Cookie Policy Generator Brazil
LGPD with ten legal bases, the ANPD as regulator, and the Consumer Defence Code sitting on top.
Brazilian cookie practice is governed by the LGPD rather than a dedicated statute, and the ANPD has published guidance treating cookie consent as ordinary LGPD consent - which means it must be free, informed, unambiguous and given for a specific purpose.
The Lei Geral de Proteção de Dados is GDPR-shaped but not GDPR-identical. It offers ten legal bases rather than six, adding credit protection and health protection among others, and it requires an encarregado - a data protection officer equivalent - whose identity must be published.
The ANPD became a fully independent authority and has moved from guidance to enforcement, issuing sanctions and publishing regulations on breach notification, small-business treatment and international transfers, including its own standard contractual clauses.
Brazilian consumer law is unusually protective and applies alongside the LGPD. The Consumer Defence Code gives a seven-day right of regret on distance purchases, reverses the burden of proof in many disputes, and treats abusive contract terms as void.
What a cookie policy in Brazil has to cover
Cookies mapped to the LGPD legal basis relied on, purpose by purpose
Consent captured before non-essential cookies are set, in Portuguese
The distinction between cookies necessary for the service and everything else
International transfers triggered by advertising and analytics providers
The encarregado named as the contact for questions about tracking
How Brazil actually moves personal data
CPF as a universal identifier
The CPF is used across Brazilian commerce, which makes almost any customer record directly identifying and raises the stakes on retention and access control.
Pix and payment data
Instant payment rails involve identifiers that link directly to a person, and the Central Bank imposes its own security expectations on participants.
Log retention under the Marco Civil
Application providers must keep access logs for six months, and connection providers for a year - a mandatory retention duty that has to be reconciled with LGPD minimisation.
Automated decisions
Article 20 gives a right to request review of decisions made solely on automated processing, which affects credit, fraud and pricing systems.
Breach notification to the ANPD
The ANPD regulation sets the deadline and content, and requires communication to affected individuals where risk is relevant.
Third parties the draft will ask you about
Stripe · Pagar.me · Mercado Pago · PagSeguro · Correios · AWS sa-east-1 · RD Station · Totvs
The rules that apply
LGPD (Lei 13.709/2018)
Ten legal bases, data subject rights including review of automated decisions, and sanctions up to 2% of Brazilian turnover capped at R$50 million per infraction.
Encarregado requirement
A data protection officer whose identity and contact must be publicly disclosed, with reduced obligations for small processing agents.
ANPD international transfer rules
Adequacy decisions, Brazilian standard contractual clauses, binding corporate rules or specific derogations.
Consumer Defence Code
Seven-day right of regret on distance sales, mandatory clear pre-contractual information, and voidance of abusive clauses.
Marco Civil da Internet
Rules on connection and application logs, retention periods and the conditions for disclosure to authorities.
What the generated cookie policy contains
What the technologies actually are
Cookies, local storage, session storage, pixels, SDKs and server-side tags - the law covers storage and access on a device, not the word "cookie".
A per-cookie table
Name, provider, purpose, category and duration for each cookie, which is the format UK and EU regulators expect to see.
Category definitions
Strictly necessary, functional, analytics and advertising, with an honest explanation of why only the first runs without consent.
How consent was obtained and how to change it
The banner, the granular choices, and a permanent link to reopen preferences - the withdrawal route has to be as easy as the acceptance route.
Third-party cookies and onward use
Which providers set cookies through your site and what they do with the data once it is theirs.
Browser and device controls
Practical instructions, plus a note that blocking strictly necessary cookies will break parts of the service.
LGPD implementation essentials
Appoint and publish an encarregado
Name and contact route, published where a data subject will find it.
Map processing to the ten bases
Including the bases with no GDPR equivalent, where they genuinely fit.
Adopt ANPD standard contractual clauses for transfers
Or document an adequacy or derogation position.
Reconcile Marco Civil log retention with minimisation
Mandatory retention is a lawful reason to keep logs; it is not a reason to keep everything else.
Align terms with the Consumer Defence Code
Seven-day regret, clear pricing, and no abusive clauses.
Where this usually goes wrong
Copying a GDPR basis table
The LGPD has ten bases including credit protection and health protection. A six-basis table both omits options and misstates the law.
No published encarregado
The identity and contact of the encarregado must be publicly disclosed. It is one of the first things a complainant looks for.
Ignoring the seven-day right of regret
It applies to distance purchases regardless of your refund policy and is separate from any faulty-goods remedy.
Assuming EU SCCs cover Brazilian transfers
The ANPD published its own standard contractual clauses. EU clauses alone are not the Brazilian mechanism.
Frequently asked questions
Does the LGPD apply to companies outside Brazil?
Yes, where processing takes place in Brazil, where it relates to offering goods or services to people in Brazil, or where the data was collected in Brazil.
Do I need an encarregado?
Yes as a general rule, and the identity and contact must be published. The ANPD has reduced obligations for small processing agents but does not remove the accountability requirement.
What is the right of regret?
A seven-day right for consumers to cancel a distance purchase without cause under the Consumer Defence Code, independent of the LGPD and of any commercial refund policy.
Do I need a cookie policy as well as a privacy policy?
In the UK and EU, yes in practice. PECR and the ePrivacy Directive regulate storing and reading information on a device separately from GDPR’s rules on processing, and the per-cookie disclosure is too detailed to bury in a privacy policy.
Do analytics cookies need consent?
In the UK and EU, yes - the ICO has said repeatedly that analytics is not "strictly necessary". Some EU regulators allow a narrow exemption for first-party, non-shared audience measurement, but the default answer is consent first.
Does a cookie policy need updating when I add a tool?
Yes, and this is the clause that goes stale fastest. Every new tag, pixel or embedded widget adds cookies your table does not list. Scanning your own site on a schedule is the only reliable way to keep it honest.
What about cookies set by embedded video and maps?
They count. An embedded YouTube player or Google Map sets third-party cookies as soon as it loads, so either it loads only after consent, or you use a privacy-preserving embed mode and say so.
Cookie Policy Generator Brazil
Answer a short questionnaire and get a draft written for Brazil. Free to start, no card required.
Generate your cookie policyOther documents for Brazil
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.