LGPD Compliance: What Websites Need in 2026
LGPD compliance for websites: does Brazil's data law apply to you, the ANPD cookie consent rules, fines up to 50 million reais, and the steps you need.
LGPD compliance means following Brazil’s data protection law, the Lei Geral de Proteção de Dados, whenever your website handles personal data belonging to people in Brazil. The law took effect on September 18, 2020, and it reaches your site even if your company sits outside Brazil, as long as you collect data from someone located there. Compliance comes down to a handful of concrete things: a lawful reason to process each piece of data, a privacy notice that explains what you collect, a way for people to exercise their rights, a cookie banner that asks before loading non-essential trackers, and reasonable security around the data you keep.
Most guides to the LGPD are written for corporate privacy teams with lawyers on staff. This one is written for the person who actually runs the website. It covers whether the law applies to you, what the ANPD (Brazil’s regulator) expects around cookies, what the fines look like now that enforcement has started, and a checklist you can work through without hiring anyone.
What is the LGPD, and what does compliance mean?
The LGPD is Brazil’s general data protection law, and complying with it means having a lawful basis for every bit of personal data your site touches, plus the notices, rights, and safeguards the law requires. Brazil passed it (Lei Geral de Proteção de Dados, Law No. 13,709) on August 14, 2018, it came into force on September 18, 2020, and the fine powers switched on August 1, 2021. It was modeled closely on Europe’s GDPR, so if you’ve handled GDPR before, most of the shape will feel familiar.

Personal data under the LGPD is any information that identifies a person or could be linked back to one. That includes the obvious things like names and email addresses, and the less obvious ones like IP addresses, cookie identifiers, device data, and location. A separate, stricter category called sensitive personal data covers things like race, religion, health, political opinions, and biometric data, and it carries tighter rules.
Two roles run through the whole law. The controller decides why and how data gets processed, which for most websites is you, the business. The operator (the LGPD’s word for what GDPR calls a processor) handles data on the controller’s behalf, like your email platform or analytics provider. You stay responsible for what your operators do with the data you hand them, so the contracts and settings you choose for those tools are part of your compliance, not an afterthought.
Compliance, in practice, isn’t a certificate you earn once. It’s an ongoing state: a lawful basis behind each processing activity, a clear privacy notice, a working way for people to ask about or delete their data, security around what you store, and records that show you did all of it. The rest of this guide breaks those down into steps you can act on.
Does the LGPD apply to your website outside Brazil?
If your website collects personal data from people who are in Brazil, the LGPD applies to you, even if your company, your servers, and your team are somewhere else entirely. The law follows the person, not your address. Article 3 is explicit about this: the LGPD covers any processing where the data is collected from individuals located in Brazil, or where the processing activity is meant to offer goods or services to people in Brazil.

That reach is the part most site owners miss. You don’t need a Brazilian office, a .com.br domain, or a single real in your bank account. If a person sitting in São Paulo fills out your contact form, buys your product, or just loads a page that drops an analytics cookie, their data is in scope. Selling in Portuguese, pricing in reais, or shipping to Brazil all make the “offering goods or services” test easy to meet, but even an English-only site can qualify when Brazilian visitors are using it.
The law carves out only a few narrow exceptions. The LGPD doesn’t apply to processing done by a person purely for personal reasons, or to data used strictly for journalistic, artistic, or academic purposes, or to certain public security and national defense activities. None of those help a normal commercial website. If you run a business site that anyone in Brazil can reach, assume you’re in scope and plan accordingly.
The ANPD confirmed in 2025 that it’s willing to act on this extraterritorial reach, issuing penalties that touched foreign platforms. So the “we’re not a Brazilian company” line isn’t the shield some site owners assume it to be. If you already geo-block Brazil entirely, that changes the picture, but very few businesses want to turn away an entire country to dodge a compliance task that mostly overlaps with what GDPR already asks.
What rights does the LGPD give people?
The LGPD gives every data subject nine rights over their personal data, listed in Article 18, and your site needs a way to honor each one. These rights are the reason you need a real process for handling requests, not just a privacy page nobody maintains.

The nine rights let a person confirm that you’re processing their data, access a copy of it, correct data that’s wrong or out of date, and ask you to anonymize, block, or delete data that’s unnecessary or handled outside the law. They can request deletion of data you processed based on their consent, move their data to another provider (portability), and learn which public and private entities you shared their data with. They can also be told about their option to refuse consent and what happens when they do.
When someone makes one of these requests, the LGPD expects you to respond. For a simplified reply you should act right away, and for a full formal declaration about the data you hold, the law gives you 15 days. That’s a tighter window than GDPR’s one month, so a manual scramble every time an email lands doesn’t scale. Decide in advance where each type of data lives and who handles the request.
You also owe people a plain privacy notice before or at the moment you collect their data. It should say what you collect, why, the legal basis you’re relying on, how long you keep it, who you share it with, and how to exercise the rights above. A notice buried in dense legal text doesn’t meet the spirit of the law, which asks for clear and accessible information. Write it so a normal visitor can actually follow it.
How does the LGPD treat cookies and consent?
Under the LGPD, most cookies that track visitors need consent before they load, and Brazil’s regulator has spelled this out directly. In October 2022 the ANPD published a guide called “Cookies e proteção de dados pessoais” (Cookies and Protection of Personal Data), and it draws a clean line: non-necessary cookies, like analytics and advertising, run on consent, while strictly necessary cookies can rely on legitimate interest.

That distinction decides how your banner has to behave. Cookies that keep the site working, like a session cookie that remembers what’s in a cart or a security token, fall under legitimate interest and can load without asking first. Everything that watches behavior for your benefit, from Google Analytics to a retargeting pixel to an embedded video that profiles the viewer, needs the visitor to agree before it runs. Loading those trackers on page arrival, then showing a banner that only informs, doesn’t meet the standard.
Consent itself has a definition in the LGPD, and it’s specific. It has to be free, informed, and unambiguous, given for a clearly stated purpose. A pre-ticked box isn’t free. A vague “by using this site you accept cookies” line isn’t informed or unambiguous. And bundling every purpose into one Accept button, with no real way to say no, fails the test. Sensitive data raises the bar further, asking for consent that’s specific and highlighted rather than folded into a general agreement.
What this means in practice is straightforward. Your site needs a consent step that appears before non-essential trackers fire, presents a genuine choice, and records what the visitor decided. That’s the same posture GDPR asks for, so a banner built to the European standard already satisfies the ANPD’s cookie guidance. Our cookie consent examples guide walks through what that looks like on a real page.
What does an LGPD cookie banner need?
A compliant LGPD cookie banner has to ask before non-essential cookies load, give a real reject option, let people choose by category, and keep a record of each choice. Those four traits separate a banner that satisfies the ANPD from one that just decorates the corner of your screen.

Asking first is the core requirement. The banner should hold back analytics, advertising, and any other non-essential script until the visitor makes a choice, rather than firing them on load and cleaning up afterward. A reject option needs to sit next to accept with similar weight, because a bright Accept button beside a buried, greyed-out decline link is the kind of dark pattern regulators have started to punish. Category control matters too, since visitors should be able to allow functional cookies while turning down advertising, instead of facing a single all-or-nothing switch.
The record is what protects you when someone asks how you handled their data. For each visitor who interacts with the banner, you want a timestamped log of what they were shown and what they chose, kept somewhere you can export it. If the ANPD ever asks you to demonstrate consent, that log is your evidence. Guessing or reconstructing after the fact doesn’t count for much.
This is where a purpose-built widget saves a lot of work. Amabrik’s cookie consent widget holds the third-party scripts you declare until the visitor agrees, shows accept and reject with equal weight, supports per-category choices, and keeps a consent log you can export as a CSV. It also handles Google Consent Mode v2 and the Global Privacy Control signal, so the same banner you set up for Brazil covers your European and California visitors without a second system. If you’re weighing options, our best cookie consent banner rundown lays them out side by side.
What are the fines, and is the ANPD enforcing?
LGPD fines run up to 2% of your company’s revenue in Brazil for the prior year, capped at 50 million reais per violation, and after a slow start the ANPD is now handing them out. For years the authority focused on guidance rather than penalties, which led some businesses to treat the law as toothless. That grace period is now firmly over.

The sanctions in the law go beyond money. The ANPD can issue warnings, order you to delete the data involved, publicize the violation, and in serious cases partially or fully suspend the activity that broke the rules. For a business that runs on its website, a suspension order can hurt more than the fine. The 2% figure is calculated on Brazilian revenue, not global turnover, which keeps it lower than GDPR’s ceiling, but the 50 million reais cap still makes a single serious violation expensive.
Enforcement picked up sharply through 2024 and 2025. The ANPD published its methodology for calculating fines in 2024, which gave it the missing piece it needed to move from threats to actual penalties. Since then it has issued administrative fines, including against foreign platforms operating in Brazil, confirming both that the numbers are real and that the extraterritorial reach from Article 3 is more than theory. The regulator has also signaled that data subject rights and consent sit high on its agenda, which are exactly the areas a website touches.
The takeaway for a site owner isn’t to panic, but to stop treating the LGPD as optional. The cost of a basic compliance setup, a consent banner, a privacy notice, a request process, is small next to a 50 million real ceiling and the reputational hit of a published violation. Regulators tend to go easier on a business that made a genuine effort than on one that ignored the law entirely.
LGPD vs GDPR: what actually changes?
If you already comply with GDPR, you’re most of the way to LGPD compliance, but a few specifics differ enough to matter. The two laws share the same core idea, a lawful basis for processing plus strong rights for individuals, and the LGPD borrowed much of its structure from the GDPR. The differences live in the details, not the philosophy.

The table below lines up the points that change how you build your compliance setup.
| Point | LGPD (Brazil) | GDPR (EU) |
|---|---|---|
| Legal bases for processing | 10 | 6 |
| Data subject rights | 9 (Article 18) | 8 |
| Response time for a full request | 15 days | 1 month |
| Maximum fine | 2% of Brazil revenue, capped at 50 million reais per violation | 4% of global revenue or 20 million euros |
| Regulator | ANPD (one national authority) | one authority per member state |
| Cookie consent | consent for non-necessary (ANPD 2022 guidance) | consent for non-necessary (ePrivacy) |
The headline differences are the wider set of legal bases (the LGPD lists 10, including some Brazil-specific ones like protection of credit), the tighter 15-day window for a full data request, and the lower fine ceiling tied to Brazilian revenue. On cookies and consent the two laws land in nearly the same place, which is why one well-built banner can serve both audiences.
The practical move is to build to the stricter standard and let it cover the rest. A consent system designed for GDPR, one that blocks non-essential cookies until opt-in, offers per-category choice, and logs every decision, already satisfies the ANPD’s cookie guidance. Add a privacy notice that names Brazil and the LGPD, wire up a request process that can hit the 15-day mark, and you’ve closed the gap. If you also serve California, our CCPA compliance checklist shows how the opt-out model there fits alongside these two.
Your LGPD checklist, without a legal team
You can get a normal website to LGPD compliance by working through a short list, no privacy department required. Start by confirming the law applies to you, which for almost any site that Brazilian visitors can reach, it does. From there, the work is concrete rather than legal.
Map the personal data your site collects, every form, cookie, pixel, and third-party script, and write down what each one gathers and where it sends the data. Pick a lawful basis for each activity, using consent for anything that tracks and legitimate interest for the genuinely necessary. Publish a privacy notice in plain language that lists what you collect, why, the basis, retention, sharing, and how to exercise rights. Put up a cookie banner that asks before non-essential trackers load, offers a real reject, allows per-category choice, and logs each decision. Set up a way to receive and answer rights requests inside the 15-day window. Then secure what you store, because a data breach turns a paperwork problem into a much larger one.
That last point is easy to skip and expensive to get wrong. If you built your site quickly, or an AI tool wrote a chunk of it, run a security scan to catch exposed files, leaked API keys, and missing security headers before someone else finds them. Data security is a stated LGPD obligation, not a nice-to-have.
None of this needs a lawyer for a standard business site, and most of it overlaps with GDPR and CCPA, so one solid setup covers several jurisdictions at once. A single cookie consent widget that handles Brazil, Europe, and California together is the closest thing to a shortcut here. Get the consent layer right, keep your notice current, and answer requests on time, and the LGPD moves from a worry to a box you’ve checked.
Yes. The LGPD follows the person, not the company's location. Under Article 3, it applies to any processing of personal data collected from people located in Brazil, or any processing meant to offer goods or services to them, no matter where your business, servers, or team sit. If Brazilian visitors can use your site and it drops cookies or collects form data, you're in scope, and the ANPD confirmed in 2025 that it will act on this reach against foreign companies.
For most sites, yes. The ANPD's 2022 cookie guidance says non-necessary cookies, like analytics and advertising, need consent before they load, while strictly necessary cookies can rely on legitimate interest. In practice that means a banner that holds back tracking scripts until the visitor agrees, offers a genuine reject option, and records the choice. A banner built to GDPR's opt-in standard already meets this.
The ANPD can fine a company up to 2% of its revenue in Brazil for the prior year, capped at 50 million reais per violation. It can also issue warnings, order data deletion, publicize the violation, and suspend the activity involved. Enforcement was slow at first, but the authority published its fine methodology in 2024 and has issued penalties since, including against foreign platforms.
Nine, listed in Article 18. People can confirm you process their data, access it, correct it, ask you to anonymize or delete unnecessary data, delete data processed on consent, move their data to another provider, learn who you shared it with, and be informed about refusing consent. Your site needs a process to answer these requests, and a full declaration is due within 15 days.
They share the same core: a lawful basis for processing and strong individual rights. The LGPD lists 10 legal bases to GDPR's 6, grants 9 data subject rights to GDPR's 8, and gives you 15 days to answer a full request rather than a month. Its maximum fine is lower, 2% of Brazilian revenue capped at 50 million reais, against GDPR's 4% of global turnover. On cookies, both require consent for non-essential trackers, so one banner can serve both.
Brazil passed the LGPD (Lei Geral de Proteção de Dados, Law No. 13,709) on August 14, 2018. It came into force on September 18, 2020, and the ANPD's power to apply administrative fines started on August 1, 2021. The regulator itself, the Autoridade Nacional de Proteção de Dados, was established in 2020.


