Join our Newsletter — 33% off our NHI Course

How should organisations design cookie consent banners to satisfy Brazil’s LGPD requirements?

Organisations should present cookies with clear, equally prominent accept and reject choices, keep non-essential cookies disabled by default, and avoid preselected checkboxes or implied consent. Access to the service should not depend on accepting non-essential cookies. The banner should also lead users to fuller information on purposes, retention, and how consent can be withdrawn through a simple mechanism.

For LGPD, the design question is not just whether consent text exists, but whether the banner gives the user a real choice. That means the accept and reject paths should be presented with comparable visibility, the default should not activate non-essential cookies, and the interface should not steer users toward consent through colour, placement, or preselection.

Where cookies are used for analytics, advertising, or other non-essential purposes, the banner should separate those purposes from strictly necessary processing. A user should be able to continue on the basis of necessary cookies alone, because consent is not meaningful if access to the service depends on agreeing to extra tracking.

That design principle aligns with data protection by design in the EU General Data Protection Regulation (GDPR), which is useful as a reference point even though LGPD is the governing law here. It also maps well to the practical structure of the Identity Data Privacy and Consent Guide, especially where consent management, minimisation, and withdrawal need to work together.

What information the banner must point users to

A compliant banner is only the entry point. It should lead to fuller notice content that explains the purposes of each cookie category, the legal basis being relied on, how long the data is retained, whether any third parties receive it, and how the user can change their preference later. The banner itself can be short, but it should not hide the real decision in a separate policy that is hard to find or harder to understand.

For cookies that are not strictly necessary, the organisation should make withdrawal as easy as acceptance. In practice, that means a persistent settings mechanism or a clearly reachable preference centre, not a buried form, account-only setting, or support ticket process. If consent cannot be withdrawn in a simple way, the original consent flow is weak even if the initial banner looked compliant.

That is where the consent record matters operationally: teams should be able to show what the user saw, what was chosen, when it was chosen, and how the preference was later changed. The banner is therefore part of a broader consent lifecycle, not a one-time UI decision.

How to translate LGPD principles into banner design

Design the banner around user action, not vendor convenience. Group cookies by purpose, use plain language, and keep the non-essential categories disabled until the user opts in. Avoid bundled consent for unrelated purposes, since a single yes does not reliably describe user intent when advertising, analytics, and preference cookies are all mixed together.

Where consent is used as the legal basis, the banner should not create pressure through friction. If rejecting cookies requires more steps than accepting them, or if the reject option is visually de-emphasised, the interface may fail the spirit of a free and informed choice. A good banner makes the two paths easy to find and equally workable.

For teams building or reviewing the implementation, this is less about copywriting and more about control design. The banner should be tested as a functional gate: do non-essential scripts stay off until consent is recorded, do preference changes take effect immediately, and can the organisation prove the default state was genuinely non-essential off? Those checks are what turn a privacy notice into an enforceable control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.

Framework Control / Reference Relevance
GDPR A.5.4 — Consent LGPD banner design hinges on valid, informed consent mechanics.
Recommendation — Design consent flows to capture informed, freely given opt-in and easy withdrawal.
ISO/IEC 27001:2022 A.5.34 — Privacy and protection of PII Cookie consent banners are a privacy control for personal data processing.
Recommendation — Define and enforce privacy notices, consent capture, and withdrawal handling for cookie processing.
NIST CSF 2.0 PR.DS-01 — Data-at-rest is protected Cookie identifiers and related data should be limited and protected by default settings.
Recommendation — Minimise collection and disable non-essential tracking until consent is recorded.

Practitioner Guidance

What to verify: Check the actual page behaviour, not just the banner text. Non-essential cookies should remain off before choice, after refresh, and after preference changes, and the reject path should be as simple to execute as the accept path.

What practitioners underestimate: The biggest failure is often implementation drift, not wording. A compliant-looking banner can still load trackers through tag managers, third-party scripts, or embedded content before consent is recorded.

Practitioner takeaway: Treat the banner as a consent enforcement control, not a notice widget, because LGPD compliance depends on how the page behaves as much as on what the user reads.