Brazil's LGPD and AI tools: what the law requires

The LGPD does not ban ChatGPT and does not require blocking AI. It requires a legal basis, records, transparency and control. Article by article, applied to corporate AI usage.

Updated August 15, 2026 · 12 min read

The question that reaches legal is almost always “can we use ChatGPT?”. It is the wrong question, which is why it never has a good answer. The LGPD does not regulate tools — it regulates the processing of personal data. The same tool can be perfectly lawful for reviewing a marketing text and unlawful for summarising a patient record.

The right question is: what personal data is going into this tool, for what purpose, under which legal basis, and is that recorded? This guide walks through what Brazil’s Law 13.709/2018 requires, article by article, applied to corporate use of artificial intelligence.

This material is informational and does not replace legal advice. Decisions on legal basis, legitimate-interest balancing and the framing of international transfers depend on the context of each operation and should be validated with your legal team or data protection officer.

When the LGPD applies to AI use

The trigger is the presence of personal data — any information relating to an identified or identifiable natural person (art. 5, I). In everyday AI use, personal data enters through routes rarely perceived as “processing”:

  • A customer or supplier name inside an email pasted in to be summarised.
  • Meeting minutes or a transcript, which contain participants’ names and voices.
  • A CV submitted for screening — and here sensitive data may be involved.
  • Payroll spreadsheets, performance reviews, attendance records.
  • A customer base uploaded to “spot patterns”.
  • A screenshot of an internal system pasted in to ask for help with an error.

Where sensitive data is involved (art. 5, II — racial origin, religious conviction, political opinion, union membership, health, sex life, genetic or biometric data), the regime is stricter: the legal bases in art. 11 are a smaller and more demanding set than those in art. 7. Biometric data deserves specific attention in voice tools — voice is biometric data, and meeting transcription is one of the most widespread AI inputs in companies today.

What the law requires, article by article

ArticleRequirementHow it shows up in AI use
Art. 6Principles: purpose, adequacy, necessity, transparency, security, prevention, accountability.Necessity is the most violated: pasting the whole spreadsheet when three columns would do is processing beyond what is needed, even with a valid legal basis.
Art. 7 and 11A legal basis for each processing operation.The basis is chosen per purpose, not per tool. The same tool can operate under different bases in different uses.
Art. 9Clear information to the data subject about purpose and sharing.If customer data goes to an AI vendor, that must be reflected in the privacy notice — and most notices were written before AI entered operations.
Art. 18Data subject rights, including erasure and information about sharing.It is impossible to answer 'who was my data shared with' if the company does not know which AI tools are in use.
Art. 20Right to review of decisions taken solely on the basis of automated processing.CV screening, credit analysis and support prioritisation done by AI land here, with a duty to disclose the criteria.
Art. 33 and 34Requirements for international transfers.Most AI tools process outside Brazil. This needs a formal route — the vendor being well known is not one.
Art. 37Record of processing activities.Each material AI use over personal data is an operation and should appear in the record. It is the most frequent audit finding.
Art. 38Data protection impact report, when requested by the authority.High-impact AI use over data subjects is a natural candidate — better produced before it is asked for.
Art. 39The processor must process data according to the controller's instructions.This requires a contract. Accepting a free tool's standard terms of service usually does not satisfy it.
Art. 46Technical and administrative security measures.Includes knowing who has access to what — hard to sustain without an inventory of what is in use.
Art. 48Notification of incidents to the authority and to data subjects within a reasonable period.Only possible with detection in place. Without visibility, the incident is discovered by third parties.

The temptation is to ask for consent for everything. In an employment relationship that is fragile: there is asymmetry between employer and employee, and consent that a person does not feel free to refuse tends not to hold up as a freely given declaration. Consent is also revocable at any time (art. 8, § 5), which makes any process depending on it unstable.

In practice, the most common framings in a corporate AI context are:

  • Performance of a contract (art. 7, V) — where processing is necessary to deliver what the customer contracted.
  • Compliance with a legal or regulatory obligation (art. 7, II) — typical in regulated sectors.
  • Legitimate interest (art. 7, IX) — the basis most used for internal productivity tools. It requires a documented balancing test between the company’s interest and the data subject’s rights, and it does not cover sensitive data.

Legitimate interest is not a wildcard: it is the basis that demands the most documentation. If you invoke it, you must be able to show the balancing test you performed, the data subject’s reasonable expectation, and the measures adopted to reduce impact. Without that document, it is an assertion, not a legal basis.

International transfers (art. 33)

Almost every meaningful AI tool processes data outside Brazil — mostly the United States, but also the United Kingdom, the European Union, India and China. Sending personal data to those tools is an international transfer and needs to fit one of the routes in art. 33.

For most companies the practical route is contractual. Brazil’s data protection authority approved standard contractual clauses in 2024 that can be adopted for this purpose, which removed much of the earlier uncertainty. It does imply something many companies never did, however: having a contract with the AI vendor. A free account accepted by an employee under standard terms of service does not establish that relationship.

One distinction confuses a lot of people: the vendor’s home country is not the same as data residency. A US company may offer processing in a specific region on its enterprise plan. Our public catalog reports the home country as a jurisdiction signal, but where data is actually processed depends on the plan you hold and must be confirmed with the vendor.

The point that decides almost everything: free vs enterprise

Between a free account and a corporate account of the same tool there is usually a difference that changes the entire legal framing: the default behaviour regarding training on your data, and the existence of a processing agreement.

Personal / free accountCorporate plan
Training on your dataFrequently enabled by defaultNormally disabled by contract
Processing agreement (art. 39)Standard terms, accepted by the employeeContract signed by the company
International transferNo formal routeAddressable via contractual clauses
Record and auditabilityNone — the company does not know it existsAdministrable and auditable

This has a direct operational consequence: knowing that “they used ChatGPT” matters less than knowing on which plan. Two people using the same tool can be in completely different legal situations. Detection that does not distinguish account and plan leaves that gap open.

Compliance checklist

In the order an auditor tends to ask — and the order in which it makes sense to solve:

  • Inventory. Is there a list of what is in use, kept current? Without it, everything below is a declaration, not evidence.
  • Record of processing (art. 37). Do AI uses over personal data appear in the record, with purpose, legal basis, categories of data subjects and recipients?
  • Legal basis. Does each purpose have a defined basis and, where it is legitimate interest, a documented balancing test?
  • Contracts (art. 39). Is there a processing agreement with the AI vendors used over personal data?
  • International transfer (art. 33). Is there a formal route for vendors processing outside Brazil?
  • Privacy notice (art. 9). Does the notice reflect sharing with AI vendors?
  • Automated decisions (art. 20). Where decisions about people are made, is there a review path and disclosure of the criteria?
  • Policy and training. Is there a published policy, communicated, with evidence of acknowledgement? See the annotated template.
  • Incident response (art. 48). Is there detection capable of noticing an incident before a third party reports it?

Note that eight of the nine items depend on the first. Compliance programmes that begin by writing the policy and the processing record over an un-inventoried environment document the company they imagine having, not the one that exists — and that gap is what shows up in the audit.

What is at stake

Sanctions under art. 52 range from a warning to a fine of up to 2% of revenue in Brazil, capped at BRL 50 million per infraction, plus blocking or deleting the data involved and public disclosure of the infraction. In practice, for most companies the relevant cost arrives before the regulator does: a corporate customer demanding privacy due diligence in the contract, an insurer asking about AI governance at renewal, and a certification audit stalling for lack of records.

Frequently asked questions

Does the LGPD ban using ChatGPT at work?

No. The LGPD bans no specific tool. It regulates the processing of personal data: if the tool receives personal data, you need a legal basis, a record of the processing activity, notice to the data subject, a contract with the vendor, and a lawful route for the international transfer. If the tool only receives non-personal data, the LGPD does not apply to that use.

Is using AI without recording it an LGPD violation even if nothing leaks?

Yes. The irregularity does not depend on an incident. Processing personal data without a legal basis (art. 7), without it appearing in the record of processing activities (art. 37) or without informing the data subject (art. 9) is non-compliance in itself. A leak is an aggravating factor, not the trigger.

Which legal basis should we use for AI at work?

It depends on the purpose, not on the tool. For internal productivity use over employee data, legitimate interest (art. 7, IX) with a documented balancing test is the usual candidate. For processing customer data within the performance of a contract, item V. Consent (item I) is rarely the best choice in an employment relationship, because of the asymmetry between the parties.

Is sending data to a US-based AI tool an international transfer?

Yes, and article 33 applies. You must fit it into one of the routes the law provides — in practice, for most companies, contractual clauses with the vendor. Brazil's data protection authority approved standard contractual clauses in 2024, which can be adopted for that purpose.

Where does your company stand today?

The free assessment is 9 questions, 5 minutes and no signup. It returns your maturity level per dimension and a prioritised action plan — enough to know where to start without buying anything.