LGPD Aviso de Privacidade Template for Brasil

Gere um documento personalizado

O que é um LGPD Aviso de Privacidade?

A Lei Geral de Proteção de Dados (LGPD) estabelece regras específicas para o tratamento de dados pessoais no Brasil, exigindo que as organizações sejam transparentes sobre suas práticas de processamento de dados. Este Aviso de Privacidade é um documento obrigatório que visa atender aos princípios de transparência e informação estabelecidos pela lei, fornecendo aos titulares dos dados todas as informações necessárias sobre como seus dados pessoais são tratados.

Com a confiança de equipes de alta performance

Perguntas frequentes

Is an LGPD privacy notice legally required for all businesses in Brasil?

Yes, under Lei nº 13.709/2018 (LGPD), any organization that processes personal data in Brasil must provide a clear and accessible privacy notice to data subjects. This requirement applies regardless of business size, with limited exceptions only for purely personal or household data processing activities.

What penalties can I face if my LGPD privacy notice is missing or incomplete?

The ANPD (National Data Protection Authority) can impose fines up to R$ 50 million or 2% of annual revenue, whichever is higher, per violation. Additionally, you may face operational suspension, data processing prohibition, and civil liability claims from affected data subjects under Article 52 of the LGPD.

How is an LGPD privacy notice different from website terms of use?

An LGPD privacy notice specifically focuses on personal data processing practices and data subject rights under the LGPD, while terms of use cover general website usage conditions and contractual relationships. The privacy notice is mandated by data protection law, whereas terms of use are primarily contractual documents.

Must my LGPD privacy notice be in Portuguese for Brasil compliance?

Yes, the privacy notice must be provided in Portuguese as it needs to be easily understandable by Brazilian data subjects. Article 9 of the LGPD requires information to be presented in clear and accessible language, which generally means the official language of Brasil.

How long does it typically take to prepare a compliant LGPD privacy notice?

Creating a comprehensive LGPD privacy notice typically takes 1-3 weeks, depending on the complexity of your data processing activities. This includes conducting a data mapping exercise, legal review, and ensuring all mandatory elements under Articles 8 and 9 of the LGPD are properly addressed.

Can I use the same privacy notice for multiple companies or websites?

No, each data controller must have its own specific privacy notice that accurately reflects their particular data processing activities. Generic or copied notices often fail to meet LGPD requirements and can result in non-compliance penalties from the ANPD.

What's the biggest mistake companies make with their LGPD privacy notices?

The most common mistake is failing to update the privacy notice when data processing activities change. Many companies also provide vague descriptions of data use purposes instead of the specific, clear explanations required by Article 9 of the LGPD, leading to transparency violations.

Revisado por

Swetha Meenal

Legal Engineer, GenieAI

Swetha Meenal profile photo

A lawyer, legal researcher and legal tech founder, Swetha has built AI products deployed inside Tier 1 firms and enterprises. She ensures GenieAI's alignment with the latest regulation and executes testing on the legal robustness of Genie output.

Revisado por

Imad Mohammed Nazar

Legal Engineer, GenieAI

Imad Mohammed Nazar profile photo

A Skadden-trained M&A lawyer, Imad advised on cross-border transactions and contractual risk before moving into legal AI. He reviews GenieAI's output for compliance and enforceability across our 150+ supported jurisdictions, as well as facilitating external benchmarking.

Jurisdição

Brasil

Publicador

GenieAI

Sector

Business

Custo

Gratuito

Última atualização

Sobre o LGPD Aviso de Privacidade

When your organization processes personal data in Brasil, the Lei Geral de Proteção de Dados (LGPD) requires you to provide clear information about your data processing activities through an Aviso de Privacidade. This privacy notice serves as a transparent communication tool between your organization and data subjects, explaining how you collect, use, store, and protect their personal information.

When do you need this document?

You need an LGPD Aviso de Privacidade whenever your organization processes personal data of individuals in Brasil. This includes collecting customer information through websites, mobile apps, or physical locations, processing employee data for HR purposes, handling client information for service delivery, or storing any personal data for business operations. E-commerce platforms, healthcare providers, financial institutions, educational organizations, and SaaS companies all require this privacy notice to operate legally in Brasil. The notice must be provided before or at the moment of data collection, ensuring data subjects are informed about your processing activities from the outset.

Key legal considerations

Your Aviso de Privacidade must include specific mandatory elements under LGPD. These include identifying the data controller and Data Protection Officer (DPO), specifying the types of personal data collected, explaining the purposes and legal bases for processing, describing data retention periods, and outlining data subject rights. You must clearly explain how individuals can exercise their rights to access, correct, delete, or port their data. The notice should detail your data sharing practices with third parties, international data transfers, and security measures implemented to protect personal information. Additionally, you must provide contact information for privacy-related inquiries and explain your complaint handling procedures.

Legal requirements in Brasil

Under Lei nº 13.709/2018 (LGPD), your privacy notice must comply with the principles of transparency, adequacy, and necessity. The document must be written in Portuguese and use clear, accessible language that the average data subject can understand. ANPD regulations require the notice to be easily accessible, preferably through a direct link on your website's homepage. You must update the privacy notice whenever there are material changes to your data processing activities and notify affected individuals. The notice must specify your legal bases for processing, which may include consent, legitimate interest, contract performance, or legal obligation. Organizations failing to provide adequate privacy notices face administrative sanctions, including warnings, fines up to 2% of annual revenue (capped at R$50 million), and operational restrictions.

Promessa de Segurança do Genie

Genie é o lugar mais seguro para redigir. Veja como priorizamos sua privacidade e segurança.

Seus dados são privados:

Não treinamos com seus dados; a IA do Genie melhora independentemente

Todos os dados armazenados no Genie são privados para sua organização

Seus documentos são protegidos:

Seus documentos são protegidos por criptografia de 256 bits ultra segura

Somos certificados ISO27001, então seus dados estão protegidos

Segurança organizacional:

Você mantém a propriedade intelectual de seus documentos e informações

Você tem controle total sobre seus dados e quem pode vê-los

Pronto para fechar acordos com confiança?
Veja o Genie em ação.