2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD Legal Bases

The 10 Legal Bases Under Brazil's LGPD Explained: Which One Should Your Business Use?

Consent is only one answer. Article 7 of Brazil's LGPD gives ten legal bases for processing ordinary personal data, and the correct choice depends on the purpose, data, relationship, necessity and legal context of each processing activity. This guide explains all ten, shows where businesses commonly misuse them, and separates Article 7 from the stricter Article 11 framework for sensitive personal data.

Published: Last reviewed: Reading time: ~21 minutes By LGPD Brazil Editorial Team

Quick Answer: What are the 10 legal bases under Brazil's LGPD?

Article 7 of the LGPD lists ten legal bases for processing ordinary personal data: consent; legal or regulatory obligation; public-policy processing by the public administration; studies by a research body; contract or requested pre-contractual steps; regular exercise of rights; protection of life or physical safety; protection of health; legitimate interest; and protection of credit. There is no sensible compliance rule that says “always use consent” or “always use legitimate interest.” The controller should select the basis that actually matches the specific purpose and facts. If the processing involves sensitive personal data, Article 11—not the ordinary Article 7 list—must be analyzed.

Key Takeaways

  • Consent is not the default legal basis for everything. It is one of ten Article 7 hypotheses.
  • Choose a legal basis per purpose. One customer record can support multiple processing activities with different legal bases.
  • “Necessary” matters. Contract, legitimate interest, life protection and several other bases have limits that prevent overbroad use.
  • Sensitive data has a separate framework. Article 11 contains its own hypotheses; legitimate interest is not one of them.
  • Public data is not “free data.” Public availability does not remove LGPD principles, purpose limits or data-subject rights.
  • Legitimate interest needs analysis, not a label. ANPD recommends a balancing test focused on purpose, necessity, expectations, rights and safeguards.
  • Children require an additional best-interest test. ANPD says Articles 7 and 11 can apply, but the child's or adolescent's best interests must prevail.

A legal basis answers a fundamental compliance question: Why is this organization legally permitted to process this personal data for this specific purpose?

The answer should be attached to a processing activity—not to a person, database or company as a whole. An online retailer might use contract necessity to fulfill an order, legal obligation to retain required tax records, legitimate interest for a carefully assessed security activity, and consent for a separate optional marketing activity.

One customer ≠ one legal basis. The same person's data may be processed for multiple independent purposes, each of which needs its own Article 7 or Article 11 analysis.

The 10 Legal Bases in Article 7

1

Consent

Article 7(I) permits processing when the data subject gives consent. The LGPD defines consent as a free, informed and unequivocal manifestation agreeing to personal-data processing for a determined purpose.

Under Article 8, the controller bears the burden of proving valid consent. Generic authorizations are null, and consent can be withdrawn at any time through a free and facilitated process.

Typical fit: genuinely optional processing where the person can make a real choice and the organization can honor withdrawal.
2

Compliance With a Legal or Regulatory Obligation

Article 7(II) applies when the controller needs to process personal data to comply with a legal or regulatory obligation. This can be highly relevant to tax, accounting, employment, financial, regulated-sector and statutory recordkeeping duties.

The controller should identify the actual obligation rather than write “legal obligation” in a spreadsheet without a legal source.

Typical fit: mandatory payroll/tax reporting, legally required records, regulatory reporting and retention required by law.
3

Public Administration and Public Policies

Article 7(III) covers processing and shared use by the public administration where data is necessary to execute public policies provided by laws or regulations or supported by contracts, agreements or similar instruments, subject to the LGPD's public-sector chapter.

This is not a general private-company basis merely because a company believes its product creates public benefit.

Typical fit: public bodies executing legally supported public policies and related public-sector processing.
4

Studies by a Research Body

Article 7(IV) permits processing for studies by a qualifying órgão de pesquisa, with anonymization guaranteed whenever possible.

The LGPD defines a research body narrowly: it includes public research entities and private nonprofit legal entities formed under Brazilian law, headquartered and domiciled in Brazil, whose institutional mission or purpose includes basic or applied historical, scientific, technological or statistical research.

Typical fit: qualifying research institutions conducting statutory research—not ordinary commercial market research simply because it is called a “study.”
5

Performance of a Contract or Requested Pre-Contractual Procedures

Article 7(V) applies where processing is necessary to perform a contract to which the data subject is a party or to carry out preliminary procedures related to a contract at the data subject's request.

This can support many core customer operations: processing an order, creating a requested paid account, arranging delivery, activating a purchased service or preparing a requested quotation where the processing is genuinely necessary.

Typical fit: account/service delivery and transaction steps the company could not reasonably perform without the relevant personal data.
6

Regular Exercise of Rights in Judicial, Administrative or Arbitral Proceedings

Article 7(VI) permits processing for the regular exercise of rights in judicial, administrative or arbitral proceedings. This can be important when personal data must be preserved, reviewed or disclosed for a legal claim, defense, investigation or dispute.

The existence of a theoretical possibility of litigation should not become a blanket excuse for indefinite retention of all information. Map the actual dispute, rights, evidence and retention rationale.

Typical fit: litigation files, administrative defenses, arbitration evidence and records necessary for establishing or defending legal rights.
7

Protection of Life or Physical Safety

Article 7(VII) permits processing to protect the life or physical safety of the data subject or another person. It is an emergency- or safety-oriented basis, not a general convenience basis.

Typical fit: urgent processing necessary to protect a person's life or physical integrity in a concrete situation.
8

Protection of Health

Article 7(VIII) permits processing for protection of health exclusively in a procedure performed by health professionals, health services or a health authority.

If the information involved is sensitive health data, Article 11 must also be read carefully because sensitive personal data has its own health-protection hypothesis.

Typical fit: health-protection processing within the professional/service/authority context specified by the law.
9

Legitimate Interest of the Controller or a Third Party

Article 7(IX) allows processing where necessary to serve legitimate interests of the controller or a third party, except where the data subject's fundamental rights and freedoms requiring personal-data protection prevail.

Article 10 adds requirements around concrete legitimate purposes, necessity, legitimate expectations, rights and freedoms, transparency and minimization. ANPD recommends a balancing test to document the analysis.

Typical fit: some security, fraud-prevention, internal administration, limited direct-marketing or service-improvement activities—only when the concrete balancing analysis supports it.
10

Protection of Credit

Article 7(X) permits processing for protection of credit, including the requirements of relevant legislation. This is a Brazil-specific basis that global teams accustomed to GDPR Article 6 should not overlook.

It does not mean every activity involving payment or financial information becomes “credit protection.” The processing needs to fit the credit-protection purpose and applicable legal framework.

Typical fit: qualifying credit-analysis and credit-protection activities under Brazil's legal framework.
Primary legal source

Article 7 contains the ten hypotheses above. Article 8 regulates consent, Article 10 regulates legitimate interest, and Article 11 establishes the separate legal framework for sensitive personal data.

Read the current compiled LGPD on Planalto .

Which Legal Basis Should Your Business Use?

The answer should come from the processing purpose and facts—not from which basis is easiest to explain in a privacy policy.

A Practical Legal-Basis Decision Sequence

  1. Define the processing activity precisely. “Marketing” is too broad. “Send product-renewal email to existing customers” is more useful.
  2. Identify the personal-data category. Ordinary data or sensitive personal data?
  3. Check for children/adolescents. If yes, add the Article 14 best-interest analysis.
  4. Identify the actual purpose. What outcome does the organization need from the data?
  5. Test specialized bases first when the facts clearly fit. Legal obligation, contract, legal claims, life, health, research, public policy or credit protection.
  6. If considering legitimate interest, perform the Article 10 / ANPD balancing analysis.
  7. If considering consent, ask whether the choice is genuinely free and whether withdrawal can be honored.
  8. Document the selected basis and rejected alternatives.
  9. Align the privacy notice and system behavior.
  10. Reassess if the purpose changes. A new purpose may require a new legal-basis decision.
Do not “pick the strongest basis.” There is no universal strongest basis. The defensible basis is the one that accurately matches the processing and whose conditions the organization can actually satisfy.

Consent receives disproportionate attention because it is visible: checkbox, toggle, signature, button. But visible does not mean valid.

Article 8 says the controller must be able to prove consent, generic authorizations are null, and consent must relate to determined purposes. Article 9 says that where consent is required, misleading, abusive or non-transparent information can make it null.

Good fit Genuine optional choice

The user can say no without losing an unrelated service and the company can honor the choice technically.

Bad signal Bundled or generic consent

“I agree to all current and future processing” is incompatible with the requirement for determined purposes.

Operational test Withdrawal

If the user withdraws consent tomorrow, can the company identify and stop the processing that depended on it?

A common mistake is asking for consent to process information that is genuinely necessary to fulfill the requested contract. That can create confusion because contract necessity and consent have different logic.

Another common mistake is the opposite: labeling optional behavioral advertising as “necessary to perform the contract.” Necessity should be interpreted in relation to the actual contractual service, not the organization's preferred monetization model.

For tracking technologies, see LGPD Cookie Consent Requirements: Analytics, Pixels and Advertising.

Legitimate Interest: The Basis That Requires the Most Explanation

Legitimate interest is flexible, but that flexibility comes with a heavier accountability burden. It is not a catch-all basis for everything the organization would like to do without consent.

ANPD's official guide says legitimate-interest processing should be preceded by a balancing test. The Agency's simplified model uses three phases: purpose; necessity; and balancing plus safeguards.

1. Purpose

Identify the specific legitimate interest of the controller or third party. The interest should be lawful, concrete and linked to a clear purpose—not a vague desire to “grow the business.”

2. Necessity

Ask whether the personal data is actually necessary for that purpose and whether the same result could reasonably be achieved through a less intrusive method. Article 10 says only data strictly necessary for the intended purpose may be processed.

3. Balancing and safeguards

Compare the interest against the data subject's legitimate expectations, rights and fundamental freedoms. Consider the relationship with the person, nature and source of data, context, risk, impact, transparency, ability to exercise rights and safeguards that reduce the intrusion.

If the balancing test shows that the data subject's rights, freedoms and legitimate expectations prevail, the controller should not use legitimate interest for that processing.

ANPD also says there is no single mandatory form for the balancing test. Its model is non-binding, and organizations can use another method if it properly addresses the LGPD requirements. For higher-impact or new-technology processing, the analysis may need to be substantially more detailed.

See our deeper upcoming cluster topic: Legitimate Interest Under LGPD: When Can Your Business Use It?

Sensitive Personal Data: Stop and Move to Article 11

Article 7's ten legal bases are the framework for ordinary personal data. If the data is sensitive, Article 11 applies.

The LGPD defines sensitive personal data to include data about racial or ethnic origin, religious conviction, political opinion, trade-union or religious/philosophical/political organization membership, health or sexual life, and genetic or biometric data when linked to a natural person.

Article 11 permits sensitive-data processing through:

  • specific and highlighted consent for specific purposes; or
  • specified no-consent situations where processing is indispensable, including legal/regulatory obligation, certain public-policy processing, research, regular exercise of rights, life/physical safety, health protection, and fraud prevention/security in electronic identification and authentication under the statutory conditions.
Legitimate interest is not an Article 11 legal basis. ANPD's legitimate-interest guide expressly states that legitimate interest under Article 7(IX) cannot be used for sensitive personal data.

That creates an important practical distinction for fraud and security teams: ordinary personal data used for fraud prevention might sometimes be analyzed under legitimate interest, while sensitive biometric data used for electronic identification/authentication needs the Article 11 framework, including its specific fraud-prevention and security hypothesis where the statutory conditions are met.

Children and Adolescents: Article 7 Can Apply, But Best Interests Must Prevail

Article 14 requires processing of children's and adolescents' personal data to be carried out in their best interests. The statutory text also contains specific consent rules for children.

ANPD resolved a major interpretation question in Enunciado No. 1/2023: personal data of children and adolescents can be processed under the legal bases in Article 7 or Article 11, provided their best interests are observed and prevail in the concrete case.

The Agency's legitimate-interest guide confirms that legitimate interest can therefore be available for children's or adolescents' ordinary personal data in appropriate cases, but it requires enhanced caution and a best-interest analysis.

This is not a shortcut around child protection. The fact that an Article 7 basis is legally available does not make the processing appropriate. The controller must still prove that the child's or adolescent's best interests prevail in the actual context.

Business Examples: Which Legal Basis Might Apply?

The following examples are starting points for analysis, not automatic legal conclusions. Details can change the result.

Processing activity Possible starting basis Why / caution
Online store fulfills a customer's order Contract — Art. 7(V) Customer and delivery data may be necessary to perform the purchase contract.
Company retains legally required tax records Legal/regulatory obligation — Art. 7(II) Identify the specific law/regulation and required retention scope.
SaaS provider creates an account requested by the user Contract / requested pre-contractual steps — Art. 7(V) Use only data necessary for the requested service; optional marketing is a separate purpose.
Company preserves records for an active legal dispute Regular exercise of rights — Art. 7(VI) Keep the evidence necessary for the concrete claim/defense; avoid blanket indefinite retention.
Business uses limited ordinary-data security monitoring Potentially legitimate interest — Art. 7(IX) Document necessity, user expectations, risk, safeguards and balancing.
Website sends optional promotional newsletters Consent or, in some contexts, legitimate interest No universal answer. Relationship, expectations, channel, targeting, opt-out and applicable sector rules matter.
Site deploys behavioral advertising pixels Often consent is the stronger candidate ANPD cookie guidance says legitimate interest is generally harder to justify for third-party profiling/cross-site advertising.
Biometric authentication for fraud/security Article 11 analysis Biometric data is sensitive. Do not use ordinary Article 7 legitimate interest merely because the purpose is security.
Qualified research body conducts a study Research — Art. 7(IV) The statutory research-body definition and anonymization-where-possible condition matter.
Credit-protection activity Credit protection — Art. 7(X) The activity must genuinely fit credit protection and applicable Brazilian legislation.

What About Publicly Available Personal Data?

Public availability does not mean the LGPD disappears. Article 7 says processing of publicly accessible personal data must consider the purpose, good faith and public interest that justified making it available.

The law also says that data made manifestly public by the data subject can be exempt from the consent requirement, but data-subject rights and LGPD principles remain protected.

Public data ≠ unrestricted reuse. Scraping a person's public profile for a completely unrelated high-risk purpose still needs a lawful purpose, applicable legal basis, transparency analysis and compliance with LGPD principles.

Can the Legal Basis Change Later?

A company should not casually switch legal bases after processing has already started merely because the original basis became inconvenient. Instead, a new or changed purpose should trigger a fresh analysis.

Article 9 specifically requires notice when consent-based processing changes to a purpose incompatible with the original consent. ANPD's legitimate-interest guide similarly says a new purpose should lead the controller to reassess which legal basis is appropriate and, if legitimate interest is chosen, to perform a new balancing assessment for that new purpose.

This is why the legal-basis register should be versioned and connected to purpose changes, new products and new vendors.

What Should Be in a Legal-Basis Decision Record?

Processing activityDescribe the actual operation—not just the system name or department.
PurposeState the specific outcome the organization is trying to achieve.
Data subjectsCustomers, employees, leads, users, children, patients or other groups.
Data categoriesIdentify ordinary versus sensitive personal data before choosing Article 7 or Article 11.
Selected legal basisRecord the specific Article 7 or Article 11 hypothesis.
Why it fitsExplain how the facts satisfy the statutory conditions.
NecessityWhich data is actually necessary and what could be removed?
Supporting law / contract / evidenceLink the obligation, contract, consent record, research qualification, balancing test or other proof.
TransparencyWhere is the purpose and processing explained to the data subject?
Rights & withdrawalHow does the chosen basis affect opposition, withdrawal, deletion or other rights handling?
Review triggerPurpose change, new data, new vendor, new technology, new geography or regulatory update.
Decision owner and dateRecord who approved the analysis and when it was last reviewed.

Common Legal-Basis Mistakes

“We use consent for everything.”

This creates unnecessary withdrawal and validity problems and can misrepresent processing that is actually required by contract or law.

“We use legitimate interest because users agreed to our Terms.”

Agreement to Terms does not itself establish legitimate interest. Article 10 requires its own purpose, necessity, expectations, rights and safeguards analysis.

“Anything related to a customer is contractual.”

Contract necessity is narrower. The processing must be necessary to perform the contract or requested pre-contractual steps. Cross-selling, broad profiling or unrelated advertising should not automatically inherit the contract basis.

“Public data needs no legal basis.”

Incorrect. Public availability changes some consent analysis but does not eliminate principles, purpose limits or rights.

“Legitimate interest works for health or biometric data.”

Incorrect. Sensitive data requires Article 11. ANPD expressly says Article 7 legitimate interest does not apply to sensitive personal data.

“Our research team can always use the research-body basis.”

Not necessarily. Article 5 contains a specific definition of a qualifying research body. Ordinary commercial product research does not automatically meet it.

“Once we choose a basis, we never need to revisit it.”

Purposes, products, vendors and technologies change. A defensible privacy program revisits the basis when the processing changes materially.

Legal bases become much easier when every purpose is already mapped.

See our 25-point LGPD Compliance Checklist for Foreign Companies and LGPD Privacy Policy Requirements to connect the basis to the processing inventory and transparency layer.

A Practical Legal-Basis Review for a SaaS Company

Consider a U.S. SaaS company serving Brazilian users. The same platform may need several separate legal-basis decisions:

SaaS purpose Possible analysis Documentation
Create paid user accountContract may apply where processing is necessary to provide the requested service.Service terms, account-field necessity, ROPA.
Invoice / tax recordsLegal or regulatory obligation may apply where Brazilian obligations require the record.Applicable law and retention schedule.
Platform security logsLegitimate interest may be assessed for ordinary data where necessity and balancing support it.Balancing test, retention, access controls.
Optional newsletterConsent or legitimate-interest analysis depending on context and expectations.Legal-basis record, unsubscribe/withdrawal, campaign source.
Behavioral ad targetingConsent may be more appropriate where tracking/profiling is intrusive.Cookie/tracker inventory, CMP records, vendor map.
Customer content processed on instructionsThe customer-controller determines the basis for its processing; the SaaS operator follows documented instructions.DPA, role map, customer instructions.
Legal dispute recordsRegular exercise of rights may apply where the data is needed for a claim or defense.Legal hold, matter file, retention rationale.

This is why a SaaS company should not publish a notice saying simply: “We process your data based on consent, contract and legitimate interests.” The useful compliance evidence is the purpose-by-purpose map behind that sentence.

For the full SaaS workflow, see Brazil LGPD for SaaS Companies: Practical Compliance Guide.

Legal Basis vs International Transfer Mechanism

Another important distinction: a legal basis for processing and a legal mechanism for an international transfer are not the same thing.

For example, a company may rely on contract necessity for an underlying customer-processing activity but still need a separate Article 33 analysis before transferring the data from Brazil to another country.

See LGPD International Data Transfers: A Practical Guide for Global Businesses.

Turn “Which Legal Basis?” Into a Documented Decision

The Brazil LGPD Compliance Playbook — 2026 Edition includes a Legal-Basis Decision Record and a Legitimate Interest Assessment, plus a Data Mapping Worksheet, Processing Inventory / ROPA, Cookie and Tracking Inventory, Vendor Review, International Transfer Review, Retention Schedule, 100-point compliance audit and 30-day implementation roadmap.

Legal-Basis Decision Record Legitimate Interest Assessment Processing Inventory / ROPA 100-point audit
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

What are the 10 legal bases under the LGPD?

Article 7 lists consent; legal/regulatory obligation; public-administration public-policy processing; research by a qualifying research body; contract or requested pre-contractual procedures; regular exercise of rights; protection of life/physical safety; protection of health; legitimate interest; and protection of credit.

Does the LGPD require consent for all personal data processing?

No. Consent is one of ten Article 7 legal bases for ordinary personal data. The correct basis depends on the purpose and facts. Even when consent is not required, LGPD principles, transparency and data-subject rights still apply.

Which LGPD legal basis is best?

There is no universally best basis. The appropriate basis is the one whose statutory conditions actually match the specific processing purpose and that the controller can document and operate consistently.

When can a business use contract as a legal basis?

Article 7(V) applies where processing is necessary to perform a contract to which the data subject is a party or to carry out preliminary procedures related to a contract at that person's request. Optional marketing or unrelated profiling should not automatically be labeled contractual.

Can legitimate interest be used for marketing?

Potentially in some contexts, but there is no blanket marketing exemption. The controller should assess the concrete legitimate purpose, necessity, relationship and expectations, impacts on rights/freedoms, transparency, safeguards and applicable sector-specific rules. More intrusive behavioral advertising can make consent a more appropriate basis.

Does legitimate interest require a balancing test?

ANPD recommends a balancing test for legitimate-interest processing. Its simplified model examines purpose, necessity, and balancing plus safeguards. If the data subject's fundamental rights, freedoms and legitimate expectations prevail, the controller should not use legitimate interest.

Can legitimate interest be used for sensitive personal data?

No. ANPD states that Article 7 legitimate interest is not applicable to sensitive personal data because it is not included in Article 11. Sensitive data requires an Article 11 hypothesis.

Can Article 7 legal bases be used for children's data?

Yes, subject to the child's or adolescent's best interests. ANPD Enunciado No. 1/2023 states that Articles 7 and 11 can be used where applicable, provided the best interests of the child or adolescent are observed and prevail in the concrete case under Article 14.

Does publicly available data require a legal basis?

The LGPD still applies to publicly accessible personal data. Article 7 requires consideration of the original purpose, good faith and public interest, and preserves LGPD principles and data-subject rights.

Can a company change legal basis after collecting the data?

A changed purpose should trigger a new legal analysis rather than an opportunistic switch of labels. The controller should assess whether the new purpose is compatible, which basis actually applies, what transparency is required and whether additional rights or safeguards are triggered.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD and official ANPD materials available on August 19, 2026. The correct legal basis depends on the exact processing purpose, data category, relationship, contract, applicable sector law, data-subject expectations, risk and other facts. Sensitive data, children's data, public-sector processing and regulated industries require additional analysis. Verify current official sources and obtain qualified Brazilian legal advice for consequential decisions.