FreePrivacyPolicy

LGPD privacy policy generator (Lei Geral de Proteção de Dados)

Generate a Brazilian-law-compliant privacy policy that satisfies ANPD's 2024 guidelines.

Generate LGPD-ready policy Free. Try it without an account.

What LGPD requires

Lei 13.709/2018 (LGPD) tracks GDPR closely but with three Brazilian particularities: (1) the role of the encarregado (DPO) is mandatory in more cases than under GDPR, (2) ANPD has issued specific rules for international transfers under Resolution CD/ANPD No. 4/2023, and (3) the legal bases include "credit protection" — relevant for fintechs. The generator handles all three.

Encarregado (DPO)

Article 41 requires every controller to appoint an encarregado (data protection officer). Small companies that are not "large-volume processors" can use a shared or external DPO. The generator publishes a contact email for the encarregado in the policy footer, which is the form ANPD expects.

Direitos do titular

Article 18 grants nine rights: confirmation of processing, access, correction, anonymisation/blocking/deletion, portability, deletion of data processed under consent, information about data sharing, information about consequences of refusing consent, and revocation of consent. The generator emits each as a labelled section with a Brazilian Portuguese fallback if you select PT-BR as the operating country.

Ready to publish?

Answer a few questions and get a hosted address that the App Store, Google Play and ad networks accept.

Generate LGPD-ready policy

Frequently asked questions

My company is outside Brazil. Does LGPD apply?
Yes, if you (a) process personal data collected in Brazil, (b) offer goods or services to people in Brazil, or (c) process data of people located in Brazil — Article 3, LGPD.
What is the LGPD fine ceiling?
Up to 2% of revenue in Brazil in the previous fiscal year, capped at R$ 50 million per infraction (Article 52). ANPD has been issuing fines since mid-2023.
Does LGPD require a DPIA?
A Relatório de Impacto à Proteção de Dados Pessoais (RIPD / DPIA) is required when processing high-risk data — for example biometric, financial, or large-scale profiling. The generator does not output a RIPD itself, but the privacy policy section flags when one is recommended.