Compliance and LGPD
CPFHub.io operates in compliance with the Lei Geral de Proteção de Dados (LGPD, Brazil's data protection law, Law No. 13.709/2018) and with industry best practices.
This document is not legal advice
The information here is for general reference. To assess compliance in your specific context, consult a legal specialist.
Data returned by the API
The API returns data from public sources only. No sensitive data (income, address, criminal records, health data) is provided.
| Field | Type | Source |
|---|---|---|
name | Full name | Public source |
nameUpper | Name in uppercase | Derived from the name |
gender | Gender (M / F) | Public registry data |
birthDate | Date of birth | Public source |
day, month, year | Date components | Derived from the date |
The Real-Time Lookup (POST /cpf/realtime) returns its own fields, obtained from Receita Federal (Brazil's federal tax authority) at the time of the call:
| Field | Type | Source |
|---|---|---|
name | Full name | Receita Federal, on demand |
birthDate | Date of birth (provided by you and confirmed by Receita Federal) | Receita Federal, on demand |
deathYear | Year of death (integer or null). Always present. null when no death is on record or when the value received is invalid. Does not include day or month | Receita Federal, on demand |
situation | Registration status of the CPF | Receita Federal, on demand |
emissionDate, emissionTime | Date and time the proof was issued | Receita Federal, on demand |
controlCode | Control code of the proof | Receita Federal, on demand |
validationUrl | Verification link on the Receita Federal website (the QR code destination) | Receita Federal, on demand |
validationHtmlUrl | Proof of the lookup stored by CPFHub.io (HTML, with QR code) | Generated by CPFHub.io |
Legal basis for use
Use of the API is allowed under the following LGPD legal bases:
Art. 7, II - Compliance with a legal or regulatory obligation: Regulated companies (financial institutions, insurers, fintechs) can use the API to meet customer identification and anti-money-laundering obligations.
Art. 7, IX - Legitimate interest: Identity verification for fraud prevention, platform security and signup integrity, as long as it is proportionate and transparent to the data subject.
Art. 7, V - Performance of a contract: Validating the data of a contracting party in order to perform the contract to which the data subject is a party.
What CPFHub.io does NOT do
- Does not sell or share usage data with third parties
- Does not return sensitive, financial or location data
- Does not cross-reference data between different customers
Customer responsibilities (you)
When you use the API, you are the processor or controller of the data in the context of your application and you are responsible for:
- Having a valid legal basis for every lookup you make
- Informing data subjects about how their data is used (transparency)
- Keeping your API key secure and not sharing it
- Using the returned data only for the stated purpose
- Not looking up CPFs in bulk without a legitimate purpose
- Handling data subject requests (access, correction, deletion) about the data you store
Misuse is prohibited
Lookups for unauthorized monitoring, harassment, discrimination or any unlawful purpose violate the Terms of Use and the LGPD. Abuse results in immediate account suspension.
Compliance with the ECA Digital (Law 15.211/2025)
Law 15.211/2025 (ECA Digital, Brazil's digital child protection law) sets age verification obligations for digital platforms that offer content or services unsuitable for minors. When you use the CPFHub.io API to meet those obligations, you remain responsible for complying with the law, and you must:
- Implement the control mechanisms required by the ANPD (Brazil's national data protection authority).
- Obtain consent from the legal guardian when needed (LGPD, art. 14).
- Document the measures taken for accountability purposes.
CPFHub.io provides the verification infrastructure. The decision to grant or block access for the end user is entirely yours.
Data security in transit
- All communications use TLS 1.2 or higher
- Always use
https://. Requests over plain HTTP get a redirect (301) to HTTPS, and many clients turn a redirectedPOSTinto aGET, which breaks the Real-Time Lookup and the batch lookup - Send the API key in the
x-api-keyheader. Avoid putting it in the URL, where it can show up in proxy and server logs
Data retention
CPFHub.io retains only:
| Data | Period | Purpose |
|---|---|---|
| Access logs (IP, timestamp, HTTP status) | 12 months | Security, diagnostics and compliance auditing (LGPD + Marco Civil, Brazil's internet civil framework law) |
| Record of each lookup (CPF looked up, result, date and the account that made it) | As set out in the Privacy Policy | History in the dashboard, credit billing, auditing and fraud prevention |
| Proof of the real-time lookup (HTML page) | As set out in the Privacy Policy | Evidence of the lookup made at Receita Federal |
| Billing data | As required by tax law | Legal obligation |
| Account data (email, name) | Lifetime of the account | Providing the service |
The CPF looked up is recorded together with your account, including when it is not found. The proof of the real-time lookup is public to anyone who has the link (validationHtmlUrl): treat that link as personal data and do not expose it.
Data subject rights
If a CPF holder asks for information about the use of their data, CPFHub.io can provide:
- Confirmation that the CPF was looked up (without identifying the customer who made the lookup)
- The origin of the data used (public source)
- A contact channel to exercise the other rights
For data subject requests: dpo@cpfhub.io
DPO contact
For compliance questions, audits or requests related to the LGPD:
Email: dpo@cpfhub.io
Response time: within 15 days
Updated on October 3, 2026