Lei Geral de Proteção de Dados
Brazil comprehensive data protection law modeled after GDPR. Applies to any processing of personal data of individuals located in Brazil, regardless of where the processor is located.
What LGPD draws on
This framework pulls on all three pillars — which is why running them as three separate tools means reconciling three sets of evidence at audit time.
Compliance
Security
What your auditor cites,
and what produces the evidence
The regulator's text is quoted below in italic, exactly as written. What follows each one is what the platform records, detects, or proves — not a claim about your compliance status, which no tool can confer.
Processing Records
Controllers and processors MUST maintain records of personal data processing operations.
A record of processing is only as good as the layer producing it. Real-time SQL auditing captures every statement against the data — the identity, the session, the client, the objects touched, the outcome — with no nightly batch window where activity goes unrecorded. Classification is what makes that a record of *regulated* data rather than a log of everything: it tells you which tables are in scope, so the register describes the processing you actually have to declare. Policy templates then produce it in the shape the framework asks for, instead of leaving you to assemble it from raw logs the week before an inspection.
Security Measures
REQUIRES technical and administrative measures to protect personal data from unauthorized access.
Continuous scanning checks each engine and version against known CVEs, missing patches, end-of-life versions, and hardening benchmarks, and extends to the network: exposed listeners, unexpected reachability, weak TLS, and drift from the documented baseline. Findings rank by exploitability and by the classification of the data at risk, so the same CVE sits differently in the queue on classified data than on a development copy — and the scan history is the evidence that the control operated continuously rather than quarterly.
Incident Communication
Security incidents MUST be communicated to the national authority and data subjects in reasonable time.
Findings route by severity to Slack, Teams, email, PagerDuty, or your SIEM, and escalate automatically when nobody acknowledges them and again when nobody resolves them. Every alert arrives with the query, the identity, and the data classification already attached, so the response starts with context rather than with an investigation. The acknowledge-to-resolve history is retained, which is what evidences that the procedure was followed. Your ticketing system stays where it is — what this produces is a finding worth opening a ticket for.
Data Subject Rights
MUST provide access to data, correction, deletion, and portability upon request.
Discovery locates every column holding a subject's data across every connected store, and the access history for that subject is reportable in minutes rather than reconstructed from tickets. The deletion or correction itself is executed by your application or your DBA — what the platform produces is the evidence of where the data was, who touched it, and that the change happened.
What LGPD covers
Art. 5(I); sensitive data at Art. 5(II); anonymisation at Art. 12
Information relating to an identified or identifiable natural person.
In scope
- Identifying information
- Data that can be linked to a person by reasonable means
Dados pessoais sensíveis — sensitive personal data (Art. 5(II))
The instrument's own term, kept as it writes it — these labels differ between frameworks on purpose.
- Racial or ethnic origin
- Religious conviction
- Political opinion
- Trade union or religious, philosophical or political organisation membership
- Health or sex life data
- Genetic or biometric data
What falls outside
Anonymised data, unless the anonymisation can be reversed with reasonable effort — Art. 12 makes reversibility the test rather than intent.
Lei 13.709/2018, Art. 5 · as at 2026-08
How LGPD is enforced
Every figure below is the ceiling the instrument publishes about itself, not a prediction of what anything would cost. Enforced by ANPD, the Brazilian national data protection authority.
| Published maximum | Charged | As at |
|---|---|---|
| 2% of revenue in Brazil | for the last financial year, excluding taxes | 2026-08 |
| BRL 50 million | the per-violation cap that sits over the percentage | 2026-08 |
Article 52 sets a simple fine of up to 2% of the group revenue in Brazil for the last financial year, excluding taxes, with a hard per-violation cap. A daily fine may run alongside it, subject to the same cap.
Maximums are ceilings set by the instrument; enforcement is discretionary and tiered.
Uncapped exposure that sits outside this instrument
These come from company law rather than from LGPD, and they are not penalties — they are liability for a loss, which is why nothing caps them at a published maximum.
Duty of oversight
Delaware, and followed in most US corporate jurisdictions. It is a rule of company law, not of any privacy or security statute.
Triggered by. A sustained or systematic failure by the board to establish a reporting system for a mission-critical risk — or, having one, consciously disregarding what it reported. The second limb is what a documented, unremediated finding goes to.
Who. Directors, in their personal capacity, in a derivative action brought on behalf of the company.
This is liability for the loss the company suffered, not a statutory penalty, so nothing caps it at a published maximum. A bad-faith finding also takes the conduct outside the exculpation and indemnification the charter would otherwise provide.
In re Caremark Int’l Deriv. Litig. (Del. Ch. 1996); Marchand v. Barnhill (Del. 2019); In re Boeing Co. Deriv. Litig. (Del. Ch. 2021).
Enforcement data reviewed August 2026. Several figures are indexed annually and move.
Built for LGPD,
not configured for it afterwards
Brazil Personal Data Monitoring
Track access to CPF, RG, and other Brazilian identifiers
LGPD Compliance Report
Document processing activities and security measures
Brazilian PII Patterns
Auto-detect CPF, CNPJ, RG, and Brazilian address formats
Incident Detection
Real-time detection of potential data breaches
Other Data Privacy frameworks
Walk into the LGPD audit knowing the answer
228 cited requirements across 57 frameworks are mapped to the controls that evidence them. A fixed-fee gap assessment tells you which of them you can already prove today.