Skip to content
Back to the blog
Privacy & LGPD

LGPD: fines can reach R$50 million — and they're already being applied

1 min read

Enforcement of Brazil's General Data Protection Law is no longer theoretical. Here's how big the risk is if you launch an app without caring about privacy.

Brazil's General Data Protection Law (LGPD, Law No. 13,709/2018) provides, in Article 52, for fines of up to 2% of the company's revenue in Brazil, capped at R$50 million per infraction. Beyond the fine, the National Data Protection Authority (ANPD) can issue warnings, block processing, and even order the deletion of data handled irregularly.

For years the law was seen as a "dead letter," but that's changed: in 2023 the ANPD applied its first sanctions and published its sanction-calculation regulation (Resolution CD/ANPD No. 4/2023), detailing how fines are computed. In other words, the risk stopped being theoretical.

For an indie app, the most common exposure points are cheap to fix and expensive to ignore: no clear privacy policy, no legal basis for collecting data, cookies without consent, and no channel for data subjects to exercise their rights. Fixing this early costs little; discovering it after a complaint costs a lot.

Put this knowledge into practice

Get real feedback and run security and privacy checks on your app, built with AI or by hand.

Create a free account