2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD Vendors & Processors

LGPD Vendor Compliance: What to Check Before Using a Processor

Cloud hosting, CRM, payroll, payment, analytics, customer support, email, AI, fraud prevention and outsourced operations can all put personal data into a vendor's environment. The LGPD does not turn procurement into a checkbox exercise: you need to understand the vendor's real role, instructions, security, subprocessors, incident process, rights support, retention and international-transfer chain before deciding whether the relationship is defensible.

Published: Last reviewed: Reading time: ~22 minutes By LGPD Brazil Editorial Team

Quick Answer: What should you check before giving an LGPD processor access to personal data?

First determine the vendor's actual role for each processing activity: controller, operator, or potentially a different role for different purposes. If the vendor is an operator, document the controller's instructions, permitted purpose, data categories, security expectations, retention/deletion, incident escalation, data-subject-rights support, subprocessors and international transfers. The LGPD does not expressly require a GDPR Article 28-style DPA in every controller–operator relationship, but ANPD says a processing contract is good practice and identifies core subjects that can be defined contractually. If data is transferred from Brazil to a foreign vendor, separately identify a valid Article 33 transfer mechanism under the current Resolution No. 19/2024 framework.

Key Takeaways

  • Role follows facts, not labels. Calling a vendor “processor” in a contract does not make it an operator if it decides its own purposes and essential elements.
  • The same vendor can have different roles. ANPD says agent roles are determined per processing operation.
  • A DPA is strongly useful even though the LGPD does not expressly mandate a GDPR-style processor contract in every case.
  • Subprocessors need visibility. ANPD recommends formal controller authorization—general or specific—before an operator appoints a suboperator.
  • Incident timing must be contractualized. The operator must inform the controller without unjustified delay, while the controller may face a three-business-day notification window for reportable incidents.
  • International transfers are a separate legal layer. A vendor contract alone is not necessarily the Article 33 transfer mechanism.
  • Vendor review should be risk-based. A newsletter tool and a biometric identity provider should not receive identical due diligence.

Vendor risk under the LGPD begins before the contract is signed. A controller that does not know what a provider will collect, where it will process the data, whether it will reuse the data for its own purposes, which subprocessors it uses or how quickly it will escalate an incident cannot meaningfully instruct or supervise the relationship.

Article 39 says an operator must process according to the controller's instructions and the controller must verify compliance with its instructions and the applicable rules. Article 46 requires processing agents to adopt technical and administrative security measures. Articles 37 and 42 also give operators direct legal significance through processing-record and liability rules.

Step One: Is the Vendor Actually an Operator?

Controller Determines the essential decisions

Defines the purpose and other essential elements of the relevant processing activity.

Operator Processes on behalf of the controller

Acts within the controller's purpose and instructions, while it may decide non-essential technical elements.

Mixed roles Analyze purpose by purpose

A vendor can be an operator for customer data and a controller for separate account, security, billing or independent product purposes.

ANPD's controller/operator guide says the same organization can be a controller in one processing operation and an operator in another. It also emphasizes that the controller is identified by the principal decisions over purpose and essential elements, while an operator acts on the controller's behalf and can determine non-essential elements such as some technical measures.

Do not outsource the role analysis to the vendor's standard contract. ANPD expressly warns that actual activity can differ from formal contractual wording. The real conduct and decision-making power should be analyzed.

Questions that expose the real role

  • Who decided why the data is being processed?
  • Who determines the essential data categories and affected people?
  • Who determines how long the processing should continue?
  • Can the vendor independently reuse customer data for product improvement, advertising, profiling or model training?
  • Can the customer meaningfully instruct the vendor to delete, return, correct or restrict the data?
  • Does the vendor merely select technical implementation details, or does it decide a new purpose?

The fifth question is particularly important for modern SaaS and AI services. A provider can be an operator for one workflow while acting as controller for a separate purpose that it determines independently. The contract and privacy notice should not hide that distinction.

What about payment providers?

ANPD's 2022 guide includes an e-commerce example in which the online sales channel is controller and the different payment services are operators. That is useful guidance for the scenario described by ANPD, but vendor classification remains functional and fact-specific. A real payment provider may have independent statutory, fraud, anti-money-laundering, network or account purposes that require a separate role analysis.

The safest editorial and compliance rule is: use ANPD examples as guidance, not as universal role labels for every commercial arrangement.

Does the LGPD Require a Data Processing Agreement?

This is a common question from companies familiar with GDPR Article 28.

ANPD's official guide states that the LGPD does not expressly require the controller and operator to sign a contract specifically governing personal-data processing. The same guide says such a contractual arrangement is a good practice because it can:

  • limit the operator's scope of activity;
  • set objective parameters for allocation of responsibilities; and
  • reduce risks and uncertainty in the processing operation.

ANPD identifies contractual topics including the object, duration, nature and purpose of processing, types of personal data, and the rights, obligations and responsibilities related to LGPD compliance.

Important legal distinction

The absence of an express GDPR-style contract mandate does not eliminate Article 39: the operator must follow the controller's instructions and the controller must verify compliance. A written DPA or equivalent contractual schedule is one of the most practical ways to make those instructions and responsibilities provable.

What should an LGPD DPA cover?

The following structure goes beyond ANPD's short illustrative list and represents a practical vendor-governance framework derived from the LGPD's operational obligations:

Contract topic What to define Why it matters
Scope & purposeServices, processing activities, purpose and controller instructions.Prevents unauthorized reuse or purpose expansion.
Data & subjectsCategories of personal data and affected groups.Supports risk, rights and security analysis.
DurationProcessing period, retention and deletion/return triggers.Connects the vendor to the controller's retention logic.
SecurityAppropriate technical and administrative measures, access, encryption, logging, testing and change management as relevant.Supports Article 46 and vendor-risk evidence.
ConfidentialityAuthorized personnel and confidentiality obligations.Reduces internal/vendor exposure.
SubprocessorsAuthorization model, notice of changes and flow-down requirements.Preserves visibility into the processing chain.
IncidentsImmediate/rapid escalation, required facts, updates, cooperation and evidence.Protects the controller's regulatory response window.
Data-subject rightsSearch, access, correction, deletion, blocking, export and routing support.The controller must be able to operationalize Article 18 rights.
International transfersLocations, remote access, subprocessors, Article 33 mechanism and change notification.Separates vendor engagement from the transfer-law layer.
Audit & evidenceCertifications, reports, questionnaires, remediation evidence or contractual audit rights proportionate to risk.Supports the controller's verification responsibility.
End of serviceReturn/deletion, account closure, backup lifecycle and confirmation.Prevents indefinite residual processing after termination.

A 15-Point LGPD Vendor Privacy and Security Review

1

Define the Business Use Case

State what the vendor will do and why personal data is needed. A vendor cannot be meaningfully reviewed if procurement cannot describe the actual processing.

Evidence: service description, business owner, purpose and workflow diagram.
2

Classify the Vendor's Role

Determine controller/operator status per purpose. Record any mixed-role or independent-use scenario.

Evidence: role matrix, vendor terms, product documentation and actual decision rights.
3

Map the Personal Data

Identify ordinary data, sensitive data, children's data, authentication data, payment data, customer content and other relevant categories.

Evidence: data fields, data subjects, source, destination and sensitivity.
4

Confirm the Instructions and Permitted Purposes

Check whether the vendor can use the data only to deliver the contracted service or also for its own analytics, advertising, benchmarking, AI/model improvement or other purposes.

Evidence: DPA, product terms, privacy notice, AI terms and opt-in/opt-out settings.
5

Assess Security Controls

Review controls proportionate to the risk: identity/access management, privileged access, encryption, vulnerability management, logging, backups, secure development, tenant separation, malware/ransomware controls, incident response and business continuity.

Evidence: security questionnaire, SOC/ISO reports where available, architecture, pen-test summary, certifications and remediation status.
6

Check Personnel Access and Confidentiality

Determine who at the vendor can access the data, why, under what authorization and with what logging and confidentiality safeguards.

Evidence: access model, role-based permissions, background/confidentiality practices as appropriate, access reviews.
7

Map Subprocessors

Identify cloud infrastructure, support, monitoring, AI, email, analytics and other downstream providers involved in the service.

Evidence: current subprocessor list, service/location/purpose, change-notification process and authorization mechanism.
8

Review Incident Escalation

Define how fast the vendor must tell you about a personal-data incident and which facts it must provide immediately and in later updates.

Evidence: contractual notification period, 24/7 contacts, escalation table and incident-information requirements.
9

Test Data Subject Rights Support

Can the vendor locate, export, correct, delete, block or otherwise act on data when the controller needs to answer a rights request?

Evidence: product functions, API/export, deletion workflow, SLA and support procedure.
10

Check Retention and Deletion

Understand active-system retention, backups, logs, legal holds, deleted accounts and how long residual copies remain.

Evidence: retention schedule, deletion documentation, backup lifecycle and termination procedure.
11

Map International Transfers and Remote Access

Record data-hosting countries, support locations, remote administrator access and subprocessor countries. Then determine the applicable Article 33 transfer mechanism.

Evidence: transfer map, exporter/importer, destination, transfer mechanism and contractual clauses.
12

Review Business Continuity and Availability

Availability can be a personal-data security issue. Understand recovery, backup, redundancy, ransomware response and service continuity for critical vendors.

Evidence: BCP/DR summary, RTO/RPO where relevant, recovery tests and incident history.
13

Evaluate Regulatory and Contractual Red Flags

Look for unresolved material security findings, refusal to explain data use, impossible deletion claims, silent subprocessor changes, undisclosed international processing or terms that allow broad independent reuse.

Evidence: exceptions log, legal/privacy review and remediation commitments.
14

Assign a Vendor Risk Tier

Do not review every vendor identically. Higher tiers can reflect sensitive data, children, large scale, critical availability, AI profiling, credentials, financial data, biometric data or broad international chains.

Evidence: risk score, review depth, approval owner and next-review date.
15

Document Approval, Conditions and Reassessment

Approval should identify unresolved conditions and triggers for reassessment: new subprocessors, security incidents, product/AI changes, new countries, material contract changes or new data categories.

Evidence: approval record, conditions, owner, review date and change-monitoring process.

A Practical Vendor Decision

  1. Approve: role, security, contract, transfer and operational controls are proportionate to the risk.
  2. Approve with conditions: remediation or contractual changes must be completed before or shortly after launch.
  3. Escalate: high-risk data, unclear role, sensitive data, AI reuse, weak incident terms or complex transfers need specialist review.
  4. Reject: the vendor cannot support the controller's legal obligations or presents risk that cannot reasonably be reduced.

Subprocessors Under the LGPD

The LGPD formally defines controller and operator, but not “suboperator.” ANPD's guide nevertheless recognizes the concept as useful for complex processing chains.

In ANPD's framework, a suboperator is engaged by the operator to help process personal data on behalf of the controller. The suboperator's direct contractual relationship is with the operator, but depending on the facts, both can perform operator functions and can be accountable before ANPD.

ANPD recommends that an operator obtain formal authorization—general or specific—from the controller before engaging a suboperator. That authorization can be included in the controller–operator contract.

“We use subprocessors” is not enough. A controller should know which downstream companies materially process its personal data, where they are located, what they do, how changes are notified and whether equivalent privacy/security obligations flow down.

General vs specific authorization

ANPD's guide gives a useful distinction: general authorization might permit a category of technical subcontracting such as cloud storage, while specific authorization may identify a particular organization for a defined purpose.

A practical modern contract can combine general authorization with:

  • a public or contractual subprocessor list;
  • advance notice of material changes;
  • a process for legitimate objections where appropriate;
  • flow-down of incident/security/deletion obligations; and
  • current transfer documentation for foreign subprocessors.

Vendor Data Breaches: Your Contract Must Beat the Regulatory Clock

ANPD's current incident guidance is clear: the controller has the legal duty to notify ANPD and affected data subjects when a confirmed personal-data incident can cause relevant risk or damage.

The operator must inform the controller without unjustified delay and provide the information needed for the controller's risk assessment and communication.

The ordinary controller notification period under Resolution 15/2024 is three business days for reportable incidents. That creates an obvious procurement problem: a vendor term promising notice “within 72 hours after final confirmation” can consume much of the controller's own decision window.

Do not copy a regulatory deadline into the vendor contract as if the vendor had the same clock. The vendor's escalation should be fast enough to leave the controller meaningful time to investigate, assess risk, prepare the ANPD filing and notify affected people if required.

ANPD expressly recommends establishing controller–operator incident-notification obligations in contract so the process can be accelerated and risks to individuals reduced.

What incident information should the vendor provide?

Discovery and chronologyWhen the vendor became aware, what happened and which systems are involved.
Affected dataCategories, approximate volume, sensitivity and whether Brazilian data is implicated.
Affected peopleKnown/estimated number and relevant vulnerable groups.
Cause and attack pathKnown or suspected cause, compromised credentials, vulnerability or accidental disclosure.
Protection in placeEncryption, tokenization, access controls and whether keys/credentials were exposed.
Containment and mitigationActions completed, planned actions and residual risk.
Subprocessor involvementWhether the incident originated deeper in the supply chain.
Ongoing updatesNamed contact, update cadence and final incident report.

See our full guide: LGPD Data Breach Notification: When and How Companies Must Respond.

Foreign Vendors and International Data Transfers

A cloud or SaaS vendor outside Brazil can create an international-transfer analysis when personal data is transferred from an exporter to an importer abroad. Remote support or downstream subprocessors may create additional paths.

Resolution CD/ANPD No. 19/2024 regulates mechanisms including:

  • adequacy decisions;
  • Brazilian Standard Contractual Clauses;
  • equivalent standard clauses recognized by ANPD;
  • specific contractual clauses approved by ANPD; and
  • binding corporate rules approved by ANPD.

ANPD's current repository says the European Union is currently recognized as adequate through Resolution No. 32/2026. It also says that, as of the current official page, no equivalent SCCs, specific contractual clauses or binding corporate rules have yet been approved in the repository.

The United States is not currently listed as an adequate destination by ANPD. A company using a U.S. SaaS provider therefore should not write “the U.S. is adequate” or assume a GDPR adequacy decision made by another authority automatically works for Brazil. ANPD expressly says adequacy decisions issued by other countries are not valid for Brazil.

Brazilian Standard Contractual Clauses

When Brazilian SCCs are the selected mechanism, ANPD says they must be incorporated without modification. Resolution 19/2024 originally gave a 12-month implementation period after publication; that implementation date has already passed.

A DPA and a transfer mechanism solve different problems. The DPA defines operational controller/operator responsibilities. The Article 33 mechanism supports the international transfer. Depending on the relationship, both may need to appear in the same contract package.

For the complete transfer analysis, see LGPD International Data Transfers: A Practical Guide for Global Businesses.

Example: Reviewing a U.S. SaaS Vendor

Imagine a Brazilian-facing company wants to use a U.S. customer-support SaaS. The platform will receive customer names, email addresses, support messages and attachments.

Review area Question Potential outcome
RoleDoes the SaaS use support content only under customer instructions?Operator for support content; separate analysis for its own billing/security/product purposes.
AIAre tickets used to train shared models or improve the vendor's product independently?If yes, role/purpose/legal-basis/transparency analysis may change.
SecurityHow are tenant data, admin access, encryption, logs and vulnerabilities handled?Approve, require remediation or reject based on risk.
SubprocessorsWhich cloud, AI, monitoring and support providers receive data?Map authorization and transfer chain.
IncidentsCan the vendor alert the controller rapidly enough?Contractual escalation shorter than the controller's external regulatory window.
RightsCan the company search, export, correct and delete ticket data?Document process and SLA.
RetentionWhat happens after ticket deletion and contract termination?Map active data, logs, backups and deletion confirmation.
TransferPersonal data moves from Brazil to a U.S. vendor.Select and document an Article 33 mechanism; do not rely on U.S. adequacy.

This example also shows why “SOC 2 certified” or “ISO certified” is not a complete LGPD vendor review. Security evidence is valuable, but it does not answer purpose, role, rights, retention, subprocessors or international transfers.

AI Vendors: Add Five Questions to the Review

AI services create a common role-expansion problem: the customer may intend the provider to process prompts or files only to deliver the service, while the provider's default terms may permit broader model improvement or analytics.

Ask:

  1. Are prompts, files, embeddings or outputs used to train shared models?
  2. Can training/model-improvement use be disabled contractually and technically?
  3. Which subprocessors/model providers receive the data?
  4. How long are prompts, outputs and logs retained?
  5. Can the provider support deletion, rights requests, incidents and location/transfer requirements?

AI does not create a new LGPD legal category by itself. It creates new processing purposes, vendors, recipients, decisions and risks that need to be mapped under the existing framework.

Vendor Rights Support: Do Not Discover the Limitation During a DSAR

Article 18 rights often require action across third-party platforms. If a person asks for correction or deletion and the relevant data sits inside a vendor's system, the controller needs a practical way to implement that request.

During procurement, test whether:

  • records can be searched by appropriate identifiers;
  • data can be exported securely;
  • correction can be applied;
  • data can be deleted or blocked where legally appropriate;
  • derived data/profiles are included where relevant;
  • subprocessors will also receive required downstream action; and
  • the vendor can explain technical limitations before they become a regulatory problem.

See our LGPD Data Subject Rights guide.

Security Due Diligence: What Does Article 46 Change?

Article 46 requires processing agents to adopt technical and administrative measures capable of protecting personal data from unauthorized access and accidental or unlawful destruction, loss, alteration, communication or other improper processing.

The statute does not prescribe one universal security questionnaire or certification. That means vendor security due diligence should be risk-based and tied to the actual data and processing.

Lower risk Limited business contact tool

Basic contact data, low volume, short retention and no privileged access may support a lighter review.

Higher risk Core customer SaaS

Large scale, account data, customer content, credentials and critical availability justify deeper evidence.

Very high risk Biometric / health / children

Sensitive or vulnerable-person processing should trigger more rigorous security, legal and governance review.

Do Operators Have Direct LGPD Liability?

Yes, although the legal responsibilities of controller and operator are not identical.

Article 42 says controllers and operators can be required to repair damage caused through unlawful processing. Article 42(1)(I) provides a specific joint-liability situation for an operator when it violates data-protection law or fails to follow the controller's lawful instructions, subject to Article 43's exclusions.

Article 37 also requires both controller and operator to maintain records of processing operations, especially when processing is based on legitimate interest.

A vendor contract does not erase statutory responsibility. Contractual allocation can clarify responsibilities and remedies between the parties, but the real processing and LGPD duties remain relevant to regulators and data subjects.

Vendor Offboarding: Compliance Does Not End When the Subscription Is Canceled

Many vendor registers are excellent at onboarding and poor at termination. That creates “zombie data”: customer information left inside inactive accounts, backups, exports, test workspaces or old integrations.

Disable integrations and credentialsRevoke API keys, SSO, service accounts, OAuth grants and admin users.
Export what must be retainedMove only data that has a continuing lawful purpose and approved destination.
Request deletion/returnFollow the contract and legal retention logic for active data.
Understand backupsRecord how long deleted customer data persists in backups and under what access restrictions.
Address subprocessorsConfirm downstream deletion/return where applicable.
Preserve compliance evidenceKeep termination, deletion confirmation, exceptions and retention rationale.
Update your ROPA and privacy noticeRemove obsolete vendor flows and disclosures.
Close transfer recordsUpdate the international-transfer inventory when the foreign processing ends.

Your vendor register should connect to the rest of the LGPD program.

Use our 25-point LGPD Compliance Checklist and LGPD for SaaS Companies guide to connect vendor review with data mapping, roles, legal bases, security, rights, incidents and transfers.

Common LGPD Vendor Compliance Mistakes

“The vendor signed our DPA, so due diligence is complete.”

A contract is important but does not prove the vendor has appropriate security, deletion, incident, rights or transfer capabilities.

“Every vendor is our operator.”

Roles depend on the actual processing. Some vendors can be independent controllers for their own purposes, and a single vendor can have mixed roles.

“They have ISO/SOC, so LGPD is covered.”

Certifications can support security due diligence but do not answer all LGPD questions about role, purpose, rights, retention and international transfers.

“We have a list of subprocessors, so we're done.”

You also need the purpose, location, change process, authorization model and relevant flow-down/transfer implications.

“The vendor has 72 hours to tell us about a breach.”

That may be too slow for the controller's Brazilian response workflow. The operator's contractual escalation should preserve the controller's own regulatory clock.

“The vendor is in the U.S., so the data transfer is automatically allowed.”

International processing requires an Article 33 analysis. The United States is not currently listed by ANPD as an adequate destination.

“We deleted the SaaS account, so the data is gone.”

Account closure and data deletion are not always the same event. Review backups, logs, subprocessors and contractual deletion timing.

Turn Vendor Due Diligence Into a Repeatable Compliance Process

The Brazil LGPD Compliance Playbook — 2026 Edition includes a dedicated Vendor Privacy and Security Review and a Data Processing Agreement Checklist, plus the International Transfer Review, Processing Inventory / ROPA, Security Incident Assessment, Retention Schedule, 100-point compliance audit and 30-day implementation roadmap.

Vendor Privacy & Security Review DPA Checklist International Transfer Review 100-point audit
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

Does the LGPD require a DPA with every processor?

The LGPD does not expressly impose a GDPR Article 28-style requirement that every controller and operator sign a specific data-processing agreement. ANPD nevertheless says such contractual definitions are good practice and identifies topics including the object, duration, nature, purpose, data types, rights, obligations and responsibilities.

How do I know whether a vendor is an operator or controller?

Analyze the real processing. The controller determines the purpose and essential elements. An operator processes on the controller's behalf and within its instructions, although it can decide non-essential technical elements. Contract labels are relevant evidence but do not override the actual facts.

Can the same vendor be both controller and operator?

Yes. ANPD says roles are defined per processing operation. A SaaS provider might be an operator for customer content while being controller for separate account administration, security, billing or another purpose it independently determines.

Can an LGPD operator use subprocessors?

Yes. Although the LGPD does not formally define suboperators, ANPD recognizes the concept. ANPD recommends that the operator obtain formal general or specific authorization from the controller before engaging a suboperator.

Who reports a vendor breach to ANPD?

The controller has the legal duty to notify ANPD and affected individuals when the reporting threshold is met. The operator must inform the controller without unjustified delay and provide the information needed for assessment and communication.

Should the DPA use a 72-hour vendor breach deadline?

Not automatically. The controller's ordinary reportable-incident window in Brazil is three business days. The vendor's internal escalation should generally be faster so the controller still has time to investigate, assess risk and prepare any required notification.

Do foreign SaaS vendors need Brazilian SCCs?

Not automatically. The company must identify the applicable Article 33 route for the transfer. Brazilian SCCs are one mechanism under Resolution 19/2024 and must be used without modification when selected. An ANPD adequacy decision may provide another route for an adequate destination.

Is the United States considered adequate under LGPD?

As of the review date, ANPD's official transfer repository lists the European Union as adequate under Resolution No. 32/2026. The United States is not listed as an adequate destination.

What should vendor security due diligence include?

It should be proportionate to risk and can include access control, encryption, logging, vulnerability management, secure development, backups, tenant isolation, incident response, business continuity, certifications, test evidence and remediation of material findings.

What should happen when the vendor contract ends?

Revoke access and integrations, return or delete data according to the lawful retention plan, understand backup persistence, address subprocessors, preserve deletion evidence, update the ROPA/vendor/transfer records and remove outdated public disclosures.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD, ANPD's official controller/operator guide, Resolution CD/ANPD No. 15/2024, Resolution CD/ANPD No. 19/2024 and current official transfer materials available on August 19, 2026. Vendor roles, contractual obligations and international-transfer mechanisms are fact-specific. The ANPD controller/operator guide is non-binding and dates from 2022; current law and later regulations take precedence where applicable. Verify current official sources and obtain qualified Brazilian legal advice for consequential vendor relationships.