Brazil — LGPD for Email Marketing
LGPD legal bases for email marketing (consent vs. legitimate interest per the ANPD guide), controller/operator roles as they hit ESPs, international transfer state (Resolução 19/2024, EU adequacy), children's-data position, and sanctions up to R$50M.
Reference10 min read
Who it is for Compliance teams, Senders
Applies to senders on any platform
ContentsOn this page — 6 sections
If you send email marketing to recipients in Brazil, the rules come from a data protection law, not from an anti-spam law. Brazil has no dedicated anti-spam statute. Email marketing to Brazilian recipients is governed by the Lei Geral de Proteção de Dados (LGPD, Lei nº 13.709/2018), a law in the style of the GDPR.
The ANPD enforces it. MP 1.317/2025 and Lei 15.352/2026 renamed it from Autoridade to Agência Nacional de Proteção de Dados, giving it the status of a regulatory agency. Unlike CASL, PECR or the Spam Act, the LGPD has no opt-in rule for each message. Instead, every processing of an email address (a piece of personal data, Art. 5 I) needs a legal basis, transparency, and respect for the rights of the data subject. The sources were read in the original Portuguese.
Legal bases for marketing (Art. 7)
Art. 7 lists ten legal bases. These two matter for marketing:
| Basis | Text | Marketing implications |
|---|---|---|
| Consent (Art. 7 I) | A free, informed and unambiguous expression of will for a determined purpose (Art. 5 XII) | Written or otherwise demonstrable (Art. 8). If written, it must be in a clause highlighted from the other contract terms (Art. 8 §1). Generic authorisations are void (Art. 8 §4). The controller bears the burden of proof (Art. 8 §2). Consent can be revoked at any time through a free and facilitated procedure (Art. 8 §5). Sharing with other controllers requires specific consent (Art. 7 §5), so a purchased list needs consent that names the buyer. |
| Legitimate interest (Art. 7 IX) | Processing necessary to serve the legitimate interests of the controller or a third party, except where the data subject's fundamental rights and freedoms prevail | Art. 10 expressly names "support and promotion of the controller's activities" (Art. 10 I) as a possible legitimate purpose, which is the basis for first-party marketing. The conditions: only data that is strictly necessary (Art. 10 §1), transparency measures (Art. 10 §2), and the ANPD may demand a data protection impact report (RIPD, Art. 10 §3). |
The other bases (performing a contract, a legal obligation, credit protection and so on) rarely support promotional email. Data that is public, or that the data subject has made manifestly public, still requires a purpose, good faith and respect for the data subject's rights (Art. 7 §§3–4). Public data is not free to use for marketing.
The ANPD legitimate-interest guide (Guia de Legítimo Interesse, Feb 2024)
The ANPD's guide sets out how Art. 7 IX and Art. 10 work in practice:
- An interest is legitimate when it is (i) compatible with the legal order, (ii) grounded in concrete situations (not abstract or speculative ones), and (iii) tied to legitimate, specific and explicit purposes.
- A balancing test (teste de balanceamento) must come before any reliance on legitimate interest, for each specific purpose. It weighs legitimacy, necessity, the impact on the data subject, and the data subject's legitimate expectations (Art. 10 II). If the test is inconclusive, or if adequate safeguards cannot be identified, use another legal basis.
- Factors for legitimate expectations: a prior direct relationship with the controller; the source and manner of collection (directly, or from a third party or public source); context and timing; and whether the marketing purpose is compatible with the purpose of collection.
- Example 5 is the reference case for marketing. A private university emailed students and staff promotions for books and cultural products from its own press, and this was accepted as legitimate interest. There was a prior relationship, the promotion supported the controller's own activities (Art. 10 I), the data was not shared with third parties, and every message carried an unsubscribe (descadastramento) mechanism as a safeguard. In practice, first-party marketing to your own customer base, with a working opt-out, can rest on legitimate interest. Cold email to strangers cannot, because there is no prior relationship and no legitimate expectation.
- Legitimate interest of a third party (Example 6: promoting a partner language school to employees) is possible, but it is harder to justify. Prior notice, an easy way to refuse, and a balancing test are expected.
- Legitimate interest is generally inappropriate for using data about children and adolescents for advertising. In Example 3, an educational app that shows ads for ultra-processed food to children fails the test, because there is no legitimate expectation and the principle of the child's best interest is violated.
- Record-keeping duty: keep the balancing test and the processing records (Art. 37 highlights records "especially when based on legitimate interest"). High-risk processing calls for a RIPD.
Data-subject rights that shape list management (Arts. 18–19)
- Confirmation that processing exists, and access to the data (in a simplified format immediately, or as a complete statement within 15 days).
- Correction; anonymisation, blocking or deletion of data that is unnecessary or non-compliant; deletion of data processed on the basis of consent (Art. 18 VI); information about sharing (Art. 18 VII); revocation of consent (Art. 18 IX); and opposition to processing that is not based on consent (Art. 18 §2). Legally, an unsubscribe is a revocation or an opposition, and it must be free of charge (Art. 18 §5).
- After a correction, deletion or blocking, the controller must notify the parties it shared the data with, so they do the same (Art. 18 §6). Suppression must therefore propagate.
Agents of treatment: controller vs. operator, and where the ESP sits
Definitions (Art. 5): the controlador (VI) makes the decisions about processing; the operador (VII) processes on behalf of the controller. Together they are the agentes de tratamento (IX). The ANPD's Guia Orientativo on agents (May 2021) explains how the roles apply:
- What distinguishes them is decision power. The controller sets the purpose and the "essential elements" (types of data, duration). The operator may decide only non-essential elements (software, technical security measures). An advertising or marketing agency that runs a campaign to the brand's specification is an operator, and the brand is the controller (guide ¶¶10–11, Example 5).
- An ESP is an operator for its customers' lists. It must process data only according to the controller's instructions (Art. 39), and should set out the arrangement in a written contract covering the object, duration, nature and purpose, types of data, and responsibilities. The guide recommends this contract but does not mandate it (¶¶53–54).
- A suboperator is a party the operator engages to help process data for the controller. This is the guide's own concept; examples are the ESP's cloud or storage vendor, or a subcontractor for delivery. The operator should obtain the controller's formal authorisation to subcontract, which may be generic or specific. Towards the ANPD, the suboperator is treated as an operator (¶¶61–66, Examples 11–12).
- Joint controllership exists when two or more controllers make common or converging decisions on the purposes and essential elements. In Example 5, two brands that share customer bases for a co-branded campaign are joint controllers, while their marketing agency remains an operator. Controllers directly involved are jointly and severally liable (Art. 42 §1 II).
- Liability (Art. 42): a controller or operator that causes damage must repair it. The operator is jointly and severally liable, just like the controller, when it breaches the LGPD's obligations or fails to follow the controller's lawful instructions (Art. 42 §1 I). Courts may reverse the burden of proof in the data subject's favour (Art. 42 §2). The practical consequence for an ESP: sending beyond the customer's instructions, or ignoring suppression, makes the ESP liable alongside the customer, as if it were a controller.
- Both agents must keep records of processing operations (Art. 37). The controller (and the operator) must appoint an encarregado (a data protection officer, DPO, Art. 41) and publish their contact details. The ANPD may waive this for small agents. Resolução CD/ANPD 2/2022 also classes the use of children's data as "high risk", even for small agents.
International transfers (Arts. 33–36, Resolução CD/ANPD nº 19/2024)
Art. 33 permits transfers:
- (I) to countries or international organisations with an adequate level of protection;
- (II) with guarantees provided by the controller: specific contractual clauses, standard contractual clauses (SCCs), global corporate norms, or seals, certificates and codes of conduct;
- (V) with authorisation from the ANPD;
- (VIII) with specific and highlighted consent, after the data subject has been told the operation is international;
- and in narrow cases of public interest, vital interest or legal obligation (IX).
The current state, according to the ANPD's international affairs page (fetched Jul 2026):
- Regulation: Resolução CD/ANPD nº 19 of 23 Aug 2024 approved the transfer regulation, including Brazilian SCCs. Existing contracts had a 12-month deadline from publication to incorporate the SCCs (that is, by Aug 2025).
- Adequacy decisions: the ANPD has recognised the European Union as adequate (Resolução CD/ANPD nº 32 of 26 Jan 2026). No other country is listed. This decision is separate from the transfer regulation above. Resolução 19/2024 is Brazil's domestic transfer framework (the Brazilian SCCs), while Resolução 32/2026 is the ANPD's recognition of the EU as adequate for data leaving Brazil. It is the Brazilian half of a mutual recognition: on the same date (26 Jan 2026), the European Commission adopted its own Art. 45 adequacy decision for Brazil (Implementing Decision (EU) 2026/179). Transfers between the EU and Brazil now flow in both directions without SCCs (see ESP Processor Obligations).
- Equivalent foreign SCCs, specific clauses and BCRs (global corporate norms): the mechanism exists, but none has been approved to date. Requests go through the ANPD's SEI system.
- The consequence for ESPs: a non-Brazilian ESP that processes Brazilian lists abroad should include the Brazilian SCCs in its data processing agreement (DPA) with Brazilian customers, or use another Art. 33 mechanism.
Children and adolescents (Art. 14 and the ANPD's interpretation)
- Art. 14: processing of data about children and adolescents must serve their best interest. Art. 14 §1 requires specific, highlighted consent from at least one parent or legal guardian for children's data. The controller must make reasonable efforts to verify the adult who consents (§5), must not make participation in games or apps conditional on providing more data than needed (§4), and must publish what it collects and how (§2). Data may be collected without consent only to contact the parents (for a single use, without storage) or to protect the child (§3), and it may never be transferred onward (§3).
- The ANPD document listed in the sources is the 2022 normative process (Nota Técnica nº 34/2022/CGN and Estudo Preliminar). It examined whether parental consent is the only legal basis. Its conclusion, interpretation 3, became Enunciado CD/ANPD nº 1 (22 May 2023): data about children and adolescents may be processed on any legal basis in Art. 7 (or Art. 11 for sensitive data), provided the best interest of the child prevails, assessed case by case under the main text of Art. 14.
- According to the legitimate-interest guide, however, advertising to children on the basis of legitimate interest will normally fail the balancing test. Processing children's data is a designated high-risk criterion that requires a RIPD. For email marketing, in practice, treat lists of under-18 recipients as requiring parental consent.
Sanctions (Art. 52)
The ANPD applies sanctions after administrative proceedings, progressively, one at a time or combined:
| Sanction | Detail |
|---|---|
| Warning | With a deadline for corrective measures |
| Fine | Up to 2% of the revenue in Brazil of the private entity or its group in the last fiscal year (net of taxes), capped at R$ 50,000,000 per infraction |
| Daily fine | Within the same R$50M cap |
| Publicising the infraction | After confirmation |
| Blocking or deletion | Of the personal data involved |
| Partial suspension of the database | Up to 6 months, extendable once |
| Suspension of the processing activity | Up to 6 months, extendable once |
| Partial or total prohibition of data-processing activities | The most severe. Suspension or prohibition applies only after a previous fine, blocking or deletion sanction for the same case (§6) |
The factors for setting a sanction (§1) include gravity, good faith, the advantage obtained, economic condition, repeat offences, the degree of damage, cooperation, adoption of good-practice and governance policies, and prompt correction. Civil liability (Art. 42) and sanctions under consumer law apply in parallel (§2).
ESP checklist for Brazilian traffic
- Map each list to a legal basis: consent records (who, when, how, and for which specific purpose), or a documented legitimate-interest balancing test with evidence of a prior relationship.
- Include a working, free unsubscribe in every message. It is both the revocation route under Art. 8 §5 and the safeguard that the ANPD's own marketing example relies on.
- Propagate suppression and deletion to all sharing partners (Art. 18 §6), and answer access requests within 15 days.
- Contract as an operator: a written DPA, processing bound by instructions, the controller's authorisation for subprocessors, and Brazilian SCCs for processing outside Brazil.
- Refuse third-party lists that lack consent specific to the purchaser (Art. 7 §5).
Not legal advice: see Compliance. To compare consent rules across jurisdictions, see CASL, UK PECR and Australia.
Check your own record
The free check reads what your domain publishes in DNS.
In this topic
- CAN-SPAM Act (United States)
- CAN-SPAM Rulemaking (16 CFR Part 316)
- CASL — Canada's Anti-Spam Legislation
- Email-Law Enforcement: CASL Cases and CAN-SPAM Statutory Detail