1. What Brazil's LGPD Says About Biometric Data — and Why AI Raises the Stakes

Brazil's General Data Protection Law (Lei nº 13.709/2018, the LGPD) doesn't treat all personal data the same way. Article 5, item II, creates a category of sensitive personal data — information that, if exposed or misused, can lead to discrimination or serious harm to the person it belongs to. Biometric data sits on that list alongside racial origin, religious belief, political opinion, health data, and sexual orientation. That's not an accident: a face, a fingerprint, an iris, or a voiceprint identifies you in a way a name or email address never could — and unlike a leaked password, there's no "resetting" your biometrics after a breach.

Article 11 requires that sensitive data can only be processed with specific, standalone consent for a clearly stated purpose — a generic "I agree to the terms" burying biometric collection somewhere in twenty pages of legalese doesn't count. There are exceptions that waive the consent requirement, such as compliance with a legal or regulatory obligation, protection of life, health care, or the regular exercise of rights, but even then the company has to clearly disclose the purpose and can't repurpose the biometric data for something else without telling you first.

9categories of sensitive personal data listed under LGPD Article 5, II — biometrics is one of them, alongside health, racial origin, and religious belief
2%of a company's Brazil revenue is the cap on LGPD administrative fines per violation, capped at R$ 50 million
Art. 20the LGPD article guaranteeing the right to review automated decisions — the most relevant provision whenever AI decides something about you based on biometric data

Here's the point most coverage of the LGPD misses: the law predates the current wave of generative AI and mass facial recognition, and it never specifically anticipated today's scenario — banks training fraud-detection models on millions of faces, health insurers running AI over iris scans, entire payrolls authenticated by fingerprint every single day. That gap between "the law technically protects you" and "enforcement actually keeps pace with the scale of the problem" is exactly what the ANPD's 2026 signal is trying to close.

2. Why the ANPD Flagged Biometrics, Health, and Financial Data With AI as a 2026 Priority

Brazil's National Data Protection Authority (ANPD) periodically publishes a regulatory agenda indicating where it plans to concentrate enforcement and rulemaking. For 2026, the stated scope explicitly includes the intersection of artificial intelligence with three categories of sensitive data: biometrics, health, and financial data. It's no coincidence these are exactly the three areas where AI systems make automated decisions with direct, immediate consequences on people's lives — approving or denying a loan, authorizing or refusing a medical procedure, confirming or rejecting an identity.

The practical driver is volume: facial recognition at digital account opening (KYC checks), biometric payroll and time-clock systems, health apps with AI symptom triage, and credit-scoring engines fed by financial and behavioral data have all scaled far faster than the authority's enforcement capacity in prior years. Flagging a priority is the ANPD's way of putting the market — banks, fintechs, healthtechs, HR platforms — on notice before it intensifies actual enforcement actions, giving companies an implicit runway to get compliant.

Data categoryExample AI useSpecific riskWhat the ANPD has signaled
BiometricsFacial recognition to open a bank account, fingerprint time clocks, voice authentication in call centersIrrevocable data — a leak has no password-reset equivalent, and re-identification across combined datasets is possibleRequiring specific consent and impact assessments (DPIA) for large-scale biometric identification systems
HealthAI symptom triage, imaging exam analysis, electronic health records with automated diagnostic suggestionsA leak can lead to discrimination in insurance or employment; a wrong automated decision has direct health consequencesExtra scrutiny on sharing health data with third parties for model training, even when supposedly anonymized
Financial dataAI credit scoring, real-time fraud detection, automated loan approvalAn automated decision without a clear explanation violates the right to review (Art. 20); algorithmic bias can reproduce historical discriminationDemanding transparency about decision criteria and a genuine channel for human review
// Practical example

Scenario: you try to open a digital bank account and the app asks for a selfie to "verify your identity with AI." Behind the screen, the system isn't just storing the photo — it's extracting a unique mathematical vector from your face (the actual biometric data) and comparing it against fraud databases and, in some cases, other customer databases within the same financial group. If that vector leaks, it can potentially be used to try to fool other facial recognition systems that use similar logic — which is exactly why the LGPD requires reinforced security for this type of data.

3. How AI Collects, Processes, and Can Expose Your Biometric Data

It's worth understanding the basic technical flow, because that's where the real risk lives. A facial recognition system doesn't store "a photo of you" in the traditional sense — it processes the image and extracts a feature vector (an embedding), a numerical sequence representing your facial geometry in compact form. It's that vector, not the original photo, that gets compared against a database for authentication. That matters because the vector is also sensitive personal data under the LGPD, even without the original image being stored — a nuance some companies wrongly use to claim they "don't store biometrics," when they actually store its mathematical representation.

The concrete risks fall into three buckets. First, leaks of biometric databases, which are structurally worse than a password leak — you can reset a password, you can't reset a fingerprint. Second, unauthorized secondary use, such as training a general-purpose AI model on faces collected for a specific purpose (a face captured for app unlock later used to train a third party's facial recognition). Third, voice cloning and deepfakes built from leaked or improperly collected biometric data, used in social-engineering scams against banks and family members — a topic we cover in depth in our guide to AI, deepfakes, and scams.

Common mistakes companies make with biometric data

Best practices serious companies follow

4. What's Already Confirmed and What's Still a Gray Area

AI regulation and biometric data protection are both moving fast, and it's easy to confuse what's already settled law with what's still being worked out. Separating the two avoids both needless alarm and overconfidence in protections that don't fully exist yet in practice.

// Confirmed

Biometric data has been sensitive personal data under the LGPD since the law took effect, requiring specific, standalone consent or an explicit legal exception (Art. 5, II and Art. 11). The right to request review of automated decisions already exists under Art. 20. The ANPD has already published a regulatory agenda explicitly naming biometrics, health, and financial data processed with AI as a 2026 enforcement priority, and it has already applied administrative sanctions under the LGPD since 2021, including fines against companies of various sizes.

// Not yet confirmed / gray area

There's still no detailed normative resolution from the ANPD dealing specifically with technical standards for AI-based biometric processing — what exists today is the LGPD's general principles applied to this context by interpretation. The exact interaction between the LGPD and Brazil's AI bill (2338/2023, still moving through Congress) in cases of overlapping sanctions isn't fully settled. There's also no public, consolidated data yet showing how many 2026 ANPD enforcement actions actually stemmed from AI-processed biometrics — flagging a priority is one thing, the real enforcement volume is something that only shows up over time.

MAKES SENSE
Demanding transparency from companies about biometric collection and using your Article 18 access right to find out exactly what a company holds on your face, fingerprint, or voice.
DOESN'T MAKE SENSE
Assuming "the law already handles everything" and never checking whether a company actually complies with the LGPD in practice — a signaled enforcement priority isn't the same as fully executed enforcement.

5. Comparison: LGPD vs. GDPR (EU) vs. CCPA/CPRA (California)

Putting the LGPD side by side with other reference laws helps clarify what Brazil already gets right and where it can still evolve. All three treat biometrics as a sensitive category, but they differ meaningfully in strictness and enforcement mechanics.

CriteriaLGPD (Brazil)GDPR (European Union)CCPA/CPRA (California, USA)
Is biometrics a sensitive category?Yes, sensitive personal data (Art. 5, II)Yes, special category of data (Art. 9)Yes, sensitive personal information since the CPRA (2023)
Consent requiredSpecific and standalone, unless a legal exception appliesExplicit, with a broader set of alternative legal bases than the LGPDOpt-out model, structurally different from prior consent
Maximum fine2% of Brazil revenue, capped at R$ 50 million per violationUp to 4% of global revenue or €20 million, whichever is higherUp to US$ 7,500 per intentional violation
Right to explanation of automated decisionsYes, Art. 20 — review upon request from the data subjectYes, Art. 22 — more robust, including the right not to be subject to a purely automated decisionMore limited rights on this specific point
Enforcement authorityANPD, created in 2018, still building institutional maturityNational authorities in each member state, decades of maturityCalifornia Privacy Protection Agency (CPPA)

Brazil is structurally aligned with the strictest international standards — the LGPD was directly modeled on the GDPR. The practical gap today lies less in the text of the law and more in enforcement maturity: the ANPD is a young authority, created in 2018 and still building operational capacity, which is why a regulatory priority signal like the one for 2026 matters so much — it indicates the authority is moving from guidance toward actual enforcement.

// Quick facts

Does the LGPD apply even if the company is foreign? Yes — if it processes data belonging to someone located in Brazil, the LGPD applies regardless of where the company is headquartered or where its servers sit. Does a social media profile photo count as biometric data? Only if it's processed to extract facial identification features — an ordinary photo without that processing isn't, by itself, biometric data. Do minors get extra protection for biometrics? Yes, processing a child or teenager's data requires specific consent from a parent or legal guardian, on top of the general rules for sensitive data.

6. Your Rights as a Brazilian Consumer: A Practical Guide

LGPD Article 18 spells out, directly, the rights you already have over any personal data of yours — biometrics included. Few people actually exercise them in practice, but every one of them can be invoked today, with no new law needed.

Right (Art. 18)What it means in practiceHow to exercise it
Confirmation and accessFind out whether a company processes your biometric data, and get a copy of itFormal request to the company's data protection officer, usually listed in the privacy policy
CorrectionFix incomplete or outdated biometric data (e.g., an old facial enrollment after a relevant change)Direct request to the company, with a response due within a reasonable time frame
DeletionErase biometric data processed based on consent, once that consent is withdrawnWithdraw consent, then follow up with a written deletion request
PortabilityRequest transfer of your data to another provider, when technically feasibleFormal request — still limited in practice for biometrics due to technical constraints
Review of automated decisionsDemand human review when an AI denies you credit, access, or a service based on your dataFormal request citing LGPD Art. 20, explicitly asking for an explanation of the criteria used
Consent withdrawalRevoke previously given authorization for biometric use at any timeThe withdrawal channel must be as simple as the one used to grant consent in the first place
// Practical example

Scenario: a bank automatically denies a credit-limit increase based on a score calculated by AI using, among other factors, behavioral patterns and financial history. Under LGPD Art. 20, you can formally request a review of that decision and demand clear information about the general criteria used in the process — the bank isn't required to disclose the entire algorithm, but it does have to explain the general logic applied, and can't simply respond "the system decided" without further explanation.

How to file a complaint with the ANPD

  1. Try resolving it directly with the company first, by contacting its data protection officer — that contact is usually listed in the privacy policy or site footer.
  2. Keep screenshots and protocol numbers of every communication, with dates — this becomes evidence if you escalate to a formal complaint later.
  3. If there's no response within a reasonable window, or the response is unsatisfactory, go to the official gov.br/anpd site and file a petition through the electronic petition system.
  4. Describe the case objectively, attach your earlier attempts at contact, and wait for a response — the ANPD can notify the company and, depending on severity, open an administrative proceeding.

7. Common Consumer Mistakes and Best Practices for Protecting Yourself

For a broader look at digital habits that reduce your exposure to excessive data collection in general, this pairs well with our guide to AI and Digital Privacy.

Recommended best practices

8. Practical Applications by Sector

The intersection of AI and biometrics shows up differently depending on the sector, and it's worth understanding where the risk tends to run highest:

9. Beyond What's Possible: Speculation and the Future — How Far Will Biometric Data Protection Go?

// Editorial note

This section separates plausible extrapolation from what still belongs to the realm of speculation. Nothing here is guaranteed.

Plausible in the short to medium term

A specific ANPD normative resolution laying out minimum technical standards for AI-based biometric processing is a natural next step, consistent with the regulatory agenda already published. Final passage of Brazil's AI bill (2338/2023) — covered in depth in our guide to Brazil's AI law — should create a specific regime for remote biometric identification systems classified as high-risk, complementing (not replacing) the LGPD.

Still distant or uncertain

A single public "LGPD compliance" seal that consumers could easily check before using an app, similar to an energy-efficiency label, doesn't exist yet and has no defined timeline. A broad ban on facial recognition in public spaces, as already exists in some cities elsewhere, isn't under serious discussion in Brazil today.

Speculation / science-fiction territory

Fully decentralized identity-verification systems, where your biometric data never leaves your own device and no central company stores it — currently discussed experimentally in blockchain-based digital-identity proposals — is technically interesting, but far from any regulatory or commercial adoption at scale in Brazil.

10. Practical Checklist: Before You Hand Over Biometric Data to an App or AI System

  1. Check whether the privacy policy clearly explains the specific purpose of biometric collection, without vague or generic language.
  2. Confirm there's an identifiable data protection officer with a working contact channel.
  3. Check whether a non-biometric authentication option exists, especially for lower-stakes services.
  4. Ask (or check the policy) whether your biometric data can be shared with third parties or used to train AI models beyond its original purpose.
  5. Keep proof of the consent you gave, so you can formally revoke it later if needed.
  6. If an automated decision goes against you (denied credit, refused access), formally request review under LGPD Art. 20.
  7. If a leak is confirmed, prioritize filing an ANPD complaint and monitor any other accounts relying on the same type of biometric authentication.

Conclusion: The LGPD Already Protects Your Biometric Data — Most People Just Don't Use It

The good news is that Brazil isn't operating in a regulatory vacuum: biometric data has been sensitive personal data under the LGPD since 2020, with specific rules on consent, access, correction, deletion, and review of automated decisions. What changed in 2026 wasn't the law — it was the ANPD's willingness to actually enforce it, precisely in the sectors where AI and biometrics intersect at the highest volume: banks, healthcare, and fintechs. That's good news for consumers, but it only works if people actually exercise the rights they already have: asking to see what a company keeps on file about your face or your fingerprint, demanding an explanation when an algorithm denies credit or access, and filing a complaint with the ANPD when that's ignored.

Start with the basics: pick one app or service you use that relies on facial recognition or biometrics — your bank, a time-clock app, a gym chain — and go pull up its privacy policy right now. Check whether there's an identifiable data protection officer, and whether consent for biometric data was actually specific, or buried inside a generic "I agree to the terms." That five-minute exercise alone tells you a lot about whether a company takes the LGPD seriously.

Frequently Asked Questions (FAQ)

Any data that identifies a person through unique physical, physiological, or behavioral traits — facial recognition, fingerprints, hand geometry, voice patterns, even typing rhythm. The LGPD classifies biometrics as sensitive personal data under Article 5, item II, which triggers stricter handling rules than ordinary data like a name or email address.

As a rule, no — processing biometric data requires specific, standalone consent under Article 11, or one of the legal exceptions, such as compliance with a regulatory obligation (which covers bank KYC checks) or protection of life. Even under an exception, the company still has to clearly disclose the purpose and can't repurpose the data without telling you first.

First, demand an incident report from the company detailing exactly what data was exposed — it's legally required to notify both the ANPD and affected individuals within a reasonable time frame. Then file a formal complaint with the ANPD through its electronic petition system, and closely monitor any bank accounts or registrations that rely on the same type of biometric authentication, since — unlike a password — leaked biometric data can't be reset.

LGPD administrative penalties can reach 2% of a company's revenue in Brazil per violation, capped at R$ 50 million, on top of blocking or deleting improperly processed data and possible public disclosure of the violation. Because biometric data is sensitive, infractions involving it tend to be treated more seriously by the ANPD.

No — the two laws complement each other. The LGPD regulates the handling of personal data itself, biometrics included, while the AI bill focuses on classifying and regulating AI systems by risk level, placing remote biometric identification systems among the high-risk category. A biometric AI system would need to comply with both laws at once.

Start by contacting the company's data protection officer directly — that contact is usually listed in the privacy policy. If there's no response within a reasonable window, or the response is unsatisfactory, you can file a petition through the ANPD's electronic petition system on its official site, gov.br/anpd, describing the case and attaching your earlier attempts at contact.

// TechTurbo Newsletter

Get the news before everyone else

AI, digital security, and technology — every week, straight to your inbox. No spam.