways

  • No Brazilian office is required for the LGPD to potentially apply.
  • The territorial test is broader than “Brazilian citizens.” Location matters.
  • A U.S. e-commerce store, SaaS company, app, marketplace, or lead-generation business can trigger Article 3.
  • If Brazilian personal data is sent to or accessed from the United States, international transfer rules may also apply.
  • Do not jump straight to a privacy policy. Start by mapping the actual processing, purposes, vendors, roles, transfers, rights workflows, security controls, and evidence.

A common question from U.S. businesses is: “We do not have an entity in Brazil, so why would Brazilian privacy law apply to us?” Under the LGPD, that is the wrong first question.

The statute expressly says its territorial scope can apply regardless of the country where the company is headquartered or where the data is located. The analysis therefore begins with the processing activity itself.

The Three Article 3 Triggers U.S. Companies Should Test

A practical applicability review should test the business against each of the three territorial triggers in Article 3 of Law No. 13,709/2018.

Article 3 trigger Practical question for a U.S. company Example
1. Processing carried out in Brazil Is any relevant processing operation actually performed in Brazilian territory? A U.S. company has Brazilian staff or infrastructure performing customer-data operations.
2. Brazil-facing purpose / individuals located in Brazil Is the processing aimed at offering or providing goods or services, or at processing data of individuals located in Brazil? A U.S. SaaS platform signs Brazilian users and processes their account, billing, support, and telemetry data.
3. Data collected in Brazil Was the personal data collected while the individual was located in Brazil? A person in São Paulo submits a form to a U.S.-hosted website and the submission enters a U.S.-based CRM.
What the official law says

The current compiled LGPD text states that Article 3 can apply regardless of the medium used, the country of the organization's headquarters, or the country where the data is located, when one of the listed territorial conditions is met.

Read the official compiled LGPD on Planalto .

Trigger 1: Processing in Brazilian Territory

If a relevant processing operation is performed in Brazil, Article 3(I) may bring that activity within scope. This can matter to a U.S. group with a Brazilian subsidiary, local employees, customer-support operations, contractors, fulfillment processes, or other operational activities involving personal data in Brazil.

Trigger 2: Brazil-Facing Processing

Article 3(II) is especially important for online businesses. The current statutory language covers processing whose purpose is the offering or provision of goods or services or the processing of data of individuals located in Brazil.

That means the analysis should not be reduced to whether the website uses a .br domain, prices in Brazilian reais, or Portuguese-language marketing. Those factors can be relevant facts, but the legal text itself requires a broader look at the purpose and the individuals whose data is being processed.

Trigger 3: Personal Data Collected in Brazil

Article 3(III) covers personal data that was collected in Brazilian territory. The law further explains that, for this purpose, personal data is considered collected in Brazil when the data subject was in Brazil at the time of collection.

For a digital company, this can make the user's physical location at collection relevant even when the website, cloud environment, CRM, or business headquarters are all outside Brazil.

Practical Examples for U.S. Businesses

The following examples are not legal conclusions for every company. They are operational screening examples showing why a U.S. business should perform an Article 3 assessment.

Strong scope signal U.S. Shopify store shipping to Brazil

A Brazilian customer creates an account, checks out, pays, receives shipping, and enters the store's marketing and support systems.

Strong scope signal U.S. SaaS with Brazilian users

The platform processes account credentials, billing information, support tickets, logs, telemetry, and user-generated data linked to people in Brazil.

Strong scope signal U.S. marketing campaign collecting Brazilian leads

People located in Brazil submit lead forms that flow into a U.S. CRM, email platform, enrichment service, and advertising stack.

Needs fact review Global website with incidental Brazilian visitors

The company does not intentionally serve Brazil, but analytics, forms, cookies, or accounts may still process data of individuals located there. The actual processing and Article 3 facts need review.

Strong scope signal U.S. app available to users in Brazil

Brazil-based users create profiles, receive services, communicate inside the app, and generate device, usage, and account data.

Needs fact review B2B vendor receiving data from a Brazilian customer

The U.S. vendor may act as an operator for some processing and as a controller for other purposes such as billing, security, or its own account administration.

A Critical Distinction: Location, Not Just Citizenship

Common mistake: saying that the LGPD applies only to “Brazilian citizens” or only to “Brazilian residents.” Article 3 uses location-based language. One territorial trigger refers to individuals located in Brazil, and the data-collection rule looks to where the individual was located at the time of collection.

This distinction matters for both compliance and content accuracy. A U.S. citizen temporarily located in Brazil can be part of a Brazil-based collection scenario. Conversely, the legal analysis should not be reduced to nationality labels when the statute asks different questions.

If the LGPD Applies, What Should a U.S. Company Review?

Applicability is only the first step. The operational question becomes: which LGPD obligations map to the company's actual processing?

A practical review usually includes at least the following workstreams:

  • Data mapping: identify where Brazilian personal data enters, moves, is stored, is accessed, and leaves the organization.
  • Controller/operator roles: determine the company's role by processing activity rather than assuming one role for the entire business.
  • Purposes and legal bases: document why each processing activity occurs and which LGPD legal basis is relied upon.
  • Transparency: make sure privacy notices describe the real operation rather than a generic policy template.
  • Cookies and tracking: inventory analytics, advertising pixels, identifiers, consent interfaces, and default behavior.
  • Marketing: review forms, CRM workflows, email, WhatsApp, remarketing, audience uploads, suppression, and opt-out processes.
  • Vendors and subprocessors: document roles, instructions, security, incident escalation, deletion, and transfers.
  • Data-subject rights: create a repeatable intake, verification, evaluation, execution, communication, and closure workflow.
  • Retention: connect retention periods to purposes, obligations, disputes, security, and deletion procedures.
  • Security and incidents: maintain appropriate safeguards and a process for assessing and escalating security incidents.

The LGPD's principles also matter operationally. The current law includes necessity/data minimization, transparency, security, prevention, and accountability among its core processing principles.

What About Sending Brazilian Personal Data to the United States?

If personal data subject to the LGPD is transferred to, stored in, or made accessible from the United States, the company should separately assess the LGPD's international data transfer rules.

2026 transfer status

ANPD's official International Affairs page states that Resolution CD/ANPD No. 19/2024 regulates international transfer mechanisms including adequacy decisions, Brazilian standard contractual clauses, equivalent standard clauses, specific contractual clauses, and binding corporate rules.

As of this article's review date, August 19, 2026, ANPD identifies the European Union as an adequate international body under Resolution No. 32/2026. The same official page does not list the United States as an adequacy decision.

Check ANPD's current International Affairs page .

For a U.S.-bound data flow, that means the company should identify the exporter, importer, purpose, categories of personal data, recipients, onward transfers, applicable safeguards, and the transfer mechanism that fits the actual relationship.

Do not treat “our cloud provider is U.S.-based” as the entire analysis. Cross-border access by global support teams, centralized security systems, analytics platforms, CRM tools, parent companies, subprocessors, and backup environments can also create international data flows that need to be mapped.

Does a U.S. Company Need an LGPD DPO / Encarregado?

Article 41 of the LGPD states that the controller must indicate an encarregado for personal-data processing. The identity and contact information of the encarregado must be made public in a clear and objective manner, preferably on the controller's website.

However, ANPD rules provide a relevant exception for qualifying small processing agents. Resolution CD/ANPD No. 2/2022 states that qualifying small processing agents are not required to appoint an encarregado, although an agent relying on that exemption must provide a communication channel for data subjects.

The exemption is not a blanket “small company” shortcut. The regulation contains eligibility conditions and limits, including rules related to high-risk processing, revenue, and economic groups.

Practical approach: determine first whether the U.S. company is acting as a controller for the relevant activity, then assess the current encarregado regulation and any exemption against the organization's actual facts.

10-Step LGPD Checklist for a U.S. Company

If the Article 3 screening indicates that the LGPD may apply, use this as a management-level starting point. It is deliberately broader than “update the privacy policy.”

Run an Article 3 scope assessment. Document which territorial trigger or triggers may apply to each Brazil-facing processing activity.
Map Brazilian personal data. Identify collection points, systems, vendors, destinations, access locations, integrations, and deletion paths.
Classify roles and responsibilities. Identify controller, operator, independent-controller, and subprocessor relationships by activity.
Document purposes and legal bases. Do not assume consent is the correct legal basis for every processing activity.
Review privacy notices and collection interfaces. Make disclosures match the real purposes, sharing, retention, rights, and contact channels.
Inventory cookies, analytics, pixels, and marketing workflows. Include CRM, email, WhatsApp, audience uploads, remarketing, enrichment, and suppression processes.
Review vendors and contracts. Map instructions, security, subprocessors, incident escalation, deletion, audit/evidence, and international transfers.
Assess international data transfers. Identify U.S.-bound data flows and document the applicable transfer mechanism and safeguards.
Build rights, retention, security, and incident workflows. Test whether the team can actually execute the process, not just describe it in a policy.
Create evidence and an ongoing review cycle. Assign owners, record decisions, track remediation, test controls, and update the program as systems and regulations change.

What U.S. Companies Often Get Wrong

“We are in the United States, so the LGPD cannot apply.”

Headquarters location alone does not resolve Article 3. The statute expressly tells you to look beyond headquarters and data location.

“LGPD only protects Brazilians.”

Article 3's territorial language focuses on processing and location, not a citizenship-only test.

“We already comply with GDPR, so LGPD is covered.”

A mature GDPR program can provide useful controls, but it should be mapped to Brazilian terminology, legal bases, regulatory rules, transfer mechanisms, rights handling, and governance requirements rather than assumed to be identical.

“We only need a Brazilian privacy policy.”

A privacy notice is only one control. The operational evidence behind it—data maps, role decisions, legal bases, vendor controls, transfer mechanisms, rights workflows, retention, security, and incident handling—is usually the larger compliance task.

Turn the Scope Question Into a Working Compliance Plan

The Brazil LGPD Compliance Playbook — 2026 Edition is an 81-page practical guide built for international businesses. It includes a 30-day implementation roadmap, a 100-point compliance audit, real business scenarios, and 16 implementation worksheets.

81-page digital playbook 100-point audit 16 worksheets 30-day action plan
Explore the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

Does the LGPD apply to a U.S. company with no office in Brazil?

It can. Article 3 applies regardless of headquarters or data location when at least one territorial trigger is present, including processing in Brazil, Brazil-facing processing involving individuals located in Brazil, or personal data collected in Brazil.

Does the LGPD protect only Brazilian citizens?

No. Article 3 uses location-based language rather than a citizenship-only test. It refers to individuals located in Brazil, and the law states that data is considered collected in Brazil when the data subject is in Brazil at the time of collection.

If a U.S. website gets a few visitors from Brazil, is the LGPD automatically triggered?

Do not decide the issue from visitor count alone. Review the actual processing against Article 3, including whether the company processes data of individuals located in Brazil, whether data is collected there, the purpose of the processing, and any applicable exceptions.

Is GDPR compliance enough for LGPD compliance?

No. GDPR controls can be a valuable starting point, but organizations should map them to the LGPD's own requirements, terminology, legal bases, data-subject rights, Brazilian regulatory rules, and international transfer mechanisms.

Does sending data to the United States create an international transfer issue?

Potentially yes. Transfers must comply with the LGPD and ANPD's International Data Transfer Regulation. As of August 19, 2026, ANPD's official adequacy information identifies the European Union as adequate; a U.S.-bound transfer should therefore be assessed for the mechanism applicable to that specific flow.

Does every U.S. company need an LGPD DPO?

Controllers are generally subject to the LGPD's encarregado requirement, but ANPD rules provide exemptions for qualifying small processing agents. Whether an exemption applies depends on the regulation and the organization's actual processing and eligibility.

Should a U.S. company use consent for every processing activity?

No. Consent is one legal basis under the LGPD, not a universal basis for all processing. A company should document the purpose and appropriate legal basis for each processing activity and apply any specific requirements associated with that basis.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against official Brazilian sources available on August 19, 2026. Laws, regulations, guidance, adequacy decisions, and enforcement practices can change. Verify current official sources and obtain qualified Brazilian legal advice for decisions involving your organization's specific facts.