Quick Answer: Does the LGPD apply to U.S. companies?
It can. Brazil's LGPD is not limited to companies incorporated in Brazil. Article 3 applies regardless of where a company is headquartered or where its databases are located when at least one territorial trigger is present: the processing occurs in Brazil; the processing is aimed at offering or providing goods or services or processing data of individuals located in Brazil; or the personal data was collected in Brazil. Applicability is fact-specific, so a U.S. company should map each Brazil-facing processing activity rather than rely on headquarters location alone.
Key Takeaways
- No Brazilian office is required for the LGPD to potentially apply.
- The territorial test is broader than “Brazilian citizens.” Location matters.
- A U.S. e-commerce store, SaaS company, app, marketplace, or lead-generation business can trigger Article 3.
- If Brazilian personal data is sent to or accessed from the United States, international transfer rules may also apply.
- Do not jump straight to a privacy policy. Start by mapping the actual processing, purposes, vendors, roles, transfers, rights workflows, security controls, and evidence.
A common question from U.S. businesses is: “We do not have an entity in Brazil, so why would Brazilian privacy law apply to us?” Under the LGPD, that is the wrong first question.
The statute expressly says its territorial scope can apply regardless of the country where the company is headquartered or where the data is located. The analysis therefore begins with the processing activity itself.
The Three Article 3 Triggers U.S. Companies Should Test
A practical applicability review should test the business against each of the three territorial triggers in Article 3 of Law No. 13,709/2018.
| Article 3 trigger | Practical question for a U.S. company | Example |
|---|---|---|
| 1. Processing carried out in Brazil | Is any relevant processing operation actually performed in Brazilian territory? | A U.S. company has Brazilian staff or infrastructure performing customer-data operations. |
| 2. Brazil-facing purpose / individuals located in Brazil | Is the processing aimed at offering or providing goods or services, or at processing data of individuals located in Brazil? | A U.S. SaaS platform signs Brazilian users and processes their account, billing, support, and telemetry data. |
| 3. Data collected in Brazil | Was the personal data collected while the individual was located in Brazil? | A person in São Paulo submits a form to a U.S.-hosted website and the submission enters a U.S.-based CRM. |
The current compiled LGPD text states that Article 3 can apply regardless of the medium used, the country of the organization's headquarters, or the country where the data is located, when one of the listed territorial conditions is met.
Trigger 1: Processing in Brazilian Territory
If a relevant processing operation is performed in Brazil, Article 3(I) may bring that activity within scope. This can matter to a U.S. group with a Brazilian subsidiary, local employees, customer-support operations, contractors, fulfillment processes, or other operational activities involving personal data in Brazil.
Trigger 2: Brazil-Facing Processing
Article 3(II) is especially important for online businesses. The current statutory language covers processing whose purpose is the offering or provision of goods or services or the processing of data of individuals located in Brazil.
That means the analysis should not be reduced to whether the website uses a .br domain, prices in Brazilian reais,
or Portuguese-language marketing. Those factors can be relevant facts, but the legal text itself requires a broader look
at the purpose and the individuals whose data is being processed.
Trigger 3: Personal Data Collected in Brazil
Article 3(III) covers personal data that was collected in Brazilian territory. The law further explains that, for this purpose, personal data is considered collected in Brazil when the data subject was in Brazil at the time of collection.
For a digital company, this can make the user's physical location at collection relevant even when the website, cloud environment, CRM, or business headquarters are all outside Brazil.
Practical Examples for U.S. Businesses
The following examples are not legal conclusions for every company. They are operational screening examples showing why a U.S. business should perform an Article 3 assessment.
A Brazilian customer creates an account, checks out, pays, receives shipping, and enters the store's marketing and support systems.
The platform processes account credentials, billing information, support tickets, logs, telemetry, and user-generated data linked to people in Brazil.
People located in Brazil submit lead forms that flow into a U.S. CRM, email platform, enrichment service, and advertising stack.
The company does not intentionally serve Brazil, but analytics, forms, cookies, or accounts may still process data of individuals located there. The actual processing and Article 3 facts need review.
Brazil-based users create profiles, receive services, communicate inside the app, and generate device, usage, and account data.
The U.S. vendor may act as an operator for some processing and as a controller for other purposes such as billing, security, or its own account administration.
A Critical Distinction: Location, Not Just Citizenship
This distinction matters for both compliance and content accuracy. A U.S. citizen temporarily located in Brazil can be part of a Brazil-based collection scenario. Conversely, the legal analysis should not be reduced to nationality labels when the statute asks different questions.
If the LGPD Applies, What Should a U.S. Company Review?
Applicability is only the first step. The operational question becomes: which LGPD obligations map to the company's actual processing?
A practical review usually includes at least the following workstreams:
- Data mapping: identify where Brazilian personal data enters, moves, is stored, is accessed, and leaves the organization.
- Controller/operator roles: determine the company's role by processing activity rather than assuming one role for the entire business.
- Purposes and legal bases: document why each processing activity occurs and which LGPD legal basis is relied upon.
- Transparency: make sure privacy notices describe the real operation rather than a generic policy template.
- Cookies and tracking: inventory analytics, advertising pixels, identifiers, consent interfaces, and default behavior.
- Marketing: review forms, CRM workflows, email, WhatsApp, remarketing, audience uploads, suppression, and opt-out processes.
- Vendors and subprocessors: document roles, instructions, security, incident escalation, deletion, and transfers.
- Data-subject rights: create a repeatable intake, verification, evaluation, execution, communication, and closure workflow.
- Retention: connect retention periods to purposes, obligations, disputes, security, and deletion procedures.
- Security and incidents: maintain appropriate safeguards and a process for assessing and escalating security incidents.
The LGPD's principles also matter operationally. The current law includes necessity/data minimization, transparency, security, prevention, and accountability among its core processing principles.
What About Sending Brazilian Personal Data to the United States?
If personal data subject to the LGPD is transferred to, stored in, or made accessible from the United States, the company should separately assess the LGPD's international data transfer rules.
ANPD's official International Affairs page states that Resolution CD/ANPD No. 19/2024 regulates international transfer mechanisms including adequacy decisions, Brazilian standard contractual clauses, equivalent standard clauses, specific contractual clauses, and binding corporate rules.
As of this article's review date, August 19, 2026, ANPD identifies the European Union as an adequate international body under Resolution No. 32/2026. The same official page does not list the United States as an adequacy decision.
For a U.S.-bound data flow, that means the company should identify the exporter, importer, purpose, categories of personal data, recipients, onward transfers, applicable safeguards, and the transfer mechanism that fits the actual relationship.
Do not treat “our cloud provider is U.S.-based” as the entire analysis. Cross-border access by global support teams, centralized security systems, analytics platforms, CRM tools, parent companies, subprocessors, and backup environments can also create international data flows that need to be mapped.
Does a U.S. Company Need an LGPD DPO / Encarregado?
Article 41 of the LGPD states that the controller must indicate an encarregado for personal-data processing. The identity and contact information of the encarregado must be made public in a clear and objective manner, preferably on the controller's website.
However, ANPD rules provide a relevant exception for qualifying small processing agents. Resolution CD/ANPD No. 2/2022 states that qualifying small processing agents are not required to appoint an encarregado, although an agent relying on that exemption must provide a communication channel for data subjects.
The exemption is not a blanket “small company” shortcut. The regulation contains eligibility conditions and limits, including rules related to high-risk processing, revenue, and economic groups.
10-Step LGPD Checklist for a U.S. Company
If the Article 3 screening indicates that the LGPD may apply, use this as a management-level starting point. It is deliberately broader than “update the privacy policy.”
What U.S. Companies Often Get Wrong
“We are in the United States, so the LGPD cannot apply.”
Headquarters location alone does not resolve Article 3. The statute expressly tells you to look beyond headquarters and data location.
“LGPD only protects Brazilians.”
Article 3's territorial language focuses on processing and location, not a citizenship-only test.
“We already comply with GDPR, so LGPD is covered.”
A mature GDPR program can provide useful controls, but it should be mapped to Brazilian terminology, legal bases, regulatory rules, transfer mechanisms, rights handling, and governance requirements rather than assumed to be identical.
“We only need a Brazilian privacy policy.”
A privacy notice is only one control. The operational evidence behind it—data maps, role decisions, legal bases, vendor controls, transfer mechanisms, rights workflows, retention, security, and incident handling—is usually the larger compliance task.
Turn the Scope Question Into a Working Compliance Plan
The Brazil LGPD Compliance Playbook — 2026 Edition is an 81-page practical guide built for international businesses. It includes a 30-day implementation roadmap, a 100-point compliance audit, real business scenarios, and 16 implementation worksheets.
Frequently Asked Questions
Does the LGPD apply to a U.S. company with no office in Brazil?
It can. Article 3 applies regardless of headquarters or data location when at least one territorial trigger is present, including processing in Brazil, Brazil-facing processing involving individuals located in Brazil, or personal data collected in Brazil.
Does the LGPD protect only Brazilian citizens?
No. Article 3 uses location-based language rather than a citizenship-only test. It refers to individuals located in Brazil, and the law states that data is considered collected in Brazil when the data subject is in Brazil at the time of collection.
If a U.S. website gets a few visitors from Brazil, is the LGPD automatically triggered?
Do not decide the issue from visitor count alone. Review the actual processing against Article 3, including whether the company processes data of individuals located in Brazil, whether data is collected there, the purpose of the processing, and any applicable exceptions.
Is GDPR compliance enough for LGPD compliance?
No. GDPR controls can be a valuable starting point, but organizations should map them to the LGPD's own requirements, terminology, legal bases, data-subject rights, Brazilian regulatory rules, and international transfer mechanisms.
Does sending data to the United States create an international transfer issue?
Potentially yes. Transfers must comply with the LGPD and ANPD's International Data Transfer Regulation. As of August 19, 2026, ANPD's official adequacy information identifies the European Union as adequate; a U.S.-bound transfer should therefore be assessed for the mechanism applicable to that specific flow.
Does every U.S. company need an LGPD DPO?
Controllers are generally subject to the LGPD's encarregado requirement, but ANPD rules provide exemptions for qualifying small processing agents. Whether an exemption applies depends on the regulation and the organization's actual processing and eligibility.
Should a U.S. company use consent for every processing activity?
No. Consent is one legal basis under the LGPD, not a universal basis for all processing. A company should document the purpose and appropriate legal basis for each processing activity and apply any specific requirements associated with that basis.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text (Planalto) Primary source for Article 3 territorial scope, definitions, principles, legal bases, rights, and Article 41.
- ANPD — English version of the Brazilian Data Protection Law Official English-language reference published by ANPD.
- ANPD — International Affairs / International Data Transfers Current transfer mechanisms and adequacy information reviewed August 19, 2026.
- ANPD — Current Regulations Official index of ANPD regulations, including the encarregado and security-incident regulations.
- ANPD Resolution CD/ANPD No. 2/2022 — Small Processing Agents Source for the small-agent encarregado exemption and related conditions.