Brazil's LGPD (Lei Geral de Proteção de Dados) closely mirrors GDPR and is enforced by the ANPD. The Central Bank also imposes strict open banking and fintech regulations.
Cleo monitors enforcement actions and guidance from these authorities in real time.
Key regulatory frameworks monitored by Cleo in Brazil.
Explore sector-specific regulatory requirements.
LGPD shares GDPR's core principles but has different legal bases, lighter penalties, and unique provisions. Cleo maps both and highlights gaps for companies operating in both jurisdictions.
The ANPD can impose fines of up to 2% of Brazilian revenue (capped at R$50 million per violation), daily penalty payments, data processing suspensions, and public disclosure of violations. Enforcement has accelerated since the first fine in 2023.
LGPD does not require strict data localization, but the Central Bank mandates that certain financial data be stored in Brazil. International data transfers are permitted under adequacy decisions, standard clauses, or specific consent. Cleo tracks evolving ANPD transfer guidance.

Run a free scan and see your regulatory perimeter mapped by AI in minutes.