← Back to blog
ByHM&C Team(Email Infrastructure & Security Specialists)

LGPD and business email: what your company needs to monitor

Brazil's data protection law (LGPD) imposes concrete obligations on how personal data is handled in company communications — including email.

Brazil's General Data Protection Law (LGPD, Law 13.709/2018) came into force in 2020 and the ANPD began enforcing fines in 2023. For companies using business email, LGPD raises practical questions: where does customer data sit? Who can access it? For how long?

What counts as personal data in email

Any information that identifies a natural person is personal data under LGPD. In business email: sender and recipient names and email addresses, CPF or national ID numbers in attachments, banking details in contracts, medical information shared in communications.

The three most common risks in business email

1. Sensitive data in plain text: proposals with customer CPF numbers, medical reports, contracts with banking details — all circulating without granular access control.

2. Indefinite retention: messages that should be discarded after a commercial relationship ends remain accessible for years.

3. No audit trail: without a record of who accessed what, it's impossible to respond to a data subject request or ANPD investigation.

How H2E Mail's LGPD module helps

H2E Mail's LGPD module automatically scans mailboxes for patterns of sensitive data: CPF, national ID, card numbers, and phone numbers. When the detected volume exceeds a configured threshold, the system issues an alert.

Questions about setting up the LGPD module on your plan? Reach the H2E Mail team via WhatsApp: +55 12 99188-7205.

LGPD and business email: what to monitor · H2E Mail