LGPD and store cameras: three things to audit before the next loss-prevention plan
The camera your store uses for loss prevention records personal data, and Brazil’s LGPD treats that as data processing. The rule looks small. The effect is not.
The Lei Geral de Proteção de Dados (Law 13.709/2018) has been in force since 2020, enforced by the ANPD. Anyone running cameras with AI analytics needs to know where the line falls, because it has already been crossed by others.
What the rule says, in plain text
A person’s image is personal data. Filming the aisle to investigate theft has a possible legal basis, tied to security and loss prevention. So far, familiar ground.
The jump is in facial recognition. Identifying a person by their face is biometric data processing, which the LGPD classifies as sensitive personal data, in article 11. The bar rises sharply. And the ANPD has acted: in 2023, it ordered a retail chain to suspend its use of facial recognition. Anyone who works the operation needs to know this before signing the project.
The systems the rule touches
It is not only the camera. The rule reaches the analytics running on top of it.
- Foot-traffic counting and heat maps, usually anonymous, sit on one side of the line.
- Facial recognition and “repeat suspect” identification sit on the other, in the sensitive-data field.
- Self-checkout cameras that verify the product mix loss prevention and customer image in the same flow.
What changes for those who thought they were compliant
Being compliant with the old camera does not cover the new analytics. The difference sits in three points, and that is what is worth auditing this quarter.
First, the legal basis for each use, separated by purpose, not one blanket “security”. Second, the image retention period, which almost nobody defines and the rule requires. Third, the Data Protection Impact Assessment, required when the processing is high risk, as biometrics is.
The second-order effect almost every plan ignores
The rule changes vendor selection. The question stops being “does the system catch theft” and becomes “where does the biometric template live, and who answers if it leaks”.
Telling legal apart from enforced is part of the work. LGPD has been in force for years; enforcement is tightening now. Whoever operated in that gap trusting “nobody will check” inherits the liability when the check arrives. It is the same discipline as separating shrinkage by source and measuring OSA with ground truth: the data needs an owner and a purpose.
Think about the camera project compliance already flagged and operations left in the “later” pile. That is the one the audit catches first.
Send me the list of store systems the rule may touch: analytics cameras, self-checkout, recognition, traffic counting. In one hour I will send back a one-page gap analysis: what is already compliant, what needs work, and the milestone tied to tightening enforcement. If a front becomes a project, the two-week Diagnóstico is the next step. We do not give legal opinions; we map the operation against the rule.