Back to the blog
Guide12 min readUpdated

LGPD Compliance for SaaS, Apps and Websites: 2026 Guide

How to make your website, app or SaaS LGPD-compliant in 2026: what Brazil's ANPD enforces, why a privacy policy isn't enough and how to avoid fines.

Diego Melo, author
Diego Melo

Security researcher and founder of No Vuln

LGPD Compliance for SaaS, Apps and Websites: 2026 Guide

Picture this: you wake up, pick up your phone, and the first message in the company group chat is a link to a news story. Your company is the headline. Data from 12,000 customers has leaked. Within 90 days, 30% of your customer base has canceled. Investors start backing away from the next round.

That scenario isn't far-fetched — it may be imminent. Here's why: through 2024, the ANPD (Brazil's National Data Protection Authority) had fined a private company for violating the LGPD (Brazil's General Data Protection Law) only once (Telekall Infoservice, a micro-business, two fines of R$ 7,200 each — R$ 14,400 total — in 2023, for selling WhatsApp contact lists without a legal basis; source: ANPD). In all of 2024, there were zero fines against private companies — only sanctions against public bodies. The stance was educational.

Starting in December 2024, that changed. The ANPD opened inspections against 20 large companies for lacking a Data Protection Officer (DPO) and a channel for data subjects — all of them came into compliance by April 2025. It no longer depends only on complaints. The LGPD allows fines of up to 2% of revenue in Brazil, capped at R$ 50 million per violation. A bill pending in Congress would add up to 4% more (up to R$ 100 million) specifically for personal data breaches. Enforcement keeps growing in 2026.

The question is no longer “what if it happens to me?” It's now: “when the ANPD knocks on my door, will I have anything to show?” And most owners of SaaS, app and e-commerce businesses in Brazil won't — not because they were careless, but because they confused paperwork compliance with technical compliance.

This is the honest guide to staying out of the next headline — whether you're a Brazilian company or a foreign one serving users in Brazil. In a 12-minute read, you'll learn:

  • What the LGPD really requires (and what it doesn't)
  • Why the most common path (paperwork only) leaves your company exposed
  • How to comply for real — paperwork + a technical layer
  • What to do now, even if you're behind

You think you're compliant. You probably aren't.

Most Brazilian companies that “became LGPD-compliant” only did the paperwork:

  • Hired a lawyer to write a privacy policy
  • Appointed a DPO (usually the part-time CFO)
  • Built a “data inventory” spreadsheet
  • Trained the team in a 2-hour workshop
  • Called it done: “we're compliant”

That process covers 30% of what the LGPD requires. The other 70% is technical — and nobody touches it because nobody on the team knows how.

And here's what happens next: the system still has the same bugs it had before the legal work. When data leaks (and the statistics say it will), the ANPD asks:

What technical measures did the company adopt to prevent this breach?

And most companies answer: “we have a privacy policy.” A privacy policy isn't a technical measure. It's a document. Without proof of a recent pentest, a technical audit or continuous monitoring, the company is treated as negligent. Maximum fine.

What the ANPD can do to your company

In order of severity:

SanctionWhen it applies
WarningA first minor violation, corrected quickly
Simple fine — up to 2% of revenue in Brazil, capped at R$ 50 millionA breach without adequate preventive measures
Daily fineOngoing non-compliance, even after a warning
Public disclosure of the violationYour company in an official ANPD notice (a headline)
Blocking of the personal dataUntil you're back in compliance — your company can't operate
Deletion of the personal dataExtreme cases — you lose your customer data
Suspension of data processing — up to 6 monthsRepeat violations, systemic non-compliance
Ban on data processing activitiesExtreme cases of neglect and collective harm

And the fine is just the start of the bill. Individual damages (civil courts) add up to R$ 3,000 to R$ 15,000 per affected customer. In a breach affecting 5,000 customers, that's up to R$ 75 million in damages alone. Does your company bring in enough to absorb that?

The cycle of destruction (in chronological order)

Every Brazilian company that suffered a serious breach in the last 3 years went through the same cycle:

  1. Day 1: A customer notices their email leaked. They post about it on social media.
  2. Days 2–3: The press picks it up. The company denies or downplays it. The worst possible move.
  3. Days 4–7: The company hires an emergency law firm. Expensive.
  4. Days 7–14: An internal investigation confirms the breach. The company has to notify the ANPD.
  5. Days 14–30: Customers are notified. 15–40% of accounts cancel over the next 4 weeks.
  6. Months 2–6: ANPD investigation. The company hires consultants + a pentest + a specialized lawyer. All under pressure.
  7. Months 6–12: ANPD decision. Fine imposed. Damage claims start coming in through the courts.
  8. Month 12+: Fallout in the next round. Investors price in the risk. Valuation drops. The cost of raising capital goes up 30–60%.

Typical total cost, as it's likely to look in 2026 (Brazilian figures):

ItemRange
ANPD fineR$ 100k to R$ 50 million
Civil damagesR$ 50k to R$ 75 million
Emergency pentest + forensicsR$ 50k to R$ 200k
PR + communicationsR$ 30k to R$ 150k
Legal feesR$ 80k to R$ 500k+
Churn (lost customers)15–40% within 90 days
Impact on valuation / next round+30 to +60% in cost of capital

How to comply for real (not just on paper)

Real LGPD compliance has two layers. Most companies only did the first. To be protected, you need both.

Layer 1 — Paperwork (lawyer / DPO)

  • Privacy policy published and up to date (not copied from another site)
  • Terms of service published, with data protection clauses
  • A formally appointed DPO — name published, dedicated email, a log of requests handled
  • Personal data inventory — what data, where, legal basis, retention, sharing
  • Contracts with processors (Vercel, AWS, Stripe, etc.) with a data protection clause (DPA)
  • A written incident response plan, 2–5 pages
  • Team training in LGPD basics

Cost of this layer in Brazil: R$ 5,000 to R$ 25,000 in legal consulting. Timeline: 4 to 8 weeks.

Layer 2 — Technical (specialized security firm)

This is where 70% of what the LGPD really requires lives. And it's the difference between “we have documents” and “we're protected”:

  • A recent formal pentest (last 12 months) with a report formatted as LGPD evidence
  • Access control validation — customer A can't see customer B's data (BOLA / IDOR)
  • Exposure checks on subdomains, admin panels and backups
  • Encryption review in transit and at rest (HTTPS, password hashing, PII encryption in the database)
  • Log and audit validation — the ability to investigate an incident after the fact
  • Cloud configuration review (AWS, GCP, Azure)
  • A prioritized remediation plan with 30/60/90-day deadlines
  • A retest after the fixes — confirmation that the bugs were fixed
  • A formal compliance statement aligned with LGPD Art. 46

In the Brazilian market, this layer costs R$ 5,000 to R$ 18,000 for a small or mid-sized company. Timeline: 3 to 5 weeks. This is the layer that dramatically lowers the fine if an incident happens — and that prevents many incidents in the first place.

Why Layer 2 CAN'T be done by your internal team

Four reasons:

  1. Whoever built the system can't see what's wrong with it. A developer's brain is wired to make things work — not to break them. It's like asking a parent to grade their own kid. Nobody is objective about their own work.
  2. The ANPD values an independent third party. In an inspection, “we tested it internally” carries far less weight than a formal report from a specialized firm. It's the difference between an internal and an external financial audit.
  3. Business logic flaws only show up under an adversarial eye. The most dangerous bugs (BOLA, race conditions, OAuth state confusion) don't show up in traditional code review. They show up when someone actually tries to attack.
  4. Your internal team is buried in the product roadmap. A professional pentest takes 80–200 focused hours. Your team doesn't have those hours to spare — and even if it did, it lacks the specialization.

That's exactly what No Vuln does

No Vuln is a Brazilian company specializing in offensive security. We attack platforms the way a real attacker would — except under contract, with an NDA, and the report goes to you at the end instead of turning into a headline.

For LGPD compliance specifically, we deliver:

  • A formal pentest scoped around personal data protection
  • An executive report with a formal statement of compliance with Art. 46 — evidence you can hand straight to the ANPD
  • A technical report linking each vulnerability to the type of personal data exposed (the LGPD calls for that traceability)
  • Calibrated severity with technical CVSS + LGPD impact (leak, loss, alteration)
  • A 30/60/90-day remediation plan
  • Retest included — once your team fixes the issues, we validate the fixes and update the report

Why we're different from a typical pentest

  • Researchers with a track record in international bug bounty programs — U.S. Department of Defense, eToro, Bitso, Hostinger
  • A proprietary methodology with 86 attack vectors and 1,017 sub-vectors mapped (vs. the 10 categories of the OWASP Top 10)
  • An arsenal of 500+ proprietary tools and modules to attack what scanners can't detect
  • 6 quality gates before every delivery — you get a validated report, not a first draft
  • Direct contact with the researcher — no account manager in between
  • A standard NDA before any technical call

LGPD investment ranges

No Vuln's pricing for international clients, in USD:

ScenarioRangeTimeline
Small company, one system, basic dataSprint (25h): US$ 3,750 to US$ 6,2502–3 weeks
Mid-sized company, multiple systems + integrationsDeep Dive (50h): US$ 7,500 to US$ 12,5003–4 weeks
Large company or sensitive data (health, financial)Full Scope (100h+): from US$ 15,0004–6 weeks
Ongoing, for a fast-scaling companyPTaaS: on requestcontinuous

The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.

The math you need to do

Grab a calculator. The figures below are Brazilian market ballparks, in reais.

Scenario A — Comply now: paperwork layer (R$ 15,000) + LGPD pentest (Sprint package, from R$ 8,750) + light ongoing testing for 12 months (R$ 18,000) = from R$ 41,750 in year one.

Scenario B — Wait for it to happen: ANPD fine (R$ 500,000 to R$ 50,000,000) + damages (R$ 100,000 to R$ 75,000,000) + legal (R$ 100,000) + emergency investigation (R$ 80,000) + churn (15–40% of the customer base) + valuation impact = at least R$ 780,000, up to tens of millions.

Scenario A costs 0.1% to 5% of Scenario B. If you were an investor looking at that ROI in a pitch, you'd approve it in 30 seconds.

What to do in 2026 (3 practical steps)

  1. Today: go through the checklist below and mark what you already have ✅ and what's missing ❌
  2. This week: book 30 minutes with No Vuln to assess the technical side
  3. This month: hire (legal help where it's missing + a pentest where there's never been one)

Quick checklist — where your company stands

  • ☐ Privacy policy published and up to date (last 12 months)
  • ☐ Terms of service published
  • ☐ DPO formally appointed, with a dedicated email
  • ☐ Personal data inventory documented
  • ☐ Processor contracts include a data protection clause
  • ☐ Written incident response plan
  • ☐ Formal pentest in the last 12 months
  • ☐ Technical report mapping vulnerabilities to personal data
  • ☐ Technical remediation plan under way
  • ☐ Audit logs with at least 90 days of retention

If you checked the first 6 but not the 4 technical ones (in bold), your company is in exactly the scenario this article opened with. You have the paperwork. You don't have the protection.

Ready to close the gap?

Book a 30-minute call with No Vuln. No commitment. Mutual NDA before any technical conversation. In 30 minutes, you'll know:

  • What LGPD evidence your company already has
  • What's missing on the technical side
  • What it costs to close the gap in your specific case
  • How long it takes to fix

Talk to a No Vuln researcher →

Or keep reading:

Share

WhatsAppLinkedInX

Next step

Want to apply this to your system?

No Vuln runs in-depth penetration tests with the same methodology described in this article. Request a proposal: mutual NDA within 24h, scope defined on a technical call.