Skip to content
← Learn

Geography

LGPD vs Bacen: mandate and diligence

What the LGPD actually requires and what Bacen requires of licensed institutions. Pentest is not named in the statute; the annual intrusion test is, in CMN Resolution 5.274/2025.

There are two distinct conversations and the market conflates them. One is the LGPD: personal-data protection for whoever processes data in Brazil. The other is Bacen: a cybersecurity policy for institutions within the scope of CMN 4,893/2021. A pentest is not the same thing in both.

What the LGPD requires

Law 13.709/2018, compiled text, accessed 2026-09-17. Art. 6(VII): technical and administrative measures able to protect data from unauthorised access and from destruction, loss, alteration, communication or dissemination. Art. 6(X): demonstrate that those measures exist and work. Arts. 46–49: security by design, a duty that survives the end of processing, incident notice, systems structured to meet security requirements. Art. 50: good practice and governance. No article names pentesting.

What Bacen names

CMN Resolution 4.893/2021, official BCB viewer, accessed 2026-09-17. The original text required periodic tests and scans to detect vulnerabilities — not an annual independent pentest. CMN Resolution 5.274 of 18 December 2025 amends that rule. Art. 3 §8(IV): intrusion tests. Art. 22-A: minimum annual cadence; independence and impartiality by a contracted person or firm, without prejudice to in-house teams; documented results and remediation plans. BCB note: adaptation by 1 March 2026. The official name is teste de intrusão, not “pentest”.

Who each rule covers

LGPD: whoever processes personal data under art. 3 — almost any digital company operating in Brazil. Bacen 4.893 / 5.274: financial institutions and others licensed by the Central Bank. If you are outside that perimeter, the annual independent intrusion test is not your mandate. It can still be what a client, an auditor or a policy asks of you.

Evidence, not theatre

A letterheaded scanner does not demonstrate art. 6(X) or art. 22-A. A report with reproducible PoCs, negative controls and the signature of whoever supervised is evidence: of diligence under the LGPD, and of an intrusion test if the contract and scope cover what Bacen asks. The window is fixed in the contract. We do not publish turnarounds or third-party percentages. The map for Brazilian companies is in penetration testing in Brazil. The method is in what a penetration test is. If doors need testing, proposed scope.

Straight answers

Does the LGPD name pentesting?

No. Law 13.709/2018, compiled text at planalto.gov.br, accessed 2026-09-17: pentest, penetration testing and intrusion testing do not appear. Chapter VII (arts. 46–50) covers security measures, incidents and good practice — not a named offensive test.

What changed with CMN Resolution 5.274/2025?

It inserted art. 22-A into CMN Resolution 4.893/2021: intrusion tests in art. 3 §8(IV) must be at least annual; performed with independence and impartiality by a contracted natural person or specialised firm, without prejudice to in-house tests; and have results, vulnerabilities and remediation plans documented. Text in the BCB normative viewer, accessed 2026-09-17. Adaptation deadline stated by the BCB: 1 March 2026.

Did 4.893/2021 already require an annual independent pentest?

No. The original 4.893 text (26 Feb 2021) required, among minimum controls, periodic tests and scans to detect vulnerabilities. It did not set an annual cadence or third-party independence for intrusion tests. That arrives with 5.274/2025.

Time to test your doors?

Tell us what needs validating. We answer with proposed scope, not a brochure.

Talk to Rekon More in Learn