Brazil LGPD (Lei 13.709/2018) Compliance — EPPA¶
EPPA processes Art. 11 sensitive data of Brazilian patients only after ANPD-aligned safeguards are in place
The LGPD treats health data with stricter conditions than ordinary personal data (Art. 11). Several mechanisms that work for non-sensitive data — including the broad legitimate-interest basis — are not available for sensitive data. Until the safeguards in §4 to §6 below are in place, EPPA must not be deployed in Brazil outside an explicit-consent research protocol.
1. Document identity¶
| Field | Value |
|---|---|
| Document title | Brazil LGPD Compliance — EPPA |
| Document ID | EPPA-BR-LGPD-001 |
| Version | 0.1 (draft) |
| Status | Draft — not approved |
| Effective date | n/a |
| Owner | LABIS UCA — Brazil Privacy lead (to be appointed) |
| Linked documents | 00-overview.md, 30-gdpr-dpia.md, 50-secdev-checklist.md |
2. Regulatory anchors¶
- Lei 13.709/2018 — Lei Geral de Proteção de Dados Pessoais (LGPD), amended by Lei 13.853/2019 and Lei 14.010/2020.
- Resolução CD/ANPD 1/2021 — Regulamento do processo de fiscalização e do processo administrativo sancionador.
- Resolução CD/ANPD 2/2022 — Regulamento de aplicação da LGPD para agentes de tratamento de pequeno porte.
- Resolução CD/ANPD 4/2023 — Regulamento de dosimetria e aplicação de sanções administrativas.
- Resolução CD/ANPD 15/2024 — Verify current number/title — guidance on data subject rights handling [TBD verify].
- Constituição Federal Art. 5 inc. LXXIX (added by EC 115/2022) — fundamental right to personal data protection.
- ANVISA RDC 751/2022 — software como dispositivo médico (parallel device-regulation track for EPPA).
3. Scope of LGPD applicability¶
Per Art. 3, LGPD applies when:
- The processing operation is carried out in Brazilian territory;
- The processing aims to offer or supply goods or services to, or process data of, individuals located in Brazilian territory; or
- The data being processed was collected in Brazilian territory.
EPPA deployed in a Brazilian clinic satisfies the first two prongs. Even an extraterritorial cloud deployment processing data of Brazilian patients falls within LGPD scope.
4. Sensitive personal data (Art. 5 inc. II + Art. 11)¶
4.1 Definition¶
Art. 5 inc. II defines "dado pessoal sensível" as data relating to racial or ethnic origin, religious conviction, political opinion, trade-union or religious-organisation membership, dado referente à saúde, sex life, genetic data and biometric data — when linked to a natural person.
EPPA processes:
- Dado referente à saúde — postural-assessment outputs, markers, clinical interpretation.
- Dado biométrico — facial features visible in the photographs.
Both are sensitive personal data under Art. 5 inc. II.
4.2 Lawful basis for sensitive data (Art. 11)¶
Unlike Art. 7 (which lists ten bases for ordinary personal data, including the broad "legitimate interest" of Art. 7 inc. IX), Art. 11 lists a narrower set for sensitive data:
| Art. 11 | Basis | EPPA applicability |
|---|---|---|
| inc. I | Specific, prominent and informed consent of the data subject or legal representative | Default for clinical research deployments. |
| inc. II(a) | Statutory or regulatory compliance by the controller | Not applicable. |
| inc. II(b) | Shared processing necessary to execute public policies provided for in laws or regulations | Not applicable (LABIS is a private university). |
| inc. II(c) | Studies by research entities, ensuring whenever possible the anonymisation of sensitive data | Available for academic research with face-blur / pseudonymisation. |
| inc. II(d) | Regular exercise of rights, including in contract and judicial procedures | Not applicable. |
| inc. II(e) | Protection of life or physical integrity | Not applicable. |
| inc. II(f) | Health protection, in procedures performed by health professionals, health services or health authorities | Available in a treating-clinician deployment. |
| inc. II(g) | Guarantee of fraud prevention and security of the holder, in identification and authentication processes in electronic systems | Not applicable. |
Legitimate interest does not apply to sensitive data
The Art. 7 inc. IX legitimate-interest basis is not available for sensitive data under Art. 11. This is a load-bearing difference from GDPR Art. 9 — in GDPR, Art. 9(2)(j) "scientific research with appropriate safeguards" mirrors LGPD Art. 11 inc. II(c) closely, but LGPD has no legitimate-interest fallback for sensitive data at all.
For EPPA, the default is Art. 11 inc. I (explicit consent), with Art. 11 inc. II(c) (research) as alternative when explicit consent is infeasible and anonymisation is practical.
5. Roles, controller and operator (Art. 5 incs. VI–VIII)¶
| LGPD term | Definition (Art. 5) | EPPA role |
|---|---|---|
| Controlador | Natural or legal person that takes decisions regarding processing | LABIS UCA in the research-use phase; the deploying clinic in a clinical deployment |
| Operador | Natural or legal person that processes personal data on behalf of the controller | Hosting provider, SMTP relay, backup processor |
| Encarregado (DPO) | Person appointed by the controller and operator | LABIS UCA must appoint one before Brazilian deployment |
5.1 DPO (Encarregado) requirement — Art. 41¶
Art. 41 requires the controller to appoint a DPO. The DPO's identity and contact information must be publicly disclosed, clearly and objectively, preferably on the controller's website.
Resolução CD/ANPD 2/2022 grants reduced obligations for "small-size processing agents", which may not be obliged to appoint a DPO under §5 of that resolution; however, processing sensitive health data on a non-trivial scale generally precludes the small-size exemption.
For EPPA, the conservative position is to appoint a DPO.
6. International transfers (Art. 33 to Art. 36)¶
6.1 General regime¶
Art. 33 enumerates the conditions under which international transfer of personal data is permitted. The conditions parallel GDPR Chapter V but diverge in detail.
| Art. 33 | Mechanism | EPPA applicability |
|---|---|---|
| inc. I | To countries or international organisations recognised by ANPD as providing an adequate level of protection | Argentina-EU-Brazil adequacy chain TBD; ANPD has not published an adequacy decision list as of date of this document |
| inc. II | Where the controller offers and proves guarantees of compliance with LGPD, including specific contractual clauses, standard contractual clauses, global corporate norms or seals/certifications regularly issued | Default for EPPA — ANPD-approved standard clauses (Resolução CD/ANPD 19/2024 [TBD verify number]) |
| inc. III | When the transfer is necessary for international legal cooperation | Not applicable |
| inc. IV | When the transfer is necessary for the protection of the life or physical integrity of the data subject or third party | Not applicable |
| inc. V | When the ANPD authorises the transfer | Per-case |
| inc. VI | When the transfer results from a commitment assumed in an international cooperation agreement | Not applicable |
| inc. VII | When the transfer is necessary for the execution of a public policy or attribution of public service | Not applicable |
| inc. VIII | When the data subject has provided specific and highlighted consent for the transfer, with prior information about the international nature of the operation, clearly distinguishing it from other purposes | Available as a backup |
| inc. IX | When necessary for the execution of a contract or preliminary procedures related to a contract of which the data subject is a party, at his/her request | Not applicable |
| inc. X | When necessary for the regular exercise of rights in judicial, administrative or arbitration procedures | Not applicable |
6.2 EPPA transfer matrix (Brazil-deployment scenario)¶
| Flow | Origin | Destination | Mechanism |
|---|---|---|---|
| App hosting (planned EU region) | BR clinic | EU | Art. 33 inc. II — ANPD standard contractual clauses with the hosting provider |
| App hosting (planned US region) | BR clinic | US | Art. 33 inc. II — ANPD standard clauses + DPIA (RIPD) per Art. 38 |
| Research-data sharing with Argentina co-investigator | BR | AR | Art. 33 inc. II — clauses; AR is not yet ANPD-adequate even though it is GDPR-adequate |
| Research-data sharing with EU co-investigator | BR | EU | Art. 33 inc. II — clauses + research-protocol consent |
ANPD adequacy list pending
As of the date of this document, ANPD has not published an adequacy decision recognising specific countries. Until that list exists, Art. 33 inc. I is unavailable in practice and every international transfer must rely on Art. 33 inc. II or inc. VIII. Monitor ANPD publications.
7. Data subject rights (Art. 18)¶
| Right | Article | EPPA SLA |
|---|---|---|
| Confirmação da existência de tratamento | Art. 18 inc. I | Within 15 days from request (Art. 19 §3) |
| Acesso aos dados | Art. 18 inc. II | Within 15 days |
| Correção | Art. 18 inc. III | Reasonable time |
| Anonimização, bloqueio ou eliminação de dados desnecessários, excessivos ou tratados em desconformidade | Art. 18 inc. IV | Reasonable time |
| Portabilidade | Art. 18 inc. V | Subject to ANPD regulation |
| Eliminação dos dados pessoais tratados com base no consentimento (com exceções) | Art. 18 inc. VI | After consent withdrawal |
| Informação sobre entidades públicas e privadas com as quais o controlador realizou uso compartilhado | Art. 18 inc. VII | On request |
| Informação sobre a possibilidade de não fornecer consentimento e sobre as consequências da negativa | Art. 18 inc. VIII | At collection |
| Revogação do consentimento | Art. 18 inc. IX, Art. 8 §5 | Immediate |
8. Incident notification (Art. 48)¶
Art. 48 requires the controller to notify the ANPD and the affected data subjects of any security incident that may create relevant risk or damage to data subjects. The wording:
O controlador deverá comunicar à autoridade nacional e ao titular a ocorrência de incidente de segurança que possa acarretar risco ou dano relevante aos titulares.
Unlike GDPR Art. 33 (72-hour fixed window), LGPD Art. 48 §1 specifies "em prazo razoável" — a reasonable time — and references the ANPD to specify this. In practice, ANPD guidance and Resolução CD/ANPD 15/2024 [TBD verify number/date] indicate a target of within two business days from knowledge for notifications to ANPD, with the data-subject notification on a slightly extended timeline.
8.1 Required content of incident notification (Art. 48 §1)¶
- Description of the nature of the affected personal data.
- Information about the data subjects involved.
- Indication of the technical and security measures used.
- Risks related to the incident.
- Reasons for delay, if applicable.
- Measures taken or to be taken to mitigate the effects of the loss.
EPPA's incident-response runbook (planned in
50-secdev-checklist.md) must produce this
content on a 24-hour SLA from confirmed incident.
9. DPIA (Relatório de Impacto à Proteção de Dados Pessoais — RIPD), Art. 38¶
Art. 38 empowers ANPD to require an RIPD ("Relatório de Impacto à Proteção
de Dados Pessoais") from the controller, particularly for high-risk
processing such as sensitive data. The GDPR DPIA in
30-gdpr-dpia.md is closely analogous and can be
adapted to LGPD requirements with the following deltas:
| GDPR Art. 35 element | LGPD Art. 38 / 50 equivalent | Notes |
|---|---|---|
| Description of processing and purpose | Same | Use GDPR DPIA §2 verbatim with LGPD reference. |
| Necessity and proportionality | Same | Re-reference Art. 11 inc. I or inc. II(c) instead of Art. 9(2)(j). |
| Risk assessment | Same | Reuse §4 of the GDPR DPIA. |
| Measures envisaged | Same | Reuse §5 of the GDPR DPIA. |
| Consultation with the DPO | Same | The DPO must be consulted. |
| ANPD consultation in high residual risk | Same in spirit | Art. 38 confers ANPD discretion. |
The RIPD must be available to ANPD on demand.
10. LGPD vs GDPR — load-bearing differences¶
| Topic | GDPR | LGPD | Implication for EPPA |
|---|---|---|---|
| Legitimate interest for sensitive data | Available under Art. 9(2)(g)–(j) with specific conditions | Not available — Art. 11 list is exhaustive | Always use consent or research-anonymisation basis |
| Incident notification | 72 hours from knowledge (Art. 33) | "Reasonable time" — ANPD guidance ≈ 2 business days [TBD] | Faster SLA in practice; align with the tighter of the two |
| Data subject right of access | 1 month (Art. 12(3)) | 15 days (Art. 19 §3) | EPPA SLA must be 15 days |
| Adequacy decisions | EU Commission publishes list | ANPD has not published a list yet | All international transfers via clauses (Art. 33 inc. II) |
| Sanctions cap | €20 M or 4 % global turnover | 2 % of revenue in Brazil, capped at BRL 50 M per infraction (Art. 52) | Different cap but still material |
| DPO disclosure | Generally required for sensitive data | Required + must be publicly disclosed (Art. 41 §1) | EPPA must publish DPO contact on the website |
| Privacy by design | Recital 78 | Art. 46 §2 | Same substantive standard |
| Anonymisation | Recital 26 | Art. 5 inc. III, Art. 12 | LGPD defines anonymisation; anonymised data is out of LGPD scope (Art. 12) |
11. ANPD oversight¶
The Autoridade Nacional de Proteção de Dados is the enforcement authority. It can:
- Issue warnings (Art. 52 inc. I).
- Impose simple fines (Art. 52 inc. II) up to 2 % of revenue in Brazil, capped at BRL 50 M.
- Impose daily fines (Art. 52 inc. III).
- Order the publication of the violation (Art. 52 inc. IV).
- Order blocking or elimination of the data (Art. 52 inc. V to VII).
- Suspend or prohibit processing (Art. 52 inc. X to XII).
Resolução CD/ANPD 4/2023 (dosimetry) lays out the methodology for calibrating sanctions.
12. Records of processing (Art. 37)¶
The controller must keep a record of processing operations. Required
content overlaps the GDPR Art. 30 ROPA. EPPA's ROPA skeleton in
30-gdpr-dpia.md §8 must be extended with LGPD-specific
columns:
- Hipótese legal aplicável (Art. 11 inc. I, II(c), II(f)).
- Encarregado (DPO) identified.
- Transferências internacionais com base no Art. 33.
13. Open questions¶
- Confirm ANPD adequacy list. Monitor ANPD publications for the first adequacy decisions.
- Confirm ANPD international transfer clauses. Verify the current Resolução number publishing the model contractual clauses (Resolução CD/ANPD 19/2024 is the working reference; verify).
- Confirm incident notification SLA. Resolução CD/ANPD 15/2024 (or equivalent) is the operative guidance; verify and lock the EPPA SLA.
- Confirm small-size exemption applicability. Likely not applicable given sensitive-data processing scale, but document the determination.
References¶
- Lei 13.709/2018 (LGPD) — https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
- Lei 13.853/2019 (amendments to LGPD) — https://www.planalto.gov.br/ccivil_03/_ato2019-2022/2019/lei/l13853.htm
- Constituição Federal Art. 5 inc. LXXIX (EC 115/2022) — https://www.planalto.gov.br/ccivil_03/constituicao/emendas/emc/emc115.htm
- Resolução CD/ANPD 1/2021 (fiscalisation) — https://www.gov.br/anpd/pt-br/assuntos/regulacao
- Resolução CD/ANPD 2/2022 (small agents) — https://www.gov.br/anpd/pt-br/assuntos/regulacao
- Resolução CD/ANPD 4/2023 (dosimetry of sanctions) — https://www.gov.br/anpd/pt-br/assuntos/regulacao
- ANPD — Autoridade Nacional de Proteção de Dados — https://www.gov.br/anpd/pt-br
- ANPD — Guia de Tratamento de Incidentes de Segurança — https://www.gov.br/anpd/pt-br/documentos-e-publicacoes
- ANVISA RDC 751/2022 (software como dispositivo médico) — https://www.gov.br/anvisa/pt-br
- Regulamento (UE) 2016/679 (GDPR) — https://eur-lex.europa.eu/eli/reg/2016/679/oj