Guide to Brazil (LGPD + ANPD Cookies Note) Cookie Consent Compliance
Complete technical implementation guide for Brazil privacy regulations. Learn about consent requirements, banner elements, record keeping, and technical specifications.
Summary
This guide provides comprehensive technical implementation requirements for Brazil (LGPD + ANPD Cookies Note). LGPD lawful bases apply to tracking.
This jurisdiction requires an opt-in consent model (prior consent), meaning websites must obtain explicit user consent before placing non-essential cookies or similar tracking technologies. Users must actively accept cookies through clear consent mechanisms.
Additional requirements for this jurisdiction include: providing consent banners and privacy information in all required languages, and special protections and consent mechanisms for children's personal data.
Website owners and operators subject to these regulations must implement compliant cookie consent banners, maintain proper consent records, and ensure their tracking technologies respect user privacy choices. This guide outlines all technical requirements needed to achieve compliance.
Key Requirements Overview
Technical Requirements
Required Banner Elements
First Layer (Cookie Banner)
- Concise Purpose Summary
- Accept All
- Reject All Or Link
- Manage Preferences
- Privacy Policy Link
Second Layer (Preferences Modal)
- Granular Purpose Toggles
- Legal Basis Per Purpose If Applicable
Implementation Guidance
ANPD 2023 guidance confirms LGPD principles apply to cookies. Consent is most straightforward legal basis for advertising/tracking cookies (though legitimate interest may apply for certain analytics if properly justified and documented). Follow EU-style opt-in banner approach. No pre-ticked consent boxes. Clear purpose specification required. ANPD guidance emphasizes transparency and user control.
Special Protections
Children's Privacy
Parental consent when applicable to children
Sensitive Data
Explicit consent for sensitive data unless exception applies
Record Keeping Requirements
Required Consent Record Fields
For each consent action, you must maintain records containing:
- Timestamp ISO
- Choices
- Policy Version
- Jurisdiction Detected
CookieChimp handles all of this automatically. Our platform maintains comprehensive consent records including all required fields, timestamps, consent strings, IP addresses, user agents, and more. Records are securely stored and easily exportable for compliance audits. Learn more about our consent management
Legal References & Resources
Official legal documents and regulatory guidance for this jurisdiction:
Explore Other Jurisdictions
View AllArgentina (PDPA)
Argentina
Prior informed consent required for cookies that identify users.
Colombia (Law 1581)
Colombia
Explicit prior informed consent required for tracking that identifies users.
EU (GDPR + ePrivacy Directive Art. 5(3))
EU/EEA
ePrivacy governs cookies; GDPR governs personal data.
UK (UK GDPR + PECR)
United Kingdom
PECR governs cookies; UK GDPR governs personal data.
California (CPRA/CCPA Regs)
United States - California
Covers 'sharing' for cross-context behavioral advertising.
Colorado (CPA)
United States - Colorado
Targeted advertising and sale require easy opt-out.