Glossary

LGPD and compliance terms, explained

Short, direct definitions of the terms that come up in every conversation about data protection and compliance — each with its legal reference.

LGPD and Compliance Glossary

LGPD

Brazilian General Data Protection Law

Brazilian law regulating the processing of personal data by individuals and organizations, public or private. It sets out principles, legal bases, data subject rights and the sanctions the ANPD may apply.

Source: Law 13.709/2018

See details

ANPD

Brazilian National Data Protection Authority

The federal body responsible for data protection in Brazil. It issues rules, supervises compliance with the LGPD and applies the administrative sanctions the law provides for.

Source: Law 13.709/2018, arts. 55-A to 55-L

Personal data

Any information relating to an identified or identifiable natural person. It includes data that identifies no one on its own but, combined with other data, leads to a specific person.

Source: LGPD, art. 5, I

Sensitive personal data

Data on racial or ethnic origin, religious belief, political opinion, union or religious, philosophical or political membership, health, sex life, plus genetic and biometric data. It requires its own legal basis and reinforced protection.

Source: LGPD, art. 5, II

Data subject

The natural person the personal data refers to. This is who may exercise the rights set out in the LGPD, such as access, correction, portability and deletion.

Source: LGPD, art. 5, V

Controller

The individual or organization that decides how personal data is processed — what is collected, for what purpose and for how long. Primary responsibility for compliance rests here.

Source: LGPD, art. 5, VI

Processor

The individual or organization that processes personal data on the controller's behalf, following its instructions. A cloud provider or a payroll system typically acts as a processor.

Source: LGPD, art. 5, VII

See details

Data Protection Officer

DPO, encarregado

The person appointed by the controller to act as the channel of communication between the company, data subjects and the ANPD. They advise the organization on data protection practices and receive data subject complaints.

Source: LGPD, art. 41

See details

Legitimate interest

A legal basis allowing processing for the legitimate purposes of the controller or a third party, provided the data subject's rights and freedoms do not prevail. It requires a documented balancing assessment.

Source: LGPD, arts. 7, IX and 10

Consent

A free, informed and unambiguous statement by which the data subject agrees to their data being processed for a specific purpose. It can be withdrawn at any time, and withdrawal must be as simple as giving it.

Source: LGPD, arts. 5, XII and 8

ROPA

Record of processing activities

An inventory documenting each of the organization's data processing activities: which data, for what purpose, under which legal basis, for how long and where it is stored. It is usually the first document requested in an inspection.

Source: LGPD, art. 37

See details

DPIA

RIPD, Data Protection Impact Assessment

A document describing processing activities that may pose a risk to civil liberties and fundamental rights, together with the measures adopted to mitigate that risk. The ANPD may require it.

Source: LGPD, arts. 5, XVII and 38

See details

Data subject request

DSR

A formal request in which a data subject exercises one of their rights — confirmation, access, correction, anonymization, portability, deletion, information on sharing or withdrawal of consent. The company must respond within the legal deadline.

Source: LGPD, art. 18

See details

Anonymization

The process of removing from data any possibility of direct or indirect association with an individual. Effectively anonymized data stops being personal data and falls outside the LGPD — provided reversal is not possible with reasonable effort.

Source: LGPD, arts. 5, XI and 12

Security incident

An event compromising the confidentiality, integrity or availability of personal data — from an attack to an email sent to the wrong recipient. Incidents posing relevant risk must be reported to the ANPD and to the affected data subjects.

Source: LGPD, art. 48

Whistleblower channel

A formal, protected route for employees and third parties to report wrongdoing such as harassment, fraud and corruption. An effective channel guarantees anonymity, allows follow-up without identification and documents how each case was handled.

Source: Law 14.457/2022; Law 12.846/2013

See details

Compliance

Integrity program

The structured set of policies, controls, training and channels an organization maintains to prevent, detect and correct wrongdoing. To carry legal weight it must be documented and auditable — not merely exist on paper.

Source: Law 12.846/2013; Decree 11.129/2022

See details

Third-party due diligence

The process of assessing suppliers and partners before and during the contractual relationship, checking integrity risk, regulatory compliance and data protection. It has become a common filter in B2B contracting and public tenders.

NR-1

The Brazilian regulatory standard setting out general occupational health and safety provisions and the management of occupational risk. Its update brought psychosocial risks — such as harassment and violence — into the company's risk management scope.