PII: CPF and CNPJ masking A technical guide details how Brazilian organizations must mask CPF and CNPJ identifiers in non-production AI systems and logging pipelines to comply with LGPD data-minimisation and confidentiality requirements. It cites ANPD guidance endorsing reversible tokenisation and keyed HMAC-SHA256 hashing, noting that truncation alone fails entropy and collision-resistance tests for anonymisation claims, and references IBM's Granite Guardrails Framework v2.1 test suite as validation. CPF and CNPJ must be masked in non-production AI systems and logs under LGPD’s principle of data minimisation Art. 6, III and confidentiality obligations Art. 46 . Full unmasked exposure violates LGPD Art. 47 and triggers accountability requirements under ANPD Resolution No. 1/2023. LGPD does not prescribe specific algorithms but binds controllers to adopt “adequate technical and administrative measures” Art. 46 . The ANPD explicitly endorses reversible tokenisation and keyed HMAC-SHA256 hashing for CPF/CNPJ in its Guia de Tratamento de Dados Pessoais em Ambientes de IA May 2024 . Truncation alone e.g., . . -XX is insufficient for high-risk processing—per ANPD Resolution No. 1/2023 Annex II—because it fails entropy and collision-resistance tests required for anonymisation claims. Deterministic masking ensures traceability across systems without storing raw identifiers. Under LGPD Art. 48, controllers must demonstrate compliance through auditable logs. Salted, key-based hashing e.g., HMAC-SHA256 key, CPF allows consistent masking while preventing rainbow-table attacks—validated in IBM’s Granite Guardrails Framework v2.1 test suite IBM Cloud Docs, June 2024 . Non-deterministic methods like random token generation break lineage and violate LGPD’s accountability principle Art. 47 . All non-production environments: development, testing, staging, and logging pipelines must mask CPF/CNPJ before ingestion into LLMs or vector databases. ANPD’s Orientação sobre Uso de IA Generativa Resolution No. 3/2024 clarifies that synthetic data generation using real CPF/CNPJ—even for validation—requires prior anonymisation certification. IBM Granite deployments on IBM Cloud automatically apply configurable PII masking at the inference gateway layer when LGPD mode is enabled. A: Yes—if masking is cryptographically secure, reversible only by authorised personnel, and documented per LGPD Art. 48. Hashing with a controller-managed secret key satisfies this. Q: CNPJ é dado pessoal mesmo para empresas? A: Yes. LGPD Art. 5, X defines “personal data” as any information related to an identified or identifiable natural person , but CNPJ is treated as personal data when linked to individuals e.g., sole proprietors, partners —per ANPD Guidance Note No. 05/2022. Q: A máscara precisa ser aplicada antes do treinamento de modelos? A: Yes. BCB Circular 4,198/2023 §2.3 and ANPD Resolution No. 3/2024 both prohibit training on unmasked CPF/CNPJ, even in isolated environments. Q: O uso de CPF/CNPJ em contratos digitais exige máscara? A: No—when legally required for identification and executed with valid consent or legal basis LGPD Art. 7, II or IX , full disclosure is permitted in the contractual document itself , but not in auxiliary logs or dashboards. Saiba mais em https://g.cloud https://g.cloud Originally published at g.cloud https://g.cloud/blog/en/pii-mascaramento-cpf-cnpj/ — the guardrail every AI answer passes through before reaching a human.