top of page
Search

The U.S. + Latin America Privacy Program: Why CCPA Doesn't Translate to LGPD

  • Oso Data Privacy
  • May 17
  • 5 min read

A "global" privacy program that was built around U.S. state law usually isn't a global privacy program. Here's where the seams show.

A common pattern: a U.S. company expands operations into Latin America — opens a Mexico City office, signs a Brazilian distributor, hires a customer success team in Colombia. The legal team is asked whether the company's privacy program covers the new operations. Someone looks at the CCPA program, decides it's a strong base, and tells the executive team: "We're covered."

They're not. Brazil's Lei Geral de Proteção de Dados (LGPD) is closer to the European GDPR than to any U.S. state privacy law, and the operational differences are large enough that a CCPA-compliant program does not satisfy LGPD by default. The same is true, with different nuances, for Mexico's LFPDPPP, Argentina's PDPA, Colombia's Law 1581, and the rest of the regional patchwork.

This piece walks through where U.S. and Latin American privacy regimes actually diverge — and why a serious U.S.+LatAm program looks structurally different from a U.S.-only one.

The fundamental difference: lawful basis vs. notice-and-opt-out

The starting point matters most.

U.S. state privacy laws generally operate on a "notice and opt-out" model. A business can collect and use personal information for a wide range of purposes, provided that it gives consumers proper notice and offers the right to opt out of certain practices (sale, sharing, targeted advertising). The default is permission, with rights to exit.

LGPD and most Latin American laws operate on a "lawful basis" model — closely modeled on GDPR. Before processing personal data, the controller must identify and document a legal basis: consent, contract performance, legal obligation, legitimate interest, vital interest, or similar. There is no general "we gave notice and they didn't opt out" default. The default is not permission.

This is a structural shift, not a cosmetic one. A CCPA-compliant data pipeline that operates on notice may have no documented lawful basis under LGPD — meaning it is non-compliant from day one in Brazil, regardless of how clean the U.S. compliance posture is.

Data subject rights: same words, different operational reality

The states and the LatAm regimes both grant consumers rights to access, correct, and delete their data. The operational realities are different.

Response timing. Under CCPA, businesses have 45 days to respond to a verifiable consumer request (extendable by another 45 days for complex requests). Under LGPD, the response period is 15 days. Under Mexico's LFPDPPP, the response period is 20 business days. A DSAR operations team built around the CCPA 45-day cadence will systematically miss Latin American deadlines.

Verification standards. U.S. state laws give businesses some discretion in verifying the identity of a requester. LGPD requires that controllers respond only to "the data subject themselves," with verification appropriate to the sensitivity. The standard for verification is interpreted more strictly in practice.

Portability. LGPD's data portability right is broader than under most U.S. state laws. It includes both content data and certain inferred data, and the format requirements are more specific.

Right to object. LGPD provides a right to object to processing in certain circumstances — a right that most U.S. state laws do not provide in equivalent form. The operational machinery for handling objections (review, decision, communication back to the data subject) needs to exist.

Cross-border transfers: the trap many U.S. companies miss

LGPD restricts international data transfers. Personal data may only be transferred out of Brazil if one of a defined set of conditions is met — country adequacy decisions, specific contractual mechanisms (standard contractual clauses), data subject consent, or one of several narrowly-construed exceptions.

A typical U.S. company architecture — data flowing back to a U.S. cloud region with no documented transfer mechanism — is not LGPD-compliant. The fix is operational: implementing the right transfer mechanism (typically SCCs in their LGPD-specific form), documenting it, and ensuring downstream vendors are aligned.

Mexico, Argentina, and Colombia each have their own cross-border transfer rules with different specifics. None of them are satisfied by a U.S.-centric infrastructure design.

This is the issue we see catch companies most often. It is also one of the more expensive to retrofit because it can require contract renegotiation with cloud providers, vendors, and customers.

Penalties: different structure, different math

U.S. state privacy laws generally impose per-violation civil penalties (often $2,500 to $7,500 per violation depending on the state and whether the violation is intentional) plus injunctive relief. Class actions exist primarily in California for breach claims.

LGPD penalties go up to 2% of the controller's revenue in Brazil for the year prior, capped at R$50,000,000 (roughly $10 million USD) per infraction. The structure is closer to GDPR's. A serious violation involving sensitive data can be substantially more expensive than the equivalent CCPA penalty.

Mexico's LFPDPPP penalties are similarly significant, and Mexico has shown an increasing willingness to enforce.

Bilingual operations are not optional

A U.S.-centric privacy program tends to assume English-language disclosures, English-language data subject request portals, and English-language vendor contracts.

Latin American regulators expect Spanish or Portuguese disclosures, in-language data subject request handling, and contracts in the local language (or properly translated and accompanied by the original). This is not a stylistic preference — it is an enforceability issue. A privacy notice that the consumer cannot read is not effective notice.

Companies operating regionally need bilingual privacy operations: disclosures, intake, response, training, contracts, and vendor management — in both languages.

A "global" privacy program that actually works

The U.S.+LatAm companies that get this right typically share a few patterns:

A two-layer policy architecture. A global baseline that covers principles applying everywhere (data minimization, security, breach response, vendor management) and a set of jurisdictional overlays that handle the specifics where each region's law differs.

Bilingual operational machinery. DSAR intake, response templates, internal training, vendor contracts, and breach notification templates exist in both English and Spanish (and Portuguese where Brazil exposure is meaningful) from day one — not as an afterthought.

A documented lawful basis register. Even for U.S.-centric processing, the company maintains a register of lawful bases for each processing activity. This costs little extra when set up at the start and is required when the program needs to support LGPD or Mexican law.

Transfer mechanism by default. Standard contractual clauses (or their LGPD-specific equivalents) are baked into vendor contracts and data flow agreements from inception. Adding them retroactively is expensive.

Regional response capacity. Either an in-region team or a clearly defined external partner who can field regulator inquiries and consumer requests in-language and in-region. Trying to handle a Brazilian regulator from a U.S. legal team is a slow-motion failure.

The strategic case for getting this right early

For U.S. companies that have any Latin American exposure today — sales, employees, vendors, customers — the cost of building privacy operations correctly the first time is meaningfully lower than the cost of retrofitting after a regulator inquiry or a customer complaint.

The other direction matters too: Latin American–origin companies expanding into the U.S. market frequently arrive with strong GDPR-style programs that need adaptation to the more fragmented U.S. state-law environment.

The seams between the two systems are the place where the actual work lives.

Oso Data Privacy operates fluently in both U.S. and Latin American privacy regimes, in English and Spanish. If your company has exposure across both — or is expanding into one from the other — the bilingual, bi-regulatory work is exactly what we do.

 
 
 

Comments


© 2025 by Oso Privacy Consultants

bottom of page