OpenRadarBLOG

Brazil’s LGPD and AI video: when the camera decides

A surveillance camera at the top and, below it, two cards of documents separated by a dashed line: on one side who decides, on the other who carries it out.
Scope

This piece describes Brazilian law — the Brazilian traffic code (Código de Trânsito Brasileiro, CTB), the Civil Code and the general data protection act (LGPD) — and the way gated communities are run in Brazil. It is not legal advice, and it does not describe the rules in force where you live. Check your own jurisdiction before acting on any of it. The physics and the engineering standards, on the other hand, are the same everywhere.

Short answer

In an outsourced video surveillance installation, whoever installed the cameras and defines the purpose is the data controller — Lei nº 13.709/2018 defines the controller as the party to whom the decisions about the processing belong (art. 5º, VI). The software vendor that processes the data on its behalf is the data processor (art. 5º, VII). A data subject request goes to the controller.

The usual legal basis for property protection is legitimate interest (art. 7º, IX), not consent. And there is one line that changes everything: facial recognition processes biometric data, which the law classifies as sensitive personal data when it is linked to a natural person (art. 5º, II), with a regime of its own in art. 11 — and with an unfavorable court precedent in Brazil.

In this piece
  1. Controller and processor
  2. Why not consent
  3. The balancing test
  4. Biometrics change the regime
  5. Detect class vs. identify
  6. Verifiable good practice

Who is the data controller and who is the data processor in outsourced video surveillance?

The LGPD assigns roles by decision-making power, not by company size and not by who wrote the software. In a gated community with cameras that usually settles without ambiguity: it was the community that decided to install them, where to point them, which rule to apply and how long to keep the footage. The vendor carries that out within the limits of the contract, and art. 39 reinforces the asymmetry — the processor processes according to the controller's instructions.

Three boxes linked by arrows: the data subject, the person filmed, with their rights; the controller, who decides purpose and legal basis and receives the data subject request; and the processor, who processes the data on the controller's behalf.
Who answers for what. The data subject request goes to the controller — the party that defines purpose, legal basis, retention and who gets access. The processor processes on its behalf and follows the instruction, sharing liability if it breaches a lawful instruction or the law. Below, the two conditions the drawing separates: legitimate interest with a documented balancing test, and the separate regime for biometric data.

The practical consequence is the one that generates most friction. The rights in art. 18 — confirmation, access, correction, anonymization, deletion, information about sharing — are exercised against the controller. A resident who wants to know which images of them exist asks the community; if the request reaches the vendor, the way forward is to pass it on and give technical support.

That exempts nobody. Art. 42 establishes that the controller or the processor that causes damage in violation of data protection law is obliged to make good on it, and Brazil's data protection authority (ANPD) records that all processing agents are subject to its enforcement when the operation takes place in national territory, when it aims to offer goods or services or to process data of individuals located here, or when the data were collected in Brazil.

Because there is no valid consent from a passer-by. The person who crosses the gatehouse was never asked, and art. 8º makes it hard to fix that afterwards: consent has to refer to specific purposes, blanket authorizations are void, the burden of proof falls on the controller, and it can be withdrawn at any moment through a free and straightforward procedure.

A security system that depends on revocable consent stops working precisely for the people with the greatest interest in revoking it. That is why the appropriate basis for property protection is normally legitimate interest.

The balancing test for legitimate interest, in plain language

Art. 7º, IX, allows processing that is necessary for the legitimate interests of the controller or of a third party, except where the fundamental rights and freedoms of the data subject prevail. That exception is the test — three questions in sequence.

  1. Is the interest legitimate and concrete? Art. 10 requires legitimate purposes considered from concrete situations. “Security” in the abstract is not a purpose; “identify a vehicle travelling above the limit on the internal road” is.
  2. Is the processing necessary to achieve it? Art. 10, § 1º, is categorical: only the data strictly necessary for the purpose may be processed. If a single record settles the matter, recording everything is excess.
  3. What would the data subject expect? A camera in a common area with controlled access, with a visible notice, is expected. Analysis of individual behavior with no notice is not — and that is where the controller's interest tends to give way.

Two obligations come with this basis and are frequently forgotten: art. 10, § 2º, requires transparency about processing based on legitimate interest, and art. 37 requires a record of processing operations, especially when they rest on that ground. Whoever picks this basis takes on the duty to document.

Facial recognition is processing of biometric data, and that changes the regime

Art. 5º, II, defines sensitive personal data to include genetic or biometric data when linked to a natural person. Sensitive data is not governed by art. 7º: it has a list of its own in art. 11, shorter and more demanding, with specific and prominent consent or exhaustively listed exemptions — none of them written with property protection in mind.

The risk is not theoretical. In May 2023, Idec reported that the Tribunal de Justiça de São Paulo — the São Paulo state appellate court — upheld on appeal the ruling against ViaQuatro, the operator of Line 4-Yellow of the São Paulo metro, for the improper use of facial recognition images of consumers, in a public civil action about the unconsented processing of passengers' biometric data for advertising purposes. Damages for collective moral harm went from R$ 100,000 to R$ 500,000, paid into the Fundo de Defesa de Direitos Difusos, Brazil's fund for diffuse rights. According to the release, a further appeal was available.

Note

This is one concrete case reported by one of the parties, not settled case law. What it demonstrates is that there is real and already materialized risk: the processing of biometric data without an adequate basis was taken to court, lost at two levels and had the damages multiplied by five. That is different from saying that facial recognition is unlawful in every circumstance.

Detecting class and behavior is a different regime from identifying who the person is

The decisive design distinction: does the system answer “there is a person in this zone at 22:14” or “this person is so-and-so”? The first produces class, position, time and behavior. The second produces identity from a bodily trait — biometrics.

It is worth not overstating the difference. An image of an identifiable person remains personal data (art. 5º, I), and the LGPD still applies in full. What changes is the category and, with it, the level of demand: you leave art. 11 and return to art. 7º, which makes legitimate interest an available basis.

The damage surface changes too. A system that never builds a biometric identifier has no database of faces to leak and cannot be repurposed to track someone across different places. It is an architectural choice with legal effect, and for that reason it has to be written into the policy, not only into the code.

Where we come in

Our privacy policy states the roles with names and addresses: for the images and the events the controller is the client, and we act as processor within the limits of the contract. It also says what the system does not do — no biometric identification, no facial recognition.

Read the privacy policy

Which good practices can a third party verify?

Compliance that cannot be checked by someone who does not trust you is a statement of intent. The table below lists only practices whose fulfilment produces an artifact — a document, a log, a screen, a deadline — that an outsider can ask to see.

Verifiable good practices in video surveillance with automatic analysis and the provision of Lei nº 13.709/2018 that supports each one. Articles checked against the consolidated text of the act on the Planalto portal.
Practice Provision Artifact it produces
Minimization: record the event, not the stream Art. 6º, III and art. 10, § 1º A specification of what is recorded and what is discarded.
Retention defined and actually enforced Arts. 15 and 16 A written period and evidence of deletion when it expires.
Transparency and notice of a monitored area Art. 6º, VI, art. 9º and art. 10, § 2º A sign on the road and a public notice with purpose and contact.
Access control and audit trail Art. 46 and art. 37 A named list of people with access and a record of operations.
A data protection officer appointed and reachable Art. 41 A published name and contact channel.
Impact assessment where the risk warrants it Art. 38 and art. 10, § 3º A report with data types, methodology and safeguards.
Incident response plan Art. 48 A written procedure for notifying the ANPD and the data subject.

Two rows deserve comment. The data protection impact assessment of art. 38 must contain, as a minimum, the types of data collected, the methodology for collection and for ensuring security, and the controller's analysis of safeguards and risk mitigation — a useful script even when nobody has demanded it; art. 10, § 3º, provides that the national authority may request it when the processing rests on legitimate interest.

And minimization. Keeping the event instead of the continuous stream is the difference between an archive of seconds and an archive of months, and it settles art. 10, § 1º, the cost of storage and the size of the damage in an incident, all at once. On what has to be inside a record for it to hold up, we wrote in video evidence that holds up.

What this piece does not claim

It is not a legal opinion and it does not replace analysis of the specific case by a qualified professional. It describes provisions of Lei nº 13.709/2018 checked against the official consolidated text and one reported court case, and nothing beyond that.

It does not claim that legitimate interest covers any video surveillance installation. It depends on the balancing test, carried out situation by situation, and it gives way when the fundamental rights and freedoms of the data subject prevail.

It does not claim that facial recognition is unlawful in Brazil. It claims that facial recognition processes sensitive data, falls under the stricter regime of art. 11 and has already produced a reported court ruling against it — which is concrete risk, not a general prohibition.

It does not describe the internal workings of OpenRadar, nor the product's periods, parameters or configurations. References to our design appear only in the public privacy policy.

Sources

  1. Brazil. Lei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais (the general data protection act), consolidated text. planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm Source of the definitions of controller and processor (art. 5º, VI and VII), of sensitive personal data including biometric data (art. 5º, II), of the principles in art. 6º, of the consent rules in art. 8º, of legitimate interest (art. 7º, IX, and art. 10), of the regime for sensitive data (art. 11), of the data subject's rights (art. 18), of termination and deletion (arts. 15 and 16), of the record of operations (art. 37), of the impact assessment (art. 38), of the instructions to the processor (art. 39), of the data protection officer (art. 41), of liability (art. 42), of security (art. 46) and of incidents (art. 48). Consulted on 4 September 2026.
  2. ANPD — Autoridade Nacional de Proteção de Dados (Brazil's data protection authority). Fiscalização. gov.br/anpd/pt-br/assuntos/fiscalizacao Source of the statement that all processing agents, controller or processor, are subject to its enforcement in the three territorial situations described. Consulted on 4 September 2026.
  3. Idec — Instituto Brasileiro de Defesa do Consumidor. Idec vence ação contra uso de reconhecimento facial e ViaQuatro é condenada a pagar indenização de R$ 500 mil, 12 May 2023. idec.org.br/release/idec-vence-acao-contra-uso-de-reconhecimento-facial-e-viaquatro-e-condenada-pagar Source of the description of the ViaQuatro case: the appellate ruling of the Tribunal de Justiça de São Paulo, the subject of the public civil action, the amounts of R$ 100,000 and R$ 500,000, the payment into the Fundo de Defesa de Direitos Difusos and the availability of a further appeal. Consulted on 4 September 2026.
Juliano Baladão Engineering at OpenRadar — measuring vehicle speed from video and producing auditable evidence on private roads.
About OpenRadar

We detect class and behavior — person, vehicle, zone, time — and we do not build a biometric identifier. It was a design decision before it was a compliance answer, and it is written into our privacy policy so that it can be held against us.

See what the system does and does not do

Also available

All posts on the blog · RSS feed