What this record can establish
- The current consolidated Portuguese text and a dated ANPD English translation used only as an accessibility aid.
- The published architecture for legal bases, rights, safeguards, transfers and sanctions.
BR · LEI 13.709 · source-led dossier
Lei Geral de Proteção de Dados Pessoais, Law 13.709/2018
What this record can establish
What it cannot establish
Instrument and status timeline
The general framework entered operation on the date recorded in the consolidated law.
BR-01 · Presidency of the Republic of BrazilThe sanction provisions followed a later commencement date.
BR-01 · Presidency of the Republic of BrazilThe official Portuguese consolidation includes amendments made in 2026. This dossier does not infer their effect beyond the cited text.
BR-01 · Presidency of the Republic of Brazil17-factor research index
Every factor remains inspectable without implying that evidence across frameworks is numerically equivalent.
How the legal architecture can be found, understood and translated into a research plan.
The official Portuguese text controls; the ANPD translation is a useful but non-controlling research aid.
How much interpretation is needed before a team can identify the rule that governs its activity?
Which entities, people, data and overseas activities fall inside the framework?
Which processing grounds exist, and how does an organisation document the one it relies on?
What must a person be told, when, and in what form before data is used?
What people can understand, choose, contest and ask organisations to do.
The LGPD sets out rights and multiple legal bases; issue-specific scope and regulator material remain necessary.
Can a person reverse a choice through a practical, understandable route?
Which rights exist, and what must happen before a person can obtain a remedy?
How does the framework recognise age, guardianship and risks to younger people?
What transparency or recourse applies when automated processing affects a person?
How duties, safeguards, risk processes and transfer mechanisms are organised.
Controller/operator duties, security and transfer routes are expressed in the law and later ANPD instruments.
Who remains accountable when processing is delegated or shared?
Which safeguards and breach steps are specified, and when are they triggered?
When must an organisation investigate and document risk before processing?
Which transfer routes exist, and what continuing safeguards travel with the data?
Which obligations create fixed costs, and what tailoring exists for smaller organisations?
Could teams implement the rule through portable patterns without weakening legal context?
How rules are supervised, enforced, explained and tested through practice.
The sanction framework is operative; a fair maturity comparison still needs a defined, dated evidence method.
How can people and organisations reach the institution, and what can it do?
How are sanctions linked to conduct, context and due process?
What has the framework's operation, guidance and enforcement record actually demonstrated?
TAKE TO COUNSEL / TEAMS
Operational questions, not prescriptions
Which of the enumerated legal bases applies to the processing activity?
What ANPD regulation or guidance supplements the controlling Portuguese text?
Which transfer mechanism and continuing safeguards apply to the destination?
Official source rail
Article revision record
This register begins with the private-preview editorial rebuild. It records material content, method, interface and trust-policy changes without inventing a history that predates the available repository evidence.
DOSSIER-LGPD-20260826-01