What Is LGPD? Your Personal Data Rights as a Consumer in Brazil

Every time you open a financial app, complete an online purchase, or register for a digital service in Brazil, your personal data is being collected, processed, and stored. The entity doing this has legal obligations toward you — obligations established by one of the most important laws in Brazil's recent history.

6 min
-
June 3, 2026

The LGPDLei Geral de Proteção de Dados Pessoais (General Personal Data Protection Law) — came into full force in September 2020 and fundamentally changed the relationship between organizations and the individuals whose data they handle.

Yet despite its importance, most Brazilian consumers have only a vague awareness of what the LGPD actually requires and, crucially, what rights it gives them. This article explains the law in clear, practical terms — what it covers, what it does not cover, what legal bases allow companies to process your data, and what you can do when your rights are violated.

What Is the LGPD?

The LGPD (Law 13,709/2018) is Brazil's comprehensive data protection legislation. It establishes rules for how organizations — public and private — must collect, store, use, share, and delete personal data belonging to individuals located in Brazil.

The law was inspired by Europe's General Data Protection Regulation (GDPR) and shares many of its core principles, while being adapted to Brazil's specific legal and economic context.

The LGPD is enforced by the ANPD (Autoridade Nacional de Proteção de Dados), Brazil's data protection authority, which has the power to investigate complaints, impose fines of up to 2% of revenue (capped at R$50 million per violation), and require organizations to change their data practices.

What Does "Personal Data" Mean Under the LGPD?

This is the first critical point: personal data is any information that identifies or makes a natural person identifiable.

This definition is deliberately broad. It includes:

  • Name, CPF, RG, date of birth
  • Email address, phone number, home address
  • Financial data: account numbers, transaction history, credit scores
  • Biometric data: fingerprints, facial recognition data
  • Behavioral data: browsing patterns, purchase history, location data
  • IP addresses and device identifiers

The LGPD also establishes a special category of sensitive personal data, which receives heightened protection:

  • Racial or ethnic origin
  • Religious beliefs
  • Political opinions
  • Trade union membership
  • Health or sex life data
  • Biometric data (particularly relevant for payment KYC processes)
  • Genetic data

The key insight — and one that surprises many people — is that data does not need to be secret or confidential to be protected by the LGPD. Even publicly available information must be processed in compliance with the law's requirements.

The 10 Legal Bases for Data Processing

One of the LGPD's most important contributions is establishing that companies cannot process your data simply because they want to. Every processing activity must have a legal basis — a specific legitimate reason defined by the law.

There are 10 legal bases in total. These are the most relevant for consumers interacting with financial and payment services:

1. Consent

The company asks for your explicit, informed, specific agreement to process your data for a defined purpose. Consent must be freely given — it cannot be a condition for accessing a service unless the processing is strictly necessary.

Important: You can withdraw consent at any time. The company must make this easy to do.

2. Legitimate Interest

The company has a legitimate business interest in processing your data that does not override your rights and freedoms. This basis requires careful balance — the company must demonstrate that its interest is real, proportionate, and that it has considered the impact on you.

3. Contract Performance

Your data can be processed when it is necessary to fulfill a contract you have with the company, or to take steps before entering into one (such as a credit assessment).

4. Legal or Regulatory Obligation

When processing is required to comply with a legal duty — for example, anti-money laundering regulations that require financial institutions to identify their customers — your consent is not needed.

5. Regular Exercise of Rights in Legal Proceedings

Data can be processed when necessary for a company to exercise or defend legal claims.

6. Protection of Life

In genuine emergencies where life is at risk, data may be processed without consent.

The practical implication: When a payment institution processes your CPF, transaction history, or biometric data for KYC compliance or regulatory reporting, it typically operates under the legal obligation basis — not consent. This means your preference not to have this data processed does not prevent the processing from occurring. The law recognizes that certain public interests — preventing financial crime, protecting the financial system — outweigh individual data preferences in specific circumstances.

Your 9 Rights as a Data Subject Under the LGPD

The LGPD grants every individual in Brazil nine specific rights regarding their personal data. These are enforceable against any organization subject to the law:

1. Right to Confirmation and Access

You have the right to know whether a company holds personal data about you and to access that data in full.

How to exercise it: Submit a formal data access request to the company's Data Protection Officer (DPO) or designated channel.

2. Right to Correction

You can require a company to correct incomplete, inaccurate, or outdated personal data.

3. Right to Anonymization, Blocking, or Deletion

You can request that unnecessary, excessive, or unlawfully processed data be anonymized, blocked, or deleted.

Important limitation: This right does not apply when the data is being processed under a legal obligation basis — for example, data retained for regulatory compliance cannot be deleted simply because you request it.

4. Right to Portability

You can request that your personal data be transferred to another service provider in a structured, machine-readable format. This is particularly relevant in Brazil's Open Finance context.

5. Right to Information About Sharing

You have the right to know which third parties your data has been shared with, and why.

6. Right to Know About Consent Consequences

Before giving consent, you have the right to be informed about what will happen to your data if you do not consent — and what the consequences of consenting are.

7. Right to Withdraw Consent

When processing is based on consent, you can withdraw it at any time. Withdrawal does not affect the lawfulness of processing that occurred before withdrawal.

8. Right to Object

You can object to processing carried out under the legitimate interest basis if you believe your rights and freedoms override the company's interest.

9. Right to Review Automated Decisions

When a significant decision affecting you (credit approval, fraud flagging, account blocking) is made solely through automated processing, you have the right to request human review.

How the LGPD Applies to Payment Institutions Specifically

Payment institutions — including digital banks, payment processors, and fintech platforms — are among the most data-intensive organizations subject to the LGPD. They collect and process:

  • Identity data during KYC onboarding (CPF, RG, biometrics)
  • Financial transaction data (amounts, recipients, timing, location)
  • Behavioral data (transaction patterns, device fingerprints)
  • Credit and risk assessment data

Under the LGPD, these institutions must:

Appoint a Data Protection Officer (DPO) responsible for overseeing compliance and serving as the point of contact for data subject requests and the ANPD.

Maintain records of processing activities documenting what data is processed, for what purpose, on which legal basis, and for how long.

Implement appropriate security measures to protect personal data against unauthorized access, accidental loss, or destruction. The BACEN (Banco Central do Brasil) has issued its own cybersecurity resolution (Resolution 4,893/2021) that establishes additional security requirements for payment institutions.

Notify the ANPD and affected individuals in the event of a data breach that poses risk to data subjects — within a reasonable timeframe (ANPD guidelines suggest 72 hours for critical incidents).

Honor data subject rights requests within 15 days of receipt.

What to Do If Your LGPD Rights Are Violated

If a company fails to respond to your data rights request, refuses to delete data without legitimate grounds, shares your data without authorization, or suffers a breach that affects you:

Step 1 — Contact the company directly. Use the official DPO or data protection channel listed in their privacy policy. Document your request with date, content, and any response received.

Step 2 — Escalate to the ANPD. File a complaint at gov.br/anpd. The ANPD accepts complaints from individuals and has the authority to investigate and sanction non-compliant organizations.

Step 3 — Consider legal action. The LGPD explicitly states that data subjects may seek compensation for material and moral damages resulting from violations. Individual claims and class actions are both legally available.

Step 4 — Report financial institution violations to BACEN. For payment-specific violations — particularly those related to KYC data, financial transaction data, or cybersecurity — the Banco Central is an additional relevant authority.

The Broader Picture: Why LGPD Matters for Financial Inclusion

The LGPD is not just a compliance framework — it is an architecture of trust. By establishing clear rules for how personal data must be handled, it creates the conditions under which consumers can engage with digital financial services with confidence.

For the millions of Brazilians who have entered the digital financial system through Pix, digital wallets, and fintech apps in recent years, knowing that their data is protected by law — and that they have enforceable rights when that protection fails — is foundational to continued participation.

Institutions that treat LGPD compliance as a genuine commitment rather than a checklist contribute to this trust. Those that treat it as a box to tick undermine it.

Conclusion

The LGPD gives Brazilian consumers real, enforceable rights over their personal data — including in the financial services context where that data is most sensitive and most consequential.

Understanding these rights is not just academic. It is a practical tool for navigating the digital economy more safely, holding institutions accountable when they fall short, and making informed decisions about who deserves your data — and your trust.

OneKey Payments is fully compliant with Brazil's LGPD, maintaining documented data processing records, a designated DPO, robust security standards aligned with BACEN Resolution 4,893/2021, and transparent privacy policies across all operations.

Learn how OneKey Payments handles your dataCompliance & Regulation | Brazil Operations

Recent Posts
June 3, 2026
How to Know If a Payment Platform Is Truly Trustworthy: 7 Signs That Matter
Not all payment platforms are equal. Behind the polished interfaces, the reassuring padlock icons, and the "bank-level security" marketing claims, there are meaningful differences in how platforms are built, regulated, and operated — differences that directly affect how safe your money and data are.
June 3, 2026
Phishing, Clean Desk & Strong Passwords: The 3 Pillars of Digital Security Every Consumer Should Know
Information security often sounds like a corporate concern — something for IT departments, not everyday people. But every consumer who uses online banking, digital wallets, payment apps, or e-commerce platforms is, in practice, responsible for securing their own digital environment.
June 3, 2026
When Can a Company Use Your Data Without Your Consent? LGPD Explained
There is a widespread misconception about Brazil's data protection law that needs to be addressed directly: the LGPD does not require consent for every use of personal data.
June 3, 2026
What Is LGPD? Your Personal Data Rights as a Consumer in Brazil
Every time you open a financial app, complete an online purchase, or register for a digital service in Brazil, your personal data is being collected, processed, and stored. The entity doing this has legal obligations toward you — obligations established by one of the most important laws in Brazil's recent history.
June 3, 2026
Conflict of Interest in Financial Services: What It Is and How to Spot It
When you ask a bank representative which product you should choose, are they recommending what is best for you — or what earns them the highest commission? When a payment platform routes your transaction through a specific provider, is it because that provider offers the best rate — or because of a commercial arrangement that benefits the platform at your expense?
June 3, 2026
What Is Ethical Conduct in Finance — and Why It Protects You as a Consumer
Every time you open a bank account, make an online payment, or share your financial data with a platform, you are placing trust in an institution. But what exactly makes a financial institution worthy of that trust?
kyc verification protection againts fraud
April 22, 2026
KYC Verification: Protection Against Fraud and Money Laundering
KYC (Know Your Customer) verification has become a fundamental process for companies operating in financial and digital sectors, especially in Latin America.
March 25, 2026
How to reduce cart abandonment with better payment options
The average cart abandonment rate is 70.19% in 2025, meaning that seven out of ten carts are abandoned before the transaction is completed.
March 18, 2026
Pix with Biometrics: How to Simplify Payments in Brazil and Increase Conversion
Brazil’s payment ecosystem continues to evolve, and one of the most promising innovations is Pix with facial biometrics
March 13, 2026
Foreign Exchange Risk in LatAm: How to Protect Your Business in International Transactions
Cross-border commerce represents a huge growth opportunity for modern businesses, but it also introduces a financial risk that many companies underestimate: foreign exchange risk.
March 13, 2026
Local vs. International Payment Methods: Which One Should You Choose?
If you run an online business in Latin America, you’ve probably experienced a frustrating paradox: customers attempting to pay with international credit cards see their transactions rejected for no apparent reason.
March 2, 2026
SBC Summit Rio 2026: One Key Payments and Virtual Pix at the Heart of Brazilian Payments
SBC Summit Rio 2026, taking place March 3–5 in Rio de Janeiro, brings together over 15,000 gaming, betting, and fintech professionals to shape the future of instant payments such as Pix.
Financial Fraud and Digital Security: How to Protect Your Money in the Online World
Every day, new scams and financial frauds emerge, trying to deceive ordinary people.With the rise of digital transactions, staying well-informed is essential to protect your data, your money, and your peace of mind.In this article, you'll learn how to identify scams, avoid traps, and keep your financial life safe in the digital environment.
Personal Budgeting and Financial Planning
Have you ever reached the end of the month without knowing where your money went? If so, you're not alone. Most people were never taught—practically speaking—how to manage their personal finances. But the good news is: that can change! In this article, we at OneKey will show you how to create a personal budget and financial plan in a simple, practical, and effective way.
Basic Banking Education: How to Understand and Make the Most of Your Bank’s Services
Did you know that many people pay bank fees without knowing why? Or miss out on free services simply because they don’t know they exist? In this article, we at OneKey will cover the fundamentals of banking education so you can use the financial system to your advantage and make smarter choices with your money!
June 26, 2025
Recurring payments reshaping LATAM
Recurring payments in LATAM are shifting from billing tools to growth engines—driving loyalty, automation, and revenue predictability.
June 26, 2025
The Power of PIX Biometrics in Brazil
From slow bank transfers to instant Pix, Brazil leads in real-time, secure, and scalable payments through bold financial innovation.
June 26, 2025
Leading Pix Biometric implementation
Pix with biometrics removes friction at checkout, boosts security and enables recurring flow: reshaping digital commerce in Brazil