Long-Tail-QA
2026-07-27 00:00 Long-Tail-QA

Do I need a DPO in Brazil?

The DPO requirement in Brazil applies to virtually every organisation that processes personal data in or targeting Brazil, regardless of where the organisation is headquartered. Brazil';s Lei Geral de Proteção de Dados (LGPD) - Law No. 13,709/2018 - mandates that controllers appoint a Data Protection Officer, known locally as the Encarregado. Failure to do so exposes the organisation to administrative sanctions enforced by the Autoridade Nacional de Proteção de Dados (ANPD). This guide explains who must appoint a DPO, what the role requires, how the ANPD has refined the obligation for smaller organisations, and what practical steps international businesses should take to comply.

What the LGPD says about the DPO requirement in Brazil

The LGPD establishes the Encarregado as a mandatory figure for data controllers. Article 41 of the LGPD states that the controller must appoint an officer responsible for handling data subject communications and interfacing with the ANPD. The law does not restrict this obligation to large companies or to specific sectors. Any legal entity or individual that decides the purposes and means of personal data processing - the controller - must designate someone to fill this role.

The Encarregado is not the same as a compliance officer or a general counsel, although the same person may hold multiple roles if there is no conflict of interest. The officer must be publicly identified: the controller is required to publish the name and contact details of the Encarregado on its website or in another easily accessible location. This transparency obligation is a practical step that many foreign companies overlook when they first enter the Brazilian market.

Processors - organisations that process data on behalf of controllers - are not explicitly required by Article 41 to appoint their own Encarregado, but the ANPD has encouraged processors to do so as a matter of good practice. In practice, processors operating in Brazil should assess their exposure carefully, because contractual obligations with controllers often require an equivalent point of contact.

Who is exempt: ANPD guidance on small and micro enterprises

The ANPD issued Resolution CD/ANPD No. 2/2022, which introduced a simplified compliance regime for small processing agents. Under this resolution, microenterprises, small enterprises, startups and non-profit organisations meeting specific size thresholds may benefit from reduced obligations, including a relaxed approach to the formal DPO appointment.

However, the exemption is not absolute. Even organisations that qualify for the simplified regime are encouraged to designate a contact point for data subjects and the ANPD. The practical difference is that the simplified regime does not require the same level of formal documentation and public disclosure that applies to larger controllers. Organisations relying on this exemption should document their eligibility carefully, because the ANPD can request evidence that the thresholds were genuinely met.

A common mistake made by foreign founders is to assume that because their Brazilian subsidiary is small, no DPO is needed at all. The ANPD';s position is more nuanced: the simplified regime reduces the burden but does not eliminate the expectation of a responsible contact. Any organisation that processes sensitive personal data - health data, biometric data, data of children - faces heightened scrutiny regardless of size.

Qualifications and structure of the DPO role in Brazil

The LGPD does not prescribe specific professional qualifications for the Encarregado. The officer can be an individual or a legal entity, an employee of the controller, or an external service provider. This flexibility is significant for international businesses that may wish to appoint a shared DPO across multiple Latin American entities or to outsource the function to a local law firm or consultancy.

The Encarregado';s core responsibilities under Article 41 include:

  • Receiving complaints and communications from data subjects and the ANPD.
  • Providing guidance to employees and contractors on data protection practices.
  • Carrying out other duties determined by the controller or established in supplementary rules.

In practice, the role also involves maintaining records of processing activities, supporting data protection impact assessments, and managing data breach notifications. The ANPD expects the Encarregado to have genuine operational authority, not merely a nominal title. Appointing a figurehead without real access to processing operations is a risk that enforcement actions have begun to expose.

For international groups, a non-resident can serve as Encarregado provided the contact details published in Brazil allow data subjects and the ANPD to reach that person effectively and in Portuguese. Many multinational companies appoint a local deputy or coordinator to handle day-to-day communications while the group DPO retains strategic oversight.

If you are structuring a compliant data governance framework for your Brazilian operations, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.

Practical scenarios: when the DPO requirement in Brazil applies to your business

Scenario one - a European e-commerce company selling to Brazilian consumers. The company collects names, addresses, payment data and browsing behaviour from Brazilian residents. Even though the company has no physical presence in Brazil, the LGPD applies because the data subjects are located in Brazil and the processing occurs in connection with the offering of goods to individuals in Brazilian territory. The company is a controller under the LGPD and must appoint an Encarregado. It must also publish that officer';s contact details in a way that Brazilian consumers can access, typically on a Portuguese-language privacy notice.

Scenario two - a Brazilian SaaS startup processing HR data for corporate clients. The startup acts as a processor for its clients but also determines certain processing purposes for its own product analytics. In its processor capacity, the startup is not formally required to appoint an Encarregado under Article 41, but its client contracts may demand one. In its controller capacity - for analytics, marketing and employee data - the obligation applies directly. The startup should appoint a single Encarregado covering both capacities and disclose this publicly.

Many organisations underestimate the cross-border dimension. The LGPD';s territorial scope, set out in Article 3, captures processing that takes place in Brazil, processing of data collected in Brazil, and processing aimed at offering goods or services to individuals in Brazil. This broad reach means that a company with no Brazilian employees or offices can still be subject to the full DPO obligation.

Penalties for non-compliance and ANPD enforcement

The ANPD is the competent authority for enforcing the LGPD. It has the power to issue warnings, impose fines, order the suspension of data processing activities, and prohibit the transfer of data to third parties. Administrative sanctions under Article 52 of the LGPD can reach up to two percent of the organisation';s revenue in Brazil in the prior financial year, capped at a significant ceiling per violation.

Failure to appoint an Encarregado, or appointing one without publishing the required contact details, constitutes a direct violation of Article 41. The ANPD has signalled in its enforcement priorities that transparency obligations - including the public identification of the Encarregado - are among the first items it checks during investigations. A non-obvious requirement is that the contact details must be kept current: if the designated officer changes, the published information must be updated promptly.

Beyond financial penalties, reputational damage is a material risk. Brazilian data subjects have the right to submit complaints directly to the ANPD, and the authority publishes information about ongoing proceedings. For companies building trust with Brazilian consumers or B2B clients, a visible compliance gap can affect commercial relationships.

In practice, founders should consider the DPO appointment not as a bureaucratic checkbox but as an operational function that reduces legal exposure across the entire data lifecycle. Organisations that integrate the Encarregado into their governance structure from the outset tend to handle data subject requests and breach notifications more efficiently, which directly affects the severity of any regulatory response.

FAQ

Does a foreign company with no office in Brazil need to appoint a DPO?

Yes, if the company processes personal data of individuals located in Brazil or collects data in Brazilian territory, the LGPD applies regardless of where the company is incorporated or physically located. Article 3 of the LGPD sets a broad territorial scope that captures cross-border processing. The company must appoint an Encarregado and publish that person';s contact details in a location accessible to Brazilian data subjects. Many foreign companies satisfy this requirement by appointing a local representative or an external service provider based in Brazil who can communicate in Portuguese with data subjects and the ANPD.

How long does it take to appoint a DPO and what does it cost?

The formal appointment itself can be completed quickly - typically within a few days - once the organisation has identified a suitable individual or service provider. The more time-consuming element is building the underlying compliance infrastructure that the Encarregado will need to operate: records of processing activities, a privacy notice, internal policies and a breach response procedure. Professional fees for an outsourced DPO service in Brazil generally fall in the low-to-mid thousands of BRL per year for smaller organisations, rising significantly for complex operations with large data volumes or sensitive data categories. The cost of non-compliance - including potential fines and reputational damage - substantially exceeds the cost of a properly structured appointment.

Can the same person serve as DPO for multiple Brazilian entities within a group?

Yes. The LGPD does not prohibit a single Encarregado from covering multiple legal entities within a corporate group, provided there is no conflict of interest and the person has sufficient capacity to fulfil the role for each entity. In practice, large groups often appoint a group-level DPO supported by local data protection coordinators in Brazil who handle day-to-day communications. The key requirement is that the contact details published for each Brazilian controller must allow data subjects and the ANPD to reach the responsible person effectively. If the group DPO is based outside Brazil, a local contact point is strongly advisable to ensure timely responses.

Conclusion

The DPO requirement in Brazil under the LGPD is broad, applying to most controllers regardless of size or location. The ANPD has provided some relief for small processing agents, but the expectation of a responsible contact point remains. Foreign companies operating in or targeting Brazil should treat the Encarregado appointment as an early compliance priority, not an afterthought.

VLO Law Firms advises international clients on DPO requirements and data protection compliance in Brazil. We can assist with Encarregado appointments, privacy notices, records of processing activities, and ongoing ANPD compliance. To request a consultation, contact: info@vlolawfirm.com