Skip to content
Back to blog
Legal12 min

Ticket Buyer Data in Brazil: LGPD 2026

The LGPD requires asking for only the minimum necessary, and Decree 13,108/2026 requires keeping each ticket's history for two years. Here's how to resolve the tension.

by Alejandro García Cestero

CEO & Founder

Quick answer

In Brazil, buyer data is governed by the LGPD, Lei 13.709/2018. Ticket sales rely on contract performance, not consent, and only the minimum necessary data is allowed. Decree 13,108/2026 adds individualised ticket linkage and a transfer history kept for two years.

In Brazil, ticket buyer data sits under two laws pulling in different directions. The LGPD requires asking for the minimum necessary and deleting data once processing ends. Decree nº 13,108, of 31 August 2026, requires linking each ticket to a person and keeping a record of ownership changes for two years. The two are compatible, but not by default.

What data can a Brazilian organiser ask for when selling a ticket?

Only what's needed to issue, deliver and validate the ticket — nothing more. The updated text of Lei nº 13.709, of 14 August 2018 defines personal data in its Article 5, I as «informação relacionada a pessoa natural identificada ou identificável» ("information related to an identified or identifiable natural person"). The filter sits in Article 6, III, the necessity principle: «limitação do tratamento ao mínimo necessário para a realização de suas finalidades, com abrangência dos dados pertinentes, proporcionais e não excessivos» ("limiting processing to the minimum necessary to achieve its purposes, covering relevant, proportionate and non-excessive data").

Two more principles from the same article govern the checkout form. Principle I requires a purpose that is «legítimos, específicos, explícitos e informados ao titular» ("legitimate, specific, explicit and disclosed to the data subject"), and principle VI requires transparency: «informações claras, precisas e facilmente acessíveis» ("clear, precise and easily accessible information"). Article 9 adds to this, requiring that the data subject be given the specific purpose and the controller's identity before any processing takes place.

The practical consequence is awkward for anyone copying a checkout form from another country: every field has to be justifiable on its own. A date of birth with no age-based pricing isn't justified. A postal address with no physical delivery isn't either. It's the same logic the GDPR applies in Europe to what data you can ask a ticket buyer for, with one difference: in Brazil, accountability is an explicit principle, Article 6, X.

Contract performance, not consent. Article 7 of the LGPD lists ten legal bases, and V is the one underpinning a ticket sale: processing «quando necessário para a execução de contrato ou de procedimentos preliminares relacionados a contrato, a pedido do titular dos dados» ("when necessary for the performance of a contract or preliminary procedures related to a contract, at the data subject's request"). Nobody needs to tick a box to receive the ticket they've bought.

Consent under Article 7, I becomes necessary again the moment the data stops serving ticket delivery: the newsletter, profiling, sharing data with the festival's sponsor. And legitimate interest under Article 7, IX isn't a blank cheque: Article 10, § 1 limits it to «dados pessoais estritamente necessários para a finalidade pretendida» ("personal data strictly necessary for the intended purpose"). A marketing newsletter only fits there if you can write down why, and exactly which data it needs.

PurposeTypical legal basisLegal provision
Issue and deliver the ticketContract performanceArt. 7, V, LGPD
Validate access at the doorContract performanceArt. 7, V, LGPD
Keep the ownership historyCompliance with a legal obligationArt. 7, II, LGPD, and Art. 17, § 1, Decree 13,108/2026
Marketing to attendeesConsent or documented legitimate interestArts. 7, I, and 10, LGPD
Facial recognition at accessSpecific, prominent consentArt. 11, I, LGPD

This table is our own reading of the cited articles, not a classification published by the ANPD. What is explicitly written is the difference in regime: the sensitive data covered by Article 5, II has its own, shorter list of legal bases in Article 11, compared with Article 7.

What does Decree 13,108/2026 require organisers to keep, and for how long?

Each ticket's history, for two years. Decree nº 13,108, of 31 August 2026, which regulates the Código de Defesa do Consumidor as it applies to ticket sales, imposes seven duties on the primary seller in its Article 4. Three of them generate data: duty I, measures «destinadas a prevenir e impedir a aquisição massiva, abusiva ou especulativa de ingressos» ("designed to prevent and stop mass, abusive or speculative ticket purchasing"); duty II, «mecanismos de vinculação individualizada de ingressos» ("mechanisms for individualised ticket linkage"); and duty VII, strengthened mechanisms for high-demand events «como a utilização de filas virtuais, pré-cadastro dos consumidores ou limitação do número de ingressos por consumidor» ("such as virtual queues, consumer pre-registration or limits on the number of tickets per consumer").

The retention periods appear in two articles. Article 17, § 1 requires «manter o histórico de transferência de cada ingresso pelo prazo mínimo de dois anos» ("keeping the transfer history of each ticket for a minimum period of two years") and handing it over to the supervisory bodies of the Sistema Nacional de Defesa do Consumidor «mediante requisição fundamentada» ("on reasoned request"). Article 15, sole paragraph, requires storing «pelo prazo mínimo de dois anos, os dados desagregados de vendas, incluídos os registros por categoria e por transação, sem identificação de dados pessoais» ("for a minimum of two years, disaggregated sales data, including records by category and transaction, without personal identification"). That last phrase is worth underlining: the decree orders that series to be anonymised, not kept with names attached.

RecordMinimum periodLegal provision
Ownership transfer history2 yearsArt. 17, § 1, Decree 13,108/2026
Disaggregated sales data, without personal identification2 yearsArt. 15, sole paragraph, Decree 13,108/2026
Security incident register5 yearsArt. 10, Resolução CD/ANPD nº 15/2024
Record of processing operationsMandatory, no fixed periodArt. 37, LGPD

The decree itself resolves the tension with the LGPD in its Article 18, III, requiring that any ownership transfer comply with «a observância à legislação de proteção de dados pessoais, assegurado o acesso às informações pelos órgãos competentes» ("compliance with personal data protection legislation, with access to information guaranteed to the competent authorities"). And Article 16, I of the LGPD allows data to be kept after processing ends for «cumprimento de obrigação legal ou regulatória pelo controlador» ("the controller's compliance with a legal or regulatory obligation"). In other words: those two years are the legal obligation that justifies not deleting the data, and nothing more than that. The rest of the buyer's profile doesn't inherit that period.

What authentication does a change of ownership require?

Whatever is proportionate to the event. Article 18, II requires «mecanismos de autenticação da identidade dos usuários envolvidos na transferência, compatíveis com a natureza do evento e com os recursos tecnológicos empregados na comercialização dos ingressos» ("authentication mechanisms for the identity of users involved in the transfer, compatible with the nature of the event and the technological resources used in ticket sales"). It's a proportionality clause within a consumer protection rule, and it fits the LGPD's necessity principle. Article 17, § 2 adds that the transfer must take place «exclusivamente por meio da plataforma oficial» ("exclusively through the official platform"), and § 3 bans charging for it.

The Ministério da Justiça e Segurança Pública framed it in those terms. In its official statement of 31 August 2026, the Secretary for Digital Rights, Victor Oliveira Fernandes, summed up the goal: «Exigir rastreabilidade, autenticação e histórico de cada operação, o mercado ganha em transparência» ("By requiring traceability, authentication and a history of every transaction, the market gains in transparency"). The same statement points to doing so «respeitando a proteção dos dados pessoais de quem compra» ("while respecting the personal data protection of buyers"). Timing matters too: the decree was published in the Diário Oficial da União on 1 September 2026, and its Article 26 staggers when it takes effect, so Articles 4, 5, 13 and 15 to 18 apply twenty days later, that is, from 21 September 2026. The detail of that staggered rollout is covered in our piece on Decree 13,108's phased entry into force.

How much data does meia-entrada really require?

More than it looks, and at two separate moments. Lei nº 12.933, of 26 December 2013 guarantees half-price tickets for students and, under its § 10, caps this at «40% (quarenta por cento) do total dos ingressos disponíveis para cada evento» ("40% of the total tickets available for each event"). Decreto nº 8.537, of 5 October 2015 spells out the check: its Article 3 requires presenting the Carteira de Identificação Estudantil «no momento da aquisição do ingresso e na portaria ou na entrada do local de realização do evento» ("at the time of purchase and at the entrance or gate of the event venue").

Article 3's § 2 lists what the card must include: full name and date of birth, a recent photo, the educational institution, level of study, and validity until 31 March of the year following issue. For low-income young people, Article 5 requires the Identidade Jovem card «acompanhada de documento de identificação com foto expedido por órgão público» ("accompanied by a photo ID issued by a public authority").

That produces a figure almost nobody works out before designing a checkout flow. For an event with 5,000 tickets on sale, the quota set by Article 9 of the decree is 2,000 discounted tickets, and each one gets checked twice: at purchase and at the door. That's up to 4,000 document checks, with photos and dates of birth on display. This figure is our own calculation based on Articles 3 and 9, not a published statistic. The read-across to the LGPD is straightforward: checking isn't the same as storing. Article 6, III gives no cover for keeping an image of the card just because it was used to validate access. The remaining meia-entrada obligations, including the booking window of up to 48 hours in advance and the disclosure duties under Article 11, are covered in our guide on how to sell tickets in Brazil.

Can you use biometrics or facial recognition at the door?

Yes, but under the narrowest legal basis the law offers. Article 5, II of the LGPD includes among sensitive personal data «dado genético ou biométrico, quando vinculado a uma pessoa natural» ("genetic or biometric data, when linked to a natural person"). And Article 11, I makes processing conditional on the data subject consenting «de forma específica e destacada, para finalidades específicas» ("specifically and prominently, for specific purposes"). A box ticked in the general terms, or a sign at the venue entrance, won't do.

An operational consequence follows from this that isn't written into the law, and we offer it as our own reading: if consent is to be freely given, the event needs an alternative access route without biometrics for anyone who doesn't consent. A turnstile with facial recognition as the only way in turns consent into a condition of entry. A named QR code, by contrast, identifies the holder without touching sensitive data — the approach we describe in our guide to access control.

One boundary is worth marking clearly. Article 1, § 2 of Decree 13,108/2026 excludes from its scope ticket sales «para eventos esportivos» ("for sporting events"), which fall instead under Lei nº 14.597, of 14 June 2023. According to the record of that law at the Câmara dos Deputados, it revoked the 2003 Estatuto de Defesa do Torcedor. We haven't been able to access its full text to verify the detail of its access rules, so we don't summarise them here: if you organise sporting events in Brazil, that is the text to read, not this decree.

What happens if the data leaves Brazil?

A safeguard is required, and since August 2025 any old contract no longer cuts it. Article 33 of the LGPD allows international transfers to countries with an adequate level of protection (item I) or when the controller «oferecer e comprovar garantias de cumprimento dos princípios» ("offers and demonstrates guarantees of compliance with the principles") (item II), among other grounds. The ANPD developed that item II through Resolução CD/ANPD nº 19, of 23 August 2024, which approves «o Regulamento de Transferência Internacional de Dados e o conteúdo das cláusulas-padrão contratuais» ("the International Data Transfer Regulation and the content of the standard contractual clauses").

The deadline is set out in the sole paragraph of Article 1: agents using contractual clauses «deverão incorporar as cláusulas-padrão contratuais aprovadas pela ANPD aos seus respectivos instrumentos contratuais, no prazo de até 12 (doze) meses, contados da data de publicação desta Resolução» ("must incorporate the standard contractual clauses approved by the ANPD into their contractual instruments, within a period of up to 12 (twelve) months, counted from the date of publication of this Resolution"). Twelve months from 23 August 2024 is 23 August 2025: that adaptation window has already closed.

This matters directly for a Brazilian organiser selling through a foreign platform or hosting data outside the country. The question for the supplier isn't whether it "complies with the LGPD", but which of the three mechanisms it uses: an adequacy decision, standard contractual clauses, or global corporate rules. It's the same due diligence exercise we describe for buyer data in the Emirates, with a different authority and a different form.

Do you need a data protection officer if you're a small promoter?

Appointing one, no; responding to the data subject, yes. Article 41 of the LGPD states that «o controlador deverá indicar encarregado pelo tratamento de dados pessoais» ("the controller must appoint a person in charge of personal data processing"), and its § 1 requires that person's identity and contact details be made public. Its § 3 empowers the ANPD to set «hipóteses de dispensa» ("exemption cases"), and it did just that.

Resolução CD/ANPD nº 2, of 27 January 2022 defines the small-scale data processing agent in its Article 2, I — micro and small businesses, startups and private-law legal entities, including non-profits — and its Article 11 exempts them from appointing a data protection officer. That article's § 1 keeps the obligation to maintain «um canal de comunicação com o titular de dados» ("a communication channel with the data subject"). There are also three easements that fit a three-person production company: simplified record-keeping of processing operations (Article 9), a security policy proportionate to «a estrutura, a escala e o volume das operações» ("the structure, scale and volume of operations") (Article 13, § 1), and double deadlines for responding to requests and reporting incidents (Article 14).

What to do when buyer data is breached

Count working days from the moment you know the incident affected personal data. Resolução CD/ANPD nº 15, of 24 April 2024 sets out in its Article 6 that «a comunicação de incidente de segurança à ANPD deverá ser realizada pelo controlador no prazo de três dias úteis» ("notification of a security incident to the ANPD must be made by the controller within three working days"), along with twelve mandatory pieces of information, including the number of data subjects affected and a breakdown by children, adolescents and the elderly. Article 9 applies the same three-working-day deadline for notifying the affected data subjects.

Article 5 decides when notification is required: an incident capable of «afetar significativamente interesses e direitos fundamentais dos titulares» ("significantly affecting the interests and fundamental rights of data subjects") that also involves, at a minimum, sensitive data, data belonging to children, adolescents or the elderly, financial data, authentication credentials, or large-scale data. A buyer database holding payment details and meia-entrada documents touches several of those criteria at once. Article 10 closes the loop with an internal incident register kept «pelo prazo mínimo de cinco anos» ("for a minimum period of five years").

For a small-scale promoter, Article 14 of Resolução nº 2/2022 doubles that deadline: six working days instead of three. This combines two separate resolutions, and the calculation is our own.

How much does non-compliance with the LGPD cost at an event?

Up to 2% of turnover, capped at 50 million reais per infringement. Article 52, II of the LGPD provides for a «multa simples, de até 2% (dois por cento) do faturamento» ("simple fine of up to 2% (two per cent) of turnover"), capped at 50,000,000 reais per infringement, and item III sets a daily fine with the same cap. The list of sanctions goes as far as partial suspension of the database for up to six months (item X) and a total ban on processing (item XII). Article 42 adds that anyone who causes harm «é obrigado a repará-lo» ("is obliged to make it good").

The calculation isn't discretionary. Resolução CD/ANPD nº 4, of 24 February 2023, which approves the Regulamento de Dosimetria, classifies infringements as minor, moderate or serious in its Article 8, and increases the penalty when there is «tratamento de dados pessoais em larga escala» ("large-scale personal data processing") alongside factors such as the use of sensitive data or data belonging to children and the elderly. Article 11 sets the base value using the classification, turnover net of taxes, and the degree of harm; Article 15 anchors the result between the appendix minimums and the 2% cap. For small-scale agents, Article 17, § 2 grants «prazo em dobro para o pagamento das multas» ("double the period for paying fines"): the deadline, not the amount.

One point of institutional context, because it changes who you're dealing with: according to the notes on the updated text published by the Câmara dos Deputados, Lei nº 15.352, of 25 February 2026, converted Medida Provisória nº 1.317, of 2025, into law and reformed Chapter IX of the LGPD — the chapter governing the ANPD itself — as well as Articles 5, 8, 23 and 41.

And what part of this does Futura Tickets cover?

It helps to separate what depends on the supplier from what belongs to the organiser. The legal basis for each field on the form, the data protection officer if you're not small-scale, notifying the ANPD within three working days, and informing data subjects, are all the controller's responsibility — that is, the organiser's. No ticketing system takes these on for you.

What does depend on the system are four specific capabilities: named tickets that don't ask for more data than necessary, ownership changes tracked within the platform, sales data exports with no personal identification, and selective deletion once the retention period ends. Futura Tickets is a Spanish SaaS ticketing platform for professional organisers, selling in 9 languages and across 11 country domains. With Futura Tickets, the attendee database belongs 100% to the organiser: emails and phone numbers are handed over in full, in compliance with the GDPR. For an event in Brazil, that means documenting the legal basis and the international transfer is on you, using whatever documentation the supplier provides: ask for it before signing, just as you would when comparing any ticketing software. The equivalent European framework is covered in our GDPR guide for organisers.

Checklist before opening ticket sales in Brazil

Eight checks, each backed by its own article.

Justify each checkout field individually. Article 6, III of the LGPD requires the minimum necessary; if you can't name a field's purpose, cut it.

Document that the legal basis is the contract, not consent. Article 7, V covers the purchase. Reserve consent for marketing and data sharing, and keep a timestamped record of it.

Separate checking from storing for meia-entrada. Article 3 of Decree 8.537/2015 requires the card to be shown at purchase and at the door; it doesn't require keeping an image of it.

Set the ownership history retention to two years. That's Article 17, § 1 of Decree 13,108/2026, and it's handed over to the Sistema Nacional de Defesa do Consumidor only on reasoned request.

Export the sales series without personal data. Article 15, sole paragraph, says it in those exact words: «sem identificação de dados pessoais» ("without personal identification").

Ask your supplier which Article 33 mechanism it uses. If standard contractual clauses apply, they should have been incorporated by 23 August 2025.

Set up the incident procedure before you need it. Three working days for the ANPD and for data subjects, six if you're small-scale, with an internal register kept for five years.

Publish a contact channel for data subjects, even if you're exempt from appointing a data protection officer. That's required by § 1 of Article 11 of Resolução nº 2/2022.

Conclusion

In 2026, Brazil added a layer of ticket traceability without touching the LGPD, and making the two fit together is left to the organiser. The decree requires linking, authenticating and retaining data; the data protection law requires limiting, informing and deleting it. The two can coexist if the sales system distinguishes between three things: the data the contract needs, the data the decree requires for two years, and the data that only survives because nobody remembered to switch it off. The split of retention periods is already written down, article by article, resolution by resolution. What isn't written down is which fields your form asks for, and that's a decision to make before opening sales, not when the request letter arrives.

Sources

Share

Frequently asked questions

Do you need consent to sell a ticket in Brazil?
Not for the purchase itself. Article 7, V of Lei 13.709/2018 allows data processing «quando necessário para a execução de contrato ou de procedimentos preliminares relacionados a contrato» ("when necessary for the performance of a contract or preliminary procedures related to a contract"). Consent is reserved for anything not needed to deliver the ticket, such as follow-up marketing or sharing data with a sponsor.
How much data can I ask a ticket buyer for?
The minimum needed to issue and validate the ticket. Article 6, III of the LGPD sets out the necessity principle: processing is limited «ao mínimo necessário para a realização de suas finalidades» ("to the minimum necessary to achieve its purposes"). Decree 13,108/2026 requires linking each ticket to a person, but doesn't specify which data point to use, so the field has to be chosen, not inherited from elsewhere.
How long must a ticket's history be kept in Brazil?
At least two years. Article 17, § 1 of Decree 13,108/2026 requires keeping each ticket's transfer history for that period and handing it over to the bodies of the Sistema Nacional de Defesa do Consumidor on reasoned request. The disaggregated sales data covered by Article 15 is kept for two years without any personal identification.
Can I use facial recognition for event access in Brazil?
Only with a stronger legal basis. Article 5, II of the LGPD classifies biometric data linked to a natural person as sensitive personal data, and Article 11, I requires consent «de forma específica e destacada, para finalidades específicas» ("given specifically and prominently, for specific purposes"). A named QR code already identifying the holder achieves the same result using non-sensitive data.
Does a small promoter need a data protection officer?
There's no obligation to appoint one. Article 11 of Resolução CD/ANPD nº 2/2022 exempts small-scale data processing agents from the obligation in Article 41 of the LGPD, but its § 1 keeps the duty to provide a communication channel with the data subject. The exemption covers the role, not the duty to respond.
What's the deadline for reporting a data breach in Brazil?
Three working days. Article 6 of Resolução CD/ANPD nº 15/2024 counts that deadline from the moment the controller becomes aware the incident affected personal data, and Article 9 sets the same deadline for notifying data subjects. Small-scale agents get double that period under Article 14 of Resolução nº 2/2022.

About the author

Alejandro García Cestero

CEO & Founder

Founder and CEO of Futura Tickets. Leads product strategy, the business and the relationship with event organisers, focused on giving them full control of their box office and their data.

LinkedIn

Do you run events and sell tickets?

We'll show you Futura Tickets in a demo built around your next event: ticket sales, access control and attendee data that stays yours.

Request free demo