Does Brazil's LGPD ban AI at work?

The LGPD does not ban ChatGPT and does not require blocking AI. It requires a legal basis, records, transparency and control. Article by article, applied to corporate AI usage.

Updated August 15, 2026 · 13 min read

The short answer: does the LGPD ban any tool?

No. The question that reaches legal is almost always “can we use ChatGPT?”, and it is the wrong question — which is why it never has a good answer. The LGPD does not regulate tools. It regulates the processing of personal data.

The same tool can be perfectly lawful for reviewing a marketing text and unlawful for summarising a patient record. What changes is not the software: it is the data going into it, for what purpose, and under which legal basis.

The right question is: what personal data is going into this tool, for what purpose, under which legal basis, and is that recorded? This guide walks through what Brazil’s Law 13.709/2018 requires, article by article, applied to corporate use of artificial intelligence.

Informational material, not legal advice. Legal basis, legitimate-interest balancing and the framing of international transfers depend on the context of each operation and should be validated with your legal team or data protection officer.

When the LGPD reaches your use of AI

The trigger is the presence of personal data — any information relating to an identified or identifiable natural person (art. 5, I). In everyday AI use, personal data enters through routes rarely perceived as processing:

  • A customer or supplier name inside an email pasted in to be summarised.
  • Meeting minutes or a transcript, which contain participants’ names and voices.
  • A CV submitted for screening — and here sensitive data may be involved.
  • Payroll spreadsheets, performance reviews, attendance records.
  • A customer base uploaded to “spot patterns”.
  • A screenshot of an internal system pasted in to ask for help with an error.

None of these feels like “data processing” to someone in a hurry. All of them are. And the scale at which they happen is now measurable: IBM’s annual study isolated the effect of unapproved AI use on real incidents.

49%

of incidents involving Shadow AI resulted in data loss or compromise and, in 21%, the organisation reported paying a regulatory fine. Unapproved AI use has real consequences for exactly the data that privacy law protects.

IBM / Ponemon Institute, Cost of a Data Breach Report 2026

Where sensitive data is involved (art. 5, II — racial origin, religious conviction, political opinion, union membership, health, sex life, genetic or biometric data), the regime is stricter: the legal bases in art. 11 are a smaller and more demanding set than those in art. 7.

Biometric data deserves specific attention in voice tools. Voice is biometric data, and automatic meeting transcription is today one of the most widespread AI inputs in companies — usually switched on by an update from a vendor that was already approved.

What the law requires, article by article

The table below is the map that tends to be missing: what each article asks for, and how that shows up in practice once the tool is an AI tool.

ArticleRequirementHow it shows up in AI use
Art. 6Principles: purpose, adequacy, necessity, transparency, security, prevention, accountability.Necessity is the most violated: pasting the whole spreadsheet when three columns would do is processing beyond what is needed, even with a valid legal basis.
Art. 7 and 11A legal basis for each processing operation.The basis is chosen per purpose, not per tool. The same tool can operate under different bases in different uses.
Art. 9Clear information to the data subject about purpose and sharing.If customer data goes to an AI vendor, that must be in the privacy notice — and most notices were written before AI entered operations.
Art. 18Data subject rights, including erasure and information about sharing.It is impossible to answer “who was my data shared with” if the company does not know which AI tools are in use.
Art. 20Right to review of decisions taken solely on the basis of automated processing.CV screening, credit analysis and support prioritisation done by AI land here, with a duty to disclose the criteria.
Art. 33 and 34Requirements for international transfers.Most AI tools process outside Brazil. This needs a formal route — the vendor being well known is not one.
Art. 37Record of processing activities.Each material AI use over personal data is an operation and should appear in the record. It is the most frequent audit finding.
Art. 38Data protection impact report, when requested by the authority.High-impact AI use over data subjects is a natural candidate — better produced before it is asked for.
Art. 39The processor must process data according to the controller's instructions.This requires a contract. Accepting a free tool's standard terms of service usually does not satisfy it.
Art. 46Technical and administrative security measures.Includes knowing who has access to what — hard to sustain without an inventory of what is in use.
Art. 48Notification of incidents to the authority and to data subjects within a reasonable period.Only possible with detection in place. Without visibility, the incident is discovered by third parties.

Article 46 deserves a parenthesis, because one number explains it better than any commentary. Among organisations that suffered breaches involving AI, IBM measured how many had adequate access control over those tools:

92%

of organisations reporting an AI-related breach lacked proper access controls for those tools. This is not a careless minority — it is the market’s default state.

IBM / Ponemon Institute, Cost of a Data Breach Report 2026

The temptation is to ask for consent for everything. In an employment relationship that is fragile: there is asymmetry between employer and employee, and consent a person does not feel free to refuse tends not to hold up as a freely given declaration.

There is a practical aggravating factor. Consent is revocable at any time (art. 8, § 5), which makes any process depending on it unstable. One employee revoking pulls the legal basis out from under the entire processing operation.

In practice, three framings dominate the corporate AI context:

  • Performance of a contract (art. 7, V) — where processing is necessary to deliver what the customer contracted.
  • Compliance with a legal or regulatory obligation (art. 7, II) — typical in regulated sectors, where the sectoral rule itself compels the processing.
  • Legitimate interest (art. 7, IX) — the basis most used for internal productivity tools. It requires a documented balancing test and does not cover sensitive data.

Legitimate interest is not a wildcard: it is the basis that demands the most documentation. If you invoke it, you must be able to show the balancing test you performed, the data subject’s reasonable expectation, and the measures adopted to reduce impact. Without that document, it is an assertion, not a legal basis.

International transfers: the deadline that already passed

Almost every meaningful AI tool processes data outside Brazil — mostly the United States, but also the United Kingdom, the European Union, India and China. Sending personal data to those tools is an international transfer and needs to fit one of the routes in article 33.

This is the part of the guide that changed most recently, and the part most companies are unaware of. On 23 August 2024, Brazil’s data protection authority published Resolution CD/ANPD No. 19/2024, approving the International Transfer Regulation and the text of the standard contractual clauses.

The resolution granted twelve months of transition to incorporate the clauses into existing contracts. That period ended on 23 August 2025. A company transferring personal data abroad on a contractual basis that has not yet adopted the text is now past the deadline, not inside an adaptation window.

Two operational details tend to catch teams by surprise. First: the standard clauses must be adopted in full and without modification, as an annex signed between exporter and importer. It is not a reference template to adapt.

The second comes before all of it: adopting standard clauses presupposes having a contract with the AI vendor. A free account accepted by an employee under standard terms of service does not establish that relationship — and that is how most AI use entered companies in the first place.

One distinction still confuses many teams: the vendor’s home country is not the same as data residency. A US company may offer processing in a specific region on its enterprise plan. Our public catalog reports the home country as a jurisdiction signal, but where data is actually processed depends on the plan you hold and must be confirmed with the vendor.

Free account vs corporate plan

Between a free account and a corporate account of the same tool there is usually a difference that changes the entire legal framing: the default behaviour regarding training on your data, and the existence of a processing agreement.

Personal / free accountCorporate plan
Training on your dataFrequently enabled by defaultNormally disabled by contract
Processing agreement (art. 39)Standard terms, accepted by the employeeContract signed by the company
International transfer (art. 33)No formal routeAddressable via the ANPD standard clauses
Record and auditabilityNone — the company does not know it existsAdministrable and auditable

This has a direct operational consequence: knowing that “they used ChatGPT” matters less than knowing on which plan. Two people using the same tool can sit in completely different legal situations.

Detection that does not distinguish account and plan leaves that gap open — and it is precisely the gap that surfaces when a data subject exercises the article 18 right and asks who their data was shared with.

A nine-point compliance checklist

In the order an auditor tends to ask — and the order in which it makes sense to solve:

  • 1. Inventory. Is there a list of what is in use, kept current? Without it, everything below is a declaration, not evidence. See how to build an AI-BOM.
  • 2. Record of processing (art. 37). Do AI uses over personal data appear in the record, with purpose, legal basis, categories of data subjects and recipients?
  • 3. Legal basis. Does each purpose have a defined basis and, where it is legitimate interest, a documented balancing test?
  • 4. Contracts (art. 39). Is there a processing agreement with the AI vendors used over personal data?
  • 5. International transfer (art. 33). Have the Resolution 19/2024 standard clauses been incorporated? The deadline was 23 August 2025.
  • 6. Privacy notice (art. 9). Does the notice reflect sharing with AI vendors?
  • 7. Automated decisions (art. 20). Where decisions about people are made, is there a review path and disclosure of the criteria?
  • 8. Policy and training. Is there a published policy, communicated, with evidence of acknowledgement? See the annotated template.
  • 9. Incident response (art. 48). Is there detection capable of noticing an incident before a third party reports it?

Note that eight of the nine items depend on the first. Compliance programmes that begin by writing the policy and the processing record over an un-inventoried environment document the company they imagine having, not the one that exists — and that gap is what shows up in the audit.

Point 9 carries a measurable cost. IBM measured the average cost of security incidents in which Shadow AI was involved:

USD 5.39 million

was the average cost of incidents involving Shadow AI, against USD 4.99 million for the global average across all breaches. Shadow AI was present in 43% of the security incidents analysed. It is an average across organisations that suffered a breach, not a forecast for your company.

IBM / Ponemon Institute, Cost of a Data Breach Report 2026

What is at stake

Sanctions under article 52 range from a warning to a fine of up to 2% of revenue in Brazil, capped at BRL 50 million per infraction, plus blocking or deleting the data involved and public disclosure of the infraction.

In practice, though, for most companies the relevant cost arrives before the regulator does: a corporate customer demanding privacy due diligence in the contract, an insurer asking about AI governance at renewal, and a certification audit stalling for lack of records.

And there is the cost of not deciding. McKinsey’s annual survey, with 1,993 respondents across 105 countries between 25 June and 29 July 2025, shows the problem has left the hypothetical:

51%

of organisations using AI report having already seen at least one negative consequence from it. At the same time, only about a third say they have scaled AI across the enterprise — exposure is growing faster than governance.

McKinsey & Company, The State of AI: Global Survey

Looking ahead, Gartner puts a date on it: by 2030, more than 40% of organisations are expected to face a security or compliance incident tied to unauthorised AI use. Today, 69% already suspect or have evidence that employees use prohibited public generative AI tools.

Frequently asked questions

Does Brazil's LGPD ban using ChatGPT at work?

No. The LGPD bans no specific tool. It regulates the processing of personal data: if the tool receives personal data, you need a legal basis, a record of the processing activity, notice to the data subject, a contract with the vendor, and a lawful route for the international transfer. If the tool only receives non-personal data, the LGPD does not apply to that use.

Is using AI without recording it a violation even if nothing leaks?

Yes. The irregularity does not depend on an incident. Processing personal data without a legal basis (art. 7), without it appearing in the record of processing activities (art. 37) or without informing the data subject (art. 9) is non-compliance in itself. A leak is an aggravating factor, not the trigger.

Which legal basis should we use for AI at work?

It depends on the purpose, not on the tool. For internal productivity use over employee data, legitimate interest (art. 7, IX) with a documented balancing test is the usual candidate. For processing customer data within the performance of a contract, item V. Consent (item I) is rarely the best choice in an employment relationship, because of the asymmetry between the parties.

Is sending data to a US-based AI tool an international transfer?

Yes, and article 33 applies. Brazil's data protection authority approved standard contractual clauses in Resolution CD/ANPD No. 19/2024, and the transition period to adopt them ended on 23 August 2025. Any company transferring personal data abroad on a contractual basis that has not yet incorporated the clauses is past the deadline.

Do we need a contract with the AI vendor?

If the tool processes personal data on your company's behalf, yes: article 39 requires the processor to follow the controller's instructions, and that presupposes a contractual instrument. A free account accepted by an employee under standard terms of service usually does not establish that relationship.

Sources

Found it useful? Share it

LinkedInX

Instagram does not open links from outside the app — we copy it for you to paste in a story or bio.

Where does your company stand today?

The free assessment is 9 questions, 5 minutes and no signup. It returns your maturity level per dimension and a prioritised action plan — enough to know where to start without buying anything.