LGPD
Brazil's comprehensive personal data protection regulation
BREEAM
Global sustainability certification for built environment performance
Quick Verdict
LGPD mandates data protection for Brazilian residents' privacy across industries, enforced by ANPD fines. BREEAM voluntarily certifies sustainable buildings via credits and audits. Companies adopt LGPD for legal compliance, BREEAM for ESG value, efficiency, and market premiums.
LGPD
Lei Geral de Proteção de Dados Pessoais (Law 13.709/2018)
Key Features
- Extraterritorial scope for Brazilian residents' data worldwide
- 10 core principles including prevention and non-discrimination
- Fines up to 2% Brazilian revenue capped R$50M
- Mandatory DPO for controllers with public disclosure
- 3-business-day breach notifications to ANPD and subjects
BREEAM
Building Research Establishment Environmental Assessment Method
Key Features
- Credit-based scoring across 10 sustainability categories
- Third-party certification with BRE quality audits
- Lifecycle schemes for new, existing, and infrastructure
- Evidence-driven compliance via technical manuals and KBCNs
- Weighted ratings from Pass to Outstanding
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
LGPD Details
What It Is
Lei Geral de Proteção de Dados Pessoais (LGPD), Law No. 13.709/2018, is Brazil's comprehensive data protection regulation. It governs personal data processing with extraterritorial scope, applying to any data of Brazilian residents. Primary purpose: safeguard privacy rights via risk-based approach, mirroring GDPR but with Brazil-specific adaptations like 10 principles.
Key Components
- **10 core principlespurpose limitation, necessity, transparency, security, prevention, non-discrimination, accountability.
- **Data subject rightsaccess, correction, deletion, portability, objection to automated decisions.
- **Legal bases10 options including consent, legitimate interests, credit protection.
- **Governancemandatory DPO for controllers, DPIAs for high-risk processing, ANPD enforcement with graduated sanctions.
Why Organizations Use It
Legal obligation with fines up to 2% Brazilian revenue (R$50M cap). Reduces breach risks, builds trust, enables market access in Brazil's digital economy. Competitive edge via privacy-by-design, synergies with GDPR.
Implementation Overview
Phased: governance, data mapping (RoPA), policies, controls, training, audits. Applies to all sizes/industries processing Brazilian data. No certification, but ANPD audits enforce compliance.
BREEAM Details
What It Is
BREEAM (Building Research Establishment Environmental Assessment Method) is a science-led sustainability certification framework for the built environment. Developed by BRE in 1990, it assesses environmental, social, and resilience performance across buildings, infrastructure, and communities. Its credit-based methodology weighs performance in key domains into ratings from Pass to Outstanding.
Key Components
- 10 core categories: Management, Health & Wellbeing, Energy, Transport, Water, Materials, Waste, Land Use & Ecology, Pollution, Innovation
- Scheme-specific technical manuals with credits, prerequisites, and evidence requirements
- Weighted scoring and third-party audits by BRE Global (UKAS-accredited to ISO/IEC 17065)
- Continuous updates via Knowledge Base Compliance Notes (KBCNs)
Why Organizations Use It
- Drives operational savings (e.g., 22-33% energy reduction), asset value uplift (up to 30% premiums), and ESG alignment
- Meets planning incentives, tenant demands, and EU Taxonomy
- Mitigates risks in carbon, resilience, and greenwashing
- Builds stakeholder trust through verified benchmarks
Implementation Overview
- Phased approach: pre-assessment, design integration, construction verification, certification
- Appoint licensed Assessor and AP early; gather auditable evidence
- Applies globally to all sizes/types; voluntary but strategic for portfolios
Key Differences
| Aspect | LGPD | BREEAM |
|---|---|---|
| Scope | Personal data processing & privacy rights | Building sustainability & environmental performance |
| Industry | All sectors processing Brazilian data | Construction, real estate, infrastructure |
| Nature | Mandatory national data protection law | Voluntary sustainability certification |
| Testing | ANPD audits, DPIAs for high-risk | Assessor-led assessments, BRE audits |
| Penalties | Fines up to 2% Brazilian revenue | No fines, loss of certification |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about LGPD and BREEAM
LGPD FAQ
BREEAM FAQ
You Might also be Interested in These Articles...

Asset-Backed Issuers and SEC Cybersecurity Rules: Applicability, Disclosures, and Compliance Roadmap
How SEC cybersecurity rules apply to asset-backed issuers (ABS): Form 10-D disclosures, ABS-EE risk management, Inline XBRL tagging, exemptions. Roadmap for tru

CMMC Level 3 Implementation Guide: Integrating NIST SP 800-172 Enhanced Controls for APT Defense
Step-by-step CMMC Level 3 guide for DIB contractors. Implement 24 NIST SP 800-172 controls on Level 2. Prep for DIBCAC, C3PAO scoping & 180-day POA&Ms. Boost cy

Top 10 SOC 2 Audit Pitfalls and Fixes: Real Auditor Red Flags from Type 2 Fieldwork with Evidence Checklists
Discover 10 common SOC 2 Type 2 audit pitfalls like evidence gaps, scope creep, vendor oversights. Get Fail/Pass visuals, client stories, checklists for 95% fir
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Check out these other Gradum.io Standards Comparison Pages
ISO 45001 vs AS9120B
Compare ISO 45001 vs AS9120B: Unpack OH&S leadership, risk planning & aerospace traceability diffs. Integrate standards, cut risks, elevate compliance. Discover now!
ISA 95 vs ISO 13485
Compare ISA 95 vs ISO 13485: ISA-95 integrates ERP-MES via Purdue levels & activity models; ISO 13485 enforces risk-based QMS for med devices. Optimize compliance—read now!
REACH vs IFS Food
Compare REACH vs IFS Food: Unlock key differences in EU chemical regs & food safety certs. Master compliance strategies, pitfalls & best practices for manufacturers. Secure market access now!