LGPD and AI: what Brazilian data protection law requires before you paste customer data into a tool
The law does not ban using AI. It holds the user responsible. And the difference between those two sentences is what separates a quiet operation from a fine.
The LGPD, Brazilian data protection law, does not mention artificial intelligence and applies to it in full, because it regulates the processing of personal data regardless of the technology. In practice that means three obligations: having a lawful basis for each use, guaranteeing by contract what the supplier does with what you send, and being able to explain and review automated decisions that affect a person. Responsibility always sits with whoever hires the tool, not with the tool supplier.
What you get from this article
- Pasting customer data into an AI tool is data processing, with every obligation that carries.
- Responsibility sits with the company using it, and does not transfer to the model supplier.
- A free plan and a business plan usually have different data policies: it is the contract that counts.
- Sensitive data, such as health and biometrics, has a stricter regime and almost never fits an ordinary tool.
- The law gives the data subject the right to request a review of an automated decision that affects them.
- The specific AI bill is still in progress and does not replace the LGPD, which is already in force.
The law does not mention AI, and applies to AI
The Brazilian General Data Protection Law, Law 13,709 of 2018, was written before generative AI existed as a product and does not mention the technology. That led many people to the wrong conclusion that there is a legal vacuum.
There is not. The LGPD regulates the processing of personal data, and it defines processing deliberately broadly: collecting, using, accessing, processing, storing, transmitting, sharing. If data identifying a person goes into an AI tool, processing occurred, and every obligation applies.
The practical consequence is immediate and uncomfortable. Copying a customer message and pasting it into an assistant to ask for a better reply is processing of personal data, with transfer to a third party, often outside the country. That is not a technical detail: it is the same classification as sending your customer base to a direct mail company.
And it is not only the text assistant. Customer service, content, CRM and routine automation all process personal data the same way: it is worth running through the list of fronts in AI for business and asking, for each one, where the data passes and where it stops.
And the point that decides everything: responsibility sits with whoever uses it. The company that hired the tool is the data controller before the law and before the data subject. Saying the supplier is a large multinational transfers no obligation at all.
The law does not ask which tool you used. It asks on what basis you processed that data, and the answer has to exist before the use.
Lawful basis: the first question, not the last
Before asking whether it is safe, the law makes you ask something else: on what basis are you processing that data? The LGPD lists ten lawful bases, and every operation has to rest on one of them. There is no processing without a basis.
Three appear most often in AI use. Performance of a contract covers what is necessary to deliver what the customer bought: using their history to answer their question rests well here. Legitimate interest covers reasonable uses the subject would expect, and requires a documented assessment that the benefit does not override the person rights. Consent is the most fragile, because it can be withdrawn at any time and has to be specific and provable.
The most common mistake is using generic consent as the solution to everything. An acceptance clause saying the company may use data to improve services does not support sending a patient record to a foreign assistant. Consent has to be informed about that specific use.
The second mistake is assuming one lawful basis covers a new use. You collected the phone number to deliver the order; using that number for a win-back campaign is a different purpose, and probably a different basis. A new purpose requires a new analysis.
What the supplier contract has to say
Here is the highest-return practical check, and it takes twenty minutes. The free plan, the personal plan and the business plan of the same tool usually have different data policies. It is the contract of your specific plan that counts, not the reputation of the brand.
Four objective questions to put to any supplier, and the answer has to be in writing, not on a FAQ page: can the content I send be used to train models? How long is it stored? In which country is it processed? Who, inside your company, can access it?
Business plans usually answer all four well, with a contractual commitment not to use content in training and defined retention periods. Free plans frequently do not, and that is exactly the plan the team uses on its own when nobody has defined an internal policy.
Add to that international transfer. Most of these tools process outside Brazil, and the LGPD requires safeguards for that, typically through appropriate contractual clauses. A serious business contract includes that chapter; a sign-up with a personal email includes nothing.
- Can the content sent be used in training? It needs to say in writing that it cannot.
- What is the retention period and how do you request deletion?
- In which country does the processing happen and with which contractual safeguards?
- Who has access to the content on the supplier side, and under what logging?
- Is there a specific data processing agreement signed with your company?
Sensitive data: the step almost everybody trips on
The LGPD creates a category with a stricter regime, and it catches many companies by surprise because the list is broader than intuition suggests.
Sensitive data is data revealing racial or ethnic origin, religious conviction, political opinion, membership of a trade union or of a religious, philosophical or political organization, plus data relating to health, to sex life, and genetic or biometric data.
That reaches far more people than it seems. Clinics, medical practices, laboratories, gyms, nutritionists, psychologists, health plans, but also a facial recognition clock-in system in a factory, or a shop recording a customer dietary restriction. All of that is sensitive data, and the list of applicable lawful bases is shorter and more demanding.
The practical recommendation, and it is deliberately conservative: sensitive data does not go into an AI tool without a specific contract, an impact assessment and a deliberate decision by whoever answers for the company. This is not a case of trying it and seeing what happens, because the damage of a leak here is not fixed with an apology.
Automated decisions: the article that matters most for AI
There is a passage in the LGPD that reads as if written for the present moment, although it is from 2018: the data subject has the right to request a review of decisions taken solely on the basis of automated processing that affect their interests.
The law gives examples that sound familiar today: decisions intended to define a personal, professional, consumer or credit profile. If an automated system denies credit, refuses a registration, classifies a customer into a risk band or discards a CV, the affected person can request a review.
That imposes two concrete obligations on whoever builds. First, logging: you have to be able to reconstruct why that decision was taken in that specific case, which requires keeping the input, the output and the criteria used. Second, a review path: there has to be a practical way for the person to request a review and for somebody to actually review it.
Here a real technical problem appears and it is worth being honest about it. Language models do not explain their own decision in an auditable way: asking the model to justify itself produces a plausible explanation, not necessarily the true reason. That is why, in a decision that affects a person, the safe design is to use deterministic rules in code to decide and AI to explain in plain language, never the other way round. It is the same rule that applies to money, detailed in AI hallucination.
The AI bill, which is not law yet
There is a lot of confusion about this, so the exact situation is worth stating. Bill 2338/2023, which creates the legal framework for artificial intelligence in Brazil, was approved by the Senate plenary on 10 December 2024 and went to the Chamber of Deputies, where it has been in a special committee since 2025 and still awaits a final vote.
The text approved by the Senate follows the logic of the European model: it classifies AI systems by risk level, with an excessive-risk category that is prohibited and a high-risk one with reinforced obligations; it establishes rights for those affected, such as information, explanation and contestation; and it provides for a governance structure and penalties.
Two practical conclusions. First: while that moves through Congress, the LGPD already applies, and it is today the instrument the authority acts with. Waiting for the AI framework to get organized is waiting to comply with a law that has been in force since 2020, with penalties applicable since 2021.
Second: anyone who has already organized lawful basis, supplier contracts, decision logging and a review path will find the AI framework an adjustment rather than a reform. Practically everything the text requires on transparency and contestation already rests on obligations that exist today.
The minimum a company needs to do this week
Without turning it into a compliance project, five measures that fit in a week and resolve most of the real exposure.
Find out what is already happening. Your team probably already uses AI with customer data, in personal accounts, without anybody knowing. Asking without an accusing tone is the first step, and it is usually revealing.
Write a one-page policy. What can be pasted into an AI tool, what cannot, which tool is the authorized one and who to ask when in doubt. One page people read is worth more than a manual nobody opens.
Centralize on a business account. Migrating from personal accounts to a plan with contractual commitments resolves training, retention and access control in one move. It is the measure with the best ratio of effort to risk eliminated.
Anonymize by default. In most tasks, the model does not need the name, the tax number or the phone to do the work. Replacing them with placeholders before sending eliminates the problem at source, and frequently improves the answer, because it removes noise.
Log where it decides. Wherever AI takes part in a decision affecting a person, keep the input, the output and the criteria, and define who reviews when somebody asks. If you want to build that alongside the technical design rather than afterwards, it is part of what ROO3 AI consulting defines at the start of a project.
Frequently asked questions
Does Brazilian data protection law ban the use of artificial intelligence?
No. The LGPD does not mention AI and does not ban it: it regulates the processing of personal data, whatever the technology. What it requires is a lawful basis for each use, transparency, security and responsibility from whoever hires the tool.
Can I paste customer data into ChatGPT or another assistant?
It depends on the plan and the lawful basis. On a personal or free plan there is normally no contractual commitment about use of content in training or about retention, which makes sending customer data risky. With a business plan that carries those commitments in writing, and with a defined lawful basis, it is workable.
Who is responsible if there is a leak, me or the supplier?
The company that hired and uses the tool is the data controller before the law and before the data subject. Hiring a well-known multinational does not transfer responsibility. The contract can distribute obligations between the parties, and it does not remove your position before whoever had their data exposed.
What is sensitive data and why does it change everything?
It is data revealing racial or ethnic origin, religious conviction, political opinion, trade union or religious, philosophical or political organization membership, plus health, sex life, genetic and biometric data. It has a shorter and more demanding list of lawful bases, and should not go into an AI tool without a specific contract and an impact assessment.
Do I have to tell the customer that I use AI in support?
The LGPD requires transparency about data processing and gives the subject the right to request a review of an automated decision affecting them. Beyond that, lying when a customer asks directly whether they are talking to a bot creates a trust problem that no support saving makes up for.
Is the Brazilian AI framework already in force?
No. Bill 2338/2023 was approved by the Senate in December 2024 and is still moving through the Chamber of Deputies, awaiting a final vote. Meanwhile the LGPD has been in force since 2020, with penalties applicable since 2021, and it is the instrument that counts today.
Rodrigo Fávaro
Founder of ROO3, a marketing and technology agency in São José do Rio Preto, Brazil. Builds AI products running in production (Tobia, gerar.app, Pense Mercado) and maintains the AI Benchmark, a public ranking of AI models. See ROO3 AI consulting.
X @rodmf LinkedIn rodrigofavaroKeep reading

WhatsApp automation with AI: what works and what does not
How WhatsApp automation with AI works, the rules of the official Meta API, what changes in billing in October 2026, and...
10 min read
AI for small business: where to start without wasting money
The practical path for a small business to start using AI: how to choose the first task, what to measure, what it costs...
11 min read
AI hallucination: why it invents and how to reduce it
What AI hallucination is, why it happens by design, what the research shows about the cause, and the techniques that...
10 min readWant to apply this in your company?
ROO3 diagnoses what can be automated first in your business. The first conversation is free.