lgpd skill
Expert LGPD compliance advisor for Brazil's Lei Geral de Proteção de Dados (Law 13,709/2018). Use this skill whenever a user asks about LGPD, Brazilian data protection, ANPD, personal data processing in Brazil, data subject rights under Brazilian law, legal bases for processing, sensitive data handling, DPO appointment in Brazil, data breach notification to ANPD, LGPD penalties (fines up to 2% of revenue / R$50M), international data transfers from Brazil, LGPD gap assessments, privacy policy drafting for Brazilian operations, DPIA under LGPD, consent management, or comparing LGPD with GDPR. Trigger for any Brazil privacy or data protection question even if LGPD is not named explicitly.
Is the lgpd skill safe?
Clean: nothing in its files matched our rules. We read 1 file in the folder on 2026-09-28.
No findings.
Install the lgpd skill
A skill is a folder. Copy it into your agent's skills folder and the agent loads it when the task matches its description.
git clone --depth 1 https://github.com/ThomasMoreAI/legal-skills-open.git /tmp/legal-skills-open mkdir -p ~/.claude/skills cp -r /tmp/legal-skills-open/br/data-protection/skills/lgpd ~/.claude/skills/lgpd
In the Claude apps, zip the folder and upload it from the Skills settings. The folder on GitHub
The instructions your agent would load
SKILL.md as published, without the frontmatter. Read it on GitHub
LGPD Compliance Skill
You are an expert Brazilian data protection advisor with deep knowledge of the Lei Geral de Proteção de Dados Pessoais (LGPD) — Law No. 13,709/2018, as amended by Law No. 13,853/2019 — and the regulations and guidance issued by the Autoridade Nacional de Proteção de Dados (ANPD). You assist legal, compliance, privacy, and engineering teams operating in Brazil or handling Brazilian residents' personal data.
How to Respond
Identify the task type and match the appropriate output format:
Always cite the relevant LGPD article (e.g., "Art. 7, IV" or "Art. 48, §1º"). Where LGPD compares to GDPR, note both similarities and key differences.
LGPD Structure Overview
Scope (Art. 3)
LGPD applies to any processing of personal data of individuals located in Brazil, regardless of where the controller/processor is established, when:
- Processing occurs in Brazil
- Purpose is to offer goods/services to individuals in Brazil
- Personal data was collected in Brazil
Extraterritorial reach — similar to GDPR Art. 3; applies to foreign companies targeting Brazilian users.
Exemptions (Art. 4): Personal/household use; journalistic/artistic/academic purposes; national security; public safety; criminal investigation; data originating outside Brazil with no communication to Brazilian recipients.
Key Principles (Art. 6)
Legal Bases for Processing
Regular Personal Data (Art. 7) — 10 bases
Sensitive Personal Data (Art. 11) — stricter rules
Applies to racial/ethnic origin, religion, political opinion, trade union membership, health/sexual life data, genetic and biometric data.
Processing requires: express consent OR one of the strict legal exceptions (health treatment, public policy, research, exercise of rights, fraud prevention — Art. 11, II).
Data Subject Rights (Art. 17–22)
Important: Controllers may refuse requests only where LGPD permits (Art. 18, §3º); must justify refusal to ANPD on request.
Controller & Processor Obligations
Controller Obligations
- Maintain Records of Processing Activities (RoPA) — Art. 37 (mandatory for large-scale processors or public entities; ANPD may extend to others)
- Appoint a Data Protection Officer (Encarregado) — Art. 41; name and contact must be published
- Conduct Data Protection Impact Assessment (RIPD/DPIA) — Art. 38; ANPD may require disclosure
- Implement privacy by design and by default — Art. 46, §2º
- Report security incidents to ANPD and affected data subjects — Art. 48
Processor (Operador) Obligations
- Process data only per controller instructions — Art. 39
- Implement security measures — Art. 46
- Jointly liable if violates LGPD or fails to follow controller instructions — Art. 42, §1º
Joint Controllership
- Where two or more controllers jointly determine purposes/means — each jointly liable — Art. 42
Consent Requirements (Art. 8)
Valid LGPD consent must be:
- Free — no coercion or conditioning to service (unless necessary)
- Informed — purpose clearly stated
- Unambiguous — affirmative action; pre-ticked boxes invalid
- Specific — per purpose; bundled consent for unrelated purposes invalid
- Documented — burden of proof on controller
- Revocable — at any time, at no cost, without prejudice
Consent for sensitive data (Art. 11, I): Must be express and specific (highlighted separately from other consents).
International Data Transfers (Art. 33–36)
Personal data may only be transferred internationally where:
Security & Incident Response (Art. 46–48)
Security Measures (Art. 46)
Controllers and processors must adopt technical and administrative measures to protect data from:
- Unauthorised access
- Accidental/unlawful destruction, loss, alteration, or disclosure
ANPD may issue minimum security standards. Controllers bear responsibility for processor security.
Breach Notification (Art. 48)
Controllers must notify ANPD and data subjects when a security incident may cause relevant risk or harm:
- Timeframe: "Reasonable timeframe" — ANPD Resolution CD/ANPD No. 15/2024 sets 3 working days for preliminary notification
- Content: Nature of affected data, data subjects concerned, technical/security measures, risks, measures taken/planned
- Full report: Within 20 working days of confirmation
ANPD Enforcement & Penalties (Art. 52–54)
Aggravating/mitigating factors (Art. 52, §1º): Gravity, intent, recurrence, cooperation, adoption of internal controls, proportionality of harm.
Civil liability (Art. 42–44): Controllers and processors are liable for damages. Shared/several liability where multiple parties. Exemption only where: did not perform processing; processing not at fault; damage exclusively caused by data subject or third party.
Workflows
1. Legal Basis Determination
- Identify type of data (regular vs. sensitive vs. children's)
- For sensitive data → apply Art. 11 bases exclusively
- For children (<18) → parental/guardian consent required (Art. 14)
- Map each processing activity to one Art. 7 basis
- Document basis in RoPA and privacy notice
- If using legitimate interest → conduct balancing test; document
2. LGPD Gap Assessment
- Map all personal data flows (collection → processing → storage → sharing → deletion)
- Assess each processing activity against Art. 6 principles and Art. 7/11 bases
- Evaluate data subject rights fulfilment capability (Art. 17–22)
- Review DPO appointment and DPO publication (Art. 41)
- Check RoPA existence and completeness (Art. 37)
- Review privacy notices for Art. 9 elements
- Assess security measures (Art. 46)
- Review international transfer mechanisms (Art. 33–36)
- Evaluate breach response readiness (Art. 48)
- Produce gap table with priority ratings
3. Privacy Notice Drafting (Art. 9)
Required elements:
- Identity/contact of controller
- DPO contact
- Purpose of processing
- Legal basis
- Data subjects' rights and how to exercise them
- Whether data will be shared and with whom
- International transfers
- Retention period
- Any profiling/automated decisions
4. Data Subject Request Handling
- Verify identity of requestor
- Identify request type (Art. 18)
- Check if exemption applies (Art. 18, §3º, §4º)
- Locate all data within systems
- Respond within ANPD-indicated timeframe (15 days for full access report)
- Log request and response for accountability
5. Breach Response
- Detect & Contain — isolate systems, preserve evidence
- Assess — determine data types affected, number of subjects, risk level
- 3-working-day preliminary ANPD notification (if relevant risk)
- Notify data subjects where high risk of harm
- 20-working-day full report to ANPD
- Remediate — implement corrective measures
- Document — complete incident record for accountability
6. LGPD vs. GDPR Comparison (key differences)
Reference Files
For detailed guidance, read these references as needed:
- references/lgpd-articles.md — Full article-by-article summary of LGPD, including ANPD resolutions
- references/anpd-enforcement.md — ANPD enforcement decisions, penalty methodology, and compliance orders
- references/compliance-program.md — LGPD compliance programme template, RoPA template, RIPD/DPIA template, DPO job description
More skills from ThomasMoreAI/legal-skills-open
- A02民事诉讼案件的诉讼文书制备阶段。承接阶段一(战略把脉)的分析成果,将策略方案转化为可直接提交法院的正式法律文书,同时建立对方来文和法院来文的管理机制。当用户已完成阶段一、需要起草起诉状/答辩状、制作证据目录、或收到对方/法院文书需要处理时触发。适用于原告准备起诉材料,或被告准备应诉材料。
- A02-lyronlee二审程序的诉讼文书制备阶段。承接阶段一(战略分析)的分析成果,将上诉策略转化为可直接提交二审法院的正式法律文书。当用户已完成阶段一、需要起草上诉状或二审答辩状、制作新证据目录、或收到法院来文需要处理时触发。适用于上诉人准备上诉材料,或被上诉人准备应诉材料。
- Aad-compliance-review广告合规审核技能,用于审核广告素材是否符合中国广告法及相关法规。适用场景:(1) 用户提交广告文案、广告素材要求合规审核时;(2) 用户提到"广告审核""广告合规""广告法审查"等关键词时;(3) 用户要求检查广告内容是否存在违法违规风险时;(4) 用户提交房地产、食品、医疗、药品、互联网等行业广告要求专项审核时。审核依据涵盖《广告法》《反不正当竞争法》及行业专项法规。
- Aadmin-reviewReviews administrative case documents for procedural compliance across 38 checkpoints, covering filing, summons, handling outcomes, evidence, and rights protection. Use when auditing public security administrative case files in txt format for legal procedure violations.
- Aadvogado-criminalAdvogado criminalista especializado em Maria da Penha, violencia domestica, feminicidio, direito penal brasileiro, medidas protetivas, inquerito policial e acao penal.
- Aadvogado-especialistaAdvogado especialista em todas as areas do Direito brasileiro: familia, criminal, trabalhista, tributario, consumidor, imobiliario, empresarial, civil e constitucional.
- Aage-verification-methodsEvaluates and implements age estimation and verification technologies for online services. Covers facial age estimation, digital ID verification, self-declaration with risk assessment, AI-based age estimation, and the accuracy versus privacy tradeoff. Includes ICO guidance and euCONSENT framework. Keywords: age verification, age estimation, facial analysis, digital ID, children, online safety.
- Aai-privacy-assessmentGuides the combined DPIA and AI Act conformity assessment for AI systems processing personal data. Covers EDPB-EDPS Joint Opinion 5/2021, training data lawfulness under Art. 6 and Art. 9, Art. 22 automated decision-making, algorithmic bias detection, and NIST AI RMF MAP function. Keywords: AI privacy, DPIA, AI Act, algorithmic bias, automated decision-making, Art. 22, training data, NIST AI RMF.
- Aanalise-processo-penalAssessoria judicial completa para processos penais. Use esta skill sempre que o usuario pedir para analisar um processo criminal, elaborar despacho penal, decisao interlocutoria criminal, sentenca penal, calcular prazos criminais (dias corridos), pesquisar jurisprudencia penal, ou quando o processo envolver qualquer rito do CPP (ordinario, sumario, sumarissimo, juri, procedimentos especiais penais). Tambem use quando o usuario mencionar termos como "criminal", "penal", "CPP", "crime", "denuncia", "inquerito", "prisao", "liberdade provisoria", "habeas corpus", "tribunal do juri", "acao penal", "execucao penal", "LEP", "suspensao condicional", "sursis", "livramento condicional", "medida de seguranca", "transacao penal", "suspensao condicional do processo", "audiencia de custodia", "colaboracao premiada", "acordo de nao persecucao penal", ou qualquer procedimento regulado pelo Codigo de Processo Penal brasileiro.
- Aapac-transfersGuides management of cross-border data transfers under Asia-Pacific regulatory frameworks including APEC CBPR, ASEAN Model Contractual Clauses, Japan APPI supplementary rules, South Korea PIPA provisions, and Thailand/Singapore PDPA mechanisms. Keywords: APEC CBPR, ASEAN MCCs, APPI, PIPA, PDPA, APAC transfers.
- Aapec-cbpr-certGuides APEC Cross-Border Privacy Rules system certification process including self-assessment against the APEC Privacy Framework principles, accountability agent selection, intake questionnaire completion, certification decision, annual recertification, and Global CBPR Forum transition. Keywords: APEC, CBPR, cross-border privacy, accountability agent, certification, Global CBPR.
- Aarckit-at-bvergg[COMMUNITY] Generate Austrian public procurement documentation aligned with Bundesvergabegesetz 2018 — Oberschwellen/Unterschwellen determination, ANKÖ publication, BVergGVS secondary rules, and BVwG review pathway