Privacy Policy Generator Brazil
LGPD with ten legal bases, the ANPD as regulator, and the Consumer Defence Code sitting on top.
A Brazilian política de privacidade has to name the encarregado, map each purpose onto one of the LGPD’s ten legal bases, and describe international transfers using the ANPD’s own mechanisms rather than the EU’s.
The Lei Geral de Proteção de Dados is GDPR-shaped but not GDPR-identical. It offers ten legal bases rather than six, adding credit protection and health protection among others, and it requires an encarregado - a data protection officer equivalent - whose identity must be published.
The ANPD became a fully independent authority and has moved from guidance to enforcement, issuing sanctions and publishing regulations on breach notification, small-business treatment and international transfers, including its own standard contractual clauses.
Brazilian consumer law is unusually protective and applies alongside the LGPD. The Consumer Defence Code gives a seven-day right of regret on distance purchases, reverses the burden of proof in many disputes, and treats abusive contract terms as void.
What a privacy policy in Brazil has to cover
The encarregado’s identity and contact, published as the LGPD requires
Purpose-by-purpose mapping to the ten LGPD legal bases
Data subject rights including confirmation of processing, anonymisation and review of automated decisions
International transfer mechanism under ANPD rules, including its standard contractual clauses
Retention that reconciles Marco Civil log duties with LGPD minimisation
How Brazil actually moves personal data
CPF as a universal identifier
The CPF is used across Brazilian commerce, which makes almost any customer record directly identifying and raises the stakes on retention and access control.
Pix and payment data
Instant payment rails involve identifiers that link directly to a person, and the Central Bank imposes its own security expectations on participants.
Log retention under the Marco Civil
Application providers must keep access logs for six months, and connection providers for a year - a mandatory retention duty that has to be reconciled with LGPD minimisation.
Automated decisions
Article 20 gives a right to request review of decisions made solely on automated processing, which affects credit, fraud and pricing systems.
Breach notification to the ANPD
The ANPD regulation sets the deadline and content, and requires communication to affected individuals where risk is relevant.
Third parties the draft will ask you about
Stripe · Pagar.me · Mercado Pago · PagSeguro · Correios · AWS sa-east-1 · RD Station · Totvs
The rules that apply
LGPD (Lei 13.709/2018)
Ten legal bases, data subject rights including review of automated decisions, and sanctions up to 2% of Brazilian turnover capped at R$50 million per infraction.
Encarregado requirement
A data protection officer whose identity and contact must be publicly disclosed, with reduced obligations for small processing agents.
ANPD international transfer rules
Adequacy decisions, Brazilian standard contractual clauses, binding corporate rules or specific derogations.
Consumer Defence Code
Seven-day right of regret on distance sales, mandatory clear pre-contractual information, and voidance of abusive clauses.
Marco Civil da Internet
Rules on connection and application logs, retention periods and the conditions for disclosure to authorities.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
LGPD implementation essentials
Appoint and publish an encarregado
Name and contact route, published where a data subject will find it.
Map processing to the ten bases
Including the bases with no GDPR equivalent, where they genuinely fit.
Adopt ANPD standard contractual clauses for transfers
Or document an adequacy or derogation position.
Reconcile Marco Civil log retention with minimisation
Mandatory retention is a lawful reason to keep logs; it is not a reason to keep everything else.
Align terms with the Consumer Defence Code
Seven-day regret, clear pricing, and no abusive clauses.
Where this usually goes wrong
Copying a GDPR basis table
The LGPD has ten bases including credit protection and health protection. A six-basis table both omits options and misstates the law.
No published encarregado
The identity and contact of the encarregado must be publicly disclosed. It is one of the first things a complainant looks for.
Ignoring the seven-day right of regret
It applies to distance purchases regardless of your refund policy and is separate from any faulty-goods remedy.
Assuming EU SCCs cover Brazilian transfers
The ANPD published its own standard contractual clauses. EU clauses alone are not the Brazilian mechanism.
Frequently asked questions
Does the LGPD apply to companies outside Brazil?
Yes, where processing takes place in Brazil, where it relates to offering goods or services to people in Brazil, or where the data was collected in Brazil.
Do I need an encarregado?
Yes as a general rule, and the identity and contact must be published. The ANPD has reduced obligations for small processing agents but does not remove the accountability requirement.
What is the right of regret?
A seven-day right for consumers to cancel a distance purchase without cause under the Consumer Defence Code, independent of the LGPD and of any commercial refund policy.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator Brazil
Answer a short questionnaire and get a draft written for Brazil. Free to start, no card required.
Generate your privacy policyOther documents for Brazil
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.