Clym Logo

LGPD Privacy Policy Requirements: A Complete Guide for 2026

Published
Updated
AS
AuthorAdam Safar
10 min read

LGPD Privacy Policy Requirements Guide

Clym's guide to LGPD privacy policy requirements: legal bases, data subject rights, DPO contact info, international transfer rules, and 2026 ANPD updates.

Summarize full article with:

Brazil’s Lei Geral de Protecao de Dados (“LGPD”), the country’s data protection law, is one of the most restrictive in the world. Modeled after Europe’s General Data Protection Regulation (“GDPR”), LGPD requires companies to comply with strict requirements related to the collection and processing of Brazilian consumers’ personal data. One of those requirements is that an organization post its privacy policy on its website, below we’ll detail how your organization can comply with this requirement.

Does my company need a privacy policy?

The short answer is yes, if your organization is subject to LGPD. One interesting aspect of LGPD is that there is no privacy policy mandate, however a key tenet of LGPD is transparency, so identifying the who, what, where, when, why and how of your data collection, transfer and storage policies, procedures and personnel is a key component of complying with LGPD. A well-drafted privacy policy can enable an organization to properly comply with LGPD.

What should I include in my privacy policy?

At a minimum, your privacy policy should:

  1. Be transparent about the personal data you collect
  • First, declare that you collect personal data

  • Second, explain what data you actually collect (e.g. IP address, email address, name, phone number, etc.)

  • Third, describe the specific purpose of the processing

  • Fourth, communicate the duration of the processing

  1. Provide the justification and reasons for collecting that data
  • LGPD sets out 10 legal grounds for data processing, so you can’t legally collect personal data unless you can justify it under one of these bases:

    • Individual consent

    • Performance of a contract with the individual

    • Legitimate interest

    • Public health

    • Protecting a credit score

    • Complying with your organization’s legal obligations

    • The individual’s safety

    • Performing public statutory duties

    • Legal proceedings

    • Research

  1. Inform individuals of their rights pursuant to LGPD
  • LGPD provides individuals with 9 specific rights that you need to tell them about, including:

    • The right to confirmation of the existence of the processing;

    • The right to access the data;

    • The right to correct incomplete, inaccurate or out-of-date data;

    • The right to anonymize, block, or delete unnecessary or excessive data or data that is not being processed in compliance with the LGPD;

    • The right to the portability of data to another service or product provider, by means of an express request

    • The right to delete personal data processed with the consent of the data subject;

    • The right to information about public and private entities with which the controller has shared data;\

    • The right to information about the possibility of denying consent and the consequences of such denial; and

    • The right to revoke consent.

  1. Communicate how individuals can contact your organization to exercise their rights
  • You need to provide at least one way for an individual to contact you about their personal data (e.g. email, phone, mail or other).

Do I need my LGPD policies in different languages?

As of this writing, we’re not aware that the privacy policy needs to be in any specific language, however LGPD does require that the language used be clear and transparent, so it is likely best to have your privacy policy be in Portuguese for Brazilian visitors.

How often do I need to update my LGPD policies?

Unlike California’s CCPA, which imposes a requirement to update your organization’s privacy policy at least every 12 months, there is no such requirement for LGPD.

What documents do I need in order to be compliant with LGPD?

A privacy policy is the document required to be compliant with LGPD.

How to add a Privacy Policy to my website?

With Clym, you can easily manage all your Privacy and other legal documents in multiple languages and versioning. We also give you the ability to embed these documents into pages or sub-domains so if you need to edit them, you only need to do it in one place. All of your policies can be timestamped, and as regulations continue to evolve, you can show your website visitors how your policies have been updated. Watch the video below for more information or click this link to learn more about our Document Management.

Key takeaways

While the LGPD does not explicitly state that a privacy policy is mandatory, it does require organizations to clearly and transparently communicate with individuals regarding their data being collected, transferred and stored. A well-drafted privacy policy can accomplish this goal, and mitigate risks associated with noncompliance with LGPD.

How can Clym help?

Clym believes in striking a balance between legal compliance and business needs, which is why we provide a cost-effective, scalable and flexible platform to comply with LGPD, GDPR, CCPA and other laws, including those in the UK, as they come online. Our platform provides consumers with an effective and easy-to-navigate way to opt-out of data collection while not infringing upon the website UI that businesses rely on to drive revenues. Contact us today about how your company can implement Clym to help manage your data privacy regulation compliance from a global perspective.

Brazil's data protection authority became a full regulatory agency in September 2025, and it now has more enforcement power than at any point since the Lei Geral de Proteção de Dados (LGPD) took effect. If your privacy policy still reads like it was written in 2021, it's overdue for a rewrite.

This guide breaks down exactly what a compliant LGPD privacy policy needs to cover in 2026, from legal bases and data subject rights to the newer transparency obligations around international transfers, children's data, and security incidents. You'll also find a practical structure you can use to build or update your own policy.

Key takeaways

  • The LGPD never uses the phrase "privacy policy," but its transparency principle makes a clear, published privacy notice effectively mandatory for most organizations.

  • A compliant policy names your organization, your legal basis for each processing activity, and how to reach your DPO or privacy contact.

  • Data subjects have nine specific rights under the LGPD, and your policy must explain how people can exercise each one.

  • New ANPD rules published between 2024 and 2026 add fresh disclosure requirements for international transfers, security incidents, and children's data.

  • LGPD fines can reach 2 percent of a company's Brazilian revenue, capped at roughly $8.4 million USD per violation.

  • There's no fixed update schedule for LGPD privacy policies, but you should revise yours whenever your data practices or Brazilian regulations change.

What is the LGPD, and does it apply to your business?

The LGPD is Brazil’s national data protection law. It governs how organizations collect, use, store, and share personal data and is enforced by Brazil’s data protection authority, the ANPD.

The LGPD may apply to your business if you:

  • Process personal data in Brazil
  • Offer goods or services to people in Brazil
  • Collect personal data from individuals located in Brazil

This can apply even if your business is headquartered outside Brazil, and the law itself does not provide a general small-business or revenue exemption.

The ANPD’s regulatory role also continues to evolve, with its 2025–2026 agenda addressing areas including AI, biometrics, anonymization, and data subject rights.

For a broader look at LGPD requirements, see Clym’s LGPD compliance overview. Below, we’ll focus specifically on what the LGPD means for your privacy policy.

This is easier to scan because the applicability criteria become the focal point, while the ANPD history and comparison with GDPR don’t overwhelm the introduction.

Does my business need a written privacy policy under the LGPD?

In practice, yes. The LGPD doesn't use the words "privacy policy" the way some US state laws do, but Article 9 establishes a right to "clear and adequate information" about processing, covering the purpose, form, and duration of processing and the identity of the controller. A written, published privacy notice (sometimes called an aviso de privacidade in Brazil) is the standard way organizations meet this transparency obligation.

What must an LGPD privacy policy include?

At minimum, your LGPD privacy policy needs to cover these categories:

  • Your organization's identity and contact details

  • The purpose, type, and duration of each processing activity

  • The legal basis for each processing activity

  • Data subject rights and how to exercise them

  • Your DPO or privacy contact information

  • Data sharing and international transfer disclosures

  • Your data retention criteria

Controller identity and contact details

Your policy should identify the data controller, meaning the organization deciding why and how personal data is processed. Local Brazilian legal practice recommends including your full legal name, tax registry number (CNPJ), and registered address or headquarters city, and clarifying whether multiple entities act as joint controllers.

Purpose and legal basis for each processing activity

The LGPD lists ten lawful bases for processing personal data, and your policy should identify which basis applies to each activity you describe, not just list all ten as generic boilerplate.

Legal basis

When it typically applies

Consent

The data subject has given specific, informed permission for a particular purpose

Legal obligation

Processing is required to comply with a law or regulation

Contract performance

Processing is necessary to execute or prepare a contract with the data subject

Legitimate interest

The controller's or a third party's interest outweighs the data subject's rights, on balance

Public administration

Processing is carried out by public authorities for public policy execution

Research

Processing supports studies by a research body, with anonymization where possible

Contract or judicial process

Processing is needed to exercise rights in a contract, judicial, or administrative proceeding

Life or physical safety protection

Processing protects the life or physical safety of the data subject or a third party

Health protection

Processing is carried out by health professionals or entities for health protection

Credit protection

Processing supports credit protection, including data included in credit-related databases

"Legitimate interest" is the basis most often misapplied. The ANPD published dedicated guidance clarifying how to document it after seeing companies lean on it as a catch-all rather than a documented, balanced assessment.

Data subject rights under the LGPD

The LGPD grants individuals nine specific rights, and your policy needs to explain each one in plain language, not just cite the article number.

  • Confirmation that processing of their data exists

  • Access to the data being processed

  • Correction of incomplete, inaccurate, or outdated data

  • Anonymization, blocking, or deletion of unnecessary or excessive data

  • Portability of data to another service or product provider

  • Deletion of personal data processed with their consent

  • Information about which public and private entities the controller has shared data with

  • Information about the option to deny consent and the consequences of doing so

  • The right to revoke consent at any time

The ANPD reformed its data subject request procedures in 2025 to streamline how these requests get handled, so it's worth confirming your intake process still matches current expectations. Clym's data subject request tools let you log, verify, and track these requests in one place instead of managing them over email.

DPO or privacy contact information

Article 41 requires you to publish contact details for your encarregado (DPO) or dedicated privacy contact, at minimum a working email address and their title or function. ANPD rules let small-sized processing agents skip a formal DPO appointment, but the obligation to publish some kind of privacy contact channel stays in place regardless of company size.

International data transfer disclosures

In August 2024, the ANPD approved a formal framework for international data transfers, covering adequacy decisions, ANPD-approved standard contractual clauses, binding corporate rules, and specific contractual clauses. The transition grace period ended in August 2025, so standard contractual clauses are now mandatory for most cross-border transfers that don't already qualify for an adequacy decision or another approved mechanism.

The biggest recent shift: in January 2026, Brazil and the European Union formalized a mutual adequacy decision, so data can now move between the EU and Brazil largely the way it already moves within the EU, without separate contractual safeguards. If your privacy policy mentions transferring data outside Brazil, and most cloud-hosted businesses do, it should name the mechanism you rely on: adequacy, standard contractual clauses, binding corporate rules, or consent.

Children's and adolescents' data

Under Article 14, the LGPD defines a "child" as anyone under 12, with adolescents covering ages 12 to 18. Processing a child's data generally requires specific, prominent consent from a parent or legal guardian, not a buried checkbox. Brazil is also tightening this further: new rules extending the Statute of the Child and Adolescent into digital environments are expected to take effect in 2026, adding fresh obligations for apps, games, and social platforms used by minors. If your service is used by anyone under 18, your privacy policy should explain your age-related data practices clearly rather than pointing to a generic terms of service page.

Security incident and breach notification disclosures

Since April 2024, ANPD rules require organizations to notify both the regulator and affected individuals within three business days of becoming aware of a qualifying security incident, doubled to six business days for small-sized processing agents, and to keep an incident record for five years. Many organizations now add a short paragraph to their privacy policy describing how they'll notify affected users after a breach, even though the LGPD's procedural deadlines technically apply to the regulator relationship rather than the policy text itself.

What happens if your privacy policy is missing or incomplete?

Administrative sanctions under the LGPD, detailed in Clym's LGPD regulation summary, can reach 2 percent of a company's revenue in Brazil, capped at roughly R$50 million (about $8.4 million USD) per violation, plus public disclosure of the violation and potential suspension of processing activities. A missing or generic privacy policy is one of the easier gaps for the ANPD, or a data subject filing a complaint, to spot.

LGPD privacy policy vs. cookie policy: what's the difference?

A privacy policy and a cookie policy cover related but distinct disclosures, and many organizations need both.

Aspect

Privacy policy

Cookie policy

Scope

All personal data processing across your business

Data collected through cookies and similar trackers

Legal basis

Any of the ten LGPD bases, depending on the activity

Consent almost always required, opt-in, no cookie walls

Where it lives

Standalone page linked site-wide

Often linked from or embedded in the consent banner

Update trigger

Any change in how you collect or use personal data

Any change in the tracking technologies you use

Cookies count as personal data processing under the LGPD when they can identify a device or user, so cookie consent has to be informed, specific, freely given, and revocable, the same standard Brazilian regulators expect for any other collection of personal data. A consent management platform handles the opt-in mechanics, while your privacy and cookie policies handle the written disclosure behind them.

How to structure your LGPD privacy policy

Use this order as a practical framework. It maps directly to the disclosure categories the LGPD's transparency principle expects.

  1. State who you are: legal name, CNPJ, registered address, and a working contact channel

  2. Describe what data you collect and why, by category: identification, contact, behavioral, technical, and sensitive data

  3. Name the legal basis for each processing activity

  4. Explain data sharing: who receives the data and why, including processors, partners, and authorities

  5. Disclose international transfers and the mechanism you rely on

  6. List data subject rights and the exact steps to exercise each one

  7. Publish your DPO or privacy contact information

  8. State your retention criteria and, where relevant, your security measures

  9. Note when the policy was last updated

Write it in plain language

The LGPD's transparency principle expects information to be clear, and dense legal language undermines that even if every required fact is technically present. Brazil isn't alone in pushing this: Quebec's privacy regulator recently published its own guidance on writing a simple, clear privacy policy, and the underlying advice, short sentences, defined terms, no unnecessary jargon, applies just as well to an LGPD notice.

What language should your LGPD privacy policy be in?

The LGPD doesn't specify a mandatory policy language, but its transparency principle requires the information to be clear and accessible to the people it protects. In practice, that means Portuguese for a Brazilian audience. If your business serves Brazilian users, publish your privacy policy in Portuguese in addition to any other languages your global policy already covers, and keep the translated version synchronized whenever you update the original.

Teams managing this manually often let translations drift out of sync after an update. Clym's policy management tools support translations across 23 languages with synchronized version control, so your Portuguese policy doesn't lag behind the English one.

How often should you update your LGPD privacy policy?

Unlike the CCPA, which requires an update at least every 12 months, the LGPD sets no fixed update schedule for privacy policies. Update yours whenever your data practices change (a new vendor, a new use of AI, a new region) or when the ANPD issues new binding rules, such as the international transfer and security incident regulations that took effect between 2024 and 2026. As a practical minimum, review your policy at least once a year even if nothing else has changed, so the "last updated" date reflects an actively maintained document.

Common mistakes to avoid in your LGPD privacy policy

  • Copying a GDPR policy without adjusting it: GDPR's six legal bases and 72-hour breach window don't map one-to-one onto the LGPD's ten bases and three-business-day incident notification rule

  • Leaving out DPO or privacy contact details: Article 41 makes this mandatory, not optional

  • Ignoring Portuguese-language readers: an English-only policy doesn't meet the transparency bar for a Brazilian audience

  • Failing to mention international transfers: if your data ever leaves Brazil, your policy needs to name the transfer mechanism

  • Treating children's data like adult data: under-12 processing needs specific, prominent guardian consent, not a buried checkbox

  • Publishing it once and forgetting it: an unmaintained policy is itself a transparency gap

How Clym can help with LGPD privacy policy requirements

Clym's policies solution lets you generate a first draft through a guided questionnaire, configure it for LGPD alongside any other regulation your business needs to support, and manage translated versions with full version history, so you can show exactly what your policy said on any given date. Combined with the consent and data subject request tools covered above, you get one governance record instead of policies, consent logs, and request trackers living in separate systems. We don't promise a specific compliance outcome. We provide the infrastructure to support your privacy program as LGPD and ANPD rules continue to evolve.

Conclusion

An LGPD privacy policy is really a transparency document dressed up as boilerplate, and Brazil's regulators are paying closer attention to the substance behind it now that the ANPD operates with the authority of a full regulatory agency. Getting the basics right, clear language, a real legal basis for every activity, an accessible way to reach your DPO, and honest disclosure of where data actually goes, covers most of what the law expects.

The parts that trip companies up are usually the newer pieces: international transfer mechanisms, breach notification timing, and children's data, all of which changed meaningfully between 2024 and 2026. None of this requires reinventing your privacy program from scratch. It requires updating the document to match what you're already doing, and keeping it current as the rules keep moving.

Frequently asked questions

LGPD stands for Lei Geral de Proteção de Dados, Brazil's General Data Protection Law. It has been in force since September 2020 and is enforced by the ANPD, Brazil's national data protection authority, which became a full regulatory agency in September 2025.

The LGPD doesn't use the exact phrase "privacy policy," but its transparency principle requires clear, accessible information about your data processing. A published privacy policy is the standard way organizations meet that requirement, making one effectively necessary for most businesses in scope.

They cover similar ground, but the LGPD has ten legal bases for processing instead of GDPR's six, a three-business-day security incident notification window instead of 72 hours, and lower maximum fines. A GDPR-only policy usually needs LGPD-specific edits, not a wholesale rewrite.

The ANPD can issue administrative sanctions, including fines of up to 2 percent of your Brazilian revenue capped at roughly R$50 million per violation, public disclosure of the violation, and restrictions on your data processing activities.

Not necessarily. ANPD rules allow small-sized processing agents to skip a formal DPO appointment, but you still need to publish some form of privacy contact information, at minimum an email address and a title or function, in your policy.

Adam Safar

Head of Digital Marketing

Adam is the Head of Digital Marketing at Clym, where he leverages his diverse expertise in marketing to support businesses with their compliance needs and drive awareness about data privacy and web accessibility. As one of the company’s original team members, Adam has been instrumental in shaping its journey from the very beginning. When he’s not diving into marketing strategies, Adam can be found cheering on his favorite sports teams or enjoying fishing.

Find out more about Adam