2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD Transparency & Notices

LGPD Privacy Policy Requirements for Foreign Websites

A copied GDPR notice, a generic “we value your privacy” statement, or a legal template that does not match the live website is not a privacy program. For organizations subject to Brazil's LGPD, the useful question is not only “Do we have a privacy policy?” but whether the information given to individuals accurately explains the real processing.

Published: Last reviewed: Reading time: ~20 minutes By LGPD Brazil Editorial Team

Quick Answer: What must an LGPD privacy policy include?

The LGPD does not require every private website to publish a document with the exact title “Privacy Policy.” It does require clear, adequate and easily accessible information about personal-data processing. Article 9 identifies information including the specific purpose of processing, the form and duration of processing, the identity and contact information of the controller, information about shared use and its purpose, the responsibilities of processing agents, and data-subject rights. In practice, a website privacy notice is one of the main tools used to provide this transparency, but it must match the organization's actual systems, purposes, vendors and data flows.

Key Takeaways

  • LGPD requires transparency, not a magic document title. “Privacy Policy” and “Privacy Notice” are implementation labels.
  • Article 9 is the core starting point. Purpose, processing form/duration, controller identity/contact, sharing, agent responsibilities and rights must be addressed appropriately.
  • The notice must describe reality. A polished template that omits pixels, CRM, cloud, support, AI or international access creates a transparency gap.
  • Legal basis belongs in the internal data map even when the public notice summarizes it. Do not guess or use consent as a universal answer.
  • Rights need a working channel. The notice should tell people how to exercise their LGPD rights, and the organization needs a process behind that link or email.
  • International transfers need more than disclosure. Transparency does not replace the Article 33 transfer mechanism.
  • Update when processing changes. New vendors, pixels, AI features, purposes, retention or transfer locations can make an old notice inaccurate.

Foreign companies often arrive in Brazil with a privacy notice built for the GDPR or U.S. state privacy laws. That can be a valuable starting point, especially if the organization already has mature data mapping and governance. But the Brazilian notice should be mapped to the LGPD rather than treated as a simple translation exercise.

If you are still determining whether the LGPD applies to your website at all, start with Does Brazil's LGPD Apply to U.S. Companies?. Once scope is established, transparency should be built from the actual processing inventory.

Privacy Policy vs Privacy Notice: Does the Name Matter?

Privacy Notice

Usually describes information given to data subjects about how their personal data is collected, used, stored, shared and otherwise processed. This is the outward-facing transparency function.

Privacy Policy

In practice, many companies use this title for the same public-facing document. Internally, “privacy policy” can also mean governance rules for employees. The LGPD focuses on the substance of transparency, not the page title.

ANPD itself publishes an Aviso de Privacidade for visitors to its website and describes its purpose as explaining how personal data is treated, especially collection, use, storage and sharing. That is a useful example of notice architecture, but it is not a universal private-sector template.

Practical recommendation: for an international English-language site, “Privacy Policy” is perfectly understandable to users. Inside the document, make clear that it is the website's privacy notice explaining personal-data processing under applicable law, including Brazil's LGPD where relevant.

Article 9: The Core Transparency Information

Article 9 gives data subjects the right to easy access to information about processing and says that information should be made available in a clear, adequate and prominent form.

The article specifically identifies:

Article 9 topic Practical website question Where to document it
Specific purpose Why are you collecting or using this data? Privacy notice + internal processing inventory.
Form and duration of processing How is the data handled and for how long? Notice summary + detailed retention schedule internally.
Controller identity Which legal or organizational entity determines the processing? Prominent controller section.
Controller contact information How can the individual reach the controller? Email, contact form, postal/other channel as appropriate.
Shared use and purpose Which types of third parties receive data and why? Recipients/service-provider section.
Responsibilities of processing agents How are controller/operator responsibilities reflected? Notice at an understandable level + contracts/ROPA internally.
Data-subject rights What rights exist and how can a person exercise them? Rights section + working request channel.
Article 9 is not the whole notice

Other LGPD provisions add information or controls that may need to appear in the transparency framework depending on the facts. Examples include consent information, data sharing, automated decisions, the encarregado's public identity/contact information, international transfers, children's data and cookie/tracking transparency.

Read the current compiled LGPD .

12 Sections a Foreign Website Should Review

1

Who Is the Controller?

Identify the entity responsible for the relevant website processing. A brand name alone can be ambiguous if the actual controller is a parent, subsidiary or another legal entity.

For a global group, do not automatically list every group company as a controller. Determine which entity actually makes the decisions for the relevant processing.

Internal evidence: legal entity, role analysis, website/business ownership, data-processing decision owners.
2

What Personal Data Do You Collect?

Describe material categories in language users can understand. Depending on the site, this can include account details, contact data, transaction data, device/browser information, IP addresses, identifiers, support communications, customer content, marketing preferences, analytics events, fraud/security data or information submitted through forms.

Avoid publishing a giant theoretical list of every possible data category if the website does not actually collect it.

Internal evidence: live form inventory, cookie/tag scan, app integrations, API map, CRM fields and support systems.
3

Where Does the Data Come From?

Explain whether personal data is provided directly by the user, generated through use of the site, obtained from a customer account administrator, received from vendors or business partners, or derived from other data.

This becomes especially important for B2B sites, lead enrichment, marketplaces, SaaS products and advertising ecosystems where the person may not have typed every piece of information directly into your website.

Internal evidence: source-of-data field in the ROPA or processing inventory.
4

Why Do You Process the Data?

Purpose is the heart of LGPD transparency. Break broad phrases such as “operate our business” into meaningful purposes: create an account, process an order, deliver a service, prevent fraud, secure the platform, respond to support, measure product performance, send requested communications, conduct marketing, or comply with legal obligations.

Internal evidence: each stated purpose mapped to an actual system, business owner and legal-basis record.
5

Which Legal Bases Do You Use?

The LGPD contains multiple legal bases. A foreign notice should not simply copy GDPR Article 6 terminology or say “we process all data with your consent.”

At a minimum, the organization should maintain an internal legal-basis record for each material purpose. Whether the public notice lists the basis purpose-by-purpose or summarizes it depends on the transparency design, but the statement must be accurate.

Where legitimate interest is used, Article 10 requires a purpose, necessity, consideration of the individual's rights and freedoms, and measures to ensure transparency.

Internal evidence: Article 7/11 basis, decision rationale, consent record where applicable, legitimate-interest assessment where used.
6

Who Receives or Shares the Data?

Article 9 requires information about shared use of data and the purpose of that sharing. Article 18 also gives the data subject a right to information about public and private entities with which the controller has shared data.

A public notice can often use understandable categories such as payment providers, cloud hosting, customer-support platforms, analytics providers, professional advisers, logistics partners or advertising platforms. But the organization should maintain the underlying vendor/recipient detail internally so it can answer a specific request.

Internal evidence: vendor register, data recipients, role, purpose, country, contract and transfer status.
7

Do You Transfer Data Internationally?

Foreign websites often process Brazilian personal data outside Brazil through cloud hosting, customer support, analytics, affiliates, security tools, payment systems or other vendors.

The notice should accurately describe relevant international processing. But transparency is only one layer: the organization must separately identify an applicable Article 33 route or mechanism under Brazil's international-transfer framework.

Internal evidence: exporter/importer, destination, purpose, data categories, onward transfers, Article 33 mechanism and current ANPD adequacy status.
8

How Long Do You Keep the Data?

Article 9 refers to the duration of processing, while Articles 15 and 16 govern termination and permitted retention. A notice does not need to reproduce a 100-row internal retention schedule, but vague statements such as “we keep information as long as necessary” are stronger when accompanied by meaningful criteria.

Different data often requires different logic: customer account data, invoices, support tickets, fraud records, analytics identifiers, marketing preferences, deleted-account backups and legal claims should not automatically share one retention period.

Internal evidence: retention schedule, trigger, period/criteria, legal rationale, deletion method and backup treatment.
9

How Do You Protect Personal Data?

Article 46 requires technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication or other improper processing.

A public notice can describe security at a responsible level without publishing information that would weaken security. Avoid impossible promises such as “100% secure” or “we guarantee no breach.”

Internal evidence: access control, encryption decisions, logging, backups, secure development, vendor security, incident response and risk management.
10

What Cookies and Tracking Technologies Do You Use?

If the website uses cookies, analytics, advertising pixels, remarketing tags or similar technologies, the privacy notice should connect to the site's actual cookie/tracking transparency and preference controls.

ANPD's official cookie guide recommends clear information, real choice where consent is used, a visible option to reject non-essential cookies, granular management, and consent-based cookies disabled by default.

Internal evidence: tracker inventory, vendor, purpose, legal basis, duration, default state, consent configuration and test results.
11

What Rights Do Brazilian Data Subjects Have?

The notice should explain the relevant LGPD rights and give a practical method to exercise them. A rights list with no working process behind it is not enough operationally.

Rights include confirmation, access, correction, anonymization/blocking/deletion where applicable, portability, information about sharing, information about consent, withdrawal of consent and review of certain automated decisions, among other rights provided by the LGPD.

Internal evidence: request intake, identity verification, ticket workflow, response templates, request log, system search map and escalation.
12

Who Is the Encarregado and How Can People Contact the Organization?

Where an encarregado is required, Article 41 and ANPD's current rules require public disclosure of the encarregado's identity and contact information in a clear and objective manner, preferably on the controller's website.

If a valid small-agent exemption applies, the organization may be exempt from appointment, but qualifying small agents that do not appoint an encarregado must still make a data-subject communication channel available.

Internal evidence: appointment/exemption analysis, public identity/contact, substitute arrangements and tested communication route.

A Useful Privacy Notice Is a View of the Data Map

The strongest way to draft a privacy notice is to create it from the processing inventory—not the other way around. For every material processing activity, the organization should know the data, source, purpose, legal basis, role, systems, recipients, transfers, retention, security controls and rights impact.

The public notice then translates the relevant parts of that internal record into clear language for individuals. That structure is also easier to update when the business changes.

How Should the Notice Explain LGPD Data-Subject Rights?

ANPD's current rights page summarizes the practical rights framework and emphasizes that individuals can request confirmation and access, correction, anonymization/blocking/deletion where applicable, portability, elimination of consent-based data subject to statutory exceptions, withdrawal of consent, information about sharing and consent, and review of automated decisions.

For confirmation/access, Article 19 provides an important Brazil-specific timing rule: the controller can provide a simplified response immediately or a clear and complete statement within up to 15 days.

Do not simply say “we respond within 30 days” because that is your GDPR workflow. Brazil has a specific 15-day rule for the clear and complete confirmation/access statement under Article 19. Your internal request process should account for that difference.

A practical rights section should answer:

  • which rights can be exercised;
  • how to submit a request;
  • how identity will be verified;
  • how the individual can contact the controller or encarregado;
  • how consent can be withdrawn where consent is used; and
  • what to expect from the request process.

ANPD also explains that a data subject may petition the Agency when the person has been unable to exercise a right with a specific controller. This makes it especially important that the published request channel actually works.

Cookies, Pixels and the Privacy Policy

A privacy notice should not be the only technical control for cookie consent. If optional trackers are based on consent, the user needs a mechanism that actually controls whether they fire.

ANPD's cookie guidance also says essential information can be given through different formats, including a dedicated section of the privacy notice, a separate cookie policy or layered cookie-banner information, provided the information is clear, precise and easily accessible.

For the deeper analysis, see LGPD Cookie Consent Requirements: Analytics, Pixels and Advertising.

How Should a Foreign Website Describe International Transfers?

A foreign company should avoid two extremes.

The first is saying nothing even though Brazilian personal data is routinely hosted or accessed abroad. The second is publishing an enormous list of every possible global location without understanding the actual flows.

A useful notice explains that relevant personal data may be processed in other countries, identifies meaningful categories of recipients or destinations where appropriate, and describes the safeguards at a level users can understand. Internally, the company should maintain the detailed transfer register and Article 33 mechanism.

Disclosure is not the transfer mechanism. Saying “your data may be transferred internationally” does not by itself satisfy Article 33. If Brazilian personal data moves to a non-adequate destination such as the United States under the current ANPD repository, the organization still needs to determine which lawful transfer route actually applies.

See our full guide: LGPD International Data Transfers: A Practical Guide for Global Businesses.

What About Automated Decisions and AI?

If the website or service uses personal data for decisions made solely through automated processing that affect an individual's interests, Article 20 can become relevant. The data subject has a right to request review and, when requested, the controller must provide clear and adequate information about the criteria and procedures used, subject to commercial and industrial secrecy.

Not every use of AI needs a long “AI privacy” section. But material AI-driven processing should not be invisible. If customer data, support content, user behavior or profiles are sent to an AI provider, incorporated into automated decisions or used for independent model-improvement purposes, map the purpose, parties, legal basis, transfers, retention and rights implications.

Does the Notice Have to Name Every Vendor?

The LGPD requires meaningful information about shared use and gives data subjects a right to information about entities with which the controller has shared data. That does not necessarily mean the public notice must become a live procurement register containing every vendor name in every case.

A common operational approach is:

  1. use clear recipient categories in the public notice where appropriate;
  2. name specific third parties where that materially improves transparency or where required by the context;
  3. maintain a current internal vendor/recipient register; and
  4. be able to answer a data subject's more specific sharing request accurately.

This structure also avoids a common failure: the public policy says “service providers,” but no one internally knows which services currently receive Brazilian personal data.

10 Common LGPD Privacy Policy Mistakes

1. Copying a GDPR policy without mapping it to LGPDTerminology, legal bases, rights timing, encarregado and transfer rules can differ.
2. Saying consent is the basis for everythingLGPD contains multiple legal bases. Consent has specific validity and withdrawal requirements.
3. Omitting the actual controllerA brand, website name or product name may not identify the entity responsible for the processing.
4. Using vague purposes“Improve our services” should not hide distinct analytics, marketing, personalization, security or AI processing.
5. Ignoring pixels and third-party scriptsThe legal text on the page does not override what the live website actually sends to advertising and analytics platforms.
6. Hiding international processingCloud, support, vendors, affiliates and remote access can create cross-border flows.
7. Offering rights with no working request processA dead mailbox or unmonitored form creates an operational compliance gap.
8. Promising impossible deletionDo not promise instant deletion from all systems if legal retention, backups or technical architecture do not support that claim.
9. Publishing only a generic DPO email where identity is requiredANPD's encarregado guidance distinguishes public identity from contact information.
10. Never updating the noticeNew vendors, tracking, AI, products, countries, purposes or legal requirements can make yesterday's notice inaccurate.

A privacy notice should be the output of a compliance process, not the beginning and end of one.

Use our 25-point LGPD Compliance Checklist to review the data map, legal bases, vendors, transfers, rights, security and governance behind the notice.

Practical LGPD Privacy Notice Template Structure

The following is a useful drafting structure—not official ANPD wording and not a substitute for tailoring the notice to the organization's actual processing:

Section What it should answer
1. ScopeWhich website, app, product or service does this notice cover?
2. ControllerWho determines the relevant personal-data processing and how can that entity be contacted?
3. Data collectedWhich meaningful categories of personal data are processed?
4. SourcesIs the data provided directly, generated automatically, received from customers/partners or derived?
5. Purposes & legal basesWhy is each material category used and what legal basis supports the processing?
6. SharingWhich recipient categories receive the data and for what purposes?
7. International transfersDoes processing occur outside Brazil and what safeguard framework is relevant?
8. RetentionHow long is data kept or which criteria determine the retention period?
9. SecurityWhat general protective approach is used without disclosing exploitable detail?
10. Cookies & trackingWhich technologies are used, why, and where can users manage applicable preferences?
11. RightsWhat LGPD rights exist and how can a person submit a request?
12. Encarregado / contactWhere required, who is the encarregado and how can that person/entity be reached?
13. Children / special contextsDoes the service process children's or sensitive data requiring additional transparency?
14. Automated decisionsAre material solely automated decisions made using personal data?
15. ChangesHow will material changes to the notice be reflected and dated?

How Often Should a Privacy Policy Be Updated?

There is no universal LGPD rule saying a privacy notice must be rewritten once every 12 months. A better governance rule is to update when the underlying processing changes and to schedule a periodic review so unnoticed changes are discovered.

Trigger a review when you:

  • add a new analytics or advertising technology;
  • change payment, cloud, CRM, support or email providers;
  • launch a new product or data-driven feature;
  • introduce AI or automated decision-making;
  • begin processing new categories of personal or sensitive data;
  • enter a new country or create a new international-transfer path;
  • change retention or deletion behavior;
  • appoint or replace the encarregado;
  • change the controller or corporate structure; or
  • respond to new ANPD regulation or guidance.

Build the Privacy Notice From the Compliance Evidence Behind It

The Brazil LGPD Compliance Playbook — 2026 Edition includes a Privacy Notice Framework, Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, Cookie and Tracking Inventory, Vendor Privacy and Security Review, International Transfer Review, Data-Subject Request tools, a 100-point compliance audit and a 30-day implementation roadmap.

Privacy Notice Framework Data Mapping Worksheet Cookie & Tracking Inventory 100-point audit
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

Does the LGPD require a privacy policy?

The LGPD does not require every private website to use a document with the exact title “Privacy Policy.” It does require clear, adequate and easily accessible information about personal-data processing. Article 9 identifies core information that must be provided. A public privacy notice or privacy policy is a common way to provide it.

What should an LGPD privacy notice include?

A practical notice should identify the controller and contact channel, describe data categories and sources, explain specific purposes and legal bases, address sharing and international transfers, explain retention and security, describe cookies/tracking where relevant, list data-subject rights and the request process, and provide encarregado identity/contact information where required. Material automated decisions and special processing contexts should also be addressed where relevant.

Can a U.S. company use its GDPR privacy policy for Brazil?

It can be a strong starting point, but it should be mapped to Brazil's law and current ANPD rules. LGPD has its own legal bases, rights framework, access timing, encarregado requirements and international-transfer regime.

Does the privacy policy have to list every vendor by name?

Article 9 requires information about shared use and its purpose, while Article 18 gives data subjects a right to information about entities with which the controller has shared data. Clear recipient categories can be appropriate in a public notice, but the controller should maintain detailed internal records and be able to answer a specific request accurately.

Should international data transfers be disclosed?

If international processing is material to how personal data is handled, it should be accurately reflected in the transparency framework. The organization must separately identify the applicable Article 33 route or transfer mechanism. Disclosure alone is not sufficient.

Does an LGPD privacy notice need to include legal bases?

The organization should document the applicable legal basis for each material processing purpose internally. Article 9 focuses on transparent information about the processing, and other LGPD provisions govern the legal bases themselves. Many organizations include legal-basis information in the public notice because it improves transparency, but the wording should be accurate and mapped to the real processing.

How quickly must a company respond to an LGPD access request?

For confirmation/access, Article 19 provides for a simplified response immediately or a clear and complete statement within up to 15 days, subject to the law and applicable regulation.

Does the privacy notice need to include the DPO's name?

Where an encarregado is required, Article 41 requires the identity and contact information to be disclosed publicly, clearly and objectively, preferably on the controller's website. ANPD's current guidance provides more detail on the identity disclosure.

Do cookies need a separate policy?

Not necessarily. ANPD's cookie guidance says essential cookie information can be provided in a dedicated section of the privacy notice, a separate cookie policy or through layered cookie-banner information, provided the information is clear, precise and easily accessible.

How often should an LGPD privacy policy be updated?

There is no universal annual update date in the LGPD. Review the notice when material processing changes and use a periodic governance review to identify new purposes, vendors, transfers, trackers, AI features, retention rules or contact details that make the notice inaccurate.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD and official ANPD materials available on August 19, 2026. Privacy-notice requirements depend on the organization's actual processing, industry, product, users, legal bases, contracts, tracking stack, countries, children/sensitive-data exposure and other applicable laws. Verify current official sources and obtain qualified Brazilian legal advice for decisions involving your organization's specific facts.