The LGPD and Cybersecurity: Obligations, the Incident Deadline and a Checklist // Compliance
Compliance · LGPD

The LGPD and Cybersecurity: Obligations, the Incident Deadline and a Checklist

The LGPD — Lei Geral de Proteção de Dados, Law 13,709/2018, Brazil’s general data protection statute — is the framework any organization processing personal data in Brazil answers to, and it is enforced by the ANPD, the Brazilian data protection authority. The part of it that causes the most day-to-day confusion in security teams is not in the statute at all — it is in the regulation. Since ANPD Board Resolution No. 15, of 24 April 2024, the “reasonable time frame” of Article 48 has become a concrete number: three business days. If the material you are working from does not cite that resolution, it describes a regime that no longer applies.

What follows is the regime in force, checked article by article against the official sources. This is not legal advice — it is the map you need in order to have a useful conversation with your legal team.

What the LGPD requires in information security (Articles 46 to 49)

Chapter VII of the LGPD is short and to the point:

Two details that are routinely missed:

There is no statutory list of mandatory controls. Article 46, §1 says the ANPD may set minimum technical standards — and so far it has not published a binding catalogue. The standard is one of adequacy: measures proportionate to the nature of the data, the volume, the risk and the state of technology.

The absence of measures creates direct civil liability. Article 44, sole paragraph: “the controller or processor who, by failing to adopt the security measures provided for in Article 46 of this Law, gives rise to the damage shall be liable for damages arising from the breach of data security”. This runs independently of any administrative sanction.

At the level of principles (Article 6), three items underpin all of this: security (VII), prevention (VIII) and accountability (X). Item X is the most demanding: you must be able to demonstrate that the measures were adopted and that they are effective. Without recorded evidence, the control does not exist as far as the regulator is concerned.

What counts as a security incident — and when it becomes reportable

Resolution 15/2024 defines a security incident as “any confirmed adverse event related to the breach of the properties of confidentiality, integrity, availability and authenticity of personal data security” (Article 3, XII).

Three practical consequences, following the guidance the ANPD itself has published:

Once the incident is confirmed, the next question is whether it may create relevant risk or harm. Article 5 sets out a cumulative test — the incident must be capable of significantly affecting data subjects’ interests and fundamental rights and, at the same time, involve at least one of these six criteria:

  1. sensitive personal data;
  2. data of children, adolescents or the elderly;
  3. financial data;
  4. system authentication data;
  5. data protected by legal, judicial or professional secrecy;
  6. data at large scale.

Paragraph 1 gives examples of what “significantly affect” means: preventing the exercise of rights or the use of a service, or causing material or moral damage such as discrimination, harm to physical integrity, to image and to reputation, financial fraud or identity theft. Paragraph 2 clarifies that “large scale” takes into account the number of data subjects, the volume of data, the duration, the frequency and the geographic extent.

Look closely at criterion 4: an exposed set of logins and passwords already satisfies the second half of the test. What remains is to assess the first — and a leaked credential tends to open the way to precisely the fraud and identity theft cited as examples in §1.

Deadlines, channel and content of the notification

To the ANPD — Article 6

Three business days, counted from the moment the controller learns that the incident affected personal data (Article 6, §1) — not from the date of the incident, and not from the end of the investigation. Saturdays, Sundays and public holidays do not count. Small-scale processing agents get double the deadline (§8), but with a caveat that is often forgotten: under Article 14, II of ANPD Board Resolution No. 2/2022, the doubled deadline does not apply where there is potential harm to the physical or moral integrity of data subjects or to national security — in those cases the same three business days apply as to everyone else.

The notification is made through electronic filing in SEI!ANPD, under the process type “ANPD – Comunicados de Incidentes”, and must be submitted by the Encarregado — the data protection officer the LGPD requires — with a document proving the appointment, or by an appointed representative. Without that proof inside the same deadline, the ANPD may open an Incident Investigation Procedure on its own initiative.

Paragraph 2 lists twelve mandatory pieces of information:

  1. the nature and category of the data affected;
  2. the number of data subjects affected, broken down for children, adolescents and the elderly;
  3. the technical and security measures adopted before and after the incident;
  4. the risks and possible impacts on data subjects;
  5. the reasons for any delay;
  6. the measures taken to reverse or mitigate the effects;
  7. the date of occurrence (where determinable) and the date of knowledge;
  8. the details of the Encarregado or of whoever represents the controller;
  9. identification of the controller and, where applicable, a declaration of small-scale status;
  10. identification of the processor, where applicable;
  11. a description of the incident, including the root cause where identifiable;
  12. the total number of data subjects whose data is processed in the affected activities.

If you cannot assemble all of that within three business days, there is a preliminary notification, to be completed with a reasoned filing within twenty business days (§3), submitted as an interim petition in the same process. The ANPD is unambiguous in its published FAQ: the preliminary notification is not sufficient to discharge the obligation under Article 48 and must be completed within the deadline.

To the data subject — Article 9

Notifying the ANPD is not enough. The ANPD itself records that Article 48 “is not discharged by merely notifying the security incident to the ANPD”: where there is relevant risk or harm, the controller must also notify the affected data subjects. These are two obligations, not one.

Same deadline: three business days from the moment of knowledge — also doubled for small-scale processing agents (Article 9, §6). The content differs — seven items, among them the nature and category of the data affected, the security measures used, the risks and possible impacts, the mitigation measures, the date of knowledge and a contact point for further information (plus the Encarregado’s details, where applicable).

Form matters as much as content:

Paragraph 5 adds a concrete incentive: including recommendations that help the data subject mitigate the effects may be treated as good practice when the ANPD calibrates a sanction (Article 52, §1, IX, of the LGPD).

And if you are the processor?

The legal duty to notify belongs to the controller. When an incident occurs, the processor must inform the controller without undue delay and provide all the information needed for the notification — and the ANPD expressly recommends that these obligations between controller and processor be set out in the contract. Translated into deadlines: the controller’s three-business-day clock does not wait for the supplier, so the processor’s deadline has to be considerably shorter than your own.

The record almost nobody keeps (Article 10)

This is the most ignored obligation in the regulation: the controller must keep a record of every security incident — including those it decided not to report — for a minimum of five years.

The record must contain, as a minimum: the date of knowledge; a general description of the circumstances; the nature and category of the data affected; the number of data subjects affected; the assessment of risk and possible harm; the corrective and mitigating measures; the form and content of the notification, if there was one; and the reasons for not notifying, where that applies.

In other words: the decision not to notify has to be documented and defensible. That record is what the ANPD will ask for if it opens an investigation — and it can request, at any time, the record of processing operations (Article 37), the Data Protection Impact Report (Article 38) and the report on how the incident was handled.

The role of the Encarregado

Article 41 of the LGPD obliges the controller to appoint an Encarregado and to publicly disclose that person’s identity and contact details, “preferably on its website”. ANPD Board Resolution No. 18, of 16 July 2024, spelled out the role:

Small-scale processing agents may be exempted from the appointment (ANPD Board Resolution No. 2/2022), except where they carry out high-risk processing, have gross revenue above the thresholds in the regulation, or belong to an economic group that exceeds them. Even when exempted, they must maintain a communication channel with data subjects.

In practice: the Encarregado is the person who files with the ANPD. If that role is not in your incident response plan, your plan does not work on day one.

Sanctions: what the ANPD can impose (Article 52)

The correct figures, straight from the statutory text:

Sanction Detail
Warning with a deadline for corrective measures
Simple fine up to 2% of revenue of the private legal entity, group or conglomerate in Brazil, for its last financial year, excluding taxes, capped in total at R$ 50,000,000.00 per infraction
Daily fine subject to the same overall cap
Publicization of the infraction once investigated and confirmed
Blocking of the data until the situation is remedied
Deletion of the data relating to the infraction
Partial suspension of the database up to 6 months, extendable for an equal period
Suspension of the processing activity up to 6 months, extendable
Partial or total prohibition of processing activities

The last three (partial suspension, suspension of the activity and prohibition) may only be applied after at least one of the sanctions of fine, publicization, blocking or deletion has already been imposed in the same case (Article 52, §6).

Calibration matters as much as the ceiling. Article 52, §1 requires the authority to consider, among other criteria: the seriousness and nature of the infraction, good faith, cooperation, repeated adoption of internal mechanisms capable of minimizing harm, a policy of good practice and governance and prompt adoption of corrective measures. ANPD Board Resolution No. 4/2023 classifies infractions as minor, medium or serious and sets out the methodology for calculating the simple fine. During proceedings the ANPD may also order immediate preventive measures and set a daily fine to secure compliance with them (Article 15 of Resolution 15/2024).

The detail that matters most to anyone working in security is in Article 48, §3: when judging seriousness, the ANPD weighs “any evidence that adequate technical measures were adopted rendering the affected personal data unintelligible to unauthorized third parties”. Well-implemented encryption is not just technical hygiene — it is a mitigating factor written into the law.

One recent institutional change is worth noting: Law No. 15,352, of 25 February 2026 (the conversion of Provisional Measure 1,317/2025), inserted Article 55-A into the LGPD and established the Agência Nacional de Proteção de Dados (ANPD) as a special-status autonomous agency linked to the Ministry of Justice and Public Security, with functional, technical, decision-making, administrative and financial autonomy, its own assets and its seat in the Federal District. The same law created a dedicated Data Protection Regulation and Enforcement career track. In practice: the same acronym, with more enforcement muscle.

Concrete technical measures

The ANPD’s information security guidance note (written for small-scale processing agents, but useful at any size) organizes the measures into administrative and technical. Cross-referencing that guidance with what Article 48 requires you to be able to answer within three business days:

Encryption. In transit, TLS/HTTPS everywhere — including internal integrations and e-mail carrying HR or health data. At rest, encryption of sensitive fields and of backups. Remember Article 48, §3: if the leaked data is unintelligible, the assessed seriousness drops.

Access control. The ANPD breaks access control into three functions: authentication (who is accessing), authorization (what they may do) and auditing (what was done). In practice: least privilege (need to know), MFA on systems holding personal data, a password complexity policy, replacement of vendor default passwords and a ban on shared accounts or passwords — which the ANPD calls a “critical vulnerability vector”.

Audit trail. Record authentications and authentication failures, access to personal data, permission changes, exports and administrative operations. The test is simple: can you say, within three business days, how many data subjects were affected, which categories of data were involved and what the root cause was? If the answer depends on archaeology in application logs, the incident has already cost you your deadline.

Retention and deletion. Collecting only what is necessary (Article 6, III) and deleting whatever no longer has an active purpose reduces the attack surface of the next incident and the number of data subjects affected. Add secure disposal of media to that.

Ransomware-resilient backup. The ANPD’s recommendation is explicit: regular, complete backups, held somewhere other than the primary storage and not synchronized in real time — so that the attacker’s encryption is not replicated into them.

Vulnerability management. Systems and applications kept up to date, patches applied, hardening (disabling unnecessary services, changing every default password, continuously reviewing what is exposed to the internet) and anti-malware installed and updated — with explicit instructions to users not to switch off security settings. The ANPD guidance cites research by CERT.br together with Cetic.br: keeping everything updated, hardening, and improving identification and authentication (including not reusing passwords) are among the three highest-impact measures.

Suppliers. A contract with a processor needs an information security clause, defined controller/processor roles and an internal notification deadline compatible with your three business days.

Practical checklist

Before (standing posture)

During (the first three business days)

After

Where a platform helps — and where it does not

Tooling does not replace a governance programme, does not appoint your Encarregado and does not file with the ANPD on your behalf. What it can do is shorten the distance between “we found something” and “we have the twelve fields filled in”. At OODA Intelligence, the components that touch that workflow are:

The rest — mapping processing activities, legal bases, contracts with processors, the decision on whether to notify — remains human work.

Official sources

Every article, deadline and figure cited here was checked against the official text:

LGPDGDPRprivacycompliancedata protection
Previous A Guide to Threat Intelligence for Businesses: Types, Cycle and Metrics

Related Posts

A Guide to Threat Intelligence for Businesses: Types, Cycle and Metrics // Articles
Articles

A Guide to Threat Intelligence for Businesses: Types, Cycle and Metrics

10.03.2026
Welcome to the OODA Intelligence Blog // News
News

Welcome to the OODA Intelligence Blog

01.03.2026