LGPD vs PDPA
LGPD
Brazil's comprehensive regulation for personal data protection
PDPA
Singapore regulation for personal data protection.
Quick Verdict
LGPD mandates comprehensive data protection for individuals located in Brazil with extraterritorial reach and ANPD enforcement, while PDPA frameworks (Singapore/Thailand) govern private sector processing with jurisdiction-specific PDPCs. Companies adopt LGPD for Brazil market access, PDPA for regional compliance and trust.
LGPD
Lei Geral de Proteção de Dados Pessoais (Law No. 13.709/2018)
Key Features
- Extraterritorial scope targeting individuals located in Brazil
- 10 core principles including prevention and non-discrimination
- 10 legal bases exceeding GDPR for flexibility
- Mandatory DPO appointment with public disclosure for controllers
- 3-business-day breach notifications to ANPD and subjects
PDPA
Personal Data Protection Act 2012
Key Features
- Mandatory Data Protection Officer appointment
- 72-hour data breach notification obligation
- Consent with withdrawal and notification requirements
- Cross-border transfer limitation safeguards
- Accountability via DPMP and policies
Detailed Analysis
A comprehensive look at the specific requirements, scope, and impact of each standard.
LGPD Details
What It Is
LGPD (Lei Geral de Proteção de Dados Pessoais, Law No. 13.709/2018) is Brazil's comprehensive data protection regulation. It governs personal data processing with extraterritorial scope, applying to any entity targeting individuals located in Brazil. Primary purpose: safeguard privacy rights via risk-based accountability, mirroring GDPR but with Brazilian adaptations like 10 principles.
Key Components
- 10 core principles: purpose limitation, necessity, transparency, security, prevention, non-discrimination, accountability.
- 10 legal bases for processing (e.g., consent, legitimate interests, credit protection).
- Data subject rights (access, deletion, portability, anonymization).
- ANPD enforcement with graduated sanctions; mandatory DPO, DPIAs, RoPAs; SCCs for transfers.
Why Organizations Use It
Mandatory compliance avoids fines up to 2% Brazilian revenue (R$50M cap), operational halts. Benefits: risk reduction, trust-building, market access in Brazil's digital economy, synergies with GDPR for multinationals, competitive differentiation via privacy-by-design.
Implementation Overview
Phased risk-based approach: governance/DPO appointment, data mapping/RoPAs, policies/controls, DSR/incident processes, vendor/SCC management, audits. Applies to all sizes/industries processing Brazilian data; no certification but ANPD audits.
PDPA Details
What It Is
PDPA (Personal Data Protection Act 2012) is Singapore's principal regulation governing collection, use, disclosure, and protection of personal data by organizations. It balances individual privacy rights with legitimate business needs through a principles-based approach, emphasizing reasonable purposes, consent, and accountability.
Key Components
- Nine core obligations: consent, notification, access/correction, accuracy, protection, retention limitation, transfer limitation, accountability, breach notification.
- Built on principles like lawfulness, transparency, and proportionality.
- Requires Data Protection Officer (DPO) appointment and Data Protection Management Programme (DPMP).
- Compliance via self-assessment, PDPC guidance; no formal certification but enforcement with fines up to 10% of annual turnover or SGD 1 million.
Why Organizations Use It
- Mandatory for Singapore organizations handling personal data.
- Mitigates regulatory fines, breach risks, reputational damage.
- Builds customer trust, enables data-driven innovation, supports cross-border operations.
Implementation Overview
- Phased: governance, data mapping, policies, controls, training, audits.
- Applies to all sizes/industries in Singapore; extraterritorial for data controllers.
- Focuses on operational maturity via inventories, DPIAs, vendor contracts.
Key Differences
| Aspect | LGPD | PDPA |
|---|---|---|
| Scope | Personal data processing in Brazil | Personal data in Singapore/Thailand/Taiwan |
| Industry | All sectors, extraterritorial for Brazilians | Private sector, jurisdiction-specific residents |
| Nature | Mandatory comprehensive law, ANPD enforcement | Mandatory acts, PDPC/PDPC enforcement varies |
| Testing | DPIAs for high-risk, ANPD audits | Risk assessments, self-assessments, audits |
| Penalties | 2% Brazilian revenue, max R$50M | SGD1M/S$1M or THB5M, varies by jurisdiction |
Scope
Industry
Nature
Testing
Penalties
Frequently Asked Questions
Common questions about LGPD and PDPA
LGPD FAQ
PDPA FAQ
You Might also be Interested in These Articles...

Image this: What if GDPR would have NOT been implemented by the EU
What if the EU never implemented GDPR? Explore this hypothetical: consumer data protection in Dec 2025, key differences, pros/cons for users & companies. Read t

HITRUST CSF MyCSF Platform Mastery: Infograph of Evidence Tagging Workflows and Top 5 Maturity Tier Acceleration Takeaways
Master MyCSF platform with infographics on evidence tagging for 1,400+ HITRUST controls across 19 domains. Cut documentation by 30%, boost Measured/Managed tier

From Hygiene to Governance: How to Scale Cyber Essentials into a Full ISO 27001 ISMS in 2026
Discover how to scale Cyber Essentials into a full ISO 27001 ISMS in 2026. Reuse evidence, map controls, meet DORA & NIS2 rules and win enterprise contracts.
Run Maturity Assessments with GRADUM
Transform your compliance journey with our AI-powered assessment platform
Assess your organization's maturity across multiple standards and regulations including ISO 27001, DORA, NIS2, NIST, GDPR, and hundreds more. Get actionable insights and track your progress with collaborative, AI-powered evaluations.
Explore More Comparisons
See how LGPD and PDPA compare against other standards