CPFHub.io
Start for free

Compliance and LGPD

CPFHub.io operates in compliance with the Lei Geral de Proteção de Dados (LGPD, Brazil's data protection law, Law No. 13.709/2018) and with industry best practices.

ℹ

This document is not legal advice

The information here is for general reference. To assess compliance in your specific context, consult a legal specialist.

Data returned by the API

The API returns data from public sources only. No sensitive data (income, address, criminal records, health data) is provided.

FieldTypeSource
nameFull namePublic source
nameUpperName in uppercaseDerived from the name
genderGender (M / F)Public registry data
birthDateDate of birthPublic source
day, month, yearDate componentsDerived from the date

The Real-Time Lookup (POST /cpf/realtime) returns its own fields, obtained from Receita Federal (Brazil's federal tax authority) at the time of the call:

FieldTypeSource
nameFull nameReceita Federal, on demand
birthDateDate of birth (provided by you and confirmed by Receita Federal)Receita Federal, on demand
deathYearYear of death (integer or null). Always present. null when no death is on record or when the value received is invalid. Does not include day or monthReceita Federal, on demand
situationRegistration status of the CPFReceita Federal, on demand
emissionDate, emissionTimeDate and time the proof was issuedReceita Federal, on demand
controlCodeControl code of the proofReceita Federal, on demand
validationUrlVerification link on the Receita Federal website (the QR code destination)Receita Federal, on demand
validationHtmlUrlProof of the lookup stored by CPFHub.io (HTML, with QR code)Generated by CPFHub.io

Use of the API is allowed under the following LGPD legal bases:

Art. 7, II - Compliance with a legal or regulatory obligation: Regulated companies (financial institutions, insurers, fintechs) can use the API to meet customer identification and anti-money-laundering obligations.

Art. 7, IX - Legitimate interest: Identity verification for fraud prevention, platform security and signup integrity, as long as it is proportionate and transparent to the data subject.

Art. 7, V - Performance of a contract: Validating the data of a contracting party in order to perform the contract to which the data subject is a party.

What CPFHub.io does NOT do

  • Does not sell or share usage data with third parties
  • Does not return sensitive, financial or location data
  • Does not cross-reference data between different customers

Customer responsibilities (you)

When you use the API, you are the processor or controller of the data in the context of your application and you are responsible for:

  • Having a valid legal basis for every lookup you make
  • Informing data subjects about how their data is used (transparency)
  • Keeping your API key secure and not sharing it
  • Using the returned data only for the stated purpose
  • Not looking up CPFs in bulk without a legitimate purpose
  • Handling data subject requests (access, correction, deletion) about the data you store
⚠

Misuse is prohibited

Lookups for unauthorized monitoring, harassment, discrimination or any unlawful purpose violate the Terms of Use and the LGPD. Abuse results in immediate account suspension.

Compliance with the ECA Digital (Law 15.211/2025)

Law 15.211/2025 (ECA Digital, Brazil's digital child protection law) sets age verification obligations for digital platforms that offer content or services unsuitable for minors. When you use the CPFHub.io API to meet those obligations, you remain responsible for complying with the law, and you must:

  • Implement the control mechanisms required by the ANPD (Brazil's national data protection authority).
  • Obtain consent from the legal guardian when needed (LGPD, art. 14).
  • Document the measures taken for accountability purposes.

CPFHub.io provides the verification infrastructure. The decision to grant or block access for the end user is entirely yours.

Data security in transit

  • All communications use TLS 1.2 or higher
  • Always use https://. Requests over plain HTTP get a redirect (301) to HTTPS, and many clients turn a redirected POST into a GET, which breaks the Real-Time Lookup and the batch lookup
  • Send the API key in the x-api-key header. Avoid putting it in the URL, where it can show up in proxy and server logs

Data retention

CPFHub.io retains only:

DataPeriodPurpose
Access logs (IP, timestamp, HTTP status)12 monthsSecurity, diagnostics and compliance auditing (LGPD + Marco Civil, Brazil's internet civil framework law)
Record of each lookup (CPF looked up, result, date and the account that made it)As set out in the Privacy PolicyHistory in the dashboard, credit billing, auditing and fraud prevention
Proof of the real-time lookup (HTML page)As set out in the Privacy PolicyEvidence of the lookup made at Receita Federal
Billing dataAs required by tax lawLegal obligation
Account data (email, name)Lifetime of the accountProviding the service

The CPF looked up is recorded together with your account, including when it is not found. The proof of the real-time lookup is public to anyone who has the link (validationHtmlUrl): treat that link as personal data and do not expose it.

Data subject rights

If a CPF holder asks for information about the use of their data, CPFHub.io can provide:

  • Confirmation that the CPF was looked up (without identifying the customer who made the lookup)
  • The origin of the data used (public source)
  • A contact channel to exercise the other rights

For data subject requests: dpo@cpfhub.io

DPO contact

For compliance questions, audits or requests related to the LGPD:

Email: dpo@cpfhub.io
Response time: within 15 days


Updated on October 3, 2026