Skip to content
Regulation & Compliance

LGPD

Lei brasileira que regula o tratamento de dados pessoais, aplicável a empresas que coletam e processam dados de usuários, inclusive prestadores de cripto.

Key points

  • The LGPD is the Brazilian law that regulates how personal data can be collected, used, stored, and shared.
  • It applies to companies that process people's data, including crypto service providers that carry out customer identification.
  • It establishes rights for data subjects and duties for organizations, with liability in case of non-compliance.

What is the LGPD?

LGPD stands for Lei Geral de Proteção de Dados, Brazil's general data protection legislation, which governs the processing of personal data. It sets rules on how organizations can collect, use, store, and share information that identifies or can identify a person. Its goal is to protect privacy and give people more control over their own data, imposing obligations on those who process it and providing for consequences for those who fail to comply with the law.

How it works

The LGPD starts from the idea that the processing of personal data needs a legitimate basis and must respect principles such as purpose, necessity, and transparency. People, referred to as data subjects, gain rights, such as knowing what data an organization holds about them, correcting information, and, in certain cases, requesting its deletion. Organizations, in turn, take on duties of security, transparency, and accountability, and may be held liable for damages and sanctions in case of non-compliance.

For virtual asset service providers, the LGPD is especially relevant. These services typically collect a lot of personal data, particularly when fulfilling customer identification and financial crime prevention obligations. This creates a delicate intersection: on one hand, compliance rules require collecting and retaining information; on the other, data protection imposes care over how that information is handled. Reconciling these requirements is part of the challenge facing those who operate in the sector.

In practice, complying with the LGPD involves adopting security measures to protect data, being transparent about its use, respecting the rights of data subjects, and having processes in place to handle incidents, such as data breaches. There is an authority responsible for overseeing enforcement of the law and guiding its interpretation. As rules and interpretations evolve, compliance requires ongoing monitoring. The concrete application to each situation depends on the rules in force and usually requires the support of specialized professionals.

Understanding the LGPD helps explain why data protection is a central responsibility for companies that process user information.

Why it matters

Understanding the LGPD helps clarify the responsibilities involved in protecting personal data, especially in crypto services that collect a lot of data for compliance purposes. For a company, this is a core obligation. This is an educational explanation and does not constitute legal or compliance advice of any kind.

Risks and limitations

Reconciling data protection with compliance requirements that demand collecting information is a practical and sensitive challenge. Rules and interpretations evolve, requiring ongoing monitoring. This text is educational and does not replace guidance from specialized professionals or consultation of applicable regulations and the competent authority.