LGPD Article 48 notification trigger — 3-business-day deadline for incidents posing relevant risk or damage
Brazil's data breach notification obligation is set out in Article 48 of Lei Geral de Proteção de Dados (LGPD, Law 13,709 of August 14, 2018). The controller (controlador) must notify both the Autoridade Nacional de Proteção de Dados (ANPD) and the affected data subjects of any security incident that may result in relevant risk or damage to the data subjects. Unlike the GDPR's bright-line 72-hour rule or the CCPA's event-driven triggers, LGPD imposes a risk-based materiality threshold: only incidents likely to cause significant harm trigger the dual notification duty.
Article 48 itself left the deadline open ("reasonable time, as defined by the national authority"), but ANPD closed that gap on April 24, 2024 with Resolution CD/ANPD No. 15/2024, approving the Regulamento de Comunicação de Incidente de Segurança (Security Incident Communication Regulation). Under Article 6 of the Regulation, the controller must notify ANPD within three business days from the date the controller became aware that the incident affected personal data. The same three-business-day clock applies to notification of affected data subjects under Article 9 of the Regulation.
"Relevant risk or damage" — the six-factor test. Resolution 15/2024 defines a notifiable security incident as one that (a) significantly affects the fundamental rights and interests of data subjects and (b) involves at least one of the following six data categories:
- Sensitive data (dados sensíveis) under LGPD Article 5(II) — racial or ethnic origin, religious belief, political opinion, trade-union or religious/philosophical/political organization membership, health or sex life, genetic or biometric data for unique identification.
- Data of children, adolescents, or elderly persons (dados de crianças, adolescentes ou idosos).
- Financial data (dados financeiros) — bank accounts, credit/debit card numbers, transaction records.
- Authentication data in systems (dados de autenticação em sistemas) — passwords, security tokens, biometric credentials.
- Data protected by legal, judicial, or professional secrecy (dados protegidos por sigilo legal, judicial ou profissional).
- Large-scale data (dados em larga escala) — the Regulation does not specify a numeric threshold; ANPD guidance recommends controllers assess volume, geographic scope, and the number of data subjects in the ordinary course of the affected processing.
The controller must evaluate both prongs cumulatively. If the breach involves one or more of the six data types but is unlikely to significantly affect fundamental rights (for example, encrypted payment-card data with keys held separately and no evidence of key compromise), notification may not be required. ANPD's published guidance expressly recommends controllers adopt a cautious posture and notify even when in doubt, because a demonstrated underestimation of risk can itself constitute a LGPD violation.
The three-business-day clock. The deadline runs from the controller's knowledge that the incident affected personal data, not from the date of the incident itself. If full information is unavailable within three business days, the controller must submit a preliminary notification with a reasoned justification and supplement it within twenty business days of the preliminary filing (Resolution 15/2024, Article 6, § 3). The same staged-notification procedure applies to data-subject communication.
Small processing agents as defined by Resolution CD/ANPD No. 2/2022 (startups, micro/small enterprises, and legal entities with gross revenue in Brazil below the statutory threshold) receive double the deadline: six business days for the initial notification and forty business days for the supplement. High-risk processing activities lose the benefit of the extended deadline even for otherwise qualifying small agents.
Form and content. Notification to ANPD must be made electronically through the agency's SEI!ANPD platform, submitted by the controller's Data Protection Officer (encarregado) or a legal representative with power of attorney. The notification must include (Article 6, § 2 of the Regulation):
- Description of the nature and categories of affected personal data, specifying whether sensitive data is involved;
- Number of affected data subjects, broken out by children, adolescents, elderly, when applicable;
- Technical and administrative security measures in place before and after the incident;
- Risk assessment and identification of possible impacts on data subjects (financial fraud, identity theft, reputational harm, inability to exercise rights);
- Date of the incident (if identifiable) and date the controller became aware;
- Reasons for any delay beyond the three-business-day deadline;
- Measures adopted or planned to reverse or mitigate harm;
- Contact information for the DPO or other point of contact.
Notification to data subjects must use simple, accessible language and should be individualized (email, SMS, letter, phone call) where feasible. If individual notification is impracticable, the controller must use broadcast channels — website banners, mobile-app notifications, social media, customer-service announcements — for at least three months and must file a declaration with ANPD within three business days of the authority notification confirming the broadcast and the channels used.
ANPD can compel broader disclosure. After receiving the controller's notification, ANPD may determine that the incident warrants ampla divulgação (broad disclosure) in mass media — print, radio, internet — at the controller's expense (LGPD Article 48, § 2). The authority may also order additional mitigation measures and can impose daily fines to secure compliance during the incident-response process. A failure to notify a clearly notifiable breach subjects the controller to administrative sanctions under LGPD Article 52, up to 2% of the legal entity's revenue in Brazil (capped at R$50 million per infraction).
Operator (processor) notification to controller. The duty under Article 48 runs to the controller, but Resolution 15/2024 clarifies that when an operator (operador) detects a breach, it must inform the controller without unjustified delay. The controller then assesses notifiability and makes the dual notification. ANPD has stated it will accept exceptional submissions from operators when circumstances warrant, but the legal obligation remains the controller's.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD), Art. 48 Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation) Source: ANPD — Comunicação de incidentes de segurança (guidance page)
Enforcement and penalties — ANPD sanctioning powers, Article 52 fine calculation, and breach-notification enforcement precedents
Controllers that fail to comply with Brazil's breach-notification obligations under LGPD Article 48 face administrative sanctions imposed by the Autoridade Nacional de Proteção de Dados (ANPD), the national data protection authority established under Articles 55-A through 55-L of the LGPD. ANPD's sanctioning authority became operational on August 1, 2021, and the agency published its Regulation on Dosimetry and Application of Administrative Sanctions (Resolution CD/ANPD No. 4) on February 27, 2023, completing the enforcement framework required under Article 53 of the LGPD.
Article 52 sanction menu — twelve graduated tiers. LGPD Article 52 authorizes ANPD to impose administrative sanctions "after an administrative proceeding that ensures the opportunity for full defense." The statute enumerates twelve sanctions, arranged in rough escalation from admonitory through pecuniary to operational suspension:
I. Advertência (warning) with indication of the deadline for corrective measures; II. Multa simples (simple fine), up to 2% of the private legal entity's gross revenue in Brazil in its last fiscal year, excluding taxes, capped at R$50,000,000 (fifty million reais) per infraction; III. Multa diária (daily fine), observing the total ceiling in item II; IV. Publicização da infração (publication of the infraction) after due investigation and confirmation; V. Bloqueio dos dados pessoais (blocking of the personal data) subject to the infraction until regularization; VI. Eliminação dos dados pessoais (deletion of the personal data) subject to the infraction; VII. Suspensão parcial do funcionamento do banco de dados (partial suspension of the database) for a maximum of six months, renewable for an equal period, until the controller regularizes the processing activity; VIII. Suspensão do exercício da atividade de tratamento (suspension of the data processing activity) for a maximum of six months, renewable for an equal period; IX. Proibição parcial do exercício de atividades relacionadas a tratamento de dados (partial prohibition of activities related to data processing); X–XII. Expanded versions of suspension and full prohibition, applied only after at least one prior sanction from items II–VI for the same specific case (Article 52, § 6).
Sanctions are applied "gradually, in isolation or cumulatively, according to the peculiarities of the specific case" (Article 52, § 1), and ANPD may compel compliance during the incident-response process through daily fines accrued until the breach is remedied.
The eleven statutory dosimetry criteria — Article 52, § 1. ANPD must assess and weigh eleven factors when selecting the type and severity of sanction:
I. The severity and nature of the infractions and the personal rights affected; II. The good faith of the infringer; III. The advantage sought or obtained by the infringer; IV. The economic condition of the infringer; V. Recidivism (repeat violations); VI. The degree of damage; VII. The cooperation of the infringer; VIII. Demonstrated adoption of internal mechanisms and procedures capable of minimizing harm, focused on secure and adequate data processing (aligned with Article 48, § 2(II)); IX. Adoption of good-practice and governance policies; X. Prompt adoption of corrective measures; and XI. Proportionality between the gravity of the fault and the intensity of the sanction.
Resolution No. 4/2023 translates these statutory criteria into a structured dosimetry methodology. For legal entities with revenue in Brazil, the base fine is calculated by multiplying a base rate (ranging from 0.1% to 2.0% depending on infraction severity) by the entity's gross revenue in Brazil (net of taxes), then adjusted upward or downward by aggravating and mitigating circumstances (including cooperation, good faith, degree of damage, recidivism, and documented governance policies). For individuals and entities without revenue, ANPD applies fixed reais ranges scaled by infraction classification and degree of damage. The methodology's Appendix I classifies infractions as gravíssima (most serious), grave (serious), média (medium), or leve (light); breach-notification failures under Article 48 are typically classified as grave or gravíssima depending on the data categories involved and the harm to data subjects.
ANPD enforcement procedure — responsive regulation in practice. ANPD's enforcement model, codified in Resolution CD/ANPD No. 1 (October 28, 2021) and amended by Resolution No. 4/2023, follows responsive regulation principles. The Coordenação-Geral de Fiscalização (General Coordination for Enforcement, CGF) conducts a preparatory investigation upon receiving a complaint, a data subject's petition, or a controller's security-incident notification. If the CGF identifies evidence of an Article 48 violation, it may first issue a preventive determination ordering the controller to communicate the breach to data subjects and to adopt specific mitigation measures within a defined deadline. Failure to comply escalates the matter to a formal processo administrativo sancionador (administrative sanctioning proceeding), in which the CGF issues an auto de infração (infraction notice). The controller has the right to a full defense and administrative appeal; the final decision may impose one or more sanctions from the Article 52 menu.
ANPD has articulated that breach-notification failures carry reputational and legal weight beyond the immediate sanction: a demonstrated underestimation of risk — or a failure to communicate when the six-factor test under Resolution 15/2024 was clearly satisfied — is itself an aggravating circumstance under the dosimetry regulation, because it shows disregard for data subjects' fundamental rights and undermines the statutory purpose of notification (enabling subjects to protect themselves post-incident).
Documented enforcement precedents for Article 48 breach-notification failures. As of May 2026, ANPD has sanctioned at least two public-sector controllers for failing to comply with Article 48's notification duty:
1. Instituto Nacional de Seguro Social (INSS) — February 2024. INSS suffered a security incident in 2022 affecting its Sistema Corporativo de Benefícios (SISBEN), which exposed CPF numbers, bank account details, and birthdates of beneficiaries — data susceptible to fraud and identity theft. ANPD determined that the incident met the "relevant risk or damage" threshold under Article 48 and ordered INSS to notify the affected data subjects. INSS argued technical infeasibility of individualizing the affected persons and refused to perform broadcast notification. ANPD rejected that defense, finding that Article 48 and Resolution 15/2024 expressly authorize ampla divulgação (broad disclosure) when individual notification is impracticable. ANPD sanctioned INSS with publicização da infração (Article 52(IV)): INSS was ordered to publish the infraction notice on its website and in the Meu INSS mobile application for sixty consecutive days. ANPD also found INSS in violation of Article 32 of Resolution No. 1/2021 for failing to comply with a prior ANPD determination to remediate the breach.
2. Secretaria de Estado de Educação do Distrito Federal (SEEDF) — February 2024. SEEDF operated an online enrollment system for an early-education program that exposed personal data of approximately 3,030 applicants through a URL-manipulation vulnerability. ANPD's investigation concluded that SEEDF failed to: (a) maintain records of processing operations (Article 37); (b) prepare a Data Protection Impact Assessment (DPIA) when requested by ANPD (Article 38); (c) notify affected data subjects of the security incident (Article 48); and (d) deploy systems meeting LGPD security and good-practice requirements (Article 5 of Resolution No. 1/2021). The Coordenação-Geral de Fiscalização applied a sanction of advertência (warning) for the Article 48 failure and an additional advertência for obstruction of ANPD's enforcement activity under Article 5(I) of the Enforcement Regulation. On administrative appeal (Deliberative Circuit CD-16/2024), ANPD's Board of Directors upheld the Article 48 advertência and consolidated the other violations into a single advertência for enforcement obstruction, emphasizing that notification to data subjects is "a fundamental measure so they can protect themselves after a security incident" and that failure to communicate deprives subjects of the ability to take protective actions such as changing passwords and monitoring for suspicious contacts.
Both decisions underscore ANPD's position that breach notification is not a pro forma compliance box but a fundamental safeguard for data subjects' ability to mitigate post-incident harm. Controllers that delay, refuse, or inadequately execute the notification duty — especially when the statutory triggers are plainly met — face escalating sanctions, and ANPD will exercise its authority under Article 48, § 2 to compel ampla divulgação in mass media at the controller's expense when individual communication proves infeasible.
No private right of action for breach-notification failures; administrative-only enforcement. LGPD Article 52's sanctions are applied exclusively by ANPD. The statute does not create a standalone private cause of action for breach-notification failures. Data subjects harmed by a controller's failure to notify may, however, pursue civil damages for material and moral harm under Brazil's Civil Code (Lei nº 10.406/2002) and Consumer Protection Code (Lei nº 8.078/1990, the Código de Defesa do Consumidor, CDC), both of which recognize breach of a statutory duty (such as Article 48) as evidence of fault and causation in a tort claim. LGPD Article 52, § 2 expressly provides that ANPD's administrative sanctions "do not replace the application of administrative, civil, or criminal sanctions provided in Law 8.078/1990 [CDC] and in specific legislation." Controllers found liable in ANPD proceedings face both the administrative fine and potential exposure to individual and collective civil claims by affected data subjects and consumer-protection organs. The Ministério Público (Public Prosecutor's Office) and consumer-defense agencies (such as PROCONs and SENACON) retain parallel enforcement authority under their own statutes, and ANPD has stated publicly that its findings may be shared with those bodies when conduct implicates consumer rights or criminal provisions.
Criminal exposure remains theoretical. Brazil's Penal Code does not currently contain a specific offense for breach-notification failure. Controllers that willfully conceal a breach involving sensitive data or authentication credentials may face investigation under general fraud (estelionato, Article 171 of the Penal Code) or computer-crime provisions (Lei nº 12.737/2012, the "Lei Carolina Dieckmann"), particularly if the failure to disclose enables subsequent fraud against data subjects. ANPD has stated that when its enforcement investigations uncover evidence of criminal conduct, it will refer the matter to the Ministério Público or the Polícia Federal. As of May 2026, no criminal prosecutions have been publicly reported for standalone breach-notification failures under LGPD Article 48.
Fine proceeds — Fundo de Defesa de Direitos Difusos. All monetary fines collected by ANPD under Article 52 are directed to the Fundo de Defesa de Direitos Difusos (Diffuse Rights Defense Fund), established under Articles 13 of Law 7.347/1985 and Law 9.008/1995. The fund finances initiatives to repair harm to the environment, consumers, cultural heritage, and other collective rights. LGPD Article 52, § 5 (inserted by Law 13.853/2019) codifies this allocation, ensuring that breach-related fines fund broader societal remediation rather than general-budget revenue.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD), Art. 52 Source: Resolution CD/ANPD No. 4, of February 24, 2023 (Regulation on Dosimetry and Application of Administrative Sanctions) Source: ANPD — Sanções Administrativas: o que muda após 1º de agosto de 2021? Source: ANPD — ANPD sanciona INSS e Secretaria de Educação do DF por violações à LGPD (February 1, 2024) Source: ANPD Deliberative Circuit CD-16/2024 (SEEDF decision, August 2024)
Article 10 recordkeeping obligation — five-year retention for all security incidents, including non-notified events
Controllers must maintain internal records of all security incidents, whether or not the incident triggered the notification duty under Article 48 of the LGPD and Resolution CD/ANPD No. 15/2024. This universal recordkeeping requirement applies even to incidents that fall below the "relevant risk or damage" threshold and therefore were never communicated to ANPD or data subjects. Article 10 of Resolution 15/2024 imposes a five-year minimum retention period, measured from the date the controller creates the incident record, not from the date of the incident itself.
The recordkeeping obligation serves three compliance functions: (1) demonstrating to ANPD during inspections that the controller maintains a systematic incident-response process and has assessed notifiability rigorously; (2) preserving evidence of the controller's good faith and cooperation when ANPD retrospectively investigates whether a breach should have been notified; and (3) satisfying the controller's broader accountability obligations under Article 37 of the LGPD (records of processing operations) and Article 50 (governance and good-practice programs). ANPD has stated publicly that a demonstrated pattern of underreporting — evidenced by internal records showing incidents the controller dismissed as non-notifiable when the six-factor test under Resolution 15/2024 was clearly satisfied — constitutes an aggravating circumstance under the dosimetry regulation and can itself warrant sanctions.
Mandatory content — Article 10, § 1 of Resolution 15/2024. The incident record must contain at minimum:
I. Date and time the incident occurred, if identifiable, and the date the controller became aware that personal data were affected; II. Description of the nature of the security incident — unauthorized access, accidental disclosure, ransomware encryption, insider exfiltration, third-party vendor breach, or other compromise; III. Categories and volume of affected personal data, specifying whether the incident involved any of the six data types enumerated in Article 5(II) of the Regulation (sensitive data under LGPD Article 5(II), children/adolescent/elderly data, financial data, authentication credentials, legally protected data, or large-scale data); IV. Estimated number of affected data subjects, broken out by vulnerable populations (children, adolescents, elderly) when applicable; V. Technical and administrative security measures in place before and after the incident; VI. Risk assessment and identified potential impacts on data subjects — identity theft, financial fraud, reputational harm, inability to exercise rights, or other consequences; VII. Mitigation and remediation measures adopted or planned; VIII. Reasons for non-notification, when the controller determined that the incident did not meet the "relevant risk or damage" threshold and therefore was not communicated to ANPD or data subjects.
Item VIII is the accountability lever. When the controller decides an incident is non-notifiable, the internal record must document the analysis — which prongs of the six-factor test were not met, why the incident was unlikely to significantly affect fundamental rights, whether encryption or other safeguards mitigated exposure, and any contemporaneous guidance from the Data Protection Officer (encarregado) or legal counsel. ANPD's Enforcement Regulation (Resolution No. 1/2021) and the 2024 incident-communication guidance expressly recommend controllers adopt a cautious posture and notify even when in doubt. An internal record that shows the controller dismissed a plainly notifiable breach — for example, exposed CPF numbers and bank-account details labeled "low risk" because the dataset was "only" 5,000 records — exposes the controller to both the Article 48 notification-failure sanction and an elevated base fine under the dosimetry methodology.
Five-year retention, minimum. The record must be preserved for at least five years from the date it was created (Article 10, caput). If sector-specific regulation, contractual obligations, or ongoing litigation require longer retention, those obligations control. For example, financial institutions subject to Central Bank of Brazil regulations or healthcare providers subject to medical-record retention rules must retain incident records for the longer of the two periods.
Exception for public entities subject to permanent-record rules. Article 10, § 2 exempts entities listed in LGPD Article 23 — public bodies, entities, and authorities processing data in the performance of their legal competencies or statutory attributions — from the five-year floor when national archival regulations classify the incident record as permanent. The Conselho Nacional de Arquivos (CONARQ) publishes retention schedules (tabelas de temporalidade) for federal, state, and municipal government agencies. If the incident record relates to a processing operation tied to a public function for which CONARQ mandates permanent archiving, the entity must follow the archival schedule rather than the five-year minimum. In practice, most security-incident records for routine administrative processing are classified as temporary rather than permanent, so the five-year rule applies in the majority of public-sector cases.
Format and accessibility. Resolution 15/2024 does not prescribe a format — controllers may maintain incident records in a digital incident-response platform (Jira Service Management, ServiceNow, or a purpose-built LGPD-compliance tool), in a secured SharePoint folder, or in a paper logbook. ANPD's enforcement guidance recommends controllers adopt a centralized incident-response log indexed by incident ID, date, and data categories, with narrative summaries and supporting forensic reports attached. The record must be accessible on reasonable notice when ANPD requests it during a processo de fiscalização (enforcement inspection) or a procedimento de apuração de incidente de segurança (PAI, incident-investigation proceeding).
When ANPD receives a complaint from a data subject, a media report of a possible breach, or intelligence from another supervisory authority, it may initiate a PAI under Articles 16–17 of Resolution 15/2024. The Coordenação de Apuração de Incidentes (CAIS/CGIS) will request the controller's incident log and supporting documentation. Controllers that fail to produce the records, produce incomplete records, or produce records that contradict the controller's contemporaneous public statements face obstruction sanctions under Article 5 of the Enforcement Regulation, in addition to any substantive Article 48 violation.
Small processing agents receive no exemption from recordkeeping. Controllers qualifying as agentes de pequeno porte under Resolution CD/ANPD No. 2/2022 (startups, micro/small enterprises, legal entities with gross revenue in Brazil below the statutory threshold) receive double the notification deadline (six business days instead of three) but must still maintain the same five-year incident records. The only recordkeeping relief for small agents is the general exemption from maintaining a full Registro de Operações de Tratamento (ROPA) under Article 37 of the LGPD unless they perform high-risk or large-scale processing. Security-incident records, however, are mandatory for all controllers regardless of size, because they directly implement the Article 48 notification duty and Article 50 governance obligation.
Cross-reference to Article 37 ROPA obligation. Controllers subject to the full Article 37 duty (those not qualifying as small agents, or qualifying small agents performing high-risk processing) must maintain a Registro de Operações de Tratamento documenting each processing activity, the categories of data, retention periods, and security measures. When a security incident occurs, the controller should cross-reference the ROPA entry for the affected processing activity in the incident record. If the incident exposes a gap between the security measures documented in the ROPA and the measures actually deployed (for example, the ROPA states "encryption at rest" but the compromised database was unencrypted), ANPD will treat that discrepancy as evidence of breach of Article 46 (security measures) and Article 50 (governance), compounding the Article 48 notification failure.
ANPD may compel production at any time. Article 8 of Resolution 15/2024 authorizes ANPD to request additional information about a security incident at any time, including the internal incident record, forensic-investigation reports, and correspondence with affected data subjects. Failure to respond within the deadline ANPD sets (typically fifteen business days under the general enforcement regulation, doubled to thirty for small agents) subjects the controller to daily fines under Article 52(III) of the LGPD. ANPD's 2024 enforcement precedents (INSS and SEEDF) demonstrate the authority's willingness to sanction public-sector controllers that obstruct incident investigations or fail to maintain adequate records.
Operator (processor) recordkeeping. Resolution 15/2024 places the notification duty on the controller (Article 48 of the LGPD), but operators that detect a breach must inform the controller without unjustified delay. Best practice, endorsed by ANPD in published guidance, is for operators to maintain their own parallel incident log documenting the date of detection, the date and content of the notification to the controller, and any mitigation measures the operator took at the controller's direction. When the controller and operator disagree about whether an incident was timely escalated, the operator's contemporaneous record is critical evidence in an ANPD enforcement proceeding.
Records as evidence in civil litigation. Although Article 10 is an administrative recordkeeping obligation owed to ANPD, the incident record is discoverable in civil damages claims brought by affected data subjects under the Civil Code and Consumer Protection Code. A well-documented incident record showing prompt detection, rigorous risk assessment, and good-faith mitigation can support a controller's defense that it acted reasonably and minimized harm. Conversely, an incomplete record or a record showing the controller delayed notification or underestimated risk strengthens the plaintiff's case for fault and causation. Controllers must balance the transparency and accountability benefits of detailed incident documentation against the litigation-exposure risk of documenting internal debates and preliminary risk assessments that might later be characterized as reckless.
Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation), Art. 10 Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD), Arts. 37, 48, 50
Data-subject notification content — Article 9 required disclosures and plain-language rule
Controllers must notify affected data subjects directly whenever a security incident meets the Article 48 / Resolution 15/2024 notifiability threshold, on the same three-business-day clock that applies to ANPD notification. The content of the data-subject communication is governed by Article 9 of Resolution CD/ANPD No. 15/2024 and differs materially from what the controller reports to the authority. Whereas ANPD notification emphasizes forensic detail and regulatory compliance evidence, the data-subject communication must be written in linguagem clara e acessível (clear and accessible language) and must enable the recipient to take immediate protective action.
Article 9 mandatory content — five core disclosures. The data-subject notification must contain at minimum:
I. Description of the nature of the affected personal data — the categories of data compromised (CPF, name, email, financial data, authentication credentials, health information, etc.), presented in terms a lay reader can understand. Controllers should avoid generic labels ("personal data") and instead specify the exact data elements exposed. For example: "Your CPF number, full name, email address, and bank account number were accessed by an unauthorized third party."
II. Information about risks related to the incident and possible impacts on the data subject — a concrete assessment of what the breach means for the individual. This must go beyond boilerplate warnings and identify the specific harms the exposed data could enable. If the incident involved CPF numbers and bank-account details, the notification should state that the subject is at risk of identity theft, fraudulent bank transfers, unauthorized credit applications, and phishing attempts. If the incident involved authentication credentials (passwords, security tokens), the notification should warn that the subject's account may be accessed by third parties and that any linked accounts using the same password are also at risk. ANPD enforcement guidance emphasizes that this element is the core accountability moment: the controller must demonstrate it has rigorously assessed impact rather than copied template language.
III. Technical and security measures used to protect the data, adopted before and after the incident — transparency about what safeguards were (or were not) in place. If the compromised data were encrypted at rest but the encryption key was also stolen, that fact must be disclosed. If the data were stored in plaintext, the notification should candidly state that no encryption was applied. Post-incident measures—password resets, temporary account suspensions, enhanced monitoring, forensic investigation—must also be described. Controllers may withhold details that would jeopardize commercial or industrial secrecy under Article 9, § 2, but the default is full disclosure.
IV. Measures that were or will be adopted to reverse or mitigate the effects of the damage — concrete steps the controller is taking to reduce harm and what the controller is asking or doing on behalf of the data subject. Common mitigation measures include: offering free credit-monitoring services for a defined period (typically 12–24 months for financial-data breaches); forcing password resets and invalidating active sessions; notifying financial institutions to flag the subject's CPF for heightened fraud scrutiny; providing a dedicated call center or email address for affected individuals to ask questions. If the controller cannot reverse the harm (for example, exposed sensitive health data cannot be "unexposed"), the notification should state that plainly and focus on what monitoring or support the controller will provide.
V. Contact information for the encarregado (Data Protection Officer) or other point of contact — a direct, functioning communication channel where the data subject can ask questions, request further information, or report suspicious activity that may be linked to the breach. The contact must be specific (a named person or dedicated email address / phone number), not a generic corporate switchboard. Article 9, § 5 requires the controller to respond to data-subject inquiries arising from the breach notification within a reasonable timeframe, and ANPD has indicated it will treat prolonged silence as evidence of failure to comply with the transparency principle under LGPD Article 6(VI).
**Plain-language obligation — Article 9, caput. Unlike the ANPD notification (which is drafted by the DPO or legal counsel for a regulatory audience), the data-subject communication must be written in linguagem clara e acessível**. ANPD's published guidance states that "clear language" means vocabulary and sentence structure comprehensible to individuals with basic literacy, avoiding legal jargon, technical acronyms, and passive-voice hedging. "Accessible" includes both linguistic accessibility (Portuguese as the primary language, with translations when the controller knows it serves a significant non-Portuguese-speaking population) and format accessibility (readable font sizes, high color contrast for vision-impaired readers, plain-text email or SMS rather than PDF attachments requiring specialized software). Controllers serving vulnerable populations—children, adolescents, elderly persons—should tailor the notification's reading level and format accordingly.
Individualized notification preferred; broadcast permitted when infeasible. Article 9, § 1 directs controllers to communicate the breach preferencialmente de forma direta e individualizada (preferably in a direct and individualized manner). Direct channels include:
- Email to the subject's registered email address;
- SMS or WhatsApp message to the subject's registered mobile number;
- Physical letter sent by registered mail to the subject's address on file;
- Phone call to the subject's registered number, with a follow-up written confirmation;
- In-app notification within a mobile application the subject has installed and authenticated.
Controllers must choose the communication channel most likely to reach the affected individual promptly. If multiple contact methods are available, best practice is to use at least two (email + SMS, or email + in-app push notification) to maximize the probability the subject sees the alert.
Broadcast notification — when individual communication is inviável. If individual notification is inviável (infeasible) because the controller lacks current contact information for affected subjects, the scale of the breach makes individualized outreach operationally impossible, or the compromised database did not include contact details, the controller must use broadcast channels (Article 9, § 3):
- The controller's website (homepage banner or dedicated breach-notification landing page);
- Mobile application notifications visible to all users upon login;
- Social media accounts operated by the controller (Facebook, Instagram, LinkedIn, Twitter/X);
- Customer service channels (call-center greeting, chatbot disclosure, in-store signage for retail locations).
The broadcast communication must remain visible and accessible for at least three months (Article 9, § 3). Within three business days of initiating the broadcast, the controller must file a declaração (declaration) with ANPD confirming the broadcast notification, listing the specific channels used, the start date, and the planned end date (Article 9, § 4). Failure to file the declaration subjects the controller to sanctions under Article 52 for incomplete notification.
ANPD guidance expressly warns that controllers may not use the infeasibility exception as a pretext to avoid individualized notification. If the controller's own data-processing practices caused the lack of contact information (for example, collecting CPF and financial data but not an email address or phone number), ANPD will treat that as evidence of a violation of the data-minimization and purpose-limitation principles (LGPD Article 6(III) and (I)), compounding the breach-notification failure.
Timing — same three-business-day clock as ANPD notification. Article 9, caput, requires data-subject notification within three business days from the date the controller became aware that the incident affected personal data—the same deadline that governs ANPD notification under Article 6. Controllers qualifying as agentes de pequeno porte receive double the deadline (six business days) for both notifications. The controller may send a preliminary notification to data subjects within the three-day window if full information is unavailable, and must supplement it within twenty business days of the preliminary communication (by analogy to Article 6, § 3, which governs ANPD notification; Article 9 does not explicitly address staged notification to subjects, but ANPD's published FAQ confirms the same framework applies).
Best practice is to notify ANPD and data subjects simultaneously or in immediate succession (ANPD first, subjects within hours). Notifying ANPD but delaying the data-subject communication for days invites the inference that the controller prioritized regulatory compliance over subject protection, which ANPD treats as an aggravating factor under the dosimetry regulation.
Language and tone — transparency over reputation management. ANPD's enforcement decisions (INSS, SEEDF) and published guidance emphasize that the data-subject notification is not a marketing opportunity or a reputation-repair exercise. Controllers may not bury the mandatory disclosures under apologetic corporate messaging, minimize the severity of the breach ("a small number of records"), or deflect accountability onto third parties ("our vendor experienced an incident") without also disclosing the controller's own role and responsibilities under LGPD. The notification must lead with the five mandatory elements in Article 9, presented in plain declarative sentences. Contextual or explanatory material (how the breach was detected, what the controller is doing to prevent recurrence) may follow, but the subject's immediate needs—what data were exposed, what risks the subject faces, what the subject should do now—come first.
No legal disclaimers or liability waivers. Controllers may not condition breach notifications on the data subject's agreement to a liability waiver, class-action waiver, or mandatory arbitration clause. Any such language in a breach notification is void under Brazilian consumer-protection law (CDC Article 51) and constitutes a separate LGPD violation (interference with the subject's exercise of rights under Article 18). If the controller anticipates civil claims, it should address those through its liability-insurance carrier and legal counsel, not through the breach-notification communication to affected individuals.
ANPD may compel revision or expanded disclosure. After receiving the controller's notification and reviewing the corresponding data-subject communication (which the controller should include as an exhibit in the ANPD filing), ANPD may determine that the communication was inadequada (inadequate) in form or content. Article 19 of Resolution 15/2024 authorizes ANPD to order the controller to corrigir (correct) the notification—for example, by reissuing it in plainer language, by adding missing risk disclosures, or by switching from broadcast to individualized channels if ANPD finds the infeasibility claim unsupported. ANPD may also invoke LGPD Article 48, § 2 to compel ampla divulgação (broad disclosure) in mass media—newspapers, radio, television, paid internet advertising—at the controller's expense, when the authority determines that existing communications are insufficient to protect affected subjects. Refusal to comply with an ANPD disclosure order triggers daily fines under Article 52(III) and potential operational sanctions (suspension of the processing activity under Article 52(VIII)).
Cross-border complications — notification in multiple jurisdictions. When the breach affects data subjects located in Brazil and in other jurisdictions (EU, UK, California, etc.), the controller must comply with all applicable notification regimes. LGPD Article 9 notification requirements are independent of and cumulative with GDPR Article 34 data-subject notification, CCPA § 1798.82 California breach-notification law, and other territorial rules. Controllers should draft a master notification satisfying the most demanding content requirements across all relevant regimes, then localize for language and jurisdiction-specific contact information. A notification that satisfies Article 9's five mandatory elements will typically also satisfy GDPR Article 34 (which requires similar disclosures of data categories, consequences, and mitigation measures) but may require supplementation for California (which mandates specific language about the subject's right to request a police report, Cal. Civ. Code § 1798.82(d)(1)(G)).
Operator (processor) coordination. Although the notification duty runs to the controller, when the breach originates in an operator's systems, the operator must provide the controller with all information necessary to complete the Article 9 notification—data categories affected, number of subjects, timeline, technical cause—without unjustified delay (Resolution 15/2024, Article 4, § 2). Well-drafted controller-processor contracts (LGPD Article 39) include a breach-notification annex specifying the operator's obligation to deliver a preliminary report within 24 hours of detection and a detailed forensic summary within 72 hours, enabling the controller to meet the three-business-day ANPD and data-subject deadlines. Operators that delay or withhold critical information, forcing the controller to file an incomplete or inaccurate notification, expose both parties to sanctions; ANPD has indicated it will treat such coordination failures as joint violations.
Recordkeeping — retain copies of all data-subject communications. Controllers must retain copies of the data-subject notifications (whether individualized emails, SMS messages, website screenshots, or social-media posts) as part of the five-year incident record required under Article 10 of Resolution 15/2024. If ANPD later investigates whether the controller satisfied Article 9, the authority will request proof that the communication was sent, that it reached the intended recipients (email delivery logs, SMS gateway confirmations, website analytics showing page views), and that it contained the five mandatory disclosures in clear language. Controllers using third-party notification vendors (email service providers, SMS platforms) should configure those systems to generate and archive delivery receipts and read confirmations (when technically feasible and not privacy-invasive).
Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation), Art. 9 Source: ANPD — Comunicação de incidente de segurança (guidance page) Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD), Art. 48
ANPD notification procedure — SEI!ANPD electronic filing, DPO/representative requirement, and mandatory form content
Controllers must file breach notifications electronically through ANPD's SEI!ANPD (Sistema Eletrônico de Informação) platform, the sole authorized channel for all administrative processes at the Autoridade Nacional de Proteção de Dados. Notification by email, mail, or in-person delivery is not permitted. Submissions outside the platform face procedural rejection and risk obstruction sanctions under Article 5 of ANPD's Enforcement Regulation (Resolution CD/ANPD No. 1/2021).
Who may file — DPO or legal representative only (Article 6, § 5). Under Article 6, § 5 of Resolution CD/ANPD No. 15/2024, breach notifications must be filed by the encarregado (Data Protection Officer, DPO, per LGPD Article 5(VIII) and Article 41) or a legal representative (representante constituído) with formal power of attorney. Documentary proof—either the DPO’s appointment or a valid power-of-attorney—must be uploaded with the initial notification (Article 6, § 6). Omission triggers a procedural deficiency notice, typically with a five-business-day cure period, after which ANPD may open an investigation (Processo de Apuração de Incidente, PAI) if unresolved (Article 6, § 7).
SEI!ANPD platform access — Gov.br authentication (material change April 2026). Effective April 2026, ANPD integrated SEI!ANPD with Brazil’s Gov.br single-sign-on system. External users (DPOs or representatives) no longer use a two-step pre-registration and approval. Instead, a controller's filer authenticates directly via Gov.br; SEI!ANPD automatically creates the external-user registration upon first platform access. The previous pre-January 2024 user invalidations no longer apply. This has eliminated registration lags and removed manual approval by ANPD’s protocol team. The login portal is at https://sei.anpd.gov.br.
Filing breach notification — structured form and attachments. Once logged in, the filer selects "Peticionamento" > "Novo" and chooses "ANPD – Comunicados de Incidentes" as the process type. The platform presents:
- Documento Principal: a fillable PDF Security Incident Communication Form mirroring Article 6, § 2 requirements—controller identity; incident description; affected data categories/volume; security measures pre- and post-incident; risk assessment; mitigation steps; delay justifications (if late); designation preliminary/complete; and required deadlines for supplement.
- Documentos Complementares: attach (1) proof of representation; (2) forensic report or incident log (if available); (3) data-subject communications (if issued or planned); (4) DPO/representative authorization for entities; (5) optional narrative supplement (using ANPD’s Formulário Complementar template if needed).
Document classification (público vs. restrito). As of August 1, 2024, SEI!ANPD’s Módulo de Pesquisa Pública allows public access to documents marked "público." Most filings should be "restrito" unless there’s a specific transparency need; redact all personal or sensitive data from publicly accessible files.
Submission and supplemental filings. Upon form and attachment completion, click "Peticionar"; the system assigns a process number. Corrections to deficiencies or post-filing supplements (final forensic reports, additional subject communications) are filed as "Intercorrente"—not as separate new petitions—to maintain a single case record. Supplemental notification is required within 20 business days for complete facts (40 for small agents).
ANPD review and follow-up. CTIS (Coordenação de Tratamento de Incidentes de Segurança) reviews the notification. ANPD may acknowledge receipt, request more information, direct mitigation, escalate to formal proceedings, or issue preventive/infraction orders. There is no fixed ANPD response timeline; in practice, review varies from two weeks to three months.
Contact for support. Platform or filing questions: protocolo@anpd.gov.br. Substantive questions about content or threshold determinations: incidentes@anpd.gov.br. Requesting ANPD guidance does not toll the notification clock.
Cross-border/foreign controllers. Filings must be in Portuguese. Foreign entities should engage a Brazil-domiciled representative with a recognized power of attorney (procuração) as per Brazilian law.
Material procedural change (April 2026): The SEI!ANPD registration process is now fully automated through Gov.br, with immediate external-user access—manual, two-step (pre-registration/approval) is obsolete.
Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation), Arts. 6–8 Source: ANPD — Comunicação de incidente de segurança (official guidance page, SEI!ANPD instructions) Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD), Art. 48 Source: ANPD — Atualização do acesso externo ao SEI!ANPD via Gov.br (April 2026 update)
What incidents are not notifiable? — LGPD Article 48 and Resolution 15/2024 below-threshold examples and safe-harbor criteria
Not every security incident involving personal data triggers Brazil's breach-notification duty under Lei Geral de Proteção de Dados (LGPD, Law 13,709/2018) Article 48 and Resolution CD/ANPD No. 15/2024. The obligation to notify the Autoridade Nacional de Proteção de Dados (ANPD) and affected data subjects arises only when an incident “may result in relevant risk or damage to data subjects”—a threshold that centers on significant impacts to fundamental rights and one or more of the six at-risk data categories enumerated in Article 5 of the Regulation.
Explicit non-notifiable scenarios ANPD's official guidance and Article 4, §1 of Resolution 15/2024 articulate scenarios where notification is not required:
- The data was adequately encrypted, anonymized, or otherwise protected by a technical safeguard such that there is no reasonable likelihood of harm (e.g., ransomware incident where data was encrypted both at rest and in transit, and encryption keys were uncompromised).
- The personal data affected does not fall within any of the six risk categories described in Article 5—i.e., does not involve sensitive data, data of children/adolescents/elderly, financial data, authentication credentials, legally protected/confidential data, or large-scale datasets. For example, a minor incident affecting de-identified support logs or generic contact information processed in low volume.
- The incident was fully contained before any unauthorized access or extraction (confirmed by forensic evidence), and there is strong evidence that no data subjects are exposed to harm.
The six risk categories defined in Article 5 are:
- Sensitive data (LGPD Article 5(II))—racial/ethnic origin, religious belief, political opinion, trade-union or organizational membership, health or sex life, genetic or biometric data for unique ID;
- Data of children, adolescents, or elderly persons;
- Financial data (bank accounts, payment card numbers, transaction records);
- Authentication credentials in systems (passwords, tokens, biometric credentials);
- Data protected by legal, judicial, or professional secrecy;
- Large-scale data (with no fixed threshold; controller must assess volume, geographical scope, and number of data subjects).
Contextual factors ANPD expects controllers to consider:
- Nature and robustness of the safeguard (Was state-of-the-art encryption used? Were keys stored separately?)
- Actual access or exposure risk (Was there evidence the attacker or unauthorized party accessed, viewed, or exfiltrated the data?)
- Mitigation actions (Were prompt technical or organizational measures taken that fully neutralized the risk before harm materialized?)
Required documentation even if not notifiable: Article 10 of Resolution 15/2024 requires controllers to maintain an internal record for all incidents, including those not notified to ANPD or data subjects. This record must detail the risk assessment performed and the reasons for non-notification, such as the presence of effective encryption, absence of risk-category data, or confirmed lack of exposure.
ANPD guidance: When in doubt, notify. ANPD’s published guidance and enforcement posture emphasize adopting a cautious approach: where materiality is uncertain or facts are ambiguous, controllers are strongly encouraged to notify. If ANPD reviews a controller’s record and finds the risk was underestimated, the controller may be sanctioned for failure to notify a notifiable breach, in addition to aggravating the base fine.
Example from ANPD FAQ (abridged):
- “If data was encrypted using a robust algorithm and no decryption was possible, there is no need to notify.”
- “If only non-personal, anonymized data were affected, notification is not required.”
- “If the incident involved personal data but did not affect rights or interests (e.g., test data not linked to real individuals), notification is not necessary.”
Controllers should cross-reference the risk/impact assessment template in Article 10(§1) of the Regulation. All non-notified incidents must be fully documented and justifiable if later audited or challenged by ANPD.
Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation), Arts. 4, 5, 10 Source: ANPD — Comunicação de incidente de segurança (official guidance and FAQ)
Small processing agents — eligibility for extended breach-notification deadlines and high-risk carve-out (Res. 2/2022 + 15/2024)
Under Brazil’s Lei Geral de Proteção de Dados (LGPD), specific breach-notification deadline relief is available for controllers and processors that qualify as “small processing agents” (agentes de pequeno porte) by meeting criteria in ANPD Resolution CD/ANPD No. 2/2022. This relief primarily extends notification and supplementation timelines for security incidents but does not relax the content or recordkeeping obligations, and it contains key exceptions for high-risk processing.
Eligibility for small processing agent status — Resolution 2/2022, Art. 3 A controller or operator qualifies as a small processing agent if it fits any of the following:
- Micro-enterprise (ME), small business (EPP), or individual microentrepreneur (MEI) as defined by Lei Complementar No. 123/2006 (generally, legal entities with up to R$4.8 million gross annual revenue);
- Startups defined by Lei Complementar No. 182/2021, Art. 4;
- Nonprofit private-law entities validly organized in Brazil;
- Other private-law legal entities that earned up to R$4.8 million gross revenue in Brazil in the prior calendar year.
The annual gross revenue calculation applies individually to each legal entity. ANPD regulations do not currently address corporate group aggregation or consolidation for this purpose.
Breach-notification deadline relief — Resolution 15/2024, Arts. 6(§4) and 9(§6) Qualifying small processing agents receive:
- Six business days (instead of three) to notify both ANPD and affected data subjects, counted from the date the controller determines that personal data were affected by a security incident.
- Forty business days (instead of twenty) to supplement a preliminary notification with missing information.
All other duties—the requirement to evaluate notifiability using the same “relevant risk or damage” test, to maintain incident records for five years, and to notify even in cases of doubt—remain unchanged.
High-risk processing carve-out — Resolution 2/2022, Art. 4; Resolution 15/2024, Art. 6(§4) A qualifying small agent loses the benefit of the extended breach-notification deadlines if it performs processing that is considered “high risk to data subjects.” High-risk is defined by scope, volume, nature of the data, or vulnerability of the population—such as large-scale processing of sensitive data or children’s data. In these scenarios, the standard deadlines (three business days for notification, twenty for supplementation) apply regardless of agent size. ANPD may also exclude a small agent from extended deadlines if it determines that such relief would endanger data subjects’ rights.
Documentation of small-agent status Any controller or processor relying on this relief must retain corporate, tax, or registration records demonstrating eligibility and cite the relevant provisions in its incident records. Failure to evidence status upon ANPD’s request may result in loss of the extended deadlines and potential sanction.
Source: Resolution CD/ANPD No. 2/2022, Arts. 3–4 Source: Resolution CD/ANPD No. 15/2024, Arts. 6, 9
"Ampla divulgação" (broad publication) orders under LGPD Article 48 §2 — ANPD powers, triggers, and controller obligations
Article 48, §2, item I of Brazil’s Lei Geral de Proteção de Dados (LGPD, Law No. 13,709/2018) empowers the Autoridade Nacional de Proteção de Dados (ANPD) to order “ampla divulgação” (broad publication) of a security incident at the controller’s expense if the authority concludes that individual notification to affected data subjects is impossible or insufficient to protect their rights. This power goes beyond the usual direct or broadcast notification channels and authorizes ANPD to require media-wide publicization to ensure potentially affected individuals are adequately informed.
Legal rule and regulatory framework
- Article 48, §2, I LGPD expressly allows ANPD to impose “adoption of measures to reverse or mitigate the effects of the incident, including ample disclosure of the fact at the expense of the controller.”
- Resolution CD/ANPD No. 15/2024 (notably Articles 3, 9, and 20) specifies that if a controller cannot individually notify all affected persons (for example, due to scale, missing contact data, or population vulnerability), ANPD may require the controller to employ additional publicity channels—including mass media. The Regulation does not mandate a fixed duration or prescribe specific outlets, leaving this to ANPD’s discretion.
How "ampla divulgação" is triggered and carried out:
- ANPD may issue an order when evidence shows individualized or even broadcast notice (e.g., website notice, social media, app banners) will not reach all at-risk data subjects, or is unlikely to mitigate relevant risks.
- The controller, upon receiving the order, must publish the prescribed information about the breach in the designated mass-media outlets (newspapers, TV, radio, or other means named by ANPD), using content, format, and frequency set by the authority. The cost of all such publications is borne by the controller.
- ANPD also has discretion under Resolution 15/2024 to set requirements for what details must be disclosed and to review proofs of compliance, but the regulation does not set a categorical minimum period or a detailed escalation sequence.
- After carrying out the required disclosure, the controller must submit a statement to ANPD in the SEI!ANPD system confirming completion, listing the channels used and the dates of publication (see Art. 9, §4).
Key distinction: “Ampla divulgação” is a preventive or remedial notification mechanism invoked during breach response. It is distinct from “publicização da infração” under Article 52(IV) LGPD, which is a sanction published after administrative due process and a finding of violation.
Enforcement and compliance:
- Failure to comply with an "ampla divulgação" order is itself a breach of LGPD and subjects the controller to possible daily fines or further regulatory action, as permitted by Article 52.
Practical examples or reported cases should be verified in public ANPD enforcement dockets for case-law application. As of June 2026, the primary sources remain black-letter law and regulation above.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD), Art. 48 §2 Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation), Arts. 3, 9, 20
Compliant breach risk assessment under LGPD — Resolution 15/2024 and ANPD’s analytic protocol
Brazil’s breach-notification trigger centers on a rigorous, fact-driven “relevant risk or damage” (risco ou dano relevante) assessment, as required by Article 48 of the LGPD and operationalized by Articles 4–6 and 10 of Resolution CD/ANPD No. 15/2024. While the threshold for notification is succinct (does the incident significantly affect data subjects’ fundamental rights AND involve at least one of six risk-category data types?), the ANPD expects controllers to follow a specific process—both substantively and in documentary form—when making this determination.
Required analytic steps for risk assessment (Resolution 15/2024 and ANPD guidance):
- Immediate containment and preliminary fact-finding. Controllers must act swiftly to contain the incident and gather all available information: date and nature of compromise, affected IT systems, attack vectors, identification of the origin (internal/external), and confirmation of whether personal data (as scoped by LGPD Article 5(I)) was involved. The controller must document the earliest evidence of compromise and the timeline to discovery.
- Data-categorization matrix. The controller must assess whether the data affected falls into any of the six risk categories in Resolution 15/2024, Article 5: (1) sensitive data (LGPD Article 5(II)); (2) children/adolescent/elderly data; (3) financial data; (4) system authentication credentials; (5) data protected by secrecy laws; (6) large-scale data. For each, the controller records the presence/absence, estimated volume, and subject demographic breakdown.
- Impact analysis (risk to fundamental rights/interests). Identify all categories of potential harm: identity theft, financial fraud, discrimination risk, inability to exercise LGPD rights, reputational injury, psychological harm, or tangible consequences such as loss of access to services. Article 6(§2) of the Regulation requires controllers to assess both objective and subjective risk, considering the data’s nature, the likelihood of misuse, and the vulnerability of the affected population.
- Technical and administrative safeguards. The risk assessment must specify which protections existed pre-incident (encryption, access control, monitoring, anonymization) and detail whether these mitigated exposure (e.g., uncompromised encryption keys or effective network segregation). If the controller claims “effective anonymization” or robust encryption as a safe harbor (per Art. 4, §1), they must evidence the algorithms and key management in place and the absence of compromise.
- Mitigation and notification criteria. The controller must document all actions taken to mitigate risk post-incident (password resets, account lockouts, third-party notification). Article 10 expressly requires a reasoned justification for the materiality decision: for non-notification, which risk-category and impact prongs were not met; for notification, how harm or risk to rights was evaluated.
- Retention and transparency requirements. The full analytic process—including investigation steps, evidence considered, risk categorization, and final determination—must be preserved for at least five years (Article 10). ANPD’s guidance recommends producing a contemporaneous narrative (in Portuguese), signed by the DPO, that cross-references forensic and legal advice.
Best practice: Use ANPD’s published template (modelo de avaliação). Though Resolution 15/2024 does not prescribe a literal template, the ANPD guidance/FAQ includes a risk assessment checklist aligned with Article 10(§1) and enforcement expects to see evidence of each decision point supported by documented fact and rationale.
Controllers who cannot show a stepwise, documented process for their risk assessment face an elevated risk of sanction if later challenged, and may be deemed to have acted negligently under both LGPD Article 48 and general civil liability standards.
Source: Resolution CD/ANPD No. 15 of 2024 (Security Incident Communication Regulation) Source: ANPD — Comunicação de incidente de segurança, FAQ/Guidance
Internal investigation and containment obligations — controller’s duty to investigate, preserve evidence, and mitigate risk before notification under Resolution 15/2024, Art. 4 and 10
Before notifying the Autoridade Nacional de Proteção de Dados (ANPD) or affected data subjects of a personal data breach, Brazilian controllers must immediately investigate and contain the incident. Resolution CD/ANPD No. 15/2024, which implements LGPD Article 48, makes clear that a prompt, documented internal investigation is not optional: it is a legal requirement that underpins both the timing and accuracy of all subsequent notifications.
Investigation and containment as prerequisites to notification (Resolution 15/2024, Arts. 4, 6, 8, 10) Upon learning of a possible or confirmed data breach, the controller must:
- Act immediately to contain the incident and mitigate ongoing harm (Art. 4, I–II). This includes disabling affected systems or accounts, changing credentials, isolating compromised networks, and engaging internal or third-party forensic specialists to understand the technical vector.
- Preserve and collect evidence for both risk assessment and potential ANPD inspection: event logs, records of access, file copies, forensic images, and communications related to the incident (Art. 10, §1, II and V). Controllers should take steps to avoid overwriting logs or purging temporary files during remediation. Preservation failures can constitute a breach of both the recordkeeping (Art. 10) and cooperation (Art. 8) duties.
- Identify what personal data and which data subjects may be at risk, applying the six-category matrix in Article 5 of Resolution 15/2024 (not LGPD Article 5). Controllers must determine if sensitive data, data of children/adolescents/elderly, financial data, authentication credentials, data protected by secrecy laws, or large-scale data are implicated. This requires more than a hypothetical—it must be a documented, fact-based assessment.
- Assess whether the incident is likely to result in “relevant risk or damage” to data subjects. The controller must make this evaluation in good faith and based on the evidence at hand, without waiting for perfect technical certainty. Resolution 15/2024 Art. 6 §1 and ANPD guidance both state that controllers must not delay notification using the excuse of incomplete technical analysis if there is already evidence of risk.
All these actions, findings, and decisions must be recorded and retained as part of the incident file for at least five years (Art. 10). ANPD can request this documentation at any stage—during or after the breach investigation (Art. 8).
Timing: when does the notification clock start? The three-business-day (or six, for small processing agents) notification deadline starts when the controller knows that personal data was affected, not merely when IT detects any anomaly. If further investigation is needed, the controller can file a preliminary notification and supplement it within 20 (or 40) business days (Art. 6, §3).
Sanction risks and compliance implications. If a controller fails to contain, investigate, or preserve evidence—or delays notification to chase certainty after confirming data exposure—these lapses can increase sanction exposure under LGPD Article 48 and Resolution 15/2024. ANPD considers poor investigation or missing records to be aggravating factors when determining fines or corrective orders.
In summary: Brazilian breach law treats incident containment and internal fact-finding as legal obligations that anchor timely and effective notification. Controllers that do not have processes in place to investigate, preserve, and document response actions face significant enforcement risk, even if notification is eventually made.
Operator breach-notification duty — obligation to notify controller without unjustified delay under LGPD and Resolution 15/2024
Under Brazil’s Lei Geral de Proteção de Dados (LGPD, Law No. 13,709/2018) and Resolution CD/ANPD No. 15/2024, the core breach-notification duty falls on the controller (controlador) — but operators (operadores, the LGPD term for processors) play a mandatory, time-sensitive role. Resolution 15/2024 makes explicit that when an operator becomes aware of a security incident involving personal data it processes on behalf of a controller, the operator must inform the controller without unjustified delay ("sem demora injustificada") (Art. 4, §2 of the Regulation). This duty applies regardless of whether the operator determines the incident is likely to be notifiable; it is for the controller to make the threshold risk assessment and file formal notifications with ANPD or data subjects as required by Article 48 LGPD and Art. 6 and 9 of Resolution 15/2024.
Timeline and required content. Resolution 15/2024 does not impose a fixed hour or day limit, but ANPD’s published guidance and best practice in controller-operator contracts establish that “without unjustified delay” means as soon as the operator has sufficient information to reasonably believe a security incident may have affected personal data. The operator’s initial notification should include:
- The date and time of the incident (or detection, if exact time is unknown);
- A description of the nature of the incident and compromised systems;
- The categories and estimated volume of affected personal data;
- Any immediate containment or mitigation measures taken;
- The date and time the operator first became aware of the incident.
If information is incomplete at first discovery, the operator should send a preliminary notification and supplement as new facts emerge. Failing to notify the controller promptly is itself a breach of LGPD duties and, depending on contract terms, may expose the operator to indemnity or termination.
Best-practice contractual terms. ANPD’s official incident-communication guidance recommends that controller-operator agreements (contratos de tratamento) include:
- An explicit clause setting the operator’s breach-communication duty “without unjustified delay”;
- A concrete timeline for initial and supplemental notification (e.g., within 24 hours of detection, with ongoing updates as new facts arise);
- A list of information to be provided with each notification;
- A requirement for the operator to cooperate with the controller (making logs, reports, and technical resources available), since the controller bears the legal responsibility for onward notification to ANPD and data subjects;
- A mechanism for documenting when notification was sent and received — email logs, incident ticketing systems, or compliance portals.
If the operator is at fault for late or incomplete controller notification, ANPD considers that an aggravating factor in enforcement — especially if it materially limits the controller’s ability to assess notifiability or meet LGPD deadlines (Art. 6, 8, and 10 of Resolution 15/2024). Controllers should audit operator compliance as part of third-party risk management.
Takeaway: The operator’s duty is not just contractual — it is grounded in black-letter regulation. It should be operationalized in agreements, incident-response playbooks, and service-level policies, with explicit reference to the LGPD and Resolution 15/2024 Articles 4, 6, and 10.
Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation), Art. 4 §2, Art. 6, Art. 10 Source: ANPD — Comunicação de incidente de segurança (official guidance page)
Supplemental notification after initial incomplete disclosure — Article 6(§3) and 9(§4) of Resolution 15/2024
When a controller cannot provide all mandatory information within the initial breach-notification deadline (three or six business days), Brazil’s breach regime requires a two-stage process: a preliminary notification (comunicação preliminar) followed by a supplemental notification (comunicação complementar) completing the missing elements. This applies to notifications both to the ANPD and to affected data subjects, as set out by Articles 6(§3) and 9(§4) of Resolution CD/ANPD No. 15/2024.
Initial notification with missing information If, by the close of the initial deadline, the controller lacks details (for example, exact categories/volume of data, impact analysis, or scope of data subjects), the law requires filing a preliminary notification. This must include all available facts, a reasoned explanation for what is missing, why, and the controller’s best estimate for when those facts will be available. Article 6(§3) formally allows this staged reporting – the controller must not delay the preliminary notification in search of completeness.
Supplemental notification — deadlines and required content Within 20 business days of the preliminary notification (or 40 business days for small processing agents), the controller must file a supplemental notification with the ANPD and/or update affected data subjects, providing all outstanding information initially lacking. The supplemental must reference the original (using the SEI!ANPD process number), specify new facts or corrections, and, for data subjects, clarify any changes in risk or recommended mitigation steps. If information is still unavailable, the controller must justify the continued lack of detail and outline ongoing efforts (Article 6(§3), second sentence).
Obligation applies to both ANPD and data subject notification Article 9(§4) requires that when initial notification to data subjects is by broadcast (for example, due to missing individualized contact data), the controller must file a declaration with ANPD within three business days listing the notification channels, and supplement this record if later clarifications emerge. The same supplement procedure applies if initial communication to subjects was necessarily generic but later investigation yields details enabling individualized notification.
Compliance risks — missed supplements and new facts Failure to timely supplement a preliminary notification is a sanctionable breach of Article 48 LGPD and Resolution 15/2024. ANPD treats unjustified delay as an aggravating circumstance under its enforcement regulation. If new facts emerge post-supplement (for example, the scope or risk is worse than believed), the controller must update both ANPD and subjects again, using the peticionamento intercorrente process in SEI!ANPD and suitably amending prior subject communications.
Practical best practices Always document efforts to acquire outstanding facts, note the status in internal records, and make clear, dated references when supplementing. Controllers should avoid generic promises to update; supplements must be concrete (new data, revised risk, actionable changes for data subjects).
Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation), Arts. 6(§3), 9(§4) Source: ANPD — Comunicação de incidente de segurança (guidance page)
Joint controller breach-notification obligations — allocation under LGPD, Resolution 15/2024, and ANPD practice
Brazil's LGPD (Lei nº 13.709/2018) recognizes the concept of joint controllers (controladores conjuntos) in Article 5, XVI and Article 42, but the statute and implementing Resolution CD/ANPD No. 15/2024 do not enumerate express breach-notification allocation rules for controllers acting jointly. Practitioners must understand both the statute's general principles and ANPD's practical expectations when a security incident impacts processing operations managed by two or more controllers in concert.
Definition and relevance of joint controllers: LGPD Article 5, XVI defines controladores conjuntos as “two or more agents who jointly decide on the processing's purposes and essential means.” Joint controllership frequently arises in co-branded services, shared infrastructure, or sector alliances (financial/health/telecom consortia), where no single entity has exclusive operational or legal control over all affected systems or data categories.
Who is responsible for breach notification?
- LGPD Article 42, §1 establishes that joint controllers are “jointly and severally liable” (responsabilidade solidária) for damages arising from unlawful processing or violations of the law. However, neither Article 48 (breach-notification) nor Resolution 15/2024 explicitly assigns notification responsibility or outlines coordination protocol for joint controllers.
- ANPD’s official breach-notification FAQ and the Incident Communication Regulation are silent about whether both (or all) joint controllers must notify, or if one may satisfy the duty on behalf of all. The practical expectation, reflected in ANPD enforcement and best practice, is:
- Any joint controller aware of a notifiable incident must act to notify the ANPD and affected data subjects within the prescribed deadlines (three or six business days). Coordination to file a single notification is strongly encouraged to avoid duplicative or conflicting communications, but failure by one controller does not excuse others.
- Agreements between controllers may allocate notification roles (for example, designating a lead controller), but such agreements do not affect statutory liability to ANPD or data subjects. If a notification failure occurs, ANPD can impose full sanctions on any joint controller.
- ANPD expects joint controllers to have documented incident-response coordination protocols. When an incident implicates multiple controllers (for example, in a data-sharing arrangement or ecosystem breach), the entities should agree in advance who will (a) assess notifiability, (b) file notifications, and (c) handle data-subject communications. These protocols should be referenced in incident records as required under Resolution 15/2024, Article 10.
ANPD’s enforcement posture: If neither joint controller notifies a plainly notifiable incident, both (or all) are exposed to sanctions for breach of Article 48, as the duty follows substantive control—not formal agreement. In enforcement actions (see public sanctions indexed by ANPD), ANPD assesses whether the parties acted in good faith to coordinate, and whether incident records reflect timely communication between controllers about the breach and intended response.
Key takeaways for practitioners:
- Joint controllers must not rely solely on private agreements to allocate LGPD notification duties—the legal obligation attaches to each controller.
- Both the ANPD and affected data subjects can hold any joint controller liable for notification failures.
- Sectoral norms or past ANPD practice may be cited as persuasive, but only primary law and ANPD guidance create safe harbors. Keep incident-response allocations in writing, documented in ROPA and incident records.
No explicit safe harbor for lead-entity notification as of June 2026. ANPD may clarify its expectations through further guidance, but current law requires all joint controllers to ensure compliance. When in doubt, file notification and reference the joint arrangement in the filing.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD), Arts. 5(XVI), 42, 48 Source: Resolution CD/ANPD No. 15 of April 24, 2024 (Security Incident Communication Regulation) Source: ANPD — Comunicação de incidente de segurança (official FAQ/guidance)
Breach notification for public-sector entities — LGPD, CONARQ, and sectoral overlays on incident reporting and record retention
Under Brazil’s LGPD (Lei nº 13.709/2018), public-sector entities such as federal, state, and municipal agencies, state-owned enterprises, and public foundations are subject to the Article 48 breach-notification requirement—there is no categorical exemption. Article 23 sets out the conditions for lawful processing by public bodies but does not carve out a separate incident-reporting regime. Resolution CD/ANPD No. 15/2024 confirms that government controllers must notify the Autoridade Nacional de Proteção de Dados (ANPD) and affected data subjects within the same three-business-day deadline as private organizations if a security incident presents "relevant risk or damage.”
Archival and record-retention overlays — CONARQ and public-archive requirements Article 10, §2 of Resolution 15/2024 expressly regulates public-sector recordkeeping: while private controllers must keep incident records for five years from creation, public entities listed in LGPD Article 23 must retain these records in alignment with national archival regulations when the CONARQ (Conselho Nacional de Arquivos) classifies them as permanent. The relevant CONARQ retention tables (tabelas de temporalidade), created under Law 8.159/1991 and Portaria AN/MJSP 93/2022, specify which agency records (including security incidents involving citizen data) are subject to permanent archiving versus those considered temporary. Typically, incident records related to public registers, pension/benefit systems, and core citizen services are permanent, while internal IT logs or minor events may be temporary and thus subject to the five-year default. Government entities must check the most current CONARQ table for their jurisdiction and document which schedule applies to each type of incident record.
Sectoral overlays and additional breach duties Sector-specific rules may impose stricter standards: for example, healthcare agencies must also comply with Ministry of Health ordinances on patient-data breach reporting, and educational bodies may have state-level requirements for student-data incident reporting and communication to parents/guardians. Article 10 of Resolution 15/2024 does not override these sectoral mandates; in practice, ANPD expects public-sector controllers both to notify under LGPD and to comply with all relevant sectoral rules, maintaining a single incident record that cross-references each legal basis. Failure to do so can result in parallel sanctions: ANPD for LGPD non-compliance, sectoral regulator for breach of sectoral duty.
Designation and proof of public officials When filing a breach notification to ANPD (see SEI!ANPD procedure), public agencies must attach (a) the portaria de designação (official designation order) for the encarregado (DPO) and (b) any administrative act authorizing the official to submit notifications externally, as required by sectoral and administrative law. ANPD’s enforcement actions against public agencies emphasize prompt, well-documented incident response and highlight that internal bureaucracy is not a defense for missing notification deadlines.
Summary for public-sector entities:
- Subject to LGPD Article 48 breach notification with sectoral/special law overlays;
- Record retention is permanent if so classified by CONARQ, otherwise minimum five years (Art. 10, §2);
- Must separately comply with stricter sectoral breach duty if applicable;
- Must file notifications through SEI!ANPD, with public-entity-specific documentation.
Source: LGPD, Lei nº 13.709, Art. 23, 48; Resolution CD/ANPD No. 15/2024, Art. 10, §2 Source: Law No. 8.159/1991 (public records), Portaria AN/MJSP 93/2022 (CONARQ rules)