Quick Answer: What should you check before giving an LGPD processor access to personal data?
First determine the vendor's actual role for each processing activity: controller, operator, or potentially a different role for different purposes. If the vendor is an operator, document the controller's instructions, permitted purpose, data categories, security expectations, retention/deletion, incident escalation, data-subject-rights support, subprocessors and international transfers. The LGPD does not expressly require a GDPR Article 28-style DPA in every controller–operator relationship, but ANPD says a processing contract is good practice and identifies core subjects that can be defined contractually. If data is transferred from Brazil to a foreign vendor, separately identify a valid Article 33 transfer mechanism under the current Resolution No. 19/2024 framework.
Key Takeaways
- Role follows facts, not labels. Calling a vendor “processor” in a contract does not make it an operator if it decides its own purposes and essential elements.
- The same vendor can have different roles. ANPD says agent roles are determined per processing operation.
- A DPA is strongly useful even though the LGPD does not expressly mandate a GDPR-style processor contract in every case.
- Subprocessors need visibility. ANPD recommends formal controller authorization—general or specific—before an operator appoints a suboperator.
- Incident timing must be contractualized. The operator must inform the controller without unjustified delay, while the controller may face a three-business-day notification window for reportable incidents.
- International transfers are a separate legal layer. A vendor contract alone is not necessarily the Article 33 transfer mechanism.
- Vendor review should be risk-based. A newsletter tool and a biometric identity provider should not receive identical due diligence.
Vendor risk under the LGPD begins before the contract is signed. A controller that does not know what a provider will collect, where it will process the data, whether it will reuse the data for its own purposes, which subprocessors it uses or how quickly it will escalate an incident cannot meaningfully instruct or supervise the relationship.
Article 39 says an operator must process according to the controller's instructions and the controller must verify compliance with its instructions and the applicable rules. Article 46 requires processing agents to adopt technical and administrative security measures. Articles 37 and 42 also give operators direct legal significance through processing-record and liability rules.
Step One: Is the Vendor Actually an Operator?
Defines the purpose and other essential elements of the relevant processing activity.
Acts within the controller's purpose and instructions, while it may decide non-essential technical elements.
A vendor can be an operator for customer data and a controller for separate account, security, billing or independent product purposes.
ANPD's controller/operator guide says the same organization can be a controller in one processing operation and an operator in another. It also emphasizes that the controller is identified by the principal decisions over purpose and essential elements, while an operator acts on the controller's behalf and can determine non-essential elements such as some technical measures.
Questions that expose the real role
- Who decided why the data is being processed?
- Who determines the essential data categories and affected people?
- Who determines how long the processing should continue?
- Can the vendor independently reuse customer data for product improvement, advertising, profiling or model training?
- Can the customer meaningfully instruct the vendor to delete, return, correct or restrict the data?
- Does the vendor merely select technical implementation details, or does it decide a new purpose?
The fifth question is particularly important for modern SaaS and AI services. A provider can be an operator for one workflow while acting as controller for a separate purpose that it determines independently. The contract and privacy notice should not hide that distinction.
What about payment providers?
ANPD's 2022 guide includes an e-commerce example in which the online sales channel is controller and the different payment services are operators. That is useful guidance for the scenario described by ANPD, but vendor classification remains functional and fact-specific. A real payment provider may have independent statutory, fraud, anti-money-laundering, network or account purposes that require a separate role analysis.
The safest editorial and compliance rule is: use ANPD examples as guidance, not as universal role labels for every commercial arrangement.
Does the LGPD Require a Data Processing Agreement?
This is a common question from companies familiar with GDPR Article 28.
ANPD's official guide states that the LGPD does not expressly require the controller and operator to sign a contract specifically governing personal-data processing. The same guide says such a contractual arrangement is a good practice because it can:
- limit the operator's scope of activity;
- set objective parameters for allocation of responsibilities; and
- reduce risks and uncertainty in the processing operation.
ANPD identifies contractual topics including the object, duration, nature and purpose of processing, types of personal data, and the rights, obligations and responsibilities related to LGPD compliance.
The absence of an express GDPR-style contract mandate does not eliminate Article 39: the operator must follow the controller's instructions and the controller must verify compliance. A written DPA or equivalent contractual schedule is one of the most practical ways to make those instructions and responsibilities provable.
What should an LGPD DPA cover?
The following structure goes beyond ANPD's short illustrative list and represents a practical vendor-governance framework derived from the LGPD's operational obligations:
| Contract topic | What to define | Why it matters |
|---|---|---|
| Scope & purpose | Services, processing activities, purpose and controller instructions. | Prevents unauthorized reuse or purpose expansion. |
| Data & subjects | Categories of personal data and affected groups. | Supports risk, rights and security analysis. |
| Duration | Processing period, retention and deletion/return triggers. | Connects the vendor to the controller's retention logic. |
| Security | Appropriate technical and administrative measures, access, encryption, logging, testing and change management as relevant. | Supports Article 46 and vendor-risk evidence. |
| Confidentiality | Authorized personnel and confidentiality obligations. | Reduces internal/vendor exposure. |
| Subprocessors | Authorization model, notice of changes and flow-down requirements. | Preserves visibility into the processing chain. |
| Incidents | Immediate/rapid escalation, required facts, updates, cooperation and evidence. | Protects the controller's regulatory response window. |
| Data-subject rights | Search, access, correction, deletion, blocking, export and routing support. | The controller must be able to operationalize Article 18 rights. |
| International transfers | Locations, remote access, subprocessors, Article 33 mechanism and change notification. | Separates vendor engagement from the transfer-law layer. |
| Audit & evidence | Certifications, reports, questionnaires, remediation evidence or contractual audit rights proportionate to risk. | Supports the controller's verification responsibility. |
| End of service | Return/deletion, account closure, backup lifecycle and confirmation. | Prevents indefinite residual processing after termination. |
A 15-Point LGPD Vendor Privacy and Security Review
Define the Business Use Case
State what the vendor will do and why personal data is needed. A vendor cannot be meaningfully reviewed if procurement cannot describe the actual processing.
Classify the Vendor's Role
Determine controller/operator status per purpose. Record any mixed-role or independent-use scenario.
Map the Personal Data
Identify ordinary data, sensitive data, children's data, authentication data, payment data, customer content and other relevant categories.
Confirm the Instructions and Permitted Purposes
Check whether the vendor can use the data only to deliver the contracted service or also for its own analytics, advertising, benchmarking, AI/model improvement or other purposes.
Assess Security Controls
Review controls proportionate to the risk: identity/access management, privileged access, encryption, vulnerability management, logging, backups, secure development, tenant separation, malware/ransomware controls, incident response and business continuity.
Check Personnel Access and Confidentiality
Determine who at the vendor can access the data, why, under what authorization and with what logging and confidentiality safeguards.
Map Subprocessors
Identify cloud infrastructure, support, monitoring, AI, email, analytics and other downstream providers involved in the service.
Review Incident Escalation
Define how fast the vendor must tell you about a personal-data incident and which facts it must provide immediately and in later updates.
Test Data Subject Rights Support
Can the vendor locate, export, correct, delete, block or otherwise act on data when the controller needs to answer a rights request?
Check Retention and Deletion
Understand active-system retention, backups, logs, legal holds, deleted accounts and how long residual copies remain.
Map International Transfers and Remote Access
Record data-hosting countries, support locations, remote administrator access and subprocessor countries. Then determine the applicable Article 33 transfer mechanism.
Review Business Continuity and Availability
Availability can be a personal-data security issue. Understand recovery, backup, redundancy, ransomware response and service continuity for critical vendors.
Evaluate Regulatory and Contractual Red Flags
Look for unresolved material security findings, refusal to explain data use, impossible deletion claims, silent subprocessor changes, undisclosed international processing or terms that allow broad independent reuse.
Assign a Vendor Risk Tier
Do not review every vendor identically. Higher tiers can reflect sensitive data, children, large scale, critical availability, AI profiling, credentials, financial data, biometric data or broad international chains.
Document Approval, Conditions and Reassessment
Approval should identify unresolved conditions and triggers for reassessment: new subprocessors, security incidents, product/AI changes, new countries, material contract changes or new data categories.
A Practical Vendor Decision
- Approve: role, security, contract, transfer and operational controls are proportionate to the risk.
- Approve with conditions: remediation or contractual changes must be completed before or shortly after launch.
- Escalate: high-risk data, unclear role, sensitive data, AI reuse, weak incident terms or complex transfers need specialist review.
- Reject: the vendor cannot support the controller's legal obligations or presents risk that cannot reasonably be reduced.
Subprocessors Under the LGPD
The LGPD formally defines controller and operator, but not “suboperator.” ANPD's guide nevertheless recognizes the concept as useful for complex processing chains.
In ANPD's framework, a suboperator is engaged by the operator to help process personal data on behalf of the controller. The suboperator's direct contractual relationship is with the operator, but depending on the facts, both can perform operator functions and can be accountable before ANPD.
ANPD recommends that an operator obtain formal authorization—general or specific—from the controller before engaging a suboperator. That authorization can be included in the controller–operator contract.
General vs specific authorization
ANPD's guide gives a useful distinction: general authorization might permit a category of technical subcontracting such as cloud storage, while specific authorization may identify a particular organization for a defined purpose.
A practical modern contract can combine general authorization with:
- a public or contractual subprocessor list;
- advance notice of material changes;
- a process for legitimate objections where appropriate;
- flow-down of incident/security/deletion obligations; and
- current transfer documentation for foreign subprocessors.
Vendor Data Breaches: Your Contract Must Beat the Regulatory Clock
ANPD's current incident guidance is clear: the controller has the legal duty to notify ANPD and affected data subjects when a confirmed personal-data incident can cause relevant risk or damage.
The operator must inform the controller without unjustified delay and provide the information needed for the controller's risk assessment and communication.
The ordinary controller notification period under Resolution 15/2024 is three business days for reportable incidents. That creates an obvious procurement problem: a vendor term promising notice “within 72 hours after final confirmation” can consume much of the controller's own decision window.
ANPD expressly recommends establishing controller–operator incident-notification obligations in contract so the process can be accelerated and risks to individuals reduced.
What incident information should the vendor provide?
See our full guide: LGPD Data Breach Notification: When and How Companies Must Respond.
Foreign Vendors and International Data Transfers
A cloud or SaaS vendor outside Brazil can create an international-transfer analysis when personal data is transferred from an exporter to an importer abroad. Remote support or downstream subprocessors may create additional paths.
Resolution CD/ANPD No. 19/2024 regulates mechanisms including:
- adequacy decisions;
- Brazilian Standard Contractual Clauses;
- equivalent standard clauses recognized by ANPD;
- specific contractual clauses approved by ANPD; and
- binding corporate rules approved by ANPD.
ANPD's current repository says the European Union is currently recognized as adequate through Resolution No. 32/2026. It also says that, as of the current official page, no equivalent SCCs, specific contractual clauses or binding corporate rules have yet been approved in the repository.
The United States is not currently listed as an adequate destination by ANPD. A company using a U.S. SaaS provider therefore should not write “the U.S. is adequate” or assume a GDPR adequacy decision made by another authority automatically works for Brazil. ANPD expressly says adequacy decisions issued by other countries are not valid for Brazil.
Brazilian Standard Contractual Clauses
When Brazilian SCCs are the selected mechanism, ANPD says they must be incorporated without modification. Resolution 19/2024 originally gave a 12-month implementation period after publication; that implementation date has already passed.
For the complete transfer analysis, see LGPD International Data Transfers: A Practical Guide for Global Businesses.
Example: Reviewing a U.S. SaaS Vendor
Imagine a Brazilian-facing company wants to use a U.S. customer-support SaaS. The platform will receive customer names, email addresses, support messages and attachments.
| Review area | Question | Potential outcome |
|---|---|---|
| Role | Does the SaaS use support content only under customer instructions? | Operator for support content; separate analysis for its own billing/security/product purposes. |
| AI | Are tickets used to train shared models or improve the vendor's product independently? | If yes, role/purpose/legal-basis/transparency analysis may change. |
| Security | How are tenant data, admin access, encryption, logs and vulnerabilities handled? | Approve, require remediation or reject based on risk. |
| Subprocessors | Which cloud, AI, monitoring and support providers receive data? | Map authorization and transfer chain. |
| Incidents | Can the vendor alert the controller rapidly enough? | Contractual escalation shorter than the controller's external regulatory window. |
| Rights | Can the company search, export, correct and delete ticket data? | Document process and SLA. |
| Retention | What happens after ticket deletion and contract termination? | Map active data, logs, backups and deletion confirmation. |
| Transfer | Personal data moves from Brazil to a U.S. vendor. | Select and document an Article 33 mechanism; do not rely on U.S. adequacy. |
This example also shows why “SOC 2 certified” or “ISO certified” is not a complete LGPD vendor review. Security evidence is valuable, but it does not answer purpose, role, rights, retention, subprocessors or international transfers.
AI Vendors: Add Five Questions to the Review
AI services create a common role-expansion problem: the customer may intend the provider to process prompts or files only to deliver the service, while the provider's default terms may permit broader model improvement or analytics.
Ask:
- Are prompts, files, embeddings or outputs used to train shared models?
- Can training/model-improvement use be disabled contractually and technically?
- Which subprocessors/model providers receive the data?
- How long are prompts, outputs and logs retained?
- Can the provider support deletion, rights requests, incidents and location/transfer requirements?
AI does not create a new LGPD legal category by itself. It creates new processing purposes, vendors, recipients, decisions and risks that need to be mapped under the existing framework.
Vendor Rights Support: Do Not Discover the Limitation During a DSAR
Article 18 rights often require action across third-party platforms. If a person asks for correction or deletion and the relevant data sits inside a vendor's system, the controller needs a practical way to implement that request.
During procurement, test whether:
- records can be searched by appropriate identifiers;
- data can be exported securely;
- correction can be applied;
- data can be deleted or blocked where legally appropriate;
- derived data/profiles are included where relevant;
- subprocessors will also receive required downstream action; and
- the vendor can explain technical limitations before they become a regulatory problem.
See our LGPD Data Subject Rights guide.
Security Due Diligence: What Does Article 46 Change?
Article 46 requires processing agents to adopt technical and administrative measures capable of protecting personal data from unauthorized access and accidental or unlawful destruction, loss, alteration, communication or other improper processing.
The statute does not prescribe one universal security questionnaire or certification. That means vendor security due diligence should be risk-based and tied to the actual data and processing.
Basic contact data, low volume, short retention and no privileged access may support a lighter review.
Large scale, account data, customer content, credentials and critical availability justify deeper evidence.
Sensitive or vulnerable-person processing should trigger more rigorous security, legal and governance review.
Do Operators Have Direct LGPD Liability?
Yes, although the legal responsibilities of controller and operator are not identical.
Article 42 says controllers and operators can be required to repair damage caused through unlawful processing. Article 42(1)(I) provides a specific joint-liability situation for an operator when it violates data-protection law or fails to follow the controller's lawful instructions, subject to Article 43's exclusions.
Article 37 also requires both controller and operator to maintain records of processing operations, especially when processing is based on legitimate interest.
Vendor Offboarding: Compliance Does Not End When the Subscription Is Canceled
Many vendor registers are excellent at onboarding and poor at termination. That creates “zombie data”: customer information left inside inactive accounts, backups, exports, test workspaces or old integrations.
Your vendor register should connect to the rest of the LGPD program.
Use our 25-point LGPD Compliance Checklist and LGPD for SaaS Companies guide to connect vendor review with data mapping, roles, legal bases, security, rights, incidents and transfers.
Common LGPD Vendor Compliance Mistakes
“The vendor signed our DPA, so due diligence is complete.”
A contract is important but does not prove the vendor has appropriate security, deletion, incident, rights or transfer capabilities.
“Every vendor is our operator.”
Roles depend on the actual processing. Some vendors can be independent controllers for their own purposes, and a single vendor can have mixed roles.
“They have ISO/SOC, so LGPD is covered.”
Certifications can support security due diligence but do not answer all LGPD questions about role, purpose, rights, retention and international transfers.
“We have a list of subprocessors, so we're done.”
You also need the purpose, location, change process, authorization model and relevant flow-down/transfer implications.
“The vendor has 72 hours to tell us about a breach.”
That may be too slow for the controller's Brazilian response workflow. The operator's contractual escalation should preserve the controller's own regulatory clock.
“The vendor is in the U.S., so the data transfer is automatically allowed.”
International processing requires an Article 33 analysis. The United States is not currently listed by ANPD as an adequate destination.
“We deleted the SaaS account, so the data is gone.”
Account closure and data deletion are not always the same event. Review backups, logs, subprocessors and contractual deletion timing.
Turn Vendor Due Diligence Into a Repeatable Compliance Process
The Brazil LGPD Compliance Playbook — 2026 Edition includes a dedicated Vendor Privacy and Security Review and a Data Processing Agreement Checklist, plus the International Transfer Review, Processing Inventory / ROPA, Security Incident Assessment, Retention Schedule, 100-point compliance audit and 30-day implementation roadmap.
Frequently Asked Questions
Does the LGPD require a DPA with every processor?
The LGPD does not expressly impose a GDPR Article 28-style requirement that every controller and operator sign a specific data-processing agreement. ANPD nevertheless says such contractual definitions are good practice and identifies topics including the object, duration, nature, purpose, data types, rights, obligations and responsibilities.
How do I know whether a vendor is an operator or controller?
Analyze the real processing. The controller determines the purpose and essential elements. An operator processes on the controller's behalf and within its instructions, although it can decide non-essential technical elements. Contract labels are relevant evidence but do not override the actual facts.
Can the same vendor be both controller and operator?
Yes. ANPD says roles are defined per processing operation. A SaaS provider might be an operator for customer content while being controller for separate account administration, security, billing or another purpose it independently determines.
Can an LGPD operator use subprocessors?
Yes. Although the LGPD does not formally define suboperators, ANPD recognizes the concept. ANPD recommends that the operator obtain formal general or specific authorization from the controller before engaging a suboperator.
Who reports a vendor breach to ANPD?
The controller has the legal duty to notify ANPD and affected individuals when the reporting threshold is met. The operator must inform the controller without unjustified delay and provide the information needed for assessment and communication.
Should the DPA use a 72-hour vendor breach deadline?
Not automatically. The controller's ordinary reportable-incident window in Brazil is three business days. The vendor's internal escalation should generally be faster so the controller still has time to investigate, assess risk and prepare any required notification.
Do foreign SaaS vendors need Brazilian SCCs?
Not automatically. The company must identify the applicable Article 33 route for the transfer. Brazilian SCCs are one mechanism under Resolution 19/2024 and must be used without modification when selected. An ANPD adequacy decision may provide another route for an adequate destination.
Is the United States considered adequate under LGPD?
As of the review date, ANPD's official transfer repository lists the European Union as adequate under Resolution No. 32/2026. The United States is not listed as an adequate destination.
What should vendor security due diligence include?
It should be proportionate to risk and can include access control, encryption, logging, vulnerability management, secure development, backups, tenant isolation, incident response, business continuity, certifications, test evidence and remediation of material findings.
What should happen when the vendor contract ends?
Revoke access and integrations, return or delete data according to the lawful retention plan, understand backup persistence, address subprocessors, preserve deletion evidence, update the ROPA/vendor/transfer records and remove outdated public disclosures.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary source for controller/operator definitions, Articles 37, 39, 42–46, security, records and liability.
- ANPD — Guide to Controllers, Operators and the Encarregado, Version 2.0 Official non-binding guidance used for role analysis, contracts, operator responsibilities, DPA topics and the suboperator concept/authorization.
- ANPD — International Data Transfers Current official framework for Resolution 19/2024, Brazilian SCCs, adequacy, equivalent/specific clauses and binding corporate rules.
- ANPD — Security Incident Communication Current official guidance for controller notification, operator escalation without unjustified delay, three-business-day timing and contractual incident duties.
- ANPD — Current Regulations Official index confirming the current status of Resolution 15/2024 and Resolution 19/2024.