Quick Answer: What must an LGPD privacy policy include?
The LGPD does not require every private website to publish a document with the exact title “Privacy Policy.” It does require clear, adequate and easily accessible information about personal-data processing. Article 9 identifies information including the specific purpose of processing, the form and duration of processing, the identity and contact information of the controller, information about shared use and its purpose, the responsibilities of processing agents, and data-subject rights. In practice, a website privacy notice is one of the main tools used to provide this transparency, but it must match the organization's actual systems, purposes, vendors and data flows.
Key Takeaways
- LGPD requires transparency, not a magic document title. “Privacy Policy” and “Privacy Notice” are implementation labels.
- Article 9 is the core starting point. Purpose, processing form/duration, controller identity/contact, sharing, agent responsibilities and rights must be addressed appropriately.
- The notice must describe reality. A polished template that omits pixels, CRM, cloud, support, AI or international access creates a transparency gap.
- Legal basis belongs in the internal data map even when the public notice summarizes it. Do not guess or use consent as a universal answer.
- Rights need a working channel. The notice should tell people how to exercise their LGPD rights, and the organization needs a process behind that link or email.
- International transfers need more than disclosure. Transparency does not replace the Article 33 transfer mechanism.
- Update when processing changes. New vendors, pixels, AI features, purposes, retention or transfer locations can make an old notice inaccurate.
Foreign companies often arrive in Brazil with a privacy notice built for the GDPR or U.S. state privacy laws. That can be a valuable starting point, especially if the organization already has mature data mapping and governance. But the Brazilian notice should be mapped to the LGPD rather than treated as a simple translation exercise.
If you are still determining whether the LGPD applies to your website at all, start with Does Brazil's LGPD Apply to U.S. Companies?. Once scope is established, transparency should be built from the actual processing inventory.
Privacy Policy vs Privacy Notice: Does the Name Matter?
Usually describes information given to data subjects about how their personal data is collected, used, stored, shared and otherwise processed. This is the outward-facing transparency function.
In practice, many companies use this title for the same public-facing document. Internally, “privacy policy” can also mean governance rules for employees. The LGPD focuses on the substance of transparency, not the page title.
ANPD itself publishes an Aviso de Privacidade for visitors to its website and describes its purpose as explaining how personal data is treated, especially collection, use, storage and sharing. That is a useful example of notice architecture, but it is not a universal private-sector template.
Article 9: The Core Transparency Information
Article 9 gives data subjects the right to easy access to information about processing and says that information should be made available in a clear, adequate and prominent form.
The article specifically identifies:
| Article 9 topic | Practical website question | Where to document it |
|---|---|---|
| Specific purpose | Why are you collecting or using this data? | Privacy notice + internal processing inventory. |
| Form and duration of processing | How is the data handled and for how long? | Notice summary + detailed retention schedule internally. |
| Controller identity | Which legal or organizational entity determines the processing? | Prominent controller section. |
| Controller contact information | How can the individual reach the controller? | Email, contact form, postal/other channel as appropriate. |
| Shared use and purpose | Which types of third parties receive data and why? | Recipients/service-provider section. |
| Responsibilities of processing agents | How are controller/operator responsibilities reflected? | Notice at an understandable level + contracts/ROPA internally. |
| Data-subject rights | What rights exist and how can a person exercise them? | Rights section + working request channel. |
Other LGPD provisions add information or controls that may need to appear in the transparency framework depending on the facts. Examples include consent information, data sharing, automated decisions, the encarregado's public identity/contact information, international transfers, children's data and cookie/tracking transparency.
12 Sections a Foreign Website Should Review
Who Is the Controller?
Identify the entity responsible for the relevant website processing. A brand name alone can be ambiguous if the actual controller is a parent, subsidiary or another legal entity.
For a global group, do not automatically list every group company as a controller. Determine which entity actually makes the decisions for the relevant processing.
What Personal Data Do You Collect?
Describe material categories in language users can understand. Depending on the site, this can include account details, contact data, transaction data, device/browser information, IP addresses, identifiers, support communications, customer content, marketing preferences, analytics events, fraud/security data or information submitted through forms.
Avoid publishing a giant theoretical list of every possible data category if the website does not actually collect it.
Where Does the Data Come From?
Explain whether personal data is provided directly by the user, generated through use of the site, obtained from a customer account administrator, received from vendors or business partners, or derived from other data.
This becomes especially important for B2B sites, lead enrichment, marketplaces, SaaS products and advertising ecosystems where the person may not have typed every piece of information directly into your website.
Why Do You Process the Data?
Purpose is the heart of LGPD transparency. Break broad phrases such as “operate our business” into meaningful purposes: create an account, process an order, deliver a service, prevent fraud, secure the platform, respond to support, measure product performance, send requested communications, conduct marketing, or comply with legal obligations.
Which Legal Bases Do You Use?
The LGPD contains multiple legal bases. A foreign notice should not simply copy GDPR Article 6 terminology or say “we process all data with your consent.”
At a minimum, the organization should maintain an internal legal-basis record for each material purpose. Whether the public notice lists the basis purpose-by-purpose or summarizes it depends on the transparency design, but the statement must be accurate.
Where legitimate interest is used, Article 10 requires a purpose, necessity, consideration of the individual's rights and freedoms, and measures to ensure transparency.
Who Receives or Shares the Data?
Article 9 requires information about shared use of data and the purpose of that sharing. Article 18 also gives the data subject a right to information about public and private entities with which the controller has shared data.
A public notice can often use understandable categories such as payment providers, cloud hosting, customer-support platforms, analytics providers, professional advisers, logistics partners or advertising platforms. But the organization should maintain the underlying vendor/recipient detail internally so it can answer a specific request.
Do You Transfer Data Internationally?
Foreign websites often process Brazilian personal data outside Brazil through cloud hosting, customer support, analytics, affiliates, security tools, payment systems or other vendors.
The notice should accurately describe relevant international processing. But transparency is only one layer: the organization must separately identify an applicable Article 33 route or mechanism under Brazil's international-transfer framework.
How Long Do You Keep the Data?
Article 9 refers to the duration of processing, while Articles 15 and 16 govern termination and permitted retention. A notice does not need to reproduce a 100-row internal retention schedule, but vague statements such as “we keep information as long as necessary” are stronger when accompanied by meaningful criteria.
Different data often requires different logic: customer account data, invoices, support tickets, fraud records, analytics identifiers, marketing preferences, deleted-account backups and legal claims should not automatically share one retention period.
How Do You Protect Personal Data?
Article 46 requires technical and administrative measures to protect personal data against unauthorized access and accidental or unlawful destruction, loss, alteration, communication or other improper processing.
A public notice can describe security at a responsible level without publishing information that would weaken security. Avoid impossible promises such as “100% secure” or “we guarantee no breach.”
What Cookies and Tracking Technologies Do You Use?
If the website uses cookies, analytics, advertising pixels, remarketing tags or similar technologies, the privacy notice should connect to the site's actual cookie/tracking transparency and preference controls.
ANPD's official cookie guide recommends clear information, real choice where consent is used, a visible option to reject non-essential cookies, granular management, and consent-based cookies disabled by default.
What Rights Do Brazilian Data Subjects Have?
The notice should explain the relevant LGPD rights and give a practical method to exercise them. A rights list with no working process behind it is not enough operationally.
Rights include confirmation, access, correction, anonymization/blocking/deletion where applicable, portability, information about sharing, information about consent, withdrawal of consent and review of certain automated decisions, among other rights provided by the LGPD.
Who Is the Encarregado and How Can People Contact the Organization?
Where an encarregado is required, Article 41 and ANPD's current rules require public disclosure of the encarregado's identity and contact information in a clear and objective manner, preferably on the controller's website.
If a valid small-agent exemption applies, the organization may be exempt from appointment, but qualifying small agents that do not appoint an encarregado must still make a data-subject communication channel available.
A Useful Privacy Notice Is a View of the Data Map
The strongest way to draft a privacy notice is to create it from the processing inventory—not the other way around. For every material processing activity, the organization should know the data, source, purpose, legal basis, role, systems, recipients, transfers, retention, security controls and rights impact.
The public notice then translates the relevant parts of that internal record into clear language for individuals. That structure is also easier to update when the business changes.
How Should the Notice Explain LGPD Data-Subject Rights?
ANPD's current rights page summarizes the practical rights framework and emphasizes that individuals can request confirmation and access, correction, anonymization/blocking/deletion where applicable, portability, elimination of consent-based data subject to statutory exceptions, withdrawal of consent, information about sharing and consent, and review of automated decisions.
For confirmation/access, Article 19 provides an important Brazil-specific timing rule: the controller can provide a simplified response immediately or a clear and complete statement within up to 15 days.
A practical rights section should answer:
- which rights can be exercised;
- how to submit a request;
- how identity will be verified;
- how the individual can contact the controller or encarregado;
- how consent can be withdrawn where consent is used; and
- what to expect from the request process.
ANPD also explains that a data subject may petition the Agency when the person has been unable to exercise a right with a specific controller. This makes it especially important that the published request channel actually works.
Cookies, Pixels and the Privacy Policy
A privacy notice should not be the only technical control for cookie consent. If optional trackers are based on consent, the user needs a mechanism that actually controls whether they fire.
ANPD's cookie guidance also says essential information can be given through different formats, including a dedicated section of the privacy notice, a separate cookie policy or layered cookie-banner information, provided the information is clear, precise and easily accessible.
For the deeper analysis, see LGPD Cookie Consent Requirements: Analytics, Pixels and Advertising.
How Should a Foreign Website Describe International Transfers?
A foreign company should avoid two extremes.
The first is saying nothing even though Brazilian personal data is routinely hosted or accessed abroad. The second is publishing an enormous list of every possible global location without understanding the actual flows.
A useful notice explains that relevant personal data may be processed in other countries, identifies meaningful categories of recipients or destinations where appropriate, and describes the safeguards at a level users can understand. Internally, the company should maintain the detailed transfer register and Article 33 mechanism.
See our full guide: LGPD International Data Transfers: A Practical Guide for Global Businesses.
What About Automated Decisions and AI?
If the website or service uses personal data for decisions made solely through automated processing that affect an individual's interests, Article 20 can become relevant. The data subject has a right to request review and, when requested, the controller must provide clear and adequate information about the criteria and procedures used, subject to commercial and industrial secrecy.
Not every use of AI needs a long “AI privacy” section. But material AI-driven processing should not be invisible. If customer data, support content, user behavior or profiles are sent to an AI provider, incorporated into automated decisions or used for independent model-improvement purposes, map the purpose, parties, legal basis, transfers, retention and rights implications.
Does the Notice Have to Name Every Vendor?
The LGPD requires meaningful information about shared use and gives data subjects a right to information about entities with which the controller has shared data. That does not necessarily mean the public notice must become a live procurement register containing every vendor name in every case.
A common operational approach is:
- use clear recipient categories in the public notice where appropriate;
- name specific third parties where that materially improves transparency or where required by the context;
- maintain a current internal vendor/recipient register; and
- be able to answer a data subject's more specific sharing request accurately.
This structure also avoids a common failure: the public policy says “service providers,” but no one internally knows which services currently receive Brazilian personal data.
10 Common LGPD Privacy Policy Mistakes
A privacy notice should be the output of a compliance process, not the beginning and end of one.
Use our 25-point LGPD Compliance Checklist to review the data map, legal bases, vendors, transfers, rights, security and governance behind the notice.
Practical LGPD Privacy Notice Template Structure
The following is a useful drafting structure—not official ANPD wording and not a substitute for tailoring the notice to the organization's actual processing:
| Section | What it should answer |
|---|---|
| 1. Scope | Which website, app, product or service does this notice cover? |
| 2. Controller | Who determines the relevant personal-data processing and how can that entity be contacted? |
| 3. Data collected | Which meaningful categories of personal data are processed? |
| 4. Sources | Is the data provided directly, generated automatically, received from customers/partners or derived? |
| 5. Purposes & legal bases | Why is each material category used and what legal basis supports the processing? |
| 6. Sharing | Which recipient categories receive the data and for what purposes? |
| 7. International transfers | Does processing occur outside Brazil and what safeguard framework is relevant? |
| 8. Retention | How long is data kept or which criteria determine the retention period? |
| 9. Security | What general protective approach is used without disclosing exploitable detail? |
| 10. Cookies & tracking | Which technologies are used, why, and where can users manage applicable preferences? |
| 11. Rights | What LGPD rights exist and how can a person submit a request? |
| 12. Encarregado / contact | Where required, who is the encarregado and how can that person/entity be reached? |
| 13. Children / special contexts | Does the service process children's or sensitive data requiring additional transparency? |
| 14. Automated decisions | Are material solely automated decisions made using personal data? |
| 15. Changes | How will material changes to the notice be reflected and dated? |
How Often Should a Privacy Policy Be Updated?
There is no universal LGPD rule saying a privacy notice must be rewritten once every 12 months. A better governance rule is to update when the underlying processing changes and to schedule a periodic review so unnoticed changes are discovered.
Trigger a review when you:
- add a new analytics or advertising technology;
- change payment, cloud, CRM, support or email providers;
- launch a new product or data-driven feature;
- introduce AI or automated decision-making;
- begin processing new categories of personal or sensitive data;
- enter a new country or create a new international-transfer path;
- change retention or deletion behavior;
- appoint or replace the encarregado;
- change the controller or corporate structure; or
- respond to new ANPD regulation or guidance.
Build the Privacy Notice From the Compliance Evidence Behind It
The Brazil LGPD Compliance Playbook — 2026 Edition includes a Privacy Notice Framework, Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, Cookie and Tracking Inventory, Vendor Privacy and Security Review, International Transfer Review, Data-Subject Request tools, a 100-point compliance audit and a 30-day implementation roadmap.
Frequently Asked Questions
Does the LGPD require a privacy policy?
The LGPD does not require every private website to use a document with the exact title “Privacy Policy.” It does require clear, adequate and easily accessible information about personal-data processing. Article 9 identifies core information that must be provided. A public privacy notice or privacy policy is a common way to provide it.
What should an LGPD privacy notice include?
A practical notice should identify the controller and contact channel, describe data categories and sources, explain specific purposes and legal bases, address sharing and international transfers, explain retention and security, describe cookies/tracking where relevant, list data-subject rights and the request process, and provide encarregado identity/contact information where required. Material automated decisions and special processing contexts should also be addressed where relevant.
Can a U.S. company use its GDPR privacy policy for Brazil?
It can be a strong starting point, but it should be mapped to Brazil's law and current ANPD rules. LGPD has its own legal bases, rights framework, access timing, encarregado requirements and international-transfer regime.
Does the privacy policy have to list every vendor by name?
Article 9 requires information about shared use and its purpose, while Article 18 gives data subjects a right to information about entities with which the controller has shared data. Clear recipient categories can be appropriate in a public notice, but the controller should maintain detailed internal records and be able to answer a specific request accurately.
Should international data transfers be disclosed?
If international processing is material to how personal data is handled, it should be accurately reflected in the transparency framework. The organization must separately identify the applicable Article 33 route or transfer mechanism. Disclosure alone is not sufficient.
Does an LGPD privacy notice need to include legal bases?
The organization should document the applicable legal basis for each material processing purpose internally. Article 9 focuses on transparent information about the processing, and other LGPD provisions govern the legal bases themselves. Many organizations include legal-basis information in the public notice because it improves transparency, but the wording should be accurate and mapped to the real processing.
How quickly must a company respond to an LGPD access request?
For confirmation/access, Article 19 provides for a simplified response immediately or a clear and complete statement within up to 15 days, subject to the law and applicable regulation.
Does the privacy notice need to include the DPO's name?
Where an encarregado is required, Article 41 requires the identity and contact information to be disclosed publicly, clearly and objectively, preferably on the controller's website. ANPD's current guidance provides more detail on the identity disclosure.
Do cookies need a separate policy?
Not necessarily. ANPD's cookie guidance says essential cookie information can be provided in a dedicated section of the privacy notice, a separate cookie policy or through layered cookie-banner information, provided the information is clear, precise and easily accessible.
How often should an LGPD privacy policy be updated?
There is no universal annual update date in the LGPD. Review the notice when material processing changes and use a periodic governance review to identify new purposes, vendors, transfers, trackers, AI features, retention rules or contact details that make the notice inaccurate.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary source for transparency, Article 9 information, legal bases, rights, retention, security, automated decisions, international transfers and the encarregado.
- ANPD — Privacy Notice Official ANPD example of a privacy notice explaining collection, use, storage and sharing on its own website.
- ANPD — Data-Subject Rights Current official overview of confirmation/access, correction, deletion/blocking/anonymization, portability, withdrawal, information rights and automated-decision review.
- ANPD — Cookies and Personal Data Protection Guidance Official guidance for cookie/tracking transparency, legal-basis analysis and banner practices.
- ANPD — International Data Transfers Current official transfer framework and repository under Resolution CD/ANPD No. 19/2024.