LGPD (Lei Geral de Proteção de Dados) + BCB Resolution 4893/2021
Brazil's combined data protection and financial cybersecurity framework. LGPD (Law 13,709/2018) establishes comprehensive data protection principles, data subject rights, international transfer rules, and ANPD oversight. BCB Resolution 4893/2021 mandates cybersecurity policy, incident response and reporting, cloud governance, board accountability, and annual cybersecurity reporting for financial institutions regulated by the Banco Central do Brasil. Includes PIX instant payment security and Open Finance Brasil API requirements.
| Clause | Title | SP 800-53 Controls |
|---|---|---|
| BCB.Art.2 | Cybersecurity Policy Requirements | |
| BCB.Art.3 | Cybersecurity Policy Principles (confidentiality, integrity, availability of data and information systems) | |
| BCB.Art.3-Supp | Risk-Based Security Controls Proportionate to Institution Size and Complexity | |
| BCB.Art.4 | Cybersecurity Policy Dissemination and Culture | |
| BCB.Art.5 | Incident Response Plan Requirements | |
| BCB.Art.5-Supp | Incident Classification and Severity Framework | |
| BCB.Art.6 | Incident Detection and Assessment Procedures | |
| BCB.Art.7 | Incident Response Actions and Containment | |
| BCB.Art.8 | Incident Reporting to BCB (Banco Central do Brasil) | |
| BCB.Art.9 | Incident Record Retention (10-year minimum) | |
| BCB.Art.10 | Cybersecurity Assessment and Testing Programme | |
| BCB.Art.11 | Cloud Computing Services Governance | |
| BCB.Art.11-Supp | Cloud Service SLA and Contract Requirements for Financial Institutions | |
| BCB.Art.12 | Cloud Provider Due Diligence and Risk Assessment | |
| BCB.Art.13 | Cloud Data Location and Residency Requirements | |
| BCB.Art.14 | Data Processing and Storage Abroad | |
| BCB.Art.15 | BCB Regulatory Access to Cloud Data and Systems | |
| BCB.Art.16 | Cloud Outsourcing Notification to BCB | |
| BCB.Art.17 | Board and Director Responsibilities for Cybersecurity | |
| BCB.Art.17-Supp | Designated Cybersecurity Director Registration with BCB | |
| BCB.Art.18 | Annual Cybersecurity Report to BCB | |
| BCB.Art.19 | Cybersecurity Assessment Programme and Continuous Improvement | |
| BCB.Art.20 | Record-Keeping and Documentation Requirements | |
| BCB.OpenFinance | Open Finance Brasil Security Requirements | |
| BCB.PIX | PIX Security Requirements (BCB Resolution 147/2021 and related provisions) | |
| LGPD.Art.6 | Processing Principles (purpose limitation, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, accountability) | |
| LGPD.Art.7 | Legal Bases for Processing Personal Data (ten legal bases) | |
| LGPD.Art.8 | Consent Requirements (free, informed, unambiguous, specific purpose) | |
| LGPD.Art.9 | Data Subject Right to Information About Processing | |
| LGPD.Art.10 | Legitimate Interest as Legal Basis | |
| LGPD.Art.11 | Processing of Sensitive Personal Data | |
| LGPD.Art.14 | Processing of Children's and Adolescents' Data | |
| LGPD.Art.15-16 | Termination of Processing and Data Deletion | |
| LGPD.Art.17-18 | Data Subject Rights (confirmation, access, correction, anonymisation, portability, deletion, information about sharing) | |
| LGPD.Art.19-20 | Data Subject Request Fulfilment and Review of Automated Decisions | |
| LGPD.Art.23-26 | Public Sector Processing Rules | |
| LGPD.Art.33-36 | International Data Transfers | |
| LGPD.Art.37-38 | Data Protection Impact Assessment (RIPD - Relatorio de Impacto a Protecao de Dados) | |
| LGPD.Art.41 | Data Protection Officer (Encarregado pelo Tratamento de Dados Pessoais) | |
| LGPD.Art.42-45 | Liability and Indemnification (controller/operator liability, burden of proof) | |
| LGPD.Art.46 | Security Measures (administrative and technical measures to protect personal data) | |
| LGPD.Art.47 | Processing Agents' Obligations (controller and operator security duties) | |
| LGPD.Art.48 | Incident Notification to ANPD and Data Subjects | |
| LGPD.Art.49 | ANPD Post-Incident Measures and Remediation Orders | |
| LGPD.Art.50 | Good Practices and Governance (privacy programme, codes of conduct) | |
| LGPD.Art.52 | Administrative Sanctions (warnings, fines, daily fines, data blocking/deletion) | |
| LGPD.Art.55-A-K | ANPD Structure, Competencies, and Regulatory Powers | |
| LGPD.BCB.Integration | LGPD-BCB Compliance Integration (dual regulatory alignment) |