Skip to content
← BlogCompliance

Cold email under Brazil's LGPD: legitimate interest and how it compares to GDPR

LGPD is modeled closely on GDPR, and legitimate interest works for B2B cold email in Brazil too. Here's the ANPD's own balancing-test guidance and where LGPD actually diverges from GDPR.

By Gabriel Lara, Developer Relations, Norbelys

Founder-reviewed ·How we research and correct articles

If your cold-email compliance program is already built around GDPR, Brazil’s LGPD (Lei Geral de Proteção de Dados Pessoais) will feel familiar fast — it was deliberately modeled on GDPR’s structure. That familiarity is useful, but it’s also exactly where senders get overconfident: “familiar” isn’t “identical,” and LGPD has its own regulator, its own guidance, and its own gaps where GDPR intuition doesn’t transfer cleanly.

Legitimate interest is the workable basis here too

LGPD’s Article 5(I) defines personal data as any information related to an identified or identifiable natural person — a named individual’s work email address fits that definition on its text, with no separate carve-out for business or professional contact details. That mirrors GDPR’s approach almost exactly: the domain owning the email account doesn’t change whether the address identifies a person.

For processing that data without consent, LGPD’s Article 7(IX) provides a legitimate interest basis, structured the same way GDPR’s is: available when the controller’s or a third party’s legitimate interests don’t override the data subject’s fundamental rights and freedoms, and explicitly not available for sensitive personal data. For B2B cold email, this is the same lever senders reach for under GDPR — see cold email rules: the EU’s GDPR for how the underlying balancing-test logic works, because LGPD’s version runs on recognizably the same logic.

The ANPD’s own balancing-test framework

Brazil’s regulator, the Autoridade Nacional de Proteção de Dados (ANPD), published a formal Guia Orientativo sobre Legítimo Interesse in February 2024, and its structure will look immediately familiar to anyone who’s built a GDPR Legitimate Interest Assessment: a three-phase test covering

  1. Finalidade (purpose) — is there a genuine, specific interest behind the processing?
  2. Necessidade (necessity) — is processing this particular data actually necessary to serve that purpose?
  3. Balanceamento e salvaguardas (balancing and safeguards) — do the data subject’s rights and freedoms outweigh the controller’s interest, and what safeguards (an honored opt-out, limited retention, relevance to the recipient) offset the impact?

That’s essentially GDPR’s LIA model with Portuguese labels, and it’s not a coincidence — LGPD’s legitimate-interest jurisprudence draws openly on the GDPR tradition it was built from. If you already run documented LIAs for GDPR-covered contacts, the same documentation discipline — purpose, necessity, a real balancing writeup per campaign type, not reconstructed after the fact — transfers structurally to a Brazilian audience. The specific facts still need to hold up on their own, though: a purpose or necessity case that’s thin for a European contact is equally thin for a Brazilian one.

Where LGPD genuinely diverges from GDPR

The resemblance is real, but three differences matter in practice for a cold-email sender:

  • No separate ePrivacy-style layer. GDPR’s legitimate-interest test governs whether you can process the data; a separate law — the ePrivacy Directive, transposed differently in each EU member state — governs whether you can send unsolicited email at all. Brazil has no equivalent second statute stacked on top of LGPD specifically for unsolicited commercial email. LGPD itself is the primary vehicle governing this processing, which in one sense simplifies the analysis — one law to satisfy instead of two — but also means there’s no separate, narrower “soft opt-in”-style provision to fall back on the way UK and EU senders sometimes can.
  • A younger regulator with a shorter enforcement track record. The ANPD only gained the operational ability to apply administrative sanctions after publishing its sanctions methodology in early 2023 — years after GDPR enforcement had already produced a substantial body of European regulatory decisions and case law. That means less precedent exists for exactly how a Brazilian regulator would treat a specific B2B cold-email fact pattern; the guidance is genuine and current, but thinner on applied examples than GDPR’s now-mature enforcement history.
  • The fine structure is expressed differently, not necessarily more or less severe. LGPD’s Article 52 caps simple fines at 2% of the Brazilian revenue of the private entity, group, or conglomerate in the prior fiscal year, net of taxes, limited to R$50 million per infraction — a percentage-of-revenue-with-a-hard-cap model, distinct from GDPR’s percentage-of-global-turnover approach. Don’t assume one maps directly onto the other when estimating exposure.

A structural note worth knowing: no cross-border adequacy shortcut yet

Under GDPR, a sender established outside the EU can sometimes rely on an adequacy decision or standard contractual clauses to justify moving EU personal data internationally with less friction. LGPD has its own international-transfer chapter with a broadly comparable purpose, but Brazil’s mechanism for recognizing other countries as offering an adequate level of protection is younger and thinner than the EU’s, which has been issuing adequacy decisions for decades. In practice, that means a sender routing Brazilian contact data through infrastructure outside Brazil should treat the international-transfer question as its own compliance item — standard contractual clauses, specific consent, or another LGPD-recognized mechanism — rather than assuming an EU-style adequacy shortcut is already available for the country the data is moving to.

What this looks like in practice

A GDPR-compliant sender extending outreach into Brazil under LGPD’s legitimate-interest basis generally needs to:

  • Run the ANPD’s three-phase test explicitly, not just assume the GDPR LIA already covers it — document purpose, necessity, and balancing for the Brazilian segment specifically.
  • Keep sensitive personal data out of the legitimate-interest justification entirely, since Article 7(IX) doesn’t reach it — that category is narrower than “anything not obviously public,” so when in doubt, treat data conservatively.
  • Honor opt-outs immediately and completely, which functions as one of the concrete safeguards the ANPD’s balancing phase expects to see, the same way an honored unsubscribe strengthens a GDPR balancing case.
  • Not assume Brazilian and EU enforcement risk are interchangeable — LGPD’s newer, still-developing enforcement track record cuts both ways: less precedent to lean on, but also a shorter list of settled hard boundaries compared with GDPR’s now years of regulatory decisions.

If GDPR is the framework you already know, cold email rules: the EU’s GDPR is the natural companion read, and CAN-SPAM vs. GDPR vs. CASL compared puts the broader opt-in-vs-opt-out landscape side by side. The universal baseline — identify yourself, give a working opt-out, honor it — still applies underneath all of this; see built on U.S. anti-spam law for how that baseline plays out under a completely different legal model, and DMARC monitoring for keeping the sending domain’s authentication behind your identity claim honest regardless of which jurisdiction you’re sending into.

Frequently asked questions

Does LGPD allow cold B2B email without consent?

LGPD's Article 7(IX) provides a legitimate-interest legal basis structured similarly to GDPR's, which can support B2B cold outreach when a documented purpose, necessity, and balancing assessment supports it, and when the recipient's rights are safeguarded — for example, with an honored opt-out. It does not apply to sensitive personal data, and consent remains an alternative basis if a legitimate-interest case is thin.

Is a business email address personal data under LGPD?

Yes. LGPD Article 5(I) defines personal data as information related to an identified or identifiable natural person, with no carve-out for business or work-related addresses. A named individual's work email fits that definition regardless of which organization owns the email domain.

How does LGPD's legitimate interest test compare to GDPR's?

The ANPD's own published guidance structures legitimate interest as a three-phase test — purpose, necessity, and balancing and safeguards — closely mirroring the purpose/necessity/balancing structure used for GDPR Legitimate Interest Assessments. The underlying logic is recognizably the same tradition; the main practical differences are that LGPD has no separate ePrivacy-style statute layered on top for email specifically, and Brazil's enforcement track record is newer than the EU's.

What are the penalties for an LGPD violation?

Article 52 of LGPD caps simple administrative fines at 2% of the violating entity's, group's, or conglomerate's revenue in Brazil in the prior fiscal year, net of taxes, limited in total to R$50 million per infraction. The ANPD also has other sanction tools available, including data blocking or deletion orders and public disclosure of the infraction.