1. What Brazil's LGPD Says About Biometric Data — and Why AI Raises the Stakes
Brazil's General Data Protection Law (Lei nº 13.709/2018, the LGPD) doesn't treat all personal data the same way. Article 5, item II, creates a category of sensitive personal data — information that, if exposed or misused, can lead to discrimination or serious harm to the person it belongs to. Biometric data sits on that list alongside racial origin, religious belief, political opinion, health data, and sexual orientation. That's not an accident: a face, a fingerprint, an iris, or a voiceprint identifies you in a way a name or email address never could — and unlike a leaked password, there's no "resetting" your biometrics after a breach.
Article 11 requires that sensitive data can only be processed with specific, standalone consent for a clearly stated purpose — a generic "I agree to the terms" burying biometric collection somewhere in twenty pages of legalese doesn't count. There are exceptions that waive the consent requirement, such as compliance with a legal or regulatory obligation, protection of life, health care, or the regular exercise of rights, but even then the company has to clearly disclose the purpose and can't repurpose the biometric data for something else without telling you first.
Here's the point most coverage of the LGPD misses: the law predates the current wave of generative AI and mass facial recognition, and it never specifically anticipated today's scenario — banks training fraud-detection models on millions of faces, health insurers running AI over iris scans, entire payrolls authenticated by fingerprint every single day. That gap between "the law technically protects you" and "enforcement actually keeps pace with the scale of the problem" is exactly what the ANPD's 2026 signal is trying to close.
2. Why the ANPD Flagged Biometrics, Health, and Financial Data With AI as a 2026 Priority
Brazil's National Data Protection Authority (ANPD) periodically publishes a regulatory agenda indicating where it plans to concentrate enforcement and rulemaking. For 2026, the stated scope explicitly includes the intersection of artificial intelligence with three categories of sensitive data: biometrics, health, and financial data. It's no coincidence these are exactly the three areas where AI systems make automated decisions with direct, immediate consequences on people's lives — approving or denying a loan, authorizing or refusing a medical procedure, confirming or rejecting an identity.
The practical driver is volume: facial recognition at digital account opening (KYC checks), biometric payroll and time-clock systems, health apps with AI symptom triage, and credit-scoring engines fed by financial and behavioral data have all scaled far faster than the authority's enforcement capacity in prior years. Flagging a priority is the ANPD's way of putting the market — banks, fintechs, healthtechs, HR platforms — on notice before it intensifies actual enforcement actions, giving companies an implicit runway to get compliant.
| Data category | Example AI use | Specific risk | What the ANPD has signaled |
|---|---|---|---|
| Biometrics | Facial recognition to open a bank account, fingerprint time clocks, voice authentication in call centers | Irrevocable data — a leak has no password-reset equivalent, and re-identification across combined datasets is possible | Requiring specific consent and impact assessments (DPIA) for large-scale biometric identification systems |
| Health | AI symptom triage, imaging exam analysis, electronic health records with automated diagnostic suggestions | A leak can lead to discrimination in insurance or employment; a wrong automated decision has direct health consequences | Extra scrutiny on sharing health data with third parties for model training, even when supposedly anonymized |
| Financial data | AI credit scoring, real-time fraud detection, automated loan approval | An automated decision without a clear explanation violates the right to review (Art. 20); algorithmic bias can reproduce historical discrimination | Demanding transparency about decision criteria and a genuine channel for human review |
Scenario: you try to open a digital bank account and the app asks for a selfie to "verify your identity with AI." Behind the screen, the system isn't just storing the photo — it's extracting a unique mathematical vector from your face (the actual biometric data) and comparing it against fraud databases and, in some cases, other customer databases within the same financial group. If that vector leaks, it can potentially be used to try to fool other facial recognition systems that use similar logic — which is exactly why the LGPD requires reinforced security for this type of data.
3. How AI Collects, Processes, and Can Expose Your Biometric Data
It's worth understanding the basic technical flow, because that's where the real risk lives. A facial recognition system doesn't store "a photo of you" in the traditional sense — it processes the image and extracts a feature vector (an embedding), a numerical sequence representing your facial geometry in compact form. It's that vector, not the original photo, that gets compared against a database for authentication. That matters because the vector is also sensitive personal data under the LGPD, even without the original image being stored — a nuance some companies wrongly use to claim they "don't store biometrics," when they actually store its mathematical representation.
The concrete risks fall into three buckets. First, leaks of biometric databases, which are structurally worse than a password leak — you can reset a password, you can't reset a fingerprint. Second, unauthorized secondary use, such as training a general-purpose AI model on faces collected for a specific purpose (a face captured for app unlock later used to train a third party's facial recognition). Third, voice cloning and deepfakes built from leaked or improperly collected biometric data, used in social-engineering scams against banks and family members — a topic we cover in depth in our guide to AI, deepfakes, and scams.
Common mistakes companies make with biometric data
- Burying biometric collection inside generic terms of use — the LGPD requires specific, standalone consent, not a clause lost among a dozen other authorizations.
- Retaining biometric vectors indefinitely without justification — the necessity principle (Art. 6) requires data to be kept only as long as the stated purpose requires.
- Reusing authentication biometrics to train an AI model — without specific consent for that new purpose, it's improper processing even if the person consented to the original use.
Best practices serious companies follow
- Explaining in plain language, at the point of collection, exactly what will happen with the biometric data and how long it will be kept.
- Offering a non-biometric alternative whenever possible (a password or token alongside facial recognition), instead of treating biometrics as the only option.
- Publishing a data protection impact assessment (DPIA) for large-scale biometric identification systems, as the ANPD recommends.
4. What's Already Confirmed and What's Still a Gray Area
AI regulation and biometric data protection are both moving fast, and it's easy to confuse what's already settled law with what's still being worked out. Separating the two avoids both needless alarm and overconfidence in protections that don't fully exist yet in practice.
Biometric data has been sensitive personal data under the LGPD since the law took effect, requiring specific, standalone consent or an explicit legal exception (Art. 5, II and Art. 11). The right to request review of automated decisions already exists under Art. 20. The ANPD has already published a regulatory agenda explicitly naming biometrics, health, and financial data processed with AI as a 2026 enforcement priority, and it has already applied administrative sanctions under the LGPD since 2021, including fines against companies of various sizes.
There's still no detailed normative resolution from the ANPD dealing specifically with technical standards for AI-based biometric processing — what exists today is the LGPD's general principles applied to this context by interpretation. The exact interaction between the LGPD and Brazil's AI bill (2338/2023, still moving through Congress) in cases of overlapping sanctions isn't fully settled. There's also no public, consolidated data yet showing how many 2026 ANPD enforcement actions actually stemmed from AI-processed biometrics — flagging a priority is one thing, the real enforcement volume is something that only shows up over time.
5. Comparison: LGPD vs. GDPR (EU) vs. CCPA/CPRA (California)
Putting the LGPD side by side with other reference laws helps clarify what Brazil already gets right and where it can still evolve. All three treat biometrics as a sensitive category, but they differ meaningfully in strictness and enforcement mechanics.
| Criteria | LGPD (Brazil) | GDPR (European Union) | CCPA/CPRA (California, USA) |
|---|---|---|---|
| Is biometrics a sensitive category? | Yes, sensitive personal data (Art. 5, II) | Yes, special category of data (Art. 9) | Yes, sensitive personal information since the CPRA (2023) |
| Consent required | Specific and standalone, unless a legal exception applies | Explicit, with a broader set of alternative legal bases than the LGPD | Opt-out model, structurally different from prior consent |
| Maximum fine | 2% of Brazil revenue, capped at R$ 50 million per violation | Up to 4% of global revenue or €20 million, whichever is higher | Up to US$ 7,500 per intentional violation |
| Right to explanation of automated decisions | Yes, Art. 20 — review upon request from the data subject | Yes, Art. 22 — more robust, including the right not to be subject to a purely automated decision | More limited rights on this specific point |
| Enforcement authority | ANPD, created in 2018, still building institutional maturity | National authorities in each member state, decades of maturity | California Privacy Protection Agency (CPPA) |
Brazil is structurally aligned with the strictest international standards — the LGPD was directly modeled on the GDPR. The practical gap today lies less in the text of the law and more in enforcement maturity: the ANPD is a young authority, created in 2018 and still building operational capacity, which is why a regulatory priority signal like the one for 2026 matters so much — it indicates the authority is moving from guidance toward actual enforcement.
Does the LGPD apply even if the company is foreign? Yes — if it processes data belonging to someone located in Brazil, the LGPD applies regardless of where the company is headquartered or where its servers sit. Does a social media profile photo count as biometric data? Only if it's processed to extract facial identification features — an ordinary photo without that processing isn't, by itself, biometric data. Do minors get extra protection for biometrics? Yes, processing a child or teenager's data requires specific consent from a parent or legal guardian, on top of the general rules for sensitive data.
6. Your Rights as a Brazilian Consumer: A Practical Guide
LGPD Article 18 spells out, directly, the rights you already have over any personal data of yours — biometrics included. Few people actually exercise them in practice, but every one of them can be invoked today, with no new law needed.
| Right (Art. 18) | What it means in practice | How to exercise it |
|---|---|---|
| Confirmation and access | Find out whether a company processes your biometric data, and get a copy of it | Formal request to the company's data protection officer, usually listed in the privacy policy |
| Correction | Fix incomplete or outdated biometric data (e.g., an old facial enrollment after a relevant change) | Direct request to the company, with a response due within a reasonable time frame |
| Deletion | Erase biometric data processed based on consent, once that consent is withdrawn | Withdraw consent, then follow up with a written deletion request |
| Portability | Request transfer of your data to another provider, when technically feasible | Formal request — still limited in practice for biometrics due to technical constraints |
| Review of automated decisions | Demand human review when an AI denies you credit, access, or a service based on your data | Formal request citing LGPD Art. 20, explicitly asking for an explanation of the criteria used |
| Consent withdrawal | Revoke previously given authorization for biometric use at any time | The withdrawal channel must be as simple as the one used to grant consent in the first place |
Scenario: a bank automatically denies a credit-limit increase based on a score calculated by AI using, among other factors, behavioral patterns and financial history. Under LGPD Art. 20, you can formally request a review of that decision and demand clear information about the general criteria used in the process — the bank isn't required to disclose the entire algorithm, but it does have to explain the general logic applied, and can't simply respond "the system decided" without further explanation.
How to file a complaint with the ANPD
- Try resolving it directly with the company first, by contacting its data protection officer — that contact is usually listed in the privacy policy or site footer.
- Keep screenshots and protocol numbers of every communication, with dates — this becomes evidence if you escalate to a formal complaint later.
- If there's no response within a reasonable window, or the response is unsatisfactory, go to the official gov.br/anpd site and file a petition through the electronic petition system.
- Describe the case objectively, attach your earlier attempts at contact, and wait for a response — the ANPD can notify the company and, depending on severity, open an administrative proceeding.
7. Common Consumer Mistakes and Best Practices for Protecting Yourself
- Accepting biometric collection without reading the stated purpose — before handing over a fingerprint, face, or voice, check whether the app clearly explains exactly what that specific data will be used for.
- Never checking whether an identifiable data protection officer exists — its absence or opacity is a warning sign about how seriously the company takes data protection.
- Ignoring data breach notifications — treat any incident notice involving biometric data as top priority, since, unlike a password, it can't be reset.
- Handing over biometrics for low-value services without real need — the more places your biometric data circulates, the bigger the attack surface if any single one of them leaks.
For a broader look at digital habits that reduce your exposure to excessive data collection in general, this pairs well with our guide to AI and Digital Privacy.
Recommended best practices
- When available, prefer a physical token or password over biometrics for lower-stakes services.
- Read the "third-party sharing" section of a privacy policy before accepting — that's where you'll find out if your biometric data can be passed on to partners.
- Set up security alerts on banking services and periodically review which apps have access to your phone's camera and microphone.
8. Practical Applications by Sector
The intersection of AI and biometrics shows up differently depending on the sector, and it's worth understanding where the risk tends to run highest:
- Banks and fintechs: facial recognition for account opening (KYC), voice or fingerprint transaction authentication, AI credit scoring using financial and behavioral data.
- Healthcare: biometrics for electronic health record access, AI symptom triage, imaging exam analysis with automated diagnostic suggestions.
- Retail and security: facial recognition cameras in stores for loss prevention, biometric access control in buildings and offices.
- Human resources: fingerprint or facial recognition time clocks, AI video analysis of candidates in hiring processes.
9. Beyond What's Possible: Speculation and the Future — How Far Will Biometric Data Protection Go?
This section separates plausible extrapolation from what still belongs to the realm of speculation. Nothing here is guaranteed.
Plausible in the short to medium term
A specific ANPD normative resolution laying out minimum technical standards for AI-based biometric processing is a natural next step, consistent with the regulatory agenda already published. Final passage of Brazil's AI bill (2338/2023) — covered in depth in our guide to Brazil's AI law — should create a specific regime for remote biometric identification systems classified as high-risk, complementing (not replacing) the LGPD.
Still distant or uncertain
A single public "LGPD compliance" seal that consumers could easily check before using an app, similar to an energy-efficiency label, doesn't exist yet and has no defined timeline. A broad ban on facial recognition in public spaces, as already exists in some cities elsewhere, isn't under serious discussion in Brazil today.
Speculation / science-fiction territory
Fully decentralized identity-verification systems, where your biometric data never leaves your own device and no central company stores it — currently discussed experimentally in blockchain-based digital-identity proposals — is technically interesting, but far from any regulatory or commercial adoption at scale in Brazil.
10. Practical Checklist: Before You Hand Over Biometric Data to an App or AI System
- Check whether the privacy policy clearly explains the specific purpose of biometric collection, without vague or generic language.
- Confirm there's an identifiable data protection officer with a working contact channel.
- Check whether a non-biometric authentication option exists, especially for lower-stakes services.
- Ask (or check the policy) whether your biometric data can be shared with third parties or used to train AI models beyond its original purpose.
- Keep proof of the consent you gave, so you can formally revoke it later if needed.
- If an automated decision goes against you (denied credit, refused access), formally request review under LGPD Art. 20.
- If a leak is confirmed, prioritize filing an ANPD complaint and monitor any other accounts relying on the same type of biometric authentication.
Conclusion: The LGPD Already Protects Your Biometric Data — Most People Just Don't Use It
The good news is that Brazil isn't operating in a regulatory vacuum: biometric data has been sensitive personal data under the LGPD since 2020, with specific rules on consent, access, correction, deletion, and review of automated decisions. What changed in 2026 wasn't the law — it was the ANPD's willingness to actually enforce it, precisely in the sectors where AI and biometrics intersect at the highest volume: banks, healthcare, and fintechs. That's good news for consumers, but it only works if people actually exercise the rights they already have: asking to see what a company keeps on file about your face or your fingerprint, demanding an explanation when an algorithm denies credit or access, and filing a complaint with the ANPD when that's ignored.
Start with the basics: pick one app or service you use that relies on facial recognition or biometrics — your bank, a time-clock app, a gym chain — and go pull up its privacy policy right now. Check whether there's an identifiable data protection officer, and whether consent for biometric data was actually specific, or buried inside a generic "I agree to the terms." That five-minute exercise alone tells you a lot about whether a company takes the LGPD seriously.
Frequently Asked Questions (FAQ)
Any data that identifies a person through unique physical, physiological, or behavioral traits — facial recognition, fingerprints, hand geometry, voice patterns, even typing rhythm. The LGPD classifies biometrics as sensitive personal data under Article 5, item II, which triggers stricter handling rules than ordinary data like a name or email address.
As a rule, no — processing biometric data requires specific, standalone consent under Article 11, or one of the legal exceptions, such as compliance with a regulatory obligation (which covers bank KYC checks) or protection of life. Even under an exception, the company still has to clearly disclose the purpose and can't repurpose the data without telling you first.
First, demand an incident report from the company detailing exactly what data was exposed — it's legally required to notify both the ANPD and affected individuals within a reasonable time frame. Then file a formal complaint with the ANPD through its electronic petition system, and closely monitor any bank accounts or registrations that rely on the same type of biometric authentication, since — unlike a password — leaked biometric data can't be reset.
LGPD administrative penalties can reach 2% of a company's revenue in Brazil per violation, capped at R$ 50 million, on top of blocking or deleting improperly processed data and possible public disclosure of the violation. Because biometric data is sensitive, infractions involving it tend to be treated more seriously by the ANPD.
No — the two laws complement each other. The LGPD regulates the handling of personal data itself, biometrics included, while the AI bill focuses on classifying and regulating AI systems by risk level, placing remote biometric identification systems among the high-risk category. A biometric AI system would need to comply with both laws at once.
Start by contacting the company's data protection officer directly — that contact is usually listed in the privacy policy. If there's no response within a reasonable window, or the response is unsatisfactory, you can file a petition through the ANPD's electronic petition system on its official site, gov.br/anpd, describing the case and attaching your earlier attempts at contact.
Get the news before everyone else
AI, digital security, and technology — every week, straight to your inbox. No spam.