Home
LGPD and Cookies all do you need to know?

LGPD and Cookies all do you need to know?

3 years ago
João Bruno Soares
9 minutes

In this article, you will have a great introduction to the topic, as well as various other variations that revolve around the subject: Cookies and LGPD.

We list concepts and examples of cookie types, how to classify them in your documentation, Privacy Policy, Legal Bases of LGPD, etc.

In effect since August 2020, the General Data Protection Law (LGPD) will require a drastic change in the operations of companies that use data from their customers and users. Starting from August, data can only be used if it complies with the principles of LGPD - the so-called Legal Bases of LGPD - and is transparently and objectively consented to.

This will cause numerous websites to not only change their privacy policies and the information their cookies store but also various processes and ways of handling people's data. In this article, we will see how the use of cookies will be affected and how your company can continue to use them in a way that respects the law.

What are cookies?

Cookies are small text files that can store what the user is doing for a certain period. Some cookies store your browsing history, as well as logins and passwords. It is because of them that you can access your Facebook account without having to enter your email every time, as the browser (using cookies) does it for you.

In addition to various functional aspects, cookies also provide excellent service in well-known systems such as Google Drive, for example. Thanks to the cookie's ability to store information, we can work on our texts, spreadsheets, presentations, even offline, and when we reconnect, our work is not lost.

There are two types of cookies:

First-Party and Third-Party Cookies, terms used to refer to cookies generated by the website owner or by third parties.

First-Party Cookies are those generated by the website's own domain. From the website owner's perspective, they are the information that visitors generate during their browsing session.

  • Which tabs you visited;
  • If you searched for a product, added it to a list, and "forgot it in the shopping cart";
  • If you filled out any forms, etc.

Many website builders or e-commerce services use cookies to provide these functionalities to their customers. So, don't be surprised if you see that your website triggers first-party cookies without notifying you. They have practically become a "market standard."

Regarding the cookie's storage capacity, this information is indeed "generated" by our browsing, and cookies are one way to store it. How does it work?

When the system generates a cookie, it has an identifier that stores the information in the company's database as well as in the visitor's browser. A very simple example is when we access a news portal and encounter the famous paywall message, "you have reached the limit of daily free articles, subscribe to our services."

How does it know that you have already read a specific article?
Simple, through the cookies it stores in your browser for each article read.
(Does this mean that if I clear my cookies or browse anonymously, I can read freely?... Wait, wait... do you think they haven't thought about that too? 😉)

On the other hand, Third-Party Cookies are cookies from third-party sources external to the website's domain. In other words, they are cookies from third-party companies that also set cookies to record information about their visitors.

Most of the time, these third-party cookies should (or at least should) all be authorized to be present. Otherwise, the website owner may be surprised by the number of entities "sucking" data from their site(s).

Here are some common examples of services that use cookies:

  • Facebook Ads
  • Google Ads
  • Google Analytics
  • Hotjar
  • Cloudflare
  • Mixpanel
  • Zendesk
    ...

How does LGPD affect the use of cookies?

5th Article 5 of the Lei Geral de Proteção de Dados - LGPD provides legal definitions of terms that you will come across frequently when researching the regulation. Among these definitions is that of personal data:

**"personal data: **information related to an identified or identifiable natural person."

We have the last two words in italic because they are the most important for the subject at hand.

Not all data that cookies carry is personal. For example, your visit to our website is not personal data. However, once you register your email on a site like Facebook, you are identifying yourself. Therefore, this is personal data that can be collected by a cookie.

And it is from there that the LGPD starts to affect how your data is used by websites and how your website handles user data.

The problem with the use of cookies arises when it is not known what data is being collected, for what purposes, and by whom. It is a matter of privacy and transparency, values that are the foundation of the LGPD.

The use of cookies that violates the LGPD will be penalized, and among the penalties are expensive fines.

Who needs a cookie policy?

All websites that process data, specifically those that use First or Third Party Cookies. If your website processes personal data or data that, when combined, can identify an individual person, it needs even more careful review of how this information is processed.

But, should this be listed in the Cookie policy or the Privacy Policy?

That depends on the company's choice to differentiate these aspects, as it may be a different approach based on the business model. Some companies address regulations for their "digital" data in the Cookie policy and the "offline" data in the Privacy Policy. However, it varies greatly, so we recommend consulting an expert who can analyze your business model and all the data flows and mappings of your company to understand the need for such differentiation.

Cookie requirements: How to keep your website compliant with LGPD.

To ensure that a website is compliant with LGPD when using cookies, there are certain principles to consider, especially if you have a valid "reason" or legal basis that supports the use of data and cookies on your site. For many, this legal basis is "Consent."

What does that mean?
In order for companies to process personal data of data subjects (individuals like you and me), they now need to have a strong legal basis provided by the law (LGPD). This "permission" is known as the Legal Bases of LGPD.

Therefore, while consent is not the only legal basis that allows companies to use data, it plays a crucial role when it comes to cookies. This is why cookie banners serve an essential purpose: notifying and informing visitors, as well as correctly collecting and storing individual consents.

Regardless of the information carried by a cookie, it should have been consented to by the user. But what makes consent valid? And what should be communicated to the user?

The user must be clearly and objectively informed about the purpose for which their data will be collected. Additionally, they must give their explicit consent, or opt-in, by clicking on a banner.

To automate this process, Cookie Notices or Cookie Banners are used.
They serve to fulfill the sixth principle of the law: transparency.

Cookie Banner or Cookie Notice

The Cookie Banner is that little pop-up window you can see on most websites nowadays, including when you entered our blog. This banner communicates that the site uses cookies. Ours says the following:

"Take control of your privacy. Our site uses cookies to enhance navigation." Then, there are two links: Privacy Policy and Terms of Use. Right after, there's a button for you to view your privacy options and an "accept" button, indicating that you agree to the use of your data.

The cookie banner, or cookie notice, which is a feature of the Consent Management Platform, serves to explicitly state the practice (use of cookies), the purpose (enhancing navigation), and offer users the possibility to fully or partially agree to the data processing.

This is what LGPD requires: transparency and objectivity, without complications.
In this way, the use of cookies is permitted and can greatly assist in your business operations.

What is the expiration period of a cookie?

GDPR, the European data protection regulation, has a limit of twelve months for the use of a cookie. However, LGPD does not establish an "expiration" deadline.

But one of the principles for data processing is necessity. According to the regulation, data can only be retained for the time necessary to fulfill its purpose. If a cookie carries information that no longer needs to be used, it becomes invalid under the law.

Additionally, there are various initiatives by browsers—especially Apple's Safari, which automatically blocks third-party cookies. This "trend," as it is known in the market, has been widely discussed since 2015, even before GDPR. However, it is always being rethought or adapted because the entire advertising and analytics market relies heavily on the widespread use of cookies.

Thus, any changes in this regard will indeed be revolutionary and will bring many changes to the ecosystem as a whole.

Cookies and LGPD in the privacy policy.

It is important that your privacy policy includes a detailed and specific explanation of how your website uses cookies.

As described earlier, many companies make distinctions between the cookie policy and the privacy policy. This is not mandatory, but it may be necessary based on the business model. So, don't cling to templates, but strengthen transparency and accessibility for the information listed there.

Cookie Pixel and Tag, what's the difference?

It is important to avoid confusion at this point, as many people end up mixing up these concepts. I'll provide a simple explanation below, which will help us understand the order of things and facilitate overall comprehension.

Remember: Tags and Pixels trigger Cookies.

  • Tag & Pixel: Code that goes into the HTML of your website to call a specific service. These are scripts (programming codes) that call a server and perform specific functions based on these requests.

  • Cookies: Text files read and triggered by Tags & Pixels, which store data and serve to identify whether a browser is new (if there is no cookie, the tag triggers) or already known (if It has the cookie, It will overwrite it).

What is the correct way to use cookies under LGPD?

To maintain compliance with the law, it is necessary to pay attention to the principles of LGPD and have knowledge of the regulation as a whole.

Furthermore, once it is decided that the company will indeed use first-party or third-party cookies in its operations, the categorization or organization of these cookies is the basis for communicating with visitors in your cookie policy and banner.

In general, the market uses five main groups to classify their tags and consequently the cookies triggered by them:

  • Necessary: Without them, your business model doesn't work, or you have to use them due to legal requirements/legislation.
    (e.g., first-party cookies, gateway authentication, etc.)

  • Advertising: With them, you trigger remarketing, populate ad pixels, email sequences, etc.
    (e.g., Facebook Pixel and Google Ads)

  • Analytics: With them, you have an analysis of what visitors do, where they come from, how they behave on your site.
    (e.g., Google Analytics, Hotjar, etc.)

  • Performance: Tags that maintain site functionality and ensure its operation, e.g., preventing DDoS attacks.
    (e.g., Cloudflare)

  • Functional: Tags that handle functional aspects, such as remembering preferences or recognizing that the user is already logged into the system.
    (e.g., Chatbots, Helpcenters)

How to manage cookies and visitor consent under LGPD?

To facilitate data collection and record user consent, there are Consent Management Platforms (CMPs) like AdOpt.

In this link, you can learn more about our service: In summary, a Cookie Banner that helps your website comply with LGPD, GPDR, CCPA... standards while also being a comprehensive tool for managing consent and communicating with visitors.

Get started for free now and avoid LGPD, GPDR, CCPA... fines!

Tags

Cookies
LGPD

Related posts

5 Common Cookie Consent Mistakes Hurting Your Compliance

Discover the 5 common **cookie consent mistakes** that risk your **compliance** and learn how to avoid heavy **fines**. Simplify your **data privacy** strategy using a reliable **[Cookie notice/banner](https://goadopt.io/en/blog/why-the-cookie-banner/)**.

AdOpt post

Connecticut CTDPA: Cookies Policy

What the Connecticut CTDPA requires from your Cookies Policy: opt-out link, opt-out preference signal from January 2025, 15-day consent revocation, teen protections, and targeted advertising definition.

AdOpt post

The Differences Between Data Controller and Data Processor - LGPD

Now that we have the data flow within your company, we need to highlight 2 aspects of LGPD that will help you determine the extent of your responsibility in relation to the many points listed in the company. I'm talking about the difference between Data Controller and Data Processor.

AdOpt post

7 Steps to GDPR-Compliant Cookie Banners in 2025

Learn the essential steps for creating GDPR-compliant cookie banners in 2025, ensuring user consent and privacy protection.

AdOpt post

5 Signs Your Website Needs an Cookie Consent Strategy

How does your website handle LGPD? What strategies does it use to comply with the General Data Protection Law? Have you thought about using a cookie notice but don't know if your site has cookies or if it's enough? If you can't answer these questions, be cautious! Your page may be exposed to fines and other sanctions.

AdOpt post

How long can we ignore LGPD?

LGPD is in effect. Despite that, there are still many companies ignoring it, but is that possible? How long can we ignore LGPD?

AdOpt post

California CCPA: DSAR Privacy Portal

How to handle DSARs under the California CCPA/CPRA: 7 consumer rights, 45-day deadline, toll-free number required, 12-month lookback, private right of action for breaches, and CPPA enforcement.

AdOpt post

LGPD: An Opportunity for Digital Marketing Agencies!

Have you ever thought that your marketing agency could find a great business opportunity in LGPD? Well, unlike what many think, it brings changes that can accelerate the demand for the services of these companies.

AdOpt post

How to delete cookies and cache in Chrome and other browsers?

Tired of the ads from that site you visited following you around? Is your computer running slow when accessing a particular website? Want to delete all cookies from a specific service or site?

AdOpt post

The Impact of Cookie Banners on Your E-commerce - LGPD

Having a cookie banner on your brand's website has become indispensable for many. However, for e-commerce websites, it has practically become an obligation to have one. This is because this type of website has a technological composition in which cookies are a structural part. Login flow, items in the shopping cart, recommendation showcases, remarketing... Most of them rely on cookies.

AdOpt post

California CPRA and Cookies: All you need to know

California CPRA explained: CCPA vs CPRA timeline and key differences, sensitive personal information, sharing of data, CPPA enforcement, GPC requirement, and tripled penalties for minors.

AdOpt post

IOWA ICDPA: DSAR and Privacy Portal

Iowa ICDPA DSAR guide: 90-day response deadline, 45-day extension, 60-day appeal process, limited deletion scope, opt-out from data sales, targeted advertising disclosure requirement, and 90-day cure period.

AdOpt post

Utah UCPA: DSAR and Privacy Portal

Utah UCPA DSAR guide: four consumer rights, limited deletion scope, no right to correct, no formal appeal process, no opt-out of profiling, 45-day deadline, and the guaranteed 30-day cure period.

AdOpt post

Montana MTCDPA: Privacy Policy

Learn what your MTCDPA Privacy Policy must include after Montana's SB 297 amendments from the conspicuous "privacy" hyperlink and last-updated date requirements to sale disclosures, minor protections, and how to keep your notice operationally aligned with your stack.

AdOpt post

Key Differences between LGPD and GDPR and the Impact on Internet Cookies

While both regulations share the goal of safeguarding individuals' rights regarding the processing of their personal data, there are some important differences between them. It is crucial to understand these distinctions and their implications, particularly in the context of internet cookies.

AdOpt post

10 Marketing Processes You Should Rethink under the LGPD!

In the end, our goal has never been to predict doom for companies or to be part of the LGPD's Apocalypse Cavalry. But, since we've been in the market for some time, these kinds of issues always catch our attention when we start data mapping and having conversations with colleagues.

AdOpt post

New Hampshire NHDPA: DSAR Privacy Portal

What is a DSAR under NHDPA? Complete guide to consumer rights, response deadlines, and building a compliant Privacy Portal for your site.

AdOpt post

Tenesse TIPA: Cookies Policy

Learn how to build a defensible TIPA Cookies Policy for Tennessee compliance covering consent architecture, opt-out requirements, the NIST affirmative defense, and how your cookie banner, privacy notice, and vendor management must work together under the Tennessee Information Protection Act.

AdOpt post

Connecticut CTDPA and Cookies: All You Need to Know

The Connecticut Data Privacy Act (CTDPA) is a state regulation designed to protect the privacy of Connecticut residents. It also regards cookies, so in this article we will help you understand all about this new privacy regulation.

AdOpt post

Colorado CPA: Cookies Policy

What the Colorado CPA requires from your Cookies Policy: mandatory Universal Opt-Out Mechanism from July 2024, targeted advertising definition, dark pattern rules, and the 24-month consent refresh.

AdOpt post

Florida FDBR: Cookies Policy

What the Florida FDBR requires from your Cookies Policy: targeted advertising across affiliated sites, opt-out for sensitive data and voice recognition, dark patterns, and tripled penalties.

AdOpt post

Google Consent Mode: Beginner to Advanced Guide.

Google Consent Mode (GCM) is nothing more than a way for you to integrate the consent you collect from your visitors into Google technologies. In this way, upon receiving this consent information, collection can only occur with authorization, thus complying with the legislation and having direct evidence of compliance as defense for both you and Google.

AdOpt post

Colorado CPA and Cookies: All You Need to Know

The Colorado Consumer Privacy Act went into effect July 1, 2023 (CPA). CPA is a vital piece of legislation designed to protect the privacy of residents in Colorado. Understanding its requirements is essential for any business operating in the state. This act is all about giving control back to the consumers regarding their personal data. But what does this mean for you and your business, especially when it comes to managing cookies on your website?

AdOpt post

Florida FDBR: Privacy Policy

What the Florida FDBR requires from your Privacy Policy: annual updates, 6 mandatory content categories, specific notices for sensitive and biometric data sales, and the 7 consumer rights.

AdOpt post

California CCPA: Privacy Policy

What the California CCPA/CPRA requires from your Privacy Policy: 12-month lookback, annual updates, Do Not Sell link, sensitive PI disclosures, toll-free number, and the 7 consumer rights.

AdOpt post

Connecticut CTDPA: Privacy Policy

What the Connecticut CTDPA requires from your Privacy Policy: active email contact, opt-out link, 15-day consent revocation, opt-out preference signal from January 2025, and teen protections.

AdOpt post

Colorado CPA: Privacy Policy

What the Colorado CPA requires from your Privacy Policy: 5 mandatory elements, purpose specification duty, secondary use prohibition, 24-month consent refresh, and Universal Opt-Out Mechanism disclosure.

AdOpt post

LGPD & COOKIES - ANPD Releases "Guidance on Cookies and Personal Data Protection"

On October 18, 2022, the National Data Protection Authority (ANPD) released the "Guidance on Cookies and Personal Data Protection." Highly anticipated by professionals in the field, this document is of utmost importance as it examines various applicable legal scenarios and establishes the requirements to be observed in the case of cookie usage.

AdOpt post

Utah UCPA and Cookies: All you need to know

Utah UCPA explained: the most business-friendly US state privacy law, dual threshold requirement, opt-out for sensitive data, no right to correct, guaranteed 30-day cure period, and key differences from other state laws.

AdOpt post

Oregon OCPA: Cookies Policy

What the Oregon OCPA requires from your Cookies Policy: opt-out link, GPC from January 2026, opt-out without authentication, derived data in scope, teen protections, and the elimination of the cure period.

AdOpt post

California CPRA: DSAR and Privacy Portal

California CPRA DSAR guide: new rights to correct and limit SPI, opt-out without multiple steps, GPC as valid opt-out, 12-month minor rule, private right of action, and CPPA enforcement.

AdOpt post

Texas TDPSA and Cookies: All You Need to Know

Your website have users accessing from Texas? So be ready… the Texas Data Privacy and Security Act is here to shake things up. Don't worry; we've got your back. This guide will walk you through everything you need to know to ensure your website complies with the new regulations.

AdOpt post

LGPD for marketing | A practical guideline.

Every day, millions of users generate data on the web, which is used by companies around the globe to improve their offerings. Therefore, in 2018, a law was created to regulate the use of personal data by companies, and this directly impacts digital marketing. We're talking about LGPD.

AdOpt post

Virginia VCDPA: DSAR Privacy Portal

How to handle DSARs under the Virginia VCDPA: consumer rights, 45-day response deadlines, the appeal process, free requests twice per year, and how to build a compliant Privacy Portal.

AdOpt post

GDPR Legal Basis: An Introduction

In this article, we'll explore the GDPR foundations and provide practical insights from the basics to more advanced concepts of its legal basis.

AdOpt post

Florida FDBR: DSAR Privacy Portal

How to handle DSARs under the Florida FDBR: 7 consumer rights, two required submission channels, 45-day deadline with only 15-day extension, tripled penalties for children, and compliance guide.

AdOpt post

IOWA ICDPA: Cookies Policy

What the Iowa ICDPA requires from your Cookies Policy: opt-out for data sales and targeted advertising, opt-out model for sensitive data, no GPC requirement, no specific link text required, and the 90-day cure period.

AdOpt post

Best practices in tag categorization

It's time to talk about one of the most impactful tasks, both for the company and for the visitors of your websites: tag categorization. But why is it so impactful? What is the relevance of this configuration and how can it affect us? It is precisely because of these common questions we receive from our clients that we have written this article on best practices in tag categorization.

AdOpt post

Montana MTCDPA: DSAR Policy

Rights, Policy and how to understand about the DSAR Montana MTCDPA

AdOpt post

What is the difference between cookies, local storage, and session storage?

Despite cookies being more well-known, what is the main difference between cookies and session storage and local storage? Why choose one over the other? This article will help you with these doubts!

AdOpt post

California CPRA: Cookies Policy

What the California CPRA requires from your Cookies Policy: the sharing concept, GPC as valid opt-out, Do Not Sell or Share link, SPI geolocation, minor protections, and retention periods.

AdOpt post

How to choose a Cookie Banner for your website

What are the criteria for this choice, and what are the strengths and weaknesses of each option? Well, we're here to help you because this decision needs to be well thought out!

AdOpt post

Fines in LGPD - What are they, amounts, and compliance deadlines

In this article, we will answer all your questions regarding fines under the LGPD (Brazil's General Data Protection Law).

AdOpt post

New Hampshire NHDPA: Cookies Policy

Cookies Policy under NHDPA explained. Discover what's mandatory, dark patterns to avoid, and how to implement legal cookie consent.

AdOpt post

Virginia VCDPA and Cookies: All you need to know

Everything you need to know about the Virginia Consumer Data Protection Act (VCDPA): who must comply, consumer rights, cookie requirements, penalties, and how to get your site in compliance.

AdOpt logoAdOpt logo

Address: 7345 W Sand Lake Road, Ste 210 Office 5898 Orlando, FL 32819

15 Rue du Général Campredon, 34000 Montpellier, France

207 Rue de Bercy, 75012 Paris, France

EIN: 86-3965064

Phone: +1 (407) 768-3792

AdOpt

Resources

Product

Certifications

Google CMP PartnerIAB Europe TCF Registered Vendor

© GO ADOPT, LLC since 2020 - Made by people who love🍪