Brazil

1 rule tracked for hiring in Brazil: what each asks of employers, what Amp does, and the primary source. Informational, not legal advice.

Last reviewed 2026-09-10

Brazil — Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018)

Candidate privacyReviewed
What it asks of employers
  • Pick a lawful reason to use candidate data and tell candidates before screening. Before you screen anyone, decide and write down your lawful reason for using candidate data (for example, consent or a legitimate business need), and give candidates the required information about how their data will be used.
  • Name a data-protection officer and answer automated-decision review requests. Publicly name a data-protection officer (a contact candidates and regulators can reach about privacy), and when a candidate asks you to review a decision that was made entirely by software, or asks what criteria it used, respond to them.
  • Report security breaches and prepare an impact report if asked. If a security breach could put candidates at real risk, report it to both the regulator and the affected candidates, and prepare a data-protection impact report if the regulator asks for one.
  • Make sure sending candidate data outside Brazil has a lawful basis. Candidate data screened through cloud software may be processed outside Brazil. As the controller, confirm a lawful basis for that transfer — an adequacy recognition or the data-protection authority's standard contractual clauses — and keep a record of it.
What Amp does
  • Amp scores every candidate on the same job-related criteria. Amp uses the same job-related scoring setup for every candidate applying to a role, which supports the requirement that screening be purposeful, relevant, and limited to what's necessary.
  • Amp checks scoring for bias across demographic groups. Amp regularly tests its candidate scoring across demographic groups to make sure screening isn't discriminating unlawfully, and keeps the results as evidence in case a regulator reviews how the software makes decisions.
  • Amp helps you handle candidate requests to see, fix, delete, or move their data. When a candidate asks to confirm what you hold, see it, delete it, or receive a copy to take elsewhere, Amp's Privacy Console lets you carry out the request on the data Amp handles for you. Corrections are made in your source system, which Amp re-syncs.
  • Amp keeps candidate data only as long as your policy allows. Amp follows the retention time limit you set and deletes candidate data once it's no longer needed for screening or the time limit is up.
  • Tamper-evident record of how screening works. Amp can produce a tamper-evident package (one you can tell hasn't been altered) that documents how scoring works and how candidate data is handled, which you can use to explain the criteria behind an automated decision or to prepare a data-protection impact report.

On the watch list

pending
Brazil — Artificial Intelligence Act (PL 2338/2023)
Approved by the Federal Senate (Dec 2024); under consideration in the Chamber of Deputies before it can be signed into law.
Projeto de Lei nº 2.338/2023