Quick Answer: What are the 10 legal bases under Brazil's LGPD?
Article 7 of the LGPD lists ten legal bases for processing ordinary personal data: consent; legal or regulatory obligation; public-policy processing by the public administration; studies by a research body; contract or requested pre-contractual steps; regular exercise of rights; protection of life or physical safety; protection of health; legitimate interest; and protection of credit. There is no sensible compliance rule that says “always use consent” or “always use legitimate interest.” The controller should select the basis that actually matches the specific purpose and facts. If the processing involves sensitive personal data, Article 11—not the ordinary Article 7 list—must be analyzed.
Key Takeaways
- Consent is not the default legal basis for everything. It is one of ten Article 7 hypotheses.
- Choose a legal basis per purpose. One customer record can support multiple processing activities with different legal bases.
- “Necessary” matters. Contract, legitimate interest, life protection and several other bases have limits that prevent overbroad use.
- Sensitive data has a separate framework. Article 11 contains its own hypotheses; legitimate interest is not one of them.
- Public data is not “free data.” Public availability does not remove LGPD principles, purpose limits or data-subject rights.
- Legitimate interest needs analysis, not a label. ANPD recommends a balancing test focused on purpose, necessity, expectations, rights and safeguards.
- Children require an additional best-interest test. ANPD says Articles 7 and 11 can apply, but the child's or adolescent's best interests must prevail.
A legal basis answers a fundamental compliance question: Why is this organization legally permitted to process this personal data for this specific purpose?
The answer should be attached to a processing activity—not to a person, database or company as a whole. An online retailer might use contract necessity to fulfill an order, legal obligation to retain required tax records, legitimate interest for a carefully assessed security activity, and consent for a separate optional marketing activity.
The 10 Legal Bases in Article 7
Consent
Article 7(I) permits processing when the data subject gives consent. The LGPD defines consent as a free, informed and unequivocal manifestation agreeing to personal-data processing for a determined purpose.
Under Article 8, the controller bears the burden of proving valid consent. Generic authorizations are null, and consent can be withdrawn at any time through a free and facilitated process.
Compliance With a Legal or Regulatory Obligation
Article 7(II) applies when the controller needs to process personal data to comply with a legal or regulatory obligation. This can be highly relevant to tax, accounting, employment, financial, regulated-sector and statutory recordkeeping duties.
The controller should identify the actual obligation rather than write “legal obligation” in a spreadsheet without a legal source.
Public Administration and Public Policies
Article 7(III) covers processing and shared use by the public administration where data is necessary to execute public policies provided by laws or regulations or supported by contracts, agreements or similar instruments, subject to the LGPD's public-sector chapter.
This is not a general private-company basis merely because a company believes its product creates public benefit.
Studies by a Research Body
Article 7(IV) permits processing for studies by a qualifying órgão de pesquisa, with anonymization guaranteed whenever possible.
The LGPD defines a research body narrowly: it includes public research entities and private nonprofit legal entities formed under Brazilian law, headquartered and domiciled in Brazil, whose institutional mission or purpose includes basic or applied historical, scientific, technological or statistical research.
Performance of a Contract or Requested Pre-Contractual Procedures
Article 7(V) applies where processing is necessary to perform a contract to which the data subject is a party or to carry out preliminary procedures related to a contract at the data subject's request.
This can support many core customer operations: processing an order, creating a requested paid account, arranging delivery, activating a purchased service or preparing a requested quotation where the processing is genuinely necessary.
Regular Exercise of Rights in Judicial, Administrative or Arbitral Proceedings
Article 7(VI) permits processing for the regular exercise of rights in judicial, administrative or arbitral proceedings. This can be important when personal data must be preserved, reviewed or disclosed for a legal claim, defense, investigation or dispute.
The existence of a theoretical possibility of litigation should not become a blanket excuse for indefinite retention of all information. Map the actual dispute, rights, evidence and retention rationale.
Protection of Life or Physical Safety
Article 7(VII) permits processing to protect the life or physical safety of the data subject or another person. It is an emergency- or safety-oriented basis, not a general convenience basis.
Protection of Health
Article 7(VIII) permits processing for protection of health exclusively in a procedure performed by health professionals, health services or a health authority.
If the information involved is sensitive health data, Article 11 must also be read carefully because sensitive personal data has its own health-protection hypothesis.
Legitimate Interest of the Controller or a Third Party
Article 7(IX) allows processing where necessary to serve legitimate interests of the controller or a third party, except where the data subject's fundamental rights and freedoms requiring personal-data protection prevail.
Article 10 adds requirements around concrete legitimate purposes, necessity, legitimate expectations, rights and freedoms, transparency and minimization. ANPD recommends a balancing test to document the analysis.
Protection of Credit
Article 7(X) permits processing for protection of credit, including the requirements of relevant legislation. This is a Brazil-specific basis that global teams accustomed to GDPR Article 6 should not overlook.
It does not mean every activity involving payment or financial information becomes “credit protection.” The processing needs to fit the credit-protection purpose and applicable legal framework.
Article 7 contains the ten hypotheses above. Article 8 regulates consent, Article 10 regulates legitimate interest, and Article 11 establishes the separate legal framework for sensitive personal data.
Which Legal Basis Should Your Business Use?
The answer should come from the processing purpose and facts—not from which basis is easiest to explain in a privacy policy.
A Practical Legal-Basis Decision Sequence
- Define the processing activity precisely. “Marketing” is too broad. “Send product-renewal email to existing customers” is more useful.
- Identify the personal-data category. Ordinary data or sensitive personal data?
- Check for children/adolescents. If yes, add the Article 14 best-interest analysis.
- Identify the actual purpose. What outcome does the organization need from the data?
- Test specialized bases first when the facts clearly fit. Legal obligation, contract, legal claims, life, health, research, public policy or credit protection.
- If considering legitimate interest, perform the Article 10 / ANPD balancing analysis.
- If considering consent, ask whether the choice is genuinely free and whether withdrawal can be honored.
- Document the selected basis and rejected alternatives.
- Align the privacy notice and system behavior.
- Reassess if the purpose changes. A new purpose may require a new legal-basis decision.
Consent: Powerful When It Is Real, Weak When It Is Forced
Consent receives disproportionate attention because it is visible: checkbox, toggle, signature, button. But visible does not mean valid.
Article 8 says the controller must be able to prove consent, generic authorizations are null, and consent must relate to determined purposes. Article 9 says that where consent is required, misleading, abusive or non-transparent information can make it null.
The user can say no without losing an unrelated service and the company can honor the choice technically.
“I agree to all current and future processing” is incompatible with the requirement for determined purposes.
If the user withdraws consent tomorrow, can the company identify and stop the processing that depended on it?
A common mistake is asking for consent to process information that is genuinely necessary to fulfill the requested contract. That can create confusion because contract necessity and consent have different logic.
Another common mistake is the opposite: labeling optional behavioral advertising as “necessary to perform the contract.” Necessity should be interpreted in relation to the actual contractual service, not the organization's preferred monetization model.
For tracking technologies, see LGPD Cookie Consent Requirements: Analytics, Pixels and Advertising.
Legitimate Interest: The Basis That Requires the Most Explanation
Legitimate interest is flexible, but that flexibility comes with a heavier accountability burden. It is not a catch-all basis for everything the organization would like to do without consent.
ANPD's official guide says legitimate-interest processing should be preceded by a balancing test. The Agency's simplified model uses three phases: purpose; necessity; and balancing plus safeguards.
1. Purpose
Identify the specific legitimate interest of the controller or third party. The interest should be lawful, concrete and linked to a clear purpose—not a vague desire to “grow the business.”
2. Necessity
Ask whether the personal data is actually necessary for that purpose and whether the same result could reasonably be achieved through a less intrusive method. Article 10 says only data strictly necessary for the intended purpose may be processed.
3. Balancing and safeguards
Compare the interest against the data subject's legitimate expectations, rights and fundamental freedoms. Consider the relationship with the person, nature and source of data, context, risk, impact, transparency, ability to exercise rights and safeguards that reduce the intrusion.
ANPD also says there is no single mandatory form for the balancing test. Its model is non-binding, and organizations can use another method if it properly addresses the LGPD requirements. For higher-impact or new-technology processing, the analysis may need to be substantially more detailed.
See our deeper upcoming cluster topic: Legitimate Interest Under LGPD: When Can Your Business Use It?
Sensitive Personal Data: Stop and Move to Article 11
Article 7's ten legal bases are the framework for ordinary personal data. If the data is sensitive, Article 11 applies.
The LGPD defines sensitive personal data to include data about racial or ethnic origin, religious conviction, political opinion, trade-union or religious/philosophical/political organization membership, health or sexual life, and genetic or biometric data when linked to a natural person.
Article 11 permits sensitive-data processing through:
- specific and highlighted consent for specific purposes; or
- specified no-consent situations where processing is indispensable, including legal/regulatory obligation, certain public-policy processing, research, regular exercise of rights, life/physical safety, health protection, and fraud prevention/security in electronic identification and authentication under the statutory conditions.
That creates an important practical distinction for fraud and security teams: ordinary personal data used for fraud prevention might sometimes be analyzed under legitimate interest, while sensitive biometric data used for electronic identification/authentication needs the Article 11 framework, including its specific fraud-prevention and security hypothesis where the statutory conditions are met.
Children and Adolescents: Article 7 Can Apply, But Best Interests Must Prevail
Article 14 requires processing of children's and adolescents' personal data to be carried out in their best interests. The statutory text also contains specific consent rules for children.
ANPD resolved a major interpretation question in Enunciado No. 1/2023: personal data of children and adolescents can be processed under the legal bases in Article 7 or Article 11, provided their best interests are observed and prevail in the concrete case.
The Agency's legitimate-interest guide confirms that legitimate interest can therefore be available for children's or adolescents' ordinary personal data in appropriate cases, but it requires enhanced caution and a best-interest analysis.
Business Examples: Which Legal Basis Might Apply?
The following examples are starting points for analysis, not automatic legal conclusions. Details can change the result.
| Processing activity | Possible starting basis | Why / caution |
|---|---|---|
| Online store fulfills a customer's order | Contract — Art. 7(V) | Customer and delivery data may be necessary to perform the purchase contract. |
| Company retains legally required tax records | Legal/regulatory obligation — Art. 7(II) | Identify the specific law/regulation and required retention scope. |
| SaaS provider creates an account requested by the user | Contract / requested pre-contractual steps — Art. 7(V) | Use only data necessary for the requested service; optional marketing is a separate purpose. |
| Company preserves records for an active legal dispute | Regular exercise of rights — Art. 7(VI) | Keep the evidence necessary for the concrete claim/defense; avoid blanket indefinite retention. |
| Business uses limited ordinary-data security monitoring | Potentially legitimate interest — Art. 7(IX) | Document necessity, user expectations, risk, safeguards and balancing. |
| Website sends optional promotional newsletters | Consent or, in some contexts, legitimate interest | No universal answer. Relationship, expectations, channel, targeting, opt-out and applicable sector rules matter. |
| Site deploys behavioral advertising pixels | Often consent is the stronger candidate | ANPD cookie guidance says legitimate interest is generally harder to justify for third-party profiling/cross-site advertising. |
| Biometric authentication for fraud/security | Article 11 analysis | Biometric data is sensitive. Do not use ordinary Article 7 legitimate interest merely because the purpose is security. |
| Qualified research body conducts a study | Research — Art. 7(IV) | The statutory research-body definition and anonymization-where-possible condition matter. |
| Credit-protection activity | Credit protection — Art. 7(X) | The activity must genuinely fit credit protection and applicable Brazilian legislation. |
What About Publicly Available Personal Data?
Public availability does not mean the LGPD disappears. Article 7 says processing of publicly accessible personal data must consider the purpose, good faith and public interest that justified making it available.
The law also says that data made manifestly public by the data subject can be exempt from the consent requirement, but data-subject rights and LGPD principles remain protected.
Can the Legal Basis Change Later?
A company should not casually switch legal bases after processing has already started merely because the original basis became inconvenient. Instead, a new or changed purpose should trigger a fresh analysis.
Article 9 specifically requires notice when consent-based processing changes to a purpose incompatible with the original consent. ANPD's legitimate-interest guide similarly says a new purpose should lead the controller to reassess which legal basis is appropriate and, if legitimate interest is chosen, to perform a new balancing assessment for that new purpose.
This is why the legal-basis register should be versioned and connected to purpose changes, new products and new vendors.
What Should Be in a Legal-Basis Decision Record?
Common Legal-Basis Mistakes
“We use consent for everything.”
This creates unnecessary withdrawal and validity problems and can misrepresent processing that is actually required by contract or law.
“We use legitimate interest because users agreed to our Terms.”
Agreement to Terms does not itself establish legitimate interest. Article 10 requires its own purpose, necessity, expectations, rights and safeguards analysis.
“Anything related to a customer is contractual.”
Contract necessity is narrower. The processing must be necessary to perform the contract or requested pre-contractual steps. Cross-selling, broad profiling or unrelated advertising should not automatically inherit the contract basis.
“Public data needs no legal basis.”
Incorrect. Public availability changes some consent analysis but does not eliminate principles, purpose limits or rights.
“Legitimate interest works for health or biometric data.”
Incorrect. Sensitive data requires Article 11. ANPD expressly says Article 7 legitimate interest does not apply to sensitive personal data.
“Our research team can always use the research-body basis.”
Not necessarily. Article 5 contains a specific definition of a qualifying research body. Ordinary commercial product research does not automatically meet it.
“Once we choose a basis, we never need to revisit it.”
Purposes, products, vendors and technologies change. A defensible privacy program revisits the basis when the processing changes materially.
Legal bases become much easier when every purpose is already mapped.
See our 25-point LGPD Compliance Checklist for Foreign Companies and LGPD Privacy Policy Requirements to connect the basis to the processing inventory and transparency layer.
A Practical Legal-Basis Review for a SaaS Company
Consider a U.S. SaaS company serving Brazilian users. The same platform may need several separate legal-basis decisions:
| SaaS purpose | Possible analysis | Documentation |
|---|---|---|
| Create paid user account | Contract may apply where processing is necessary to provide the requested service. | Service terms, account-field necessity, ROPA. |
| Invoice / tax records | Legal or regulatory obligation may apply where Brazilian obligations require the record. | Applicable law and retention schedule. |
| Platform security logs | Legitimate interest may be assessed for ordinary data where necessity and balancing support it. | Balancing test, retention, access controls. |
| Optional newsletter | Consent or legitimate-interest analysis depending on context and expectations. | Legal-basis record, unsubscribe/withdrawal, campaign source. |
| Behavioral ad targeting | Consent may be more appropriate where tracking/profiling is intrusive. | Cookie/tracker inventory, CMP records, vendor map. |
| Customer content processed on instructions | The customer-controller determines the basis for its processing; the SaaS operator follows documented instructions. | DPA, role map, customer instructions. |
| Legal dispute records | Regular exercise of rights may apply where the data is needed for a claim or defense. | Legal hold, matter file, retention rationale. |
This is why a SaaS company should not publish a notice saying simply: “We process your data based on consent, contract and legitimate interests.” The useful compliance evidence is the purpose-by-purpose map behind that sentence.
For the full SaaS workflow, see Brazil LGPD for SaaS Companies: Practical Compliance Guide.
Legal Basis vs International Transfer Mechanism
Another important distinction: a legal basis for processing and a legal mechanism for an international transfer are not the same thing.
For example, a company may rely on contract necessity for an underlying customer-processing activity but still need a separate Article 33 analysis before transferring the data from Brazil to another country.
See LGPD International Data Transfers: A Practical Guide for Global Businesses.
Turn “Which Legal Basis?” Into a Documented Decision
The Brazil LGPD Compliance Playbook — 2026 Edition includes a Legal-Basis Decision Record and a Legitimate Interest Assessment, plus a Data Mapping Worksheet, Processing Inventory / ROPA, Cookie and Tracking Inventory, Vendor Review, International Transfer Review, Retention Schedule, 100-point compliance audit and 30-day implementation roadmap.
Frequently Asked Questions
What are the 10 legal bases under the LGPD?
Article 7 lists consent; legal/regulatory obligation; public-administration public-policy processing; research by a qualifying research body; contract or requested pre-contractual procedures; regular exercise of rights; protection of life/physical safety; protection of health; legitimate interest; and protection of credit.
Does the LGPD require consent for all personal data processing?
No. Consent is one of ten Article 7 legal bases for ordinary personal data. The correct basis depends on the purpose and facts. Even when consent is not required, LGPD principles, transparency and data-subject rights still apply.
Which LGPD legal basis is best?
There is no universally best basis. The appropriate basis is the one whose statutory conditions actually match the specific processing purpose and that the controller can document and operate consistently.
When can a business use contract as a legal basis?
Article 7(V) applies where processing is necessary to perform a contract to which the data subject is a party or to carry out preliminary procedures related to a contract at that person's request. Optional marketing or unrelated profiling should not automatically be labeled contractual.
Can legitimate interest be used for marketing?
Potentially in some contexts, but there is no blanket marketing exemption. The controller should assess the concrete legitimate purpose, necessity, relationship and expectations, impacts on rights/freedoms, transparency, safeguards and applicable sector-specific rules. More intrusive behavioral advertising can make consent a more appropriate basis.
Does legitimate interest require a balancing test?
ANPD recommends a balancing test for legitimate-interest processing. Its simplified model examines purpose, necessity, and balancing plus safeguards. If the data subject's fundamental rights, freedoms and legitimate expectations prevail, the controller should not use legitimate interest.
Can legitimate interest be used for sensitive personal data?
No. ANPD states that Article 7 legitimate interest is not applicable to sensitive personal data because it is not included in Article 11. Sensitive data requires an Article 11 hypothesis.
Can Article 7 legal bases be used for children's data?
Yes, subject to the child's or adolescent's best interests. ANPD Enunciado No. 1/2023 states that Articles 7 and 11 can be used where applicable, provided the best interests of the child or adolescent are observed and prevail in the concrete case under Article 14.
Does publicly available data require a legal basis?
The LGPD still applies to publicly accessible personal data. Article 7 requires consideration of the original purpose, good faith and public interest, and preserves LGPD principles and data-subject rights.
Can a company change legal basis after collecting the data?
A changed purpose should trigger a new legal analysis rather than an opportunistic switch of labels. The controller should assess whether the new purpose is compatible, which basis actually applies, what transparency is required and whether additional rights or safeguards are triggered.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary statutory source for Articles 5–14, including definitions, the ten Article 7 bases, consent, legitimate interest, sensitive data and children's data.
- ANPD — Legal Hypotheses for Personal-Data Processing: Legitimate Interest Official ANPD guidance page for legitimate-interest interpretation and the balancing-test framework.
- ANPD — Full Legitimate Interest Guide Primary guidance used for sensitive-data restrictions, children's data, purpose, necessity, legitimate expectations, safeguards and balancing-test documentation.
- ANPD Enunciado No. 1/2023 — Children and Adolescents Official interpretation confirming that Article 7 or Article 11 legal bases may apply to children and adolescents when their best interests are observed and prevail.