Privacy has become law. But has it become culture?
Imagine your company has just launched a new app. Simple, intuitive, and free. In less than a week, you have 10 downloads. What you may not have realized is that, by processing location data, contacts, and user preferences, you are treading on regulated and sensitive ground. The LGPD (Brazilian General Data Protection Law) isn't just on paper. It enforces. And, increasingly, it punishes.
In Brazil in 2025, the protection of personal data has ceased to be a technical debate and has become an institutional, legal, and reputational imperative. Law No. 13.709/2018, known as LGPD, was born under the sign of convergence: between fundamental rights, technological innovation, and corporate responsibility. But the question that crosses companies, governments, and citizens is as simple as it is difficult to answer: has the LGPD taken hold?

While it has created a new market, regulated practices, and raised the level of digital awareness, it still faces resistance, informality, and inequality in its implementation. This is especially true in the private sector, where promises of compliance do not always translate into real cultural changes.
The LGPD (Brazilian General Data Protection Law) has brought about a radical change in the private sector, but this change is far from homogeneous, profound, and sustainable. The law exists. The opportunities are real. The regulatory environment is strengthening. But the real challenge is not normative, it is cultural.
The LGPD (Brazilian General Data Protection Law) was disruptive in one essential aspect: it broke with the logic of voluntary good practice and transformed privacy into a positive legal duty, requiring actions, records, and proof. What was once a recommendation is now a norm with the force of law.
In the private sector, this should have reshaped how data is handled across all areas: contracts, marketing, HR, IT, customer service, governance. And indeed, large companies began to react: banks, health insurance companies, e-commerce businesses, digital platforms, and multinationals created internal committees, appointed DPOs, and conducted training and mapping sessions.
But this movement was largely reactive and concentrated in companies with greater exposure. In small and medium-sized enterprises, the LGPD (Brazilian General Data Protection Law) often continues to be a "future problem," something to think about "when an inspector shows up," which reveals a culture of superficial, non-strategic compliance.
The LGPD (Brazilian General Data Protection Law) has given citizens, as data subjects, an unprecedented leading role. They now have the right to know what data is being processed, for what purpose, by whom, and for how long. They can request correction, deletion, and portability. They can say: "No, I do not authorize it."
But are consumers aware of this? And more importantly, are companies prepared to respect these rights?
While large corporations have created privacy portals and specific channels for data subjects, most Brazilian companies do not respond to requests within the legal timeframe, do not know how to track data within their own systems, and have not trained their customer service or legal teams to deal with data subjects. The leadership exists on paper. In reality, it is an unrealized potential. And the price of this gap is high: individual lawsuits, administrative proceedings, and an erosion of consumer trust.
Despite this, the LGPD (Brazilian General Data Protection Law) also opened up an extraordinary economic opportunity. Instead of hindering innovation, it spurred the emergence of new roles (DPO, privacy manager), new companies (PrivacyTechs), and new products (courses, audits, consent platforms). An ecosystem flourished.
At the same time, the LGPD (Brazilian General Data Protection Law) imposed a change that is troubling: companies are now obligated to report their own mistakes. Article 48 requires that security incidents be reported to the ANPD (National Data Protection Authority) and to those affected. Resolution CD/ANPD No. 15/2024 detailed this process. But to date, most notifications come from the press or complaints from data subjects, and not from the companies involved.
Privacy by Design and Privacy by Default also remain, to a large extent, concepts far removed from reality. Many websites still collect excessive data. Applications demand unnecessary permissions. Consent is disguised in complex forms. Data protection is still thought of as a patch, not as a fundamental principle.
The diagnosis is clear: there has been progress in organized and exposed sectors, but there is great inequality in the implementation of the law. Data protection in the private sector has evolved, but not enough. And not for everyone.
And what about the public sector?
In 2022, a Brazilian citizen attempted to exercise their right to access data processed by the city hall of their city, a capital in the Northeast region of Brazil. They received a response stating that "the municipality does not have the structure to comply with the LGPD (Brazilian General Data Protection Law)." The document was signed by a civil servant who didn't even know what a DPO (Data Protection Officer) was.
While the LGPD (Brazilian General Data Protection Law) triggered a rush to comply in the private sector, the scenario is different in the public sector: slow, uneven, and often ignored. The same law that demands transparency, security, and respect for the rights of the data subject also applies to the Federal Government, States, the Federal District, and Municipalities, but the level of compliance is still far below what the legislation requires.
The federal government has made further progress. Ministries, autonomous agencies, and regulatory bodies such as the Federal Revenue Service, INSS (National Institute of Social Security), Anvisa (National Health Surveillance Agency), and the Gov.br Portal have created internal policies, appointed DPOs (Data Protection Officers), and initiated governance programs. Higher courts have also done their homework.
But outside the federal sphere, the reality is rapidly deteriorating. More than 60% of state courts have not yet completed their data mapping. In municipalities, most city halls do not even have a privacy policy, nor trained staff. Data from students, patients, and beneficiaries of social programs are processed without consent, without transparency, and without control.
And what about governance? In many education and healthcare systems, the CPF (Brazilian taxpayer ID number) has become a universal password. Sensitive data of children, the elderly, psychiatric patients, and vulnerable individuals is stored without encryption, without auditing, and without a defined purpose. This is not just a technical failure. It's an ethical failure.
Oversight is also uneven. The ANPD (National Data Protection Authority) has been more forceful in targeting the private sector. In the public sector, the Public Prosecutor's Office of the Federal District and Territories (MPDFT), with its specialized unit, has partially filled this role. The TCU (Federal Court of Accounts) also requires compliance plans. However, in states and municipalities, the involvement of local Public Prosecutor's Offices and Courts of Accounts is almost nonexistent.
Real-life cases demonstrate the risks. In 2021, data from over 200 million Brazilians was exposed after failures in the Ministry of Health's systems. Municipal educational platforms exposed student data without consent. Data from the Emergency Aid program was shared with private entities without a clear legal basis.
Seven years after its enactment, the LGPD (Brazilian General Data Protection Law) remains an open challenge for the Brazilian public sector. This is not due to a lack of regulations, but rather a lack of culture, structure, and commitment. Data protection cannot be treated as an "IT project" or a "legal agenda item." Within the State, it needs to be a republican commitment to human dignity.
And what have we learned from all this?
Privacy is a fundamental right, but it only exists if it is protected. Compliance is not an end, it is a means. Responsibility lies with everyone. Governance is what ensures continuity. And trust is the most valuable asset in the digital age.
Despite the progress, the challenges are glaring. There is a lack of genuine adherence to a culture of data protection. Data mapping is often superficial. Consent management remains weak. Incident response continues to be improvised. In states and municipalities, the scenario is worse: there is no standardization, a shortage of staff, and no budget.
But there is still work to be done. And it needs to be done now.
Companies must elevate the LGPD (Brazilian General Data Protection Law) to a strategic level. This includes appointing Data Protection Officers (DPOs), reviewing systems, adopting privacy by design, and listening to data subjects.
Public managers must assume ethical leadership. Institutionalize data protection as a public policy. Train teams. Demand a budget. Make the issue a priority.
And what about citizens? They need to be informed, demand accountability, and report abuses. Privacy is not just a right. It's the boundary between freedom and submission in the digital world.
Because data isn't just numbers. It's stories. It's lives. And protecting it is protecting humanity itself.
"Privacy is the space between the human being and the algorithm. It is there that freedom breathes."
Would you like to read more texts by this author? Click here and understand the relationship between your data, fraud, and the LGPD (Brazilian General Data Protection Law).



















