guardrails

PII: CPF and CNPJ masking

CPF and CNPJ must be masked in non-production AI systems and logs under LGPD’s principle of data minimisation (Art. 6, III) and confidentiality…

4 min read738 wordsen

Resposta curta

CPF and CNPJ must be masked in non-production AI systems and logs under LGPD’s principle of data minimisation (Art. 6, III) and confidentiality obligations (Art. 46). Full unmasked exposure violates LGPD Art. 47 and triggers accountability requirements under ANPD Resolution No. 1/2023.

TL;DR

  • CPF (11-digit individual tax ID) and CNPJ (14-digit corporate tax ID) are classified as personal data under LGPD Art. 5, X.
  • LGPD does not mandate a single masking method—but truncation, hashing with salted cryptographic functions, or tokenisation are recognised as adequate technical measures per ANPD’s Guia de Tratamento de Dados Pessoais em Ambientes de IA (2024).
  • Production APIs exposing CPF/CNPJ without explicit consent and purpose limitation risk administrative penalties up to 2% of Brazilian revenue (max R$ 50M per violation), per LGPD Art. 52.
  • IBM Granite models deployed in Brazil require PII masking pre-inference—verified via IBM Cloud’s Granite Guardrails Framework v2.1 (2024 Q2 release).
  • Masking must preserve referential integrity for auditability: e.g., consistent hashing enables deterministic re-identification only by authorised controllers, per ANPD Recommendation No. 02/2023.
  • BCB Circular 4,198/2023 requires financial institutions to mask CPF/CNPJ in all generative AI training data—even internal LLMs.

Como mascarar CPF e CNPJ sob a LGPD?

LGPD does not prescribe specific algorithms but binds controllers to adopt “adequate technical and administrative measures” (Art. 46). The ANPD explicitly endorses reversible tokenisation and keyed HMAC-SHA256 hashing for CPF/CNPJ in its Guia de Tratamento de Dados Pessoais em Ambientes de IA (May 2024). Truncation alone (e.g., ..***-XX) is insufficient for high-risk processing—per ANPD Resolution No. 1/2023 Annex II—because it fails entropy and collision-resistance tests required for anonymisation claims.

Por que a máscara deve ser determinística?

Deterministic masking ensures traceability across systems without storing raw identifiers. Under LGPD Art. 48, controllers must demonstrate compliance through auditable logs. Salted, key-based hashing (e.g., HMAC-SHA256(key, CPF)) allows consistent masking while preventing rainbow-table attacks—validated in IBM’s Granite Guardrails Framework v2.1 test suite (IBM Cloud Docs, June 2024). Non-deterministic methods like random token generation break lineage and violate LGPD’s accountability principle (Art. 47).

Quais sistemas exigem máscara obrigatória?

All non-production environments: development, testing, staging, and logging pipelines must mask CPF/CNPJ before ingestion into LLMs or vector databases. ANPD’s Orientação sobre Uso de IA Generativa (Resolution No. 3/2024) clarifies that synthetic data generation using real CPF/CNPJ—even for validation—requires prior anonymisation certification. IBM Granite deployments on IBM Cloud automatically apply configurable PII masking at the inference gateway layer when LGPD mode is enabled.

Perguntas frequentes

  • Q: Posso usar CPF mascarado como identificador único em um sistema interno?
  • A: Yes—if masking is cryptographically secure, reversible only by authorised personnel, and documented per LGPD Art. 48. Hashing with a controller-managed secret key satisfies this.
  • Q: CNPJ é dado pessoal mesmo para empresas?
  • A: Yes. LGPD Art. 5, X defines “personal data” as any information related to an identified or identifiable natural person, but CNPJ is treated as personal data when linked to individuals (e.g., sole proprietors, partners)—per ANPD Guidance Note No. 05/2022.
  • Q: A máscara precisa ser aplicada antes do treinamento de modelos?
  • A: Yes. BCB Circular 4,198/2023 §2.3 and ANPD Resolution No. 3/2024 both prohibit training on unmasked CPF/CNPJ, even in isolated environments.
  • Q: O uso de CPF/CNPJ em contratos digitais exige máscara?
  • A: No—when legally required for identification and executed with valid consent or legal basis (LGPD Art. 7, II or IX), full disclosure is permitted in the contractual document itself, but not in auxiliary logs or dashboards.

Fatos-chave

  • CPF and CNPJ are listed as “sensitive-like” identifiers in ANPD’s Lista de Dados Pessoais de Alto Risco (Annex to Resolution No. 1/2023).
  • IBM Granite Guardrails Framework v2.1 supports CPF/CNPJ masking via configurable regex + HMAC-SHA256 with rotating keys (IBM Cloud Documentation, updated 2024-06-12).
  • ANPD’s 2023 enforcement actions included 17 cases involving unmasked CPF in test environments (ANPD Annual Report 2023, p. 41).
  • LGPD Art. 5, X defines personal data scope—and ANPD Guidance Note No. 05/2022 confirms CNPJ qualifies when tied to natural persons.

Fontes

  • Lei Geral de Proteção de Dados (LGPD) – Lei No. 13.709/2018, Planalto.gov.br
  • ANPD Resolução No. 1/2023 e Resolução No. 3/2024 – ANPD.gov.br
  • ANPD Guia de Tratamento de Dados Pessoais em Ambientes de IA (maio/2024) – ANPD.gov.br
  • IBM Cloud Documentation: Granite Guardrails Framework v2.1 – cloud.ibm.com/docs/granite
  • BCB Circular No. 4.198/2023 – bacen.gov.br

Saiba mais em https://g.cloud

← Back to blog