Compliance

Brazil’s LGPD, and why a BR visitor is treated as opt-in.

The LGPD is structurally close to the GDPR (ten legal bases, a national authority, real fines), but it has no ePrivacy counterpart. The consent question therefore turns on which basis you are relying on for the processing itself.

Law
Lei nº 13.709/2018 (LGPD)
Detected as
BR
Regulator
ANPD
Default model
Opt-in

The shape of the law

The LGPD took effect in September 2020, with administrative sanctions available from August 2021. It applies to processing carried out in Brazil, processing aimed at offering goods or services in Brazil, and processing of data collected in Brazil: the same extraterritorial logic the GDPR uses.

Article 7 lists ten legal bases. Consent is the first, and where it is relied on, Article 8 requires it to be given in writing or by another means that demonstrates the holder’s intent, for specified purposes, and revocably. Generic consent is expressly invalid. There is no separate statute governing storage on a device, so cookies are analysed as processing like anything else.

In practice, advertising and behavioural profiling are hard to run on any basis other than consent, and the ANPD’s published guidance on cookies pushes firmly towards an explicit choice with a genuine option to refuse.

What each region profile resolves to

Region profileResolved modelWhat the visitor sees
Regional defaultsopt-inNothing optional loads until a choice is made
Global strictopt-inNothing optional loads until a choice is made, everywhere
Global balancedopt-inNothing optional loads until a choice is made
EU and UK opt-innoneNo banner

BR is in the engine’s opt-in set, so Regional defaults and Global balanced both resolve to opt-in. The one profile that produces nothing for a Brazilian visitor is "EU and UK opt-in", which is scoped to the EEA, the UK and Switzerland by design.

Configuring for Brazil

  • Publish the banner in Portuguese. The runtime matches the visitor’s browser languages against the translations in the published configuration, so add pt or pt-BR and write the category descriptions there too.
  • Keep purposes specific. Article 8 §4 invalidates consent for generic purposes, which is an argument for splitting a broad "marketing" bucket into named custom purposes where your uses genuinely differ.
  • Make revocation easy and visible. Article 8 §5 gives the holder the right to revoke at any time by an express and free procedure; the preference centre is that procedure.
  • Keep the evidence. Article 8 §2 puts the burden of proving consent on the controller, which is the same demonstrability duty the consent record is designed to meet.

Sanctions under Article 52 run to 2% of the group’s revenue in Brazil for the preceding financial year, capped at R$50 million per infraction, alongside publicising the violation and blocking or deleting the data involved.

This is a product reference, not legal advice

It describes how StrongPrivacy behaves and summarises published law so you can configure the product deliberately. Whether a particular configuration satisfies your obligations is a question for your own counsel, who knows your data flows and your risk position.

Common questions

Does the LGPD require prior consent for cookies?

Not through a dedicated cookie rule. The processing needs an LGPD legal basis. Consent may be the more appropriate basis for advertising or profiling in many configurations, while a legitimate-interest analysis is purpose- and risk-specific and can be difficult to sustain. StrongPrivacy uses opt-in as a conservative product default, not as a claim that consent is the only lawful basis.

Is a Portuguese banner required?

The statute requires information to be given clearly and adequately. A banner a Brazilian visitor cannot read does not meet that standard in any practical sense. Add pt-BR to the property’s translations; the runtime will select it from the visitor’s browser language preferences.

Does StrongPrivacy record which law applied?

It records the location the decision was made from (`BR`) and the configuration version that was live at the time. The jurisdiction and consent model are derived from that location and that configuration rather than stored as separate fields, which means they can be recomputed from the record rather than taken on trust.

Sources and verification

Verified on . Product-behaviour statements were checked against the current implementation and tests. The links below are the verification basis recorded for this article. They support the stated facts, not a legal conclusion for every site or configuration; recheck changing vendor behaviour before relying on it in production.

See what your own site is loading

A browser scan reports the requests and storage it observed during the sampled journey. Use configured workspace scans to compare the states and pages that matter to your implementation.