Join our Newsletter — 33% off our NHI Course
Foundations & NHI Taxonomy

LGPD

← Back to Glossary
By NHI Mgmt Group Updated September 23, 2026 Domain: Foundations & NHI Taxonomy

Brazil’s General Personal Data Protection Law is the country’s core privacy statute for the collection, processing, disclosure, and erasure of personal data. It sets rules for lawful processing, data subject rights, breach handling, and enforcement by the ANPD. The law applies beyond Brazil in some situations and requires ongoing governance, not one-time compliance work.

What LGPD Covers in Practice

LGPD is Brazil’s core privacy law, but it functions less like a one-time compliance checklist and more like an operating model for how organisations collect, use, share, retain, and delete personal data. Its scope reaches consent, lawful bases, data subject rights, vendor handling, breach response, and cross-border processing decisions.

For practitioners, the important point is that LGPD is not limited to a privacy notice or a legal policy. It creates ongoing obligations around data mapping, accountability, controller and operator roles, retention discipline, and evidence that processing remains lawful as systems and use cases change.

Data Subject Rights, Lawful Processing, and Governance

LGPD centres on the conditions under which personal data may be processed and the rights individuals can exercise over that data. That includes access, correction, anonymisation, portability, deletion where applicable, and information about processing activities. In practice, those rights force organisations to maintain inventory, traceability, and response procedures that can actually be executed.

The governance challenge is that lawful processing is not a static statement. Organisations need to know what data they hold, why they hold it, who receives it, and how long it stays in circulation. Where processing changes, the legal basis, notice, and retention logic may need to change as well.

For privacy and security teams, this is where classification and lifecycle control matter most. Sensitive records, shared datasets, and outsourced processing create a larger compliance surface than a simple customer-facing policy suggests. The law’s operational burden is therefore as much about control evidence as it is about legal wording.

Breach Handling, Third Parties, and Cross-Border Use

LGPD also matters because personal data often moves through processors, cloud services, analytics platforms, and international service providers. That introduces exposure around data sharing, sub-processing, and the organisation’s ability to demonstrate oversight over third parties that touch personal data.

Breach handling is part of the same picture. A privacy programme under LGPD needs a way to recognise incidents, assess whether personal data was affected, and coordinate legal, technical, and notification steps without depending on ad hoc judgment during an active event.

In this sense, LGPD is both a privacy rule and a data-risk control framework. The law pushes organisations to know where personal data lives, who can reach it, and whether the transfer path, retention period, or handling process matches the original purpose.

For broader privacy governance, the NIST Privacy Framework is a useful companion reference because it helps translate privacy obligations into repeatable governance and risk management practices.

How LGPD Should Be Operationalised

LGPD becomes manageable when it is treated as an operating control set rather than a legal artifact. That means building data maps, defining ownership for each processing activity, documenting lawful bases, and aligning retention and deletion to business purpose instead of legacy system defaults.

It also means making privacy requests and incident handling testable. If a team cannot locate data, confirm the processor chain, or delete records on demand, the organisation does not merely have a documentation gap, it has a control gap. The same applies to vendor governance: privacy terms must be backed by technical and procedural oversight.

For implementation guidance on this kind of control thinking, the NIST Cybersecurity Framework 2.0 helps structure governance, identification, protection, detection, response, and recovery activities around the personal-data lifecycle. Where identity and access control become part of the privacy posture, NIST SP 800-63 Digital Identity Guidelines is useful for strengthening authentication assurance around systems that expose personal data.

Risk and Threat Considerations

LGPD creates risk when organisations cannot reliably discover personal data, justify processing, or prove deletion and retention behaviour. That exposure becomes more severe when data is widely distributed across SaaS platforms, suppliers, analytics pipelines, or legacy systems with weak ownership.

Failure mechanism: weak inventory, unclear legal basis, and poor processor oversight can turn routine data handling into unauthorized retention, excessive disclosure, or failed breach response.

Impact: the result can be regulatory action, forced remediation, loss of trust, and a materially larger blast radius when personal data is exposed or mishandled.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

NIST CSF 2.0, NIST SP 800-63, NIST AI RMF and CIS Controls v8 set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST CSF 2.0GV — GovernLGPD requires ongoing privacy governance and accountability for personal data processing.
ID — IdentifyLGPD depends on knowing what personal data exists, where it resides, and who processes it.
RS — RespondLGPD breach handling requires incident response and notification coordination for personal data events.
Recommendation — Establish governance for lawful processing, ownership, and evidence across the personal-data lifecycle. Inventory personal-data processing, systems, and third parties so legal and operational obligations are visible. Coordinate privacy incident handling and notification decisions through a tested response process.
NIST SP 800-63IAL — Identity Assurance LevelLGPD-sensitive systems often need stronger identity assurance to protect personal data access.
AAL — Authenticator Assurance LevelAuthenticator strength materially affects unauthorized access risk to LGPD-regulated personal data.
FAL — Federation Assurance LevelCross-organisational processing under LGPD often relies on federated identity assurance.
Recommendation — Use higher-assurance authentication for systems that expose or process personal data. Require phishing-resistant authenticators where access to personal data is high risk. Constrain federated access paths that carry personal data across organisational boundaries.
NIST AI RMFGOVERN — GovernPrivacy obligations under LGPD align with accountable risk governance and oversight practices.
MEASURE — MeasureLGPD compliance needs measurable control evidence for access, retention, and handling outcomes.
MANAGE — ManageLGPD requires operational treatment of privacy risk, not just policy statements.
Recommendation — Assign accountability for personal-data risk and review processing changes through governance. Measure whether personal-data controls are working and remediate gaps with evidence. Manage privacy risk through documented controls, monitoring, and corrective action.
CIS Controls v85 — Account ManagementLGPD enforcement depends on controlling who can access systems containing personal data.
Recommendation — Remove unnecessary accounts and review access to personal-data systems regularly.

Practitioner Guidance

Governance implication: LGPD works best when privacy ownership is assigned to the same operational owners who control the underlying data flows, not left only to legal or policy teams. That makes it easier to keep lawful basis, retention, and vendor oversight aligned as systems evolve.

Practitioner takeaway: If you cannot explain a processing activity in terms of purpose, authority, recipients, retention, and deletion, you do not yet have an LGPD-ready control posture.

Deepen Your Knowledge

Sign up to our weekly newsletter — get 33% off our NHI Foundation Level Course

    NHIMG Editorial Note
    Reviewed and updated by the NHIMG editorial team on September 23, 2026.
    NHI Mgmt Group — the #1 independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org