LGPD (General Data Protection Law) affects every app that collects user data. Fines can reach R$50 million per infraction. This guide shows how to adapt your application to Brazilian privacy legislation.
What is LGPD
Definition
Law 13,709/2018. Regulates the processing of personal data in Brazil.
Inspiration
Based on European GDPR.
Term
In force since 2020. Inspection by ANPD.
Scope
Any processing of data of people in Brazil.
Personal Data
Definition
Information related to an identified or identifiable natural person.
Examples
Name, email, telephone, IP, location, device ID.
Sensitive Data
Health, religion, biometrics. Extra protection.
Anonymization
Data that does not identify a person is not personal.
Principles of LGPD
Purpose
Legitimate, specific, informed purpose.
Suitability
Compatible with stated purpose.
Necessity
Minimum required for purpose.
Free Access
Facilitated data consultation.
Quality
Accurate, clear, updated data.
Transparency
Clear information about treatment.
Security
Protective measures.
Prevention
Prevent damage.
Non-Discrimination
Discriminatory treatment prohibited.
Legal Bases
Consent
Clear authorization from the holder.
Contract Execution
Necessary to fulfill contract.
Legitimate Interest
Legitimate interest of the controller.
Life Protection
Emergency situations.
Legal Compliance
Required by law.
Others
Public policies, studies, credit.
Consent in Apps
Requirements
Free, informed, unambiguous, specific.
Collection
Clear moment, simple language.
Granularity
Ultimately, I don't "accept everything."
Revocation
Easy to withdraw consent.
Registration
Prove that consent was given.
Rights of Holders
Access
Know what data is processed.
Correction
Update incorrect data.
Elimination
Delete data no longer needed.
Portability
Receive data in a usable format.
Information
Know with whom data is shared.
Revocation
Withdraw consent.
Opposition
Oppose treatment.
Implementation in the App
Privacy by Design
Privacy by design.
Minimum Collection
Only what is necessary.
Privacy Policy
Clear, accessible, updated.
Terms of Use
Separate from the privacy policy.
Consent UI
Clear interface for consent.
Data Access
Functionality to exercise rights.
Analytics Consent
Cookies/SDKs
Analytics tools collect data.
Opt-In vs Opt-Out
LGPD suggests opt-in for non-essentials.
Incognito Mode
Analytics without personal identification.
Push Notifications
Optin for Shipping
System already requires permission.
Content
Do not send sensitive data in a visible push.
Preferences
Allow control over notification types.
Third parties and SDKs
Due Diligence
Are SDKs compliant?
DPA
Data Processing Agreements.
International Transfer
Data sent outside Brazil?
List of Third Parties
Disclose processors in the policy.
Data Security
Encryption
In transit (HTTPS) and at rest.
Restricted Access
Minimum required.
Logs
Record accesses for auditing.
Retention
Don't keep more than you need.
Disposal
Safe disposal.
Children and Adolescents
Consent
Parental consent for children under 18.
Treatment
Stricter rules.
Children's Games and Apps
Special attention.
Person in Charge (DPO)
Function
Responsible for compliance.
Mandatory
It depends on the size and activity.
Advertising
Contact must be public.
Incidents
Notification
ANPD and holders in case of leak.
Deadline
Reasonable deadline. ANPD will define.
Plan
Documented procedure.
Penalties
Warning
Correction within deadline.
Fine
Up to 2% of revenue, limited to R$50 million.
Publication
Make the infraction public.
Blocking
Of personal data.
Elimination
Data processed irregularly.
Conclusion
LGPD requires attention from every app that processes personal data. Implement appropriate consent, respect rights, minimize collection and protect information. Compliance is an investment in trust and risk reduction.
##FAQs
1) My small app needs to comply with LGPD? Yes. The law applies to any data processing.
2) Google Analytics violates LGPD? It can, if there is no consent. Configure correctly.
3) Do I need a DPO? It depends. For many apps, it is not mandatory but it is good practice to have someone responsible.
4) How to prove consent? Timestamped logs of acceptance. Keep records.
5) Can I delete user data? Must, when requested (with some legal exceptions).
Also read
- Digital Compliance: Compliance Guide for Digital Products
- LGPD two years later: what has really changed in Brazilian companies
- LGPD in 2026: what has changed, what has not yet been complied with and what is coming
- LGPD in Startups: Compliance and Data Protection Strategies
- Personalization in apps: a quick guide to getting it right without hacking
- Data Leakage Protection: Security Guide
