CORUZEN
Back to blog

LGPD for websites: what is actually required

By CORUZEN Team · Jul 30, 2026 · 3 min read

LGPD for websites: what is actually required

Brazil's LGPD (Law No. 13,709/2018) has been in full effect for five years and still causes confusion — partly because many people learned about it through generic cookie banners and privacy policy templates copied without review. The result is a mix of real requirements and urban legend. Let's separate the two.

What's genuinely required

A published, accessible privacy policy. Any site that collects any personal data — even just an email in a contact form — needs to clearly state what it collects, why, and how the person can exercise their rights. It doesn't need to be a 20-page document full of legalese; it needs to be true and clear.

Controller identification. The law (art. 41) requires it to be clear who's responsible for processing the data — a name (or legal entity name) and a contact channel. Small businesses, under ANPD Resolution CD/ANPD No. 2/2022, may use an effective communication channel instead of formally appointing a data protection officer (DPO).

A legal basis for each processing activity. Every reason for collecting data needs to fit one of the hypotheses in LGPD's art. 7 — consent, contract performance, legitimate interest, legal obligation, among others. A contact form, for example, typically relies on consent + legitimate interest (responding to the request).

A channel for data subjects to exercise their rights. Confirmation of processing, access, correction, deletion, portability, consent withdrawal — the person needs a way to ask for this, and you need to respond.

What depends on context (not a fixed rule)

Cookie banner. It's only required if the site actually uses non-essential cookies — tracking, advertising, third-party analytics. A technical, essential cookie (like one that stores a chosen language) doesn't need prior consent, because it falls under the "strictly necessary" exception — but it should still be described in the privacy policy.

A formally appointed data protection officer (DPO). As mentioned above, small businesses with low-risk processing can waive this formal appointment, as long as they maintain an effective communication channel. Larger companies, or ones processing sensitive data at scale, typically need a real DPO.

Explicit consent via checkbox. Not every data processing activity requires an "I agree" checkbox. If the legal basis is contract performance or well-justified legitimate interest, explicit consent often isn't even the right mechanism — forcing an unnecessary checkbox just creates friction without real legal value.

What's a myth

  • "Every company needs to register its website with the ANPD." No such registry exists. The ANPD regulates, enforces, and receives complaints — but there's no mandatory site registration.
  • "Without ISO certification, the company is non-compliant." Information security certifications (ISO 27001, for example) aren't required by LGPD — they help demonstrate good practice, but they aren't a legal requirement.
  • "A company registration number is mandatory in the privacy policy." It's recommended and reinforces controller identification, but companies still formalizing their legal structure can operate with a clear contact channel in the meantime.

Where most companies get it wrong in practice

It's usually not lack of will — it's the generic template. Downloading a ready-made privacy policy from the internet, swapping in the company name, and publishing without reviewing what it actually describes is worse than having nothing: the policy ends up claiming practices the company doesn't follow (or fails to describe practices it does follow), which is a more visible form of non-compliance than the absence of the document.

The safer path is to review the policy based on what the site actually does — what data the contact form really collects, whether there's a real tracking cookie, who actually answers the contact email — and adjust the text to reflect that, not the other way around.

Information security and LGPD compliance go hand in hand: there's no point having a flawless privacy policy if the site itself has vulnerabilities that expose the data it promises to protect. It's worth reviewing both sides — start with the technical checklist if you haven't already.

Want to see this in practice?

Check out CORUZEN SECURITY and see how it solves this in your company's day to day.

Explore CORUZEN SECURITY