Orange textured background

Brazil: national law

LGPD and fingerprinting

How Brazil's Lei Geral de Proteção de Dados (LGPD) treats browser and device fingerprinting, the ten lawful bases under Article 7, and the ANPD's 2023 guidance on cookies and similar technologies.

Reviewed

RegionBrazil (national)
RegulatorAutoridade Nacional de Proteção de Dados (ANPD)
Effective18 September 2020 (administrative sanctions from 1 August 2021)
Max penalty2% of the controller's Brazilian revenue, up to BRL 50 million per infringement
Status in-force

What the LGPD says about fingerprinting

The LGPD (Lei Geral de Proteção de Dados Pessoais, Lei nº 13.709 de 14 de agosto de 2018) does not use the word 'fingerprinting'. It uses the broad concept of 'dado pessoal' (personal data), defined in Article 5(I) as any information related to an identified or identifiable natural person. A browser fingerprint that allows you to recognise the same user across requests makes that user identifiable, and therefore the fingerprint is personal data.

This framing tracks GDPR closely, which is not an accident: the LGPD was drafted in conscious dialogue with the EU regulation, with several articles reading as a Portuguese-language restatement of GDPR provisions. The differences are real but operational: the LGPD has ten lawful bases instead of GDPR's six, weaker territoriality, and a different fine structure.

The ten lawful bases under Article 7

Where GDPR offers six lawful bases for processing, the LGPD's Article 7 lists ten. For a fingerprinting deployment, the operationally relevant ones are consent (Article 7(I)), legal obligation (Article 7(II)), execution of a contract (Article 7(V)), legitimate interest (Article 7(IX), elaborated in Article 10), and credit protection (Article 7(X)).

Legitimate interest under Article 10 of the LGPD is broader than under GDPR. The article specifically allows processing for 'support and promotion of the controller's activities' and 'protection of the credit holder', both of which can be construed to cover narrow anti-fraud fingerprinting flows. As under GDPR, the basis requires a documented balancing test (LIA) and cannot be used to override the data subject's fundamental rights.

Article 7 bases most relevant to fingerprinting

  1. Consent (Article 7(I)): must be free, informed and unambiguous; written or by another means demonstrating the data subject's will (Article 5(XII)).
  2. Compliance with a legal or regulatory obligation by the controller (Article 7(II)): e.g. anti-money-laundering device binding.
  3. Execution of a contract or preliminary procedures requested by the data subject (Article 7(V)): workable for in-product fingerprinting that the user has explicitly requested as part of the service.
  4. Legitimate interest of the controller or third party (Article 7(IX)): see Article 10 for the balancing requirements; the most flexible basis for fraud and security purposes.
  5. Protection of credit (Article 7(X)): applies narrowly to bureaus and credit decisions but can support fingerprinting in a credit-fraud context.
  6. Regular exercise of rights in judicial, administrative or arbitration proceedings (Article 7(VI)): narrow.

Consent under the LGPD

When consent is the chosen basis, Article 5(XII) defines it as a 'free, informed and unambiguous demonstration whereby the data subject agrees to the processing of his/her personal data for a specific purpose'. Article 8 adds that consent must be provided in writing or by another means demonstrating the data subject's will, and that the controller bears the burden of proof. Tacit consent, pre-ticked boxes, and 'continued use of the site' are non-compliant under the LGPD just as they are under GDPR.

The ANPD's 2023 cookie guide reinforced these positions and added a specific recommendation: the 'reject all' option must be available at the same level as 'accept all' in the first layer of a consent banner. The guide does not have the force of law but the ANPD has stated it will use the guide as a reference in enforcement proceedings.

Sensitive personal data (Article 5(II))

The LGPD defines a 'dado pessoal sensível' (sensitive personal data) category in Article 5(II): data on racial or ethnic origin, religious belief, political opinion, trade union or religious/philosophical/political membership, health or sex life, genetic or biometric data when linked to a natural person. Article 11 limits the lawful bases available for sensitive data and requires specific consent for the consent basis.

Biometric data is the key concept for fingerprinting. The ANPD has indicated, consistent with the European Data Protection Board, that the biometric category is reserved for data 'resulting from a specific technical processing relating to the physical, physiological or behavioural characteristics' of a person used to identify them, which is closer to facial recognition and gait analysis than to a standard browser fingerprint. A canvas hash or audio context hash is not, on its own, biometric data.

Fingerprinting purposes mapped to the LGPD

PurposeSuggested Article 7 basisNotes
Anti-fraud on payment or loginLegitimate interest (Art. 7(IX) + Art. 10)Document the LIA; isolate the flow from analytics
Bot mitigation on public formsLegitimate interestSame
Account takeover detectionLegitimate interest or contract performance (Art. 7(V))Contract basis only if explicit in the ToS
Credit-fraud verificationCredit protection (Art. 7(X)) or legal obligationNarrow and bureau-specific
Behavioural advertisingConsent (Art. 7(I))Cannot rely on legitimate interest
Product analyticsConsent or legitimate interestANPD has not ruled out legitimate interest here, but documentation matters
Personalisation / recommendationConsentANPD treats this as opt-in

Territorial scope: Article 3 and the practical reach

Article 3 of the LGPD extends the law to processing activities that (i) are carried out in Brazil, (ii) have the purpose of offering goods or services to data subjects located in Brazil, or (iii) involve the processing of data of subjects located in Brazil at the time of collection.

A fingerprinting SDK loaded by a Brazilian user's browser is processing data of a subject located in Brazil at the moment of collection, which means the LGPD applies even if the controller's servers, headquarters and shareholders are all outside Brazil. There is no de minimis exemption for low-volume operators.

Enforcement: the ANPD's accelerating pace

Administrative sanctions under the LGPD became enforceable on 1 August 2021, after a one-year transitional period. The ANPD took a deliberate, education-first posture for the first eighteen months, issuing guidance and warnings rather than fines. That changed materially in 2023-2024.

Article 52 of the LGPD sets the sanction ladder: warning, simple fine, daily fine, publicity of the infringement, blocking or deletion of the data, suspension of database operation, and prohibition of processing activities. Fines top out at 2% of the controller's Brazilian revenue, capped at BRL 50 million per infringement. Daily fines can stack.

Enforcement actions worth knowing

  • ANPD v. Serasa Experian (August 2022): preventive measure halting the sale of personal data, with reasoning that applies to any device-identifier resale.
  • ANPD v. Telekall Infoservice (August 2024): BRL 14,400. The ANPD's first published material fine under the LGPD, modest in size but precedent-setting on procedure.
  • ANPD opinion on TikTok data flows (October 2023): not a fine, but flagged cross-border transfer of behavioural data as a 2024 enforcement priority.
  • ANPD enforcement workplan 2024-2026 (published October 2024): named 'targeted advertising and tracking technologies' as a priority area, which is the practical reading bracket for fingerprinting.
  • ANPD reprimand of public bodies for SaaS data leaks (multiple 2024): turned on retention and access controls, with reasoning applicable to fingerprint-data retention.

Data subject rights and the DPO requirement

Article 18 of the LGPD grants nine rights to data subjects, including access, correction, anonymisation, portability, deletion, information about with whom data has been shared, and the right to revoke consent. These map closely to GDPR rights and apply to any fingerprint-derived personal data.

Article 41 requires the appointment of a Data Protection Officer (Encarregado) by controllers. The ANPD's Resolution CD/ANPD 2/2022 carved out 'small processing agents' (small businesses and startups under certain revenue thresholds) from the DPO requirement, but they remain bound by every other LGPD obligation. A fingerprinting deployment that touches Brazilian users is almost always significant enough to warrant a designated DPO.

How Benny the Doorman fits into an LGPD-aware deployment

Benny is a fingerprinting SDK. The choice of lawful basis under LGPD Article 7 is the controller's call, and the integration pattern follows from it. For consent-based purposes, the fingerprint call is gated behind the user's explicit acceptance in your consent management platform. For legitimate-interest-based purposes (anti-fraud, security), the LIA is documented in your RIPD (Relatório de Impacto à Proteção de Dados Pessoais, the LGPD's equivalent of a DPIA), and the fingerprint pipeline is isolated from any consent-required downstream use.

Benny's standard DPA is available with an LGPD addendum that addresses Article 39 controller-operator obligations and Articles 33-36 on international data transfers. Benny's processing infrastructure sits in Chennai, India; transfers from Brazil to India rest on a contractual transfer mechanism under Article 33(II), as India is not currently listed in any ANPD adequacy determination.

Frequently asked questions

Does the LGPD apply to browser fingerprinting?

Yes. Fingerprints fall within the LGPD's broad definition of personal data in Article 5(I) whenever they allow you to recognise the same user. The law applies regardless of whether you operate inside Brazil: Article 3 extends it to any processing of data of subjects located in Brazil at the moment of collection.

Do I need consent for fingerprinting under the LGPD?

Not necessarily. Consent (Article 7(I)) is one of ten lawful bases. Legitimate interest (Article 7(IX) and Article 10) is workable for narrow anti-fraud and security purposes with a documented assessment. For advertising, personalisation and analytics, consent is the safer basis.

Is a fingerprint considered sensitive personal data under the LGPD?

Not by default. Article 5(II) reserves the sensitive category for biometric data resulting from specific technical processing used to identify a person, plus a closed list of other categories. A standard browser fingerprint is not biometric data; a behavioural-biometrics fingerprint may be.

What does the ANPD's 2023 cookie guide say about fingerprinting?

It confirms that fingerprinting falls within the LGPD's scope and recommends that consent, when used, follow the standard set in Article 5(XII), namely free, informed and unambiguous, with a 'reject all' option as prominent as 'accept all' in the first layer of a consent banner.

What are the fines for non-compliant fingerprinting under the LGPD?

Up to 2% of the controller's Brazilian revenue, capped at BRL 50 million per infringement. Daily fines and non-monetary sanctions (suspension of processing, deletion of databases) can also be imposed.

Does the LGPD apply to non-Brazilian companies?

Yes. Article 3 extends to controllers and processors anywhere in the world whose processing has the purpose of offering goods or services to data subjects in Brazil, or that involves data of subjects located in Brazil at the time of collection.

Do I need to appoint a DPO under the LGPD?

Article 41 requires a DPO (Encarregado) by default. The ANPD's Resolution CD/ANPD 2/2022 carves out 'small processing agents', but most fingerprinting-enabled services exceed those thresholds in practice. Even when an Encarregado is not required, the underlying obligations still apply.

Can I transfer fingerprint data from Brazil to other countries?

Yes, under Article 33's mechanisms: including adequacy determinations from the ANPD (none yet covering most non-EU destinations), standard contractual clauses, or specific consent. Most controllers rely on contractual clauses with their fingerprinting vendor.

Tooling

Benny the Doorman is built for this compliance posture.

Free, cookieless fingerprinting that defers to your consent management platform, runs on Indian infrastructure, and ships with a DPA addendum sized for the jurisdiction above.

Last reviewed 2026-06-06