LGPD Privacy Policy Requirements Guide
Clym's guide to LGPD privacy policy requirements: legal bases, data subject rights, DPO contact info, international transfer rules, and 2026 ANPD updates.
Clym's guide to LGPD privacy policy requirements: legal bases, data subject rights, DPO contact info, international transfer rules, and 2026 ANPD updates.
Brazil’s Lei Geral de Protecao de Dados (“LGPD”), the country’s data protection law, is one of the most restrictive in the world. Modeled after Europe’s General Data Protection Regulation (“GDPR”), LGPD requires companies to comply with strict requirements related to the collection and processing of Brazilian consumers’ personal data. One of those requirements is that an organization post its privacy policy on its website, below we’ll detail how your organization can comply with this requirement.
The short answer is yes, if your organization is subject to LGPD. One interesting aspect of LGPD is that there is no privacy policy mandate, however a key tenet of LGPD is transparency, so identifying the who, what, where, when, why and how of your data collection, transfer and storage policies, procedures and personnel is a key component of complying with LGPD. A well-drafted privacy policy can enable an organization to properly comply with LGPD.
At a minimum, your privacy policy should:
First, declare that you collect personal data
Second, explain what data you actually collect (e.g. IP address, email address, name, phone number, etc.)
Third, describe the specific purpose of the processing
Fourth, communicate the duration of the processing
LGPD sets out 10 legal grounds for data processing, so you can’t legally collect personal data unless you can justify it under one of these bases:
Individual consent
Performance of a contract with the individual
Public health
Protecting a credit score
Complying with your organization’s legal obligations
The individual’s safety
Performing public statutory duties
Legal proceedings
Research
LGPD provides individuals with 9 specific rights that you need to tell them about, including:
The right to confirmation of the existence of the processing;
The right to access the data;
The right to correct incomplete, inaccurate or out-of-date data;
The right to anonymize, block, or delete unnecessary or excessive data or data that is not being processed in compliance with the LGPD;
The right to the portability of data to another service or product provider, by means of an express request
The right to delete personal data processed with the consent of the data subject;
The right to information about public and private entities with which the controller has shared data;\
The right to information about the possibility of denying consent and the consequences of such denial; and
The right to revoke consent.
As of this writing, we’re not aware that the privacy policy needs to be in any specific language, however LGPD does require that the language used be clear and transparent, so it is likely best to have your privacy policy be in Portuguese for Brazilian visitors.
Unlike California’s CCPA, which imposes a requirement to update your organization’s privacy policy at least every 12 months, there is no such requirement for LGPD.
A privacy policy is the document required to be compliant with LGPD.
With Clym, you can easily manage all your Privacy and other legal documents in multiple languages and versioning. We also give you the ability to embed these documents into pages or sub-domains so if you need to edit them, you only need to do it in one place. All of your policies can be timestamped, and as regulations continue to evolve, you can show your website visitors how your policies have been updated. Watch the video below for more information or click this link to learn more about our Document Management.
While the LGPD does not explicitly state that a privacy policy is mandatory, it does require organizations to clearly and transparently communicate with individuals regarding their data being collected, transferred and stored. A well-drafted privacy policy can accomplish this goal, and mitigate risks associated with noncompliance with LGPD.
Clym believes in striking a balance between legal compliance and business needs, which is why we provide a cost-effective, scalable and flexible platform to comply with LGPD, GDPR, CCPA and other laws, including those in the UK, as they come online. Our platform provides consumers with an effective and easy-to-navigate way to opt-out of data collection while not infringing upon the website UI that businesses rely on to drive revenues. Contact us today about how your company can implement Clym to help manage your data privacy regulation compliance from a global perspective.
Brazil's data protection authority became a full regulatory agency in September 2025, and it now has more enforcement power than at any point since the Lei Geral de Proteção de Dados (LGPD) took effect. If your privacy policy still reads like it was written in 2021, it's overdue for a rewrite.
This guide breaks down exactly what a compliant LGPD privacy policy needs to cover in 2026, from legal bases and data subject rights to the newer transparency obligations around international transfers, children's data, and security incidents. You'll also find a practical structure you can use to build or update your own policy.
Key takeaways
The LGPD never uses the phrase "privacy policy," but its transparency principle makes a clear, published privacy notice effectively mandatory for most organizations.
A compliant policy names your organization, your legal basis for each processing activity, and how to reach your DPO or privacy contact.
Data subjects have nine specific rights under the LGPD, and your policy must explain how people can exercise each one.
New ANPD rules published between 2024 and 2026 add fresh disclosure requirements for international transfers, security incidents, and children's data.
LGPD fines can reach 2 percent of a company's Brazilian revenue, capped at roughly $8.4 million USD per violation.
There's no fixed update schedule for LGPD privacy policies, but you should revise yours whenever your data practices or Brazilian regulations change.
The LGPD is Brazil’s national data protection law. It governs how organizations collect, use, store, and share personal data and is enforced by Brazil’s data protection authority, the ANPD.
The LGPD may apply to your business if you:
This can apply even if your business is headquartered outside Brazil, and the law itself does not provide a general small-business or revenue exemption.
The ANPD’s regulatory role also continues to evolve, with its 2025–2026 agenda addressing areas including AI, biometrics, anonymization, and data subject rights.
For a broader look at LGPD requirements, see Clym’s LGPD compliance overview. Below, we’ll focus specifically on what the LGPD means for your privacy policy.
This is easier to scan because the applicability criteria become the focal point, while the ANPD history and comparison with GDPR don’t overwhelm the introduction.
Does my business need a written privacy policy under the LGPD?
In practice, yes. The LGPD doesn't use the words "privacy policy" the way some US state laws do, but Article 9 establishes a right to "clear and adequate information" about processing, covering the purpose, form, and duration of processing and the identity of the controller. A written, published privacy notice (sometimes called an aviso de privacidade in Brazil) is the standard way organizations meet this transparency obligation.
At minimum, your LGPD privacy policy needs to cover these categories:
Your organization's identity and contact details
The purpose, type, and duration of each processing activity
The legal basis for each processing activity
Data subject rights and how to exercise them
Your DPO or privacy contact information
Data sharing and international transfer disclosures
Your data retention criteria
Your policy should identify the data controller, meaning the organization deciding why and how personal data is processed. Local Brazilian legal practice recommends including your full legal name, tax registry number (CNPJ), and registered address or headquarters city, and clarifying whether multiple entities act as joint controllers.
The LGPD lists ten lawful bases for processing personal data, and your policy should identify which basis applies to each activity you describe, not just list all ten as generic boilerplate.
Legal basis | When it typically applies |
|---|---|
Consent | The data subject has given specific, informed permission for a particular purpose |
Legal obligation | Processing is required to comply with a law or regulation |
Contract performance | Processing is necessary to execute or prepare a contract with the data subject |
Legitimate interest | The controller's or a third party's interest outweighs the data subject's rights, on balance |
Public administration | Processing is carried out by public authorities for public policy execution |
Research | Processing supports studies by a research body, with anonymization where possible |
Contract or judicial process | Processing is needed to exercise rights in a contract, judicial, or administrative proceeding |
Life or physical safety protection | Processing protects the life or physical safety of the data subject or a third party |
Health protection | Processing is carried out by health professionals or entities for health protection |
Credit protection | Processing supports credit protection, including data included in credit-related databases |
"Legitimate interest" is the basis most often misapplied. The ANPD published dedicated guidance clarifying how to document it after seeing companies lean on it as a catch-all rather than a documented, balanced assessment.
The LGPD grants individuals nine specific rights, and your policy needs to explain each one in plain language, not just cite the article number.
Confirmation that processing of their data exists
Access to the data being processed
Correction of incomplete, inaccurate, or outdated data
Anonymization, blocking, or deletion of unnecessary or excessive data
Portability of data to another service or product provider
Deletion of personal data processed with their consent
Information about which public and private entities the controller has shared data with
Information about the option to deny consent and the consequences of doing so
The right to revoke consent at any time
The ANPD reformed its data subject request procedures in 2025 to streamline how these requests get handled, so it's worth confirming your intake process still matches current expectations. Clym's data subject request tools let you log, verify, and track these requests in one place instead of managing them over email.
Article 41 requires you to publish contact details for your encarregado (DPO) or dedicated privacy contact, at minimum a working email address and their title or function. ANPD rules let small-sized processing agents skip a formal DPO appointment, but the obligation to publish some kind of privacy contact channel stays in place regardless of company size.
In August 2024, the ANPD approved a formal framework for international data transfers, covering adequacy decisions, ANPD-approved standard contractual clauses, binding corporate rules, and specific contractual clauses. The transition grace period ended in August 2025, so standard contractual clauses are now mandatory for most cross-border transfers that don't already qualify for an adequacy decision or another approved mechanism.
The biggest recent shift: in January 2026, Brazil and the European Union formalized a mutual adequacy decision, so data can now move between the EU and Brazil largely the way it already moves within the EU, without separate contractual safeguards. If your privacy policy mentions transferring data outside Brazil, and most cloud-hosted businesses do, it should name the mechanism you rely on: adequacy, standard contractual clauses, binding corporate rules, or consent.
Under Article 14, the LGPD defines a "child" as anyone under 12, with adolescents covering ages 12 to 18. Processing a child's data generally requires specific, prominent consent from a parent or legal guardian, not a buried checkbox. Brazil is also tightening this further: new rules extending the Statute of the Child and Adolescent into digital environments are expected to take effect in 2026, adding fresh obligations for apps, games, and social platforms used by minors. If your service is used by anyone under 18, your privacy policy should explain your age-related data practices clearly rather than pointing to a generic terms of service page.
Since April 2024, ANPD rules require organizations to notify both the regulator and affected individuals within three business days of becoming aware of a qualifying security incident, doubled to six business days for small-sized processing agents, and to keep an incident record for five years. Many organizations now add a short paragraph to their privacy policy describing how they'll notify affected users after a breach, even though the LGPD's procedural deadlines technically apply to the regulator relationship rather than the policy text itself.
Administrative sanctions under the LGPD, detailed in Clym's LGPD regulation summary, can reach 2 percent of a company's revenue in Brazil, capped at roughly R$50 million (about $8.4 million USD) per violation, plus public disclosure of the violation and potential suspension of processing activities. A missing or generic privacy policy is one of the easier gaps for the ANPD, or a data subject filing a complaint, to spot.
A privacy policy and a cookie policy cover related but distinct disclosures, and many organizations need both.
Aspect | Privacy policy | Cookie policy |
|---|---|---|
Scope | All personal data processing across your business | Data collected through cookies and similar trackers |
Legal basis | Any of the ten LGPD bases, depending on the activity | Consent almost always required, opt-in, no cookie walls |
Where it lives | Standalone page linked site-wide | Often linked from or embedded in the consent banner |
Update trigger | Any change in how you collect or use personal data | Any change in the tracking technologies you use |
Cookies count as personal data processing under the LGPD when they can identify a device or user, so cookie consent has to be informed, specific, freely given, and revocable, the same standard Brazilian regulators expect for any other collection of personal data. A consent management platform handles the opt-in mechanics, while your privacy and cookie policies handle the written disclosure behind them.
Use this order as a practical framework. It maps directly to the disclosure categories the LGPD's transparency principle expects.
State who you are: legal name, CNPJ, registered address, and a working contact channel
Describe what data you collect and why, by category: identification, contact, behavioral, technical, and sensitive data
Name the legal basis for each processing activity
Explain data sharing: who receives the data and why, including processors, partners, and authorities
Disclose international transfers and the mechanism you rely on
List data subject rights and the exact steps to exercise each one
Publish your DPO or privacy contact information
State your retention criteria and, where relevant, your security measures
Note when the policy was last updated
The LGPD's transparency principle expects information to be clear, and dense legal language undermines that even if every required fact is technically present. Brazil isn't alone in pushing this: Quebec's privacy regulator recently published its own guidance on writing a simple, clear privacy policy, and the underlying advice, short sentences, defined terms, no unnecessary jargon, applies just as well to an LGPD notice.
The LGPD doesn't specify a mandatory policy language, but its transparency principle requires the information to be clear and accessible to the people it protects. In practice, that means Portuguese for a Brazilian audience. If your business serves Brazilian users, publish your privacy policy in Portuguese in addition to any other languages your global policy already covers, and keep the translated version synchronized whenever you update the original.
Teams managing this manually often let translations drift out of sync after an update. Clym's policy management tools support translations across 23 languages with synchronized version control, so your Portuguese policy doesn't lag behind the English one.
Unlike the CCPA, which requires an update at least every 12 months, the LGPD sets no fixed update schedule for privacy policies. Update yours whenever your data practices change (a new vendor, a new use of AI, a new region) or when the ANPD issues new binding rules, such as the international transfer and security incident regulations that took effect between 2024 and 2026. As a practical minimum, review your policy at least once a year even if nothing else has changed, so the "last updated" date reflects an actively maintained document.
Copying a GDPR policy without adjusting it: GDPR's six legal bases and 72-hour breach window don't map one-to-one onto the LGPD's ten bases and three-business-day incident notification rule
Leaving out DPO or privacy contact details: Article 41 makes this mandatory, not optional
Ignoring Portuguese-language readers: an English-only policy doesn't meet the transparency bar for a Brazilian audience
Failing to mention international transfers: if your data ever leaves Brazil, your policy needs to name the transfer mechanism
Treating children's data like adult data: under-12 processing needs specific, prominent guardian consent, not a buried checkbox
Publishing it once and forgetting it: an unmaintained policy is itself a transparency gap
Clym's policies solution lets you generate a first draft through a guided questionnaire, configure it for LGPD alongside any other regulation your business needs to support, and manage translated versions with full version history, so you can show exactly what your policy said on any given date. Combined with the consent and data subject request tools covered above, you get one governance record instead of policies, consent logs, and request trackers living in separate systems. We don't promise a specific compliance outcome. We provide the infrastructure to support your privacy program as LGPD and ANPD rules continue to evolve.
An LGPD privacy policy is really a transparency document dressed up as boilerplate, and Brazil's regulators are paying closer attention to the substance behind it now that the ANPD operates with the authority of a full regulatory agency. Getting the basics right, clear language, a real legal basis for every activity, an accessible way to reach your DPO, and honest disclosure of where data actually goes, covers most of what the law expects.
The parts that trip companies up are usually the newer pieces: international transfer mechanisms, breach notification timing, and children's data, all of which changed meaningfully between 2024 and 2026. None of this requires reinventing your privacy program from scratch. It requires updating the document to match what you're already doing, and keeping it current as the rules keep moving.
LGPD stands for Lei Geral de Proteção de Dados, Brazil's General Data Protection Law. It has been in force since September 2020 and is enforced by the ANPD, Brazil's national data protection authority, which became a full regulatory agency in September 2025.
The LGPD doesn't use the exact phrase "privacy policy," but its transparency principle requires clear, accessible information about your data processing. A published privacy policy is the standard way organizations meet that requirement, making one effectively necessary for most businesses in scope.
They cover similar ground, but the LGPD has ten legal bases for processing instead of GDPR's six, a three-business-day security incident notification window instead of 72 hours, and lower maximum fines. A GDPR-only policy usually needs LGPD-specific edits, not a wholesale rewrite.
The ANPD can issue administrative sanctions, including fines of up to 2 percent of your Brazilian revenue capped at roughly R$50 million per violation, public disclosure of the violation, and restrictions on your data processing activities.
Not necessarily. ANPD rules allow small-sized processing agents to skip a formal DPO appointment, but you still need to publish some form of privacy contact information, at minimum an email address and a title or function, in your policy.