Glossary
LGPD and compliance terms, explained
Short, direct definitions of the terms that come up in every conversation about data protection and compliance — each with its legal reference.
LGPD and Compliance Glossary
LGPD
Brazilian General Data Protection LawBrazilian law regulating the processing of personal data by individuals and organizations, public or private. It sets out principles, legal bases, data subject rights and the sanctions the ANPD may apply.
Source: Law 13.709/2018
See detailsANPD
Brazilian National Data Protection AuthorityThe federal body responsible for data protection in Brazil. It issues rules, supervises compliance with the LGPD and applies the administrative sanctions the law provides for.
Source: Law 13.709/2018, arts. 55-A to 55-L
Personal data
Any information relating to an identified or identifiable natural person. It includes data that identifies no one on its own but, combined with other data, leads to a specific person.
Source: LGPD, art. 5, I
Sensitive personal data
Data on racial or ethnic origin, religious belief, political opinion, union or religious, philosophical or political membership, health, sex life, plus genetic and biometric data. It requires its own legal basis and reinforced protection.
Source: LGPD, art. 5, II
Data subject
The natural person the personal data refers to. This is who may exercise the rights set out in the LGPD, such as access, correction, portability and deletion.
Source: LGPD, art. 5, V
Controller
The individual or organization that decides how personal data is processed — what is collected, for what purpose and for how long. Primary responsibility for compliance rests here.
Source: LGPD, art. 5, VI
Processor
The individual or organization that processes personal data on the controller's behalf, following its instructions. A cloud provider or a payroll system typically acts as a processor.
Source: LGPD, art. 5, VII
See detailsData Protection Officer
DPO, encarregadoThe person appointed by the controller to act as the channel of communication between the company, data subjects and the ANPD. They advise the organization on data protection practices and receive data subject complaints.
Source: LGPD, art. 41
See detailsLegal basis
The legal ground authorizing a given processing of personal data. The LGPD provides 10 bases for ordinary data — including consent, contract performance, legal obligation and legitimate interest — and every processing activity must rest on at least one.
Source: LGPD, art. 7
See detailsLegitimate interest
A legal basis allowing processing for the legitimate purposes of the controller or a third party, provided the data subject's rights and freedoms do not prevail. It requires a documented balancing assessment.
Source: LGPD, arts. 7, IX and 10
Consent
A free, informed and unambiguous statement by which the data subject agrees to their data being processed for a specific purpose. It can be withdrawn at any time, and withdrawal must be as simple as giving it.
Source: LGPD, arts. 5, XII and 8
ROPA
Record of processing activitiesAn inventory documenting each of the organization's data processing activities: which data, for what purpose, under which legal basis, for how long and where it is stored. It is usually the first document requested in an inspection.
Source: LGPD, art. 37
See detailsDPIA
RIPD, Data Protection Impact AssessmentA document describing processing activities that may pose a risk to civil liberties and fundamental rights, together with the measures adopted to mitigate that risk. The ANPD may require it.
Source: LGPD, arts. 5, XVII and 38
See detailsData subject request
DSRA formal request in which a data subject exercises one of their rights — confirmation, access, correction, anonymization, portability, deletion, information on sharing or withdrawal of consent. The company must respond within the legal deadline.
Source: LGPD, art. 18
See detailsAnonymization
The process of removing from data any possibility of direct or indirect association with an individual. Effectively anonymized data stops being personal data and falls outside the LGPD — provided reversal is not possible with reasonable effort.
Source: LGPD, arts. 5, XI and 12
Security incident
An event compromising the confidentiality, integrity or availability of personal data — from an attack to an email sent to the wrong recipient. Incidents posing relevant risk must be reported to the ANPD and to the affected data subjects.
Source: LGPD, art. 48
Whistleblower channel
A formal, protected route for employees and third parties to report wrongdoing such as harassment, fraud and corruption. An effective channel guarantees anonymity, allows follow-up without identification and documents how each case was handled.
Source: Law 14.457/2022; Law 12.846/2013
See detailsCompliance
Integrity programThe structured set of policies, controls, training and channels an organization maintains to prevent, detect and correct wrongdoing. To carry legal weight it must be documented and auditable — not merely exist on paper.
Source: Law 12.846/2013; Decree 11.129/2022
See detailsThird-party due diligence
The process of assessing suppliers and partners before and during the contractual relationship, checking integrity risk, regulatory compliance and data protection. It has become a common filter in B2B contracting and public tenders.
NR-1
The Brazilian regulatory standard setting out general occupational health and safety provisions and the management of occupational risk. Its update brought psychosocial risks — such as harassment and violence — into the company's risk management scope.