Skip to main content
v2026.11,610 entries · CC-BY 4.0
LAC HealthLaboratory & ResearchLab & research supplies.Reagents, consumables, PPE & instruments — documented, fast, chain-of-custody shipping.Shop lac.us lac.us

Brazil’s LGPD and Research Data: The Academic-Purpose and Anonymized-Data Exemptions

How Brazil’s LGPD (Law 13,709/2018) applies to research data: the Article 7/11 lawful bases for research bodies, the partial Article 4 academic-purpose exemption, the Article 12 anonymized-data exclusion, and the mandatory Encarregado (DPO) under Article 41.

Brazil’s Lei Geral de Proteção de Dados (LGPD), Law No. 13,709/2018, is Brazil’s comprehensive data protection statute, broadly comparable in scope and structure to the EU’s GDPR. It applies to any processing of personal data carried out in Brazil, or targeting individuals in Brazil, regardless of where the processing entity is based — which means a university, funder, or international research collaboration handling data on Brazilian participants is in scope even if no part of the study is physically conducted in Brazil. Enforcement sits with the Autoridade Nacional de Proteção de Dados (ANPD), Brazil’s national data protection authority, created under Law No. 13,853/2019 and made an independent federal authority by Law No. 14,460/2022.

This guide covers what research administrators, data stewards, and institutional privacy officers specifically need to know: the lawful bases the LGPD provides for processing personal data in research, the partial academic-purpose exemption and its real limits, how anonymized data is treated differently from personal data, and the mandatory Encarregado (data protection officer) role every controller must appoint. It is distinct from CASRAI’s guide to CNPq’s Scientific Integrity Policy, which covers research-misconduct oversight in Brazil, not data-privacy law — an institution operating in Brazil needs to satisfy both frameworks, but they govern different things.

The academic-purpose exemption in Article 4 is partial, not blanket

LGPD Article 4, item II excludes processing carried out “for exclusively journalistic, artistic, or academic purposes” from parts of the law’s general application. It is a common misreading to treat this as a full carve-out for research. It is not: the same provision explicitly conditions the academic exemption on compliance with Articles 7 and 11 — the articles that set out the lawful bases for processing ordinary and sensitive personal data, respectively. In practice, this means academic processing is exempted from some of the LGPD’s general procedural apparatus (for example, some of the data-subject-request mechanics built for commercial controllers) but still has to rest on one of the specific lawful bases the law provides, and still has to respect the sensitive-data protections in Article 11 when special-category data — health status, genetic data, biometric data, and similar — is involved.

The ANPD has published a technical study addressing exactly this question — how the LGPD applies to data processing for academic purposes and for studies carried out by research bodies — reflecting how frequently institutions have needed clarification on where the exemption’s boundary actually sits. The practical takeaway for a research-compliance office: do not rely on “this is academic research” alone as a legal basis. Identify which Article 7 (or Article 11, for sensitive data) basis applies, and document it, the same way you would document a lawful basis under GDPR Article 6.

The specific lawful basis for research: Article 7, item IV

Article 7 lists the lawful bases that justify processing ordinary personal data under the LGPD — consent, contract performance, legal obligation, and so on. Item IV is the basis built specifically for research: it permits processing “to carry out studies by a research body, ensuring, whenever possible, the anonymization of personal data.” Two things about that wording matter for compliance:

  • It is tied to a “research body” (órgão de pesquisa). The LGPD defines this in Article 5 as a public or private, non-profit-oriented entity established under Brazilian law and headquartered in Brazil, whose institutional purpose or mission statement includes basic or applied research of a historical, scientific, technological, or statistical nature. A commercial entity running a study is not automatically a “research body” for purposes of this basis; a university, public research institute, or a similarly constituted non-profit research organization typically is.
  • Anonymization is an obligation, not an option, “whenever possible.” The basis does not excuse a research body from anonymizing where anonymization is technically and practically feasible — it only recognizes that some study designs (longitudinal cohorts that need to re-contact participants, for instance) cannot function on fully anonymized data. Where anonymization is not possible, the processing still needs a documented justification for why, and the data still needs to be handled under the LGPD’s general security and minimization principles.

For sensitive personal data specifically — health data, genetic data, biometric data, data on racial or ethnic origin, religious conviction, and other special categories listed in Article 5, item II — the parallel research basis is Article 11, item II, subitem “c,” which authorizes processing “when indispensable for” the study, again with anonymization required whenever possible. This is the provision that most directly governs clinical, epidemiological, genomic, and public-health research involving identifiable participant data.

Anonymized data: outside the LGPD’s scope, with one important caveat

Article 12 provides that anonymized data is not considered personal data for purposes of the LGPD, with one explicit exception: if the anonymization process can be reversed using reasonable means available at the time of processing, the data is treated as personal data again. This “reasonable means” reversibility test is the same conceptual test the GDPR applies to anonymization (recital 26) — it is a moving target tied to available re-identification techniques, computing capability, and auxiliary data sources, not a one-time technical determination you can make and forget.

This distinction is why anonymization and pseudonymization are not interchangeable for LGPD purposes, even though both are common data-minimization techniques in research pipelines. CASRAI’s Anonymization vs. Pseudonymization comparison covers the technical and regulatory difference in detail; the short version for LGPD compliance is that pseudonymized data (a reversible key held by the controller) remains personal data and needs a lawful basis under Article 7 or 11, while genuinely anonymized data — irreversible by reasonable means — falls outside the law’s scope under Article 12. Where a research design can tolerate it, fully synthetic data is a further option that avoids LGPD applicability altogether for the synthetic dataset itself; see CASRAI’s guide to synthetic data in research for how that data class is generated, documented, and shared.

Article 13 adds a parallel rule specifically for the health field: when personal data is used by the public sector to conduct studies in public health, it must be processed within the public body itself and, whenever possible, made available in anonymized form. This is the provision most relevant to health ministries, public university hospitals, and SUS-affiliated research units running population-level health studies.

The mandatory Encarregado (Data Protection Officer)

Article 41 requires every controller — a term that includes universities, research institutes, and any organization that determines the purposes and means of processing personal data under the LGPD, without a small-controller exemption built into the statute itself — to appoint an Encarregado, the LGPD’s equivalent of a GDPR Data Protection Officer. The ANPD has since issued complementary rules (under the Article 41, paragraph 3 rulemaking power) creating a limited exemption path for small processing agents, defined by Resolution CD/ANPD No. 2/2022, but the baseline obligation in the statute itself applies broadly, and most research institutions of any real size fall outside the small-agent carve-out.

The Encarregado’s role, per Article 41, paragraph 2, is to:

  • Accept complaints and communications from data subjects, and provide clarifications and adopt measures in response;
  • Receive communications from the ANPD and act on them;
  • Guide the organization’s staff and contractors on data protection practices; and
  • Carry out any other duties assigned by the controller or established in the ANPD’s complementary regulations.

Article 41, paragraph 1 requires the Encarregado’s identity and contact information to be published clearly and objectively, preferably on the controller’s own website — the equivalent of the public DPO contact requirement under GDPR Article 37. In November 2024 the ANPD opened enforcement proceedings against a batch of companies specifically for failing to appoint an Encarregado or failing to publish contact information, an early signal that this is an obligation the authority audits and enforces in practice, not a formality institutions can leave undocumented.

Practical compliance checklist for research administrators

  • Map the lawful basis before data collection begins. Identify whether the study relies on Article 7, item IV (ordinary data) or Article 11, item II(c) (sensitive data), or on a different basis such as consent, and document that determination alongside the protocol — the same discipline institutions already apply to IRB/ethics-committee review.
  • Confirm the processing entity actually qualifies as a “research body” under the Article 5 definition before relying on the research-specific bases.
  • Build anonymization into the data management plan wherever the study design allows it, and document why it isn’t feasible where it genuinely isn’t — “whenever possible” is a standard the ANPD can test, not a box to check.
  • Re-evaluate anonymization periodically against re-identification risk, since Article 12’s “reasonable means” test shifts as re-identification techniques and auxiliary datasets improve.
  • Appoint and publish an Encarregado, with contact details on the institution’s website, and confirm the role’s Article 41 responsibilities are actually staffed, not just nominally assigned.
  • Treat LGPD compliance as separate from, and additional to, research-integrity oversight such as CNPq’s misconduct framework, funder DMP requirements, or ethics-committee approval — satisfying one does not satisfy the others.

Frequently asked questions

Does the LGPD apply to a foreign university collaborating with a Brazilian institution?

Yes, if the processing involves personal data of individuals located in Brazil, or is carried out in Brazil, the LGPD applies regardless of where the collaborating institution is headquartered — the same extraterritorial logic as the GDPR.

Is consent always required to process research participant data under the LGPD?

No. Consent is one of ten lawful bases in Article 7, but Article 7, item IV provides a separate, research-specific basis that does not require consent, provided the processing is carried out by a qualifying research body and anonymization is applied whenever possible. Ethics-committee informed-consent requirements are a separate obligation under Brazilian research-ethics rules and should not be conflated with the LGPD lawful-basis question.

Can a small research lab skip appointing an Encarregado?

Only within the narrow small-processing-agent exemption the ANPD has defined by resolution (Resolution CD/ANPD No. 2/2022); the statutory default in Article 41 is that every controller appoints one, and institutions should confirm they actually meet the resolution’s specific criteria before relying on the exemption rather than assuming it applies.

Does anonymizing data once satisfy the LGPD permanently?

No. Article 12 ties the anonymized/personal-data distinction to whether reversal is possible “using reasonable means” available at the time, which is not a fixed technical bar — data anonymized adequately today can require re-assessment as re-identification techniques and available auxiliary data change.

Related CASRAI resources

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →