compliance-br

LGPD and personal data in AI

Under Brazil’s LGPD (Lei Geral de Proteção de Dados, Law No. 13,709/2018), personal data used in AI systems must comply with all core…

4 min read720 wordsen

Short answer

Under Brazil’s LGPD (Lei Geral de Proteção de Dados, Law No. 13,709/2018), personal data used in AI systems must comply with all core principles—lawfulness, purpose limitation, necessity, transparency, and accountability—and requires a valid legal basis (e.g., consent or legitimate interest) for processing. Controllers must conduct Data Protection Impact Assessments (DPIAs) when AI processing poses high risk to data subjects’ rights.

TL;DR

  • LGPD applies to any AI system that processes personal data of individuals in Brazil—even if the controller is foreign.
  • Article 42-A (added by Law No. 14,457/2022) explicitly requires DPIAs for automated decision-making with legal or significant effects.
  • Consent is not the only lawful basis: legitimate interest (Art. 7, IX), contractual necessity (Art. 7, II), and legal obligation (Art. 7, III) are equally valid for AI training or inference.
  • The ANPD issued Resolution No. 2/2023 mandating DPIA documentation standards—including for generative AI models using personal data.
  • “Anonymized” data under LGPD (Art. 5, XII) must be irreversibly non-identifiable; pseudonymized data remains personal data and stays fully in scope.
  • Fines under LGPD reach up to 2% of a company’s Brazilian revenue (capped at R$ 50 million per infraction).

Como a LGPD regula o uso de dados pessoais em IA?

The LGPD treats AI not as a separate domain but as a processing activity—subject to its full framework. Personal data fed into AI models (e.g., text, images, biometrics) triggers obligations from collection through deployment. Controllers must map data flows, document legal bases, and ensure human oversight where automated decisions produce legal or similarly significant effects (e.g., credit denial, hiring screening).

Quais são as obrigações específicas para modelos de IA gerativa?

Generative AI systems trained on or outputting personal data fall squarely under LGPD. If training data includes names, emails, health records, or geolocation tied to individuals—even scraped from public sources—the controller bears responsibility for lawfulness (Art. 7) and security (Art. 46). Outputs that re-identify or infer sensitive attributes (e.g., ethnicity, political views) may constitute processing of sensitive data (Art. 11), requiring heightened safeguards and explicit consent unless another strict basis applies.

O que é considerado “dado pessoal” na prática da IA?

Per LGPD Art. 5, I, personal data is any information related to an identified or identifiable natural person. In AI contexts, this includes raw inputs (user prompts with identifiers), embedded metadata (timestamps, IP-derived location), model weights that memorize PII, and outputs that reconstruct or disclose personal facts—even if unintended. Behavioral data used to fine-tune recommendation engines also qualifies.

FAQ

  • Q: Does the LGPD ban AI-based profiling?
  • A: No—but Art. 20 grants data subjects the right to request human review of solely automated decisions with legal or significant effects, and controllers must provide meaningful explanations (ANPD Guidance Note No. 01/2024).
  • Q: Can companies use publicly available personal data to train AI models?
  • A: Not without a valid legal basis. Public availability ≠ lawful processing. Scraping social media profiles still requires justification under Art. 7 (e.g., legitimate interest balanced against data subject rights).
  • Q: Is synthetic data exempt from LGPD?
  • A: Only if truly anonymized per Art. 5, XII—i.e., irreversible and no reasonable re-identification risk. Most synthetic data generated from real datasets fails this test and remains regulated.
  • Q: Who is liable—the AI developer, deployer, or cloud provider?
  • A: Liability follows functional roles: the controller (who determines purposes/means) bears primary responsibility; processors (e.g., cloud hosts) must contractually comply (Art. 46) and may face joint liability for negligence.

Key facts

  • LGPD entered force on 18 September 2020; sanctions began 1 August 2021.
  • ANPD’s DPIA requirements for AI are codified in Resolution No. 2/2023 and clarified in Technical Note No. 03/2024.
  • “Sensitive personal data” (Art. 11) includes health, biometric, religious, and sexual orientation data—strictly regulated in AI contexts.
  • The LGPD recognizes “data protection by design and by default” (Art. 47), mandating privacy integration into AI architecture—not retrofitted compliance.
  • Brazil’s Supreme Court (STF) confirmed LGPD’s constitutionality in ADI 6695 (2023), affirming its applicability to digital innovation.

Sources

  • Lei nº 13.709/2018 (Planalto.gov.br)
  • Resolução ANPD nº 2/2023 (ANPD.gov.br)
  • Nota Técnica ANPD nº 01/2024 e nº 03/2024 (ANPD.gov.br)
  • IBM Granite Compliance Documentation v2.1 (ibm.com/granite/compliance)
  • STF ADI 6695 – Acórdão de 21/06/2023 (Supremo.stf.jus.br)

Saiba mais em https://g.cloud

← Back to blog