LGPD penetration testing: documented technical evidence for Article 46 of Brazil's LGPD.

Brazil's General Data Protection Law (LGPD) requires technical and administrative measures capable of protecting personal data. A documented pentest is one of the few concrete ways to prove it. Our report serves as evidence in inspections by the ANPD (Brazil's National Data Protection Authority), in enterprise customer audits and in due diligence — for companies that operate in Brazil or serve Brazilian users.

  • Mutual NDA within 24h
  • Retest included
  • Direct contact with the researcher

What the LGPD requires

The LGPD doesn't mention pentesting. What it does say is more dangerous.

Brazil's General Data Protection Law (Law 13,709/2018) doesn't mention penetration testing by name. What it requires is broader — and therefore much harder to meet without concrete technical evidence.

Art. 46. Processing agents shall adopt security, technical and administrative measures able to protect personal data from unauthorized access and from accidental or unlawful situations of destruction, loss, alteration, communication or any form of improper or unlawful processing.

“Technical measures able to protect.” What does that mean in practice? The ANPD hasn't published a checklist. But in actual inspection cases, three things carry the most weight:

  1. A documented security policy — can be written in-house
  2. Team training — can be done in-house
  3. A recent penetration test — requires an independent technical third party

The first two are self-declared. The third is the only one that proves your company did what's expected of a diligent company.

Real inspection cases

When the ANPD comes knocking, what does it ask for?

In an inspection, the ANPD typically asks for documentary evidence of the technical and organizational measures adopted:

  • Privacy and information security policy
  • Personal data inventory and legal bases (Art. 7 and Art. 11)
  • Record of processing activities (Art. 37)
  • Incident response plan
  • Evidence of recent security testing — pentest, vulnerability scanning, code review
  • DPIA (Data Protection Impact Assessment) for high-risk processing

Without the pentest item, the company's defense is weaker. With a recent documented pentest (≤ 12 months), the company demonstrates a posture of due care — which reduces the severity of any administrative sanction.

LGPD fines go up to 2% of revenue in Brazil (capped at R$ 50 million per violation). A pentest costs a fraction of 1% of that. The math is trivial.

Scope

What an LGPD penetration test covers

Personal data collection and storage

  • Endpoints that collect data — forms, APIs, webhooks
  • Data leakage through responses (excessive data exposure)
  • BOLA — user A accessing user B's personal data
  • Logs with personal data in plain text (improper internal access)
  • Publicly exposed backups (S3, GCS)
  • Cache poisoning leaking data between users

Data subject rights (Art. 18)

  • Access — the endpoint leaks third-party data via IDOR/BOLA
  • Correction — mass assignment allows changing sensitive fields
  • Anonymization/Deletion — the endpoint doesn't fully anonymize; data persists in logs/backups
  • Portability — the export endpoint leaks other data subjects' data

Sharing with processors

  • SSRF via webhooks to processors (leakage by proxy)
  • Replay of sensitive events
  • Signature bypass in third-party integrations
  • Logs shared beyond what's necessary

Incident response (Art. 48)

  • Ability to detect unauthorized access attempts
  • An adequate audit trail
  • Time to detection and containment

Cross-cutting hardening

  • Full OWASP Top 10 (XSS, SQLi, SSRF, deserialization)
  • Full OWASP API Top 10 (BOLA, BFLA, BOPLA, mass assignment)
  • Authentication, sessions and MFA
  • Cloud configuration (S3, IAM, IMDSv1)

Report

What you get — a format built for inspection evidence

No Vuln's LGPD pentest report is structured to serve as immediate documentary evidence in any inspection or audit:

  • Executive summary aligned with Art. 46 — a formal statement of technical measures
  • Findings × personal data map — each vulnerability linked to the type of personal data exposed
  • Calibrated severity with CVSS 4.0 + LGPD impact (leakage, loss, unauthorized alteration)
  • Remediation plan with 30/60/90-day priorities
  • Retest included within the plan's timeline — an updated report after the fix strengthens the evidence
  • Signed compliance statement, dated and with a clear scope

The document serves as evidence for:

  • The ANPD in administrative inspections
  • Enterprise customer contractual audits (security clauses)
  • M&A and investment due diligence
  • Cyber insurance renewals and new policies

Pricing

LGPD penetration testing pricing

ScenarioPrice rangeCoverage
Small company, one system, basic personal dataSprint (25h): US$ 3,750 to US$ 6,250Web + API focused on personal data, black box
Mid-sized company, multiple systemsDeep Dive (50h): US$ 7,500 to US$ 12,500+ integrations + webhooks + LGPD Art. 18 endpoints
Large company, sensitive data or children's dataFull Scope (100h+): from US$ 15,000Full white box + DPIA-aligned + log review
Recurring, for fast-scaling companiesPTaaS: on requestContinuous monitoring + 1 retest per month

Every engagement gets a custom quote once the scope is defined. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.

FAQ

Frequently asked questions

  • Does the LGPD require penetration testing?

    The LGPD (Brazil's General Data Protection Law) doesn't mention penetration testing by name, but Article 46 requires technical and administrative security measures capable of protecting personal data. A documented pentest is one of the few concrete ways to demonstrate that compliance in an inspection by the ANPD (Brazil's National Data Protection Authority) or in a customer audit.

  • Does a pentest report carry weight with the ANPD in an inspection?

    It carries weight as evidence, not as certification — the ANPD doesn't pre-approve pentest reports. In an inspection, it assesses whether the company adopted the technical measures Article 46 requires. A report with a clear scope, the methodology applied, a list of findings with severity, a remediation plan and a formal statement helps demonstrate that compliance. No Vuln reports are delivered in that format.

  • How much does an LGPD penetration test cost?

    Small company (one system, basic personal data): Sprint (25h), US$ 3,750 to US$ 6,250. Mid-sized company (multiple systems): Deep Dive (50h), US$ 7,500 to US$ 12,500. Large company (sensitive data): Full Scope (100h+), from US$ 15,000. PTaaS (recurring, for fast-scaling companies): on request. The hourly rate ranges from US$ 150 to US$ 250 per hour.

  • How long is an LGPD pentest valid?

    We recommend a documented pentest within a window of up to 12 months. For companies with a high rate of change (SaaS, fintechs, e-commerce), a monthly or quarterly recurring pentest is a better fit.

Next step

Meet LGPD requirements with technical evidence.

Request a proposal. Mutual NDA within 24h, scope defined in a technical call, formal proposal within 3 business days.

Talk to a researcher