← Frameworks / Privacy & Regulatory

LGPD (Lei Geral de Proteção de Dados) + BCB Resolution 4893/2021

Brazil's combined data protection and financial cybersecurity framework. LGPD (Law 13,709/2018) establishes comprehensive data protection principles, data subject rights, international transfer rules, and ANPD oversight. BCB Resolution 4893/2021 mandates cybersecurity policy, incident response and reporting, cloud governance, board accountability, and annual cybersecurity reporting for financial institutions regulated by the Banco Central do Brasil. Includes PIX instant payment security and Open Finance Brasil API requirements.

Clause Title SP 800-53 Controls
BCB.Art.2 Cybersecurity Policy Requirements
BCB.Art.3 Cybersecurity Policy Principles (confidentiality, integrity, availability of data and information systems)
BCB.Art.3-Supp Risk-Based Security Controls Proportionate to Institution Size and Complexity
BCB.Art.4 Cybersecurity Policy Dissemination and Culture
BCB.Art.5 Incident Response Plan Requirements
BCB.Art.5-Supp Incident Classification and Severity Framework
BCB.Art.6 Incident Detection and Assessment Procedures
BCB.Art.7 Incident Response Actions and Containment
BCB.Art.8 Incident Reporting to BCB (Banco Central do Brasil)
BCB.Art.9 Incident Record Retention (10-year minimum)
BCB.Art.10 Cybersecurity Assessment and Testing Programme
BCB.Art.11 Cloud Computing Services Governance
BCB.Art.11-Supp Cloud Service SLA and Contract Requirements for Financial Institutions
BCB.Art.12 Cloud Provider Due Diligence and Risk Assessment
BCB.Art.13 Cloud Data Location and Residency Requirements
BCB.Art.14 Data Processing and Storage Abroad
BCB.Art.15 BCB Regulatory Access to Cloud Data and Systems
BCB.Art.16 Cloud Outsourcing Notification to BCB
BCB.Art.17 Board and Director Responsibilities for Cybersecurity
BCB.Art.17-Supp Designated Cybersecurity Director Registration with BCB
BCB.Art.18 Annual Cybersecurity Report to BCB
BCB.Art.19 Cybersecurity Assessment Programme and Continuous Improvement
BCB.Art.20 Record-Keeping and Documentation Requirements
BCB.OpenFinance Open Finance Brasil Security Requirements
BCB.PIX PIX Security Requirements (BCB Resolution 147/2021 and related provisions)
LGPD.Art.6 Processing Principles (purpose limitation, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, accountability)
LGPD.Art.7 Legal Bases for Processing Personal Data (ten legal bases)
LGPD.Art.8 Consent Requirements (free, informed, unambiguous, specific purpose)
LGPD.Art.9 Data Subject Right to Information About Processing
LGPD.Art.10 Legitimate Interest as Legal Basis
LGPD.Art.11 Processing of Sensitive Personal Data
LGPD.Art.14 Processing of Children's and Adolescents' Data
LGPD.Art.15-16 Termination of Processing and Data Deletion
LGPD.Art.17-18 Data Subject Rights (confirmation, access, correction, anonymisation, portability, deletion, information about sharing)
LGPD.Art.19-20 Data Subject Request Fulfilment and Review of Automated Decisions
LGPD.Art.23-26 Public Sector Processing Rules
LGPD.Art.33-36 International Data Transfers
LGPD.Art.37-38 Data Protection Impact Assessment (RIPD - Relatorio de Impacto a Protecao de Dados)
LGPD.Art.41 Data Protection Officer (Encarregado pelo Tratamento de Dados Pessoais)
LGPD.Art.42-45 Liability and Indemnification (controller/operator liability, burden of proof)
LGPD.Art.46 Security Measures (administrative and technical measures to protect personal data)
LGPD.Art.47 Processing Agents' Obligations (controller and operator security duties)
LGPD.Art.48 Incident Notification to ANPD and Data Subjects
LGPD.Art.49 ANPD Post-Incident Measures and Remediation Orders
LGPD.Art.50 Good Practices and Governance (privacy programme, codes of conduct)
LGPD.Art.52 Administrative Sanctions (warnings, fines, daily fines, data blocking/deletion)
LGPD.Art.55-A-K ANPD Structure, Competencies, and Regulatory Powers
LGPD.BCB.Integration LGPD-BCB Compliance Integration (dual regulatory alignment)