The LGPD and Cybersecurity: Obligations, the Incident Deadline and a Checklist
The LGPD — Lei Geral de Proteção de Dados, Law 13,709/2018, Brazil’s general data protection statute — is the framework any organization processing personal data in Brazil answers to, and it is enforced by the ANPD, the Brazilian data protection authority. The part of it that causes the most day-to-day confusion in security teams is not in the statute at all — it is in the regulation. Since ANPD Board Resolution No. 15, of 24 April 2024, the “reasonable time frame” of Article 48 has become a concrete number: three business days. If the material you are working from does not cite that resolution, it describes a regime that no longer applies.
What follows is the regime in force, checked article by article against the official sources. This is not legal advice — it is the map you need in order to have a useful conversation with your legal team.
What the LGPD requires in information security (Articles 46 to 49)
Chapter VII of the LGPD is short and to the point:
- Article 46. Adopt “security, technical and administrative measures capable of protecting personal data from unauthorized access and from accidental or unlawful situations of destruction, loss, alteration, communication or any form of inappropriate or unlawful processing”. §2 requires those measures to be observed “from the design phase of the product or service through to its execution” — privacy by design with the force of law.
- Article 47. The obligation holds “even after the end” of processing. A decommissioned database is not an unprotected database.
- Article 49. Systems “must be structured so as to meet security requirements, standards of good practice and governance”.
Two details that are routinely missed:
There is no statutory list of mandatory controls. Article 46, §1 says the ANPD may set minimum technical standards — and so far it has not published a binding catalogue. The standard is one of adequacy: measures proportionate to the nature of the data, the volume, the risk and the state of technology.
The absence of measures creates direct civil liability. Article 44, sole paragraph: “the controller or processor who, by failing to adopt the security measures provided for in Article 46 of this Law, gives rise to the damage shall be liable for damages arising from the breach of data security”. This runs independently of any administrative sanction.
At the level of principles (Article 6), three items underpin all of this: security (VII), prevention (VIII) and accountability (X). Item X is the most demanding: you must be able to demonstrate that the measures were adopted and that they are effective. Without recorded evidence, the control does not exist as far as the regulator is concerned.
What counts as a security incident — and when it becomes reportable
Resolution 15/2024 defines a security incident as “any confirmed adverse event related to the breach of the properties of confidentiality, integrity, availability and authenticity of personal data security” (Article 3, XII).
Three practical consequences, following the guidance the ANPD itself has published:
- A vulnerability is not an incident. The mere existence of a flaw triggers nothing. Exploitation of it, however, can.
- Unavailability counts. This is not only about leaks. Ransomware that locks access to patient records is an incident, even with no exfiltration.
- Anonymized data does not count. An incident involving only anonymized data, or data that does not relate to an identified or identifiable natural person, does not have to be reported.
Once the incident is confirmed, the next question is whether it may create relevant risk or harm. Article 5 sets out a cumulative test — the incident must be capable of significantly affecting data subjects’ interests and fundamental rights and, at the same time, involve at least one of these six criteria:
- sensitive personal data;
- data of children, adolescents or the elderly;
- financial data;
- system authentication data;
- data protected by legal, judicial or professional secrecy;
- data at large scale.
Paragraph 1 gives examples of what “significantly affect” means: preventing the exercise of rights or the use of a service, or causing material or moral damage such as discrimination, harm to physical integrity, to image and to reputation, financial fraud or identity theft. Paragraph 2 clarifies that “large scale” takes into account the number of data subjects, the volume of data, the duration, the frequency and the geographic extent.
Look closely at criterion 4: an exposed set of logins and passwords already satisfies the second half of the test. What remains is to assess the first — and a leaked credential tends to open the way to precisely the fraud and identity theft cited as examples in §1.
Deadlines, channel and content of the notification
To the ANPD — Article 6
Three business days, counted from the moment the controller learns that the incident affected personal data (Article 6, §1) — not from the date of the incident, and not from the end of the investigation. Saturdays, Sundays and public holidays do not count. Small-scale processing agents get double the deadline (§8), but with a caveat that is often forgotten: under Article 14, II of ANPD Board Resolution No. 2/2022, the doubled deadline does not apply where there is potential harm to the physical or moral integrity of data subjects or to national security — in those cases the same three business days apply as to everyone else.
The notification is made through electronic filing in SEI!ANPD, under the process type “ANPD – Comunicados de Incidentes”, and must be submitted by the Encarregado — the data protection officer the LGPD requires — with a document proving the appointment, or by an appointed representative. Without that proof inside the same deadline, the ANPD may open an Incident Investigation Procedure on its own initiative.
Paragraph 2 lists twelve mandatory pieces of information:
- the nature and category of the data affected;
- the number of data subjects affected, broken down for children, adolescents and the elderly;
- the technical and security measures adopted before and after the incident;
- the risks and possible impacts on data subjects;
- the reasons for any delay;
- the measures taken to reverse or mitigate the effects;
- the date of occurrence (where determinable) and the date of knowledge;
- the details of the Encarregado or of whoever represents the controller;
- identification of the controller and, where applicable, a declaration of small-scale status;
- identification of the processor, where applicable;
- a description of the incident, including the root cause where identifiable;
- the total number of data subjects whose data is processed in the affected activities.
If you cannot assemble all of that within three business days, there is a preliminary notification, to be completed with a reasoned filing within twenty business days (§3), submitted as an interim petition in the same process. The ANPD is unambiguous in its published FAQ: the preliminary notification is not sufficient to discharge the obligation under Article 48 and must be completed within the deadline.
To the data subject — Article 9
Notifying the ANPD is not enough. The ANPD itself records that Article 48 “is not discharged by merely notifying the security incident to the ANPD”: where there is relevant risk or harm, the controller must also notify the affected data subjects. These are two obligations, not one.
Same deadline: three business days from the moment of knowledge — also doubled for small-scale processing agents (Article 9, §6). The content differs — seven items, among them the nature and category of the data affected, the security measures used, the risks and possible impacts, the mitigation measures, the date of knowledge and a contact point for further information (plus the Encarregado’s details, where applicable).
Form matters as much as content:
- plain, easily understood language;
- direct and individual wherever data subjects are identifiable — telephone, e-mail, electronic message or letter;
- if that is not feasible, publication through the available channels (website, app, social media), directly and easily visible, for a minimum period of three months;
- and a declaration filed in the process confirming that the notification was made, stating the means used, within three business days after the end of the deadline (§4).
Paragraph 5 adds a concrete incentive: including recommendations that help the data subject mitigate the effects may be treated as good practice when the ANPD calibrates a sanction (Article 52, §1, IX, of the LGPD).
And if you are the processor?
The legal duty to notify belongs to the controller. When an incident occurs, the processor must inform the controller without undue delay and provide all the information needed for the notification — and the ANPD expressly recommends that these obligations between controller and processor be set out in the contract. Translated into deadlines: the controller’s three-business-day clock does not wait for the supplier, so the processor’s deadline has to be considerably shorter than your own.
The record almost nobody keeps (Article 10)
This is the most ignored obligation in the regulation: the controller must keep a record of every security incident — including those it decided not to report — for a minimum of five years.
The record must contain, as a minimum: the date of knowledge; a general description of the circumstances; the nature and category of the data affected; the number of data subjects affected; the assessment of risk and possible harm; the corrective and mitigating measures; the form and content of the notification, if there was one; and the reasons for not notifying, where that applies.
In other words: the decision not to notify has to be documented and defensible. That record is what the ANPD will ask for if it opens an investigation — and it can request, at any time, the record of processing operations (Article 37), the Data Protection Impact Report (Article 38) and the report on how the incident was handled.
The role of the Encarregado
Article 41 of the LGPD obliges the controller to appoint an Encarregado and to publicly disclose that person’s identity and contact details, “preferably on its website”. ANPD Board Resolution No. 18, of 16 July 2024, spelled out the role:
- the Encarregado may be a natural person (in-house or external) or a legal entity, and the appointment requires a formal instrument in writing, dated and signed, describing the ways of working and the activities — a document the ANPD may demand at any time;
- the processing agent must provide resources (human, technical and administrative), guarantee technical autonomy and direct access to the highest level of management;
- the Encarregado must be involved in the recording and notification of incidents, in the record of processing operations, in the impact report, in internal oversight mechanisms and in contractual instruments;
- there is a conflict of interest where the role is combined with functions that decide the means and purposes of processing — heads of IT, HR, finance or health are the classic cases cited by the ANPD, and a proven conflict may itself give rise to a sanction;
- and one point of relief: the Encarregado is not the party answerable to the ANPD for the compliance of the processing. That responsibility sits with the controller.
Small-scale processing agents may be exempted from the appointment (ANPD Board Resolution No. 2/2022), except where they carry out high-risk processing, have gross revenue above the thresholds in the regulation, or belong to an economic group that exceeds them. Even when exempted, they must maintain a communication channel with data subjects.
In practice: the Encarregado is the person who files with the ANPD. If that role is not in your incident response plan, your plan does not work on day one.
Sanctions: what the ANPD can impose (Article 52)
The correct figures, straight from the statutory text:
| Sanction | Detail |
|---|---|
| Warning | with a deadline for corrective measures |
| Simple fine | up to 2% of revenue of the private legal entity, group or conglomerate in Brazil, for its last financial year, excluding taxes, capped in total at R$ 50,000,000.00 per infraction |
| Daily fine | subject to the same overall cap |
| Publicization of the infraction | once investigated and confirmed |
| Blocking of the data | until the situation is remedied |
| Deletion of the data | relating to the infraction |
| Partial suspension of the database | up to 6 months, extendable for an equal period |
| Suspension of the processing activity | up to 6 months, extendable |
| Partial or total prohibition | of processing activities |
The last three (partial suspension, suspension of the activity and prohibition) may only be applied after at least one of the sanctions of fine, publicization, blocking or deletion has already been imposed in the same case (Article 52, §6).
Calibration matters as much as the ceiling. Article 52, §1 requires the authority to consider, among other criteria: the seriousness and nature of the infraction, good faith, cooperation, repeated adoption of internal mechanisms capable of minimizing harm, a policy of good practice and governance and prompt adoption of corrective measures. ANPD Board Resolution No. 4/2023 classifies infractions as minor, medium or serious and sets out the methodology for calculating the simple fine. During proceedings the ANPD may also order immediate preventive measures and set a daily fine to secure compliance with them (Article 15 of Resolution 15/2024).
The detail that matters most to anyone working in security is in Article 48, §3: when judging seriousness, the ANPD weighs “any evidence that adequate technical measures were adopted rendering the affected personal data unintelligible to unauthorized third parties”. Well-implemented encryption is not just technical hygiene — it is a mitigating factor written into the law.
One recent institutional change is worth noting: Law No. 15,352, of 25 February 2026 (the conversion of Provisional Measure 1,317/2025), inserted Article 55-A into the LGPD and established the Agência Nacional de Proteção de Dados (ANPD) as a special-status autonomous agency linked to the Ministry of Justice and Public Security, with functional, technical, decision-making, administrative and financial autonomy, its own assets and its seat in the Federal District. The same law created a dedicated Data Protection Regulation and Enforcement career track. In practice: the same acronym, with more enforcement muscle.
Concrete technical measures
The ANPD’s information security guidance note (written for small-scale processing agents, but useful at any size) organizes the measures into administrative and technical. Cross-referencing that guidance with what Article 48 requires you to be able to answer within three business days:
Encryption. In transit, TLS/HTTPS everywhere — including internal integrations and e-mail carrying HR or health data. At rest, encryption of sensitive fields and of backups. Remember Article 48, §3: if the leaked data is unintelligible, the assessed seriousness drops.
Access control. The ANPD breaks access control into three functions: authentication (who is accessing), authorization (what they may do) and auditing (what was done). In practice: least privilege (need to know), MFA on systems holding personal data, a password complexity policy, replacement of vendor default passwords and a ban on shared accounts or passwords — which the ANPD calls a “critical vulnerability vector”.
Audit trail. Record authentications and authentication failures, access to personal data, permission changes, exports and administrative operations. The test is simple: can you say, within three business days, how many data subjects were affected, which categories of data were involved and what the root cause was? If the answer depends on archaeology in application logs, the incident has already cost you your deadline.
Retention and deletion. Collecting only what is necessary (Article 6, III) and deleting whatever no longer has an active purpose reduces the attack surface of the next incident and the number of data subjects affected. Add secure disposal of media to that.
Ransomware-resilient backup. The ANPD’s recommendation is explicit: regular, complete backups, held somewhere other than the primary storage and not synchronized in real time — so that the attacker’s encryption is not replicated into them.
Vulnerability management. Systems and applications kept up to date, patches applied, hardening (disabling unnecessary services, changing every default password, continuously reviewing what is exposed to the internet) and anti-malware installed and updated — with explicit instructions to users not to switch off security settings. The ANPD guidance cites research by CERT.br together with Cetic.br: keeping everything updated, hardening, and improving identification and authentication (including not reusing passwords) are among the three highest-impact measures.
Suppliers. A contract with a processor needs an information security clause, defined controller/processor roles and an internal notification deadline compatible with your three business days.
Practical checklist
Before (standing posture)
- Encarregado appointed, contact details published on the website, free of conflicts of interest and with direct access to senior management
- Record of processing operations (Article 37) kept current — it is the source of the “total number of data subjects” in item 12
- A map of where sensitive, financial, authentication and children’s/adolescents’/elderly people’s data lives
- A written information security policy, reviewed periodically
- MFA, least privilege and periodic access reviews
- Encryption in transit and at rest, with key management
- An audit trail of authentication, access, modification and export — with retention compatible with the five years in Article 10
- Tested backups, offline or with a non-synchronized copy
- Security clauses and notification deadlines in contracts with processors
- Training and an internal channel for reporting incidents and vulnerabilities
During (the first three business days)
- Confirm that an adverse event occurred and that personal data was affected — the clock starts here
- Contain and preserve evidence (do not wipe logs to “clean up” the environment)
- Apply the Article 5 test: does it significantly affect rights and involve one of the six criteria?
- Bring in the Encarregado and assemble the 12 fields required by Article 6, §2
- File in SEI!ANPD with proof of representation — a preliminary notification if necessary
- Notify data subjects in plain language, individually, with mitigation recommendations
- If not everyone can be identified, publish through a wide-reaching channel and keep it up for 3 months
After
- Complete the notification within 20 business days, with reasons
- File the declaration confirming that data subjects were notified
- Record the incident with the 8 items required by Article 10 — including if you decided not to notify
- A post-mortem with root cause and documented corrective measures (direct weight in sanction calibration)
- Reassess the impact report and the affected controls
Where a platform helps — and where it does not
Tooling does not replace a governance programme, does not appoint your Encarregado and does not file with the ANPD on your behalf. What it can do is shorten the distance between “we found something” and “we have the twelve fields filled in”. At OODA Intelligence, the components that touch that workflow are:
- Audit & Compliance — more than 50 event types (authentication, data access, configuration changes, incidents), configurable retention, an integrity hash chain and immutable export (WORM).
- Users & Access — RBAC per module and action, MFA (TOTP, WebAuthn, SMS), SAML 2.0/OIDC SSO and access reviews.
- Incident Management — a response lifecycle with an immutable timeline and encrypted attachments, useful for producing the Article 10 record.
- Per-organization isolation and encryption of sensitive fields, as described on our LGPD page.
The rest — mapping processing activities, legal bases, contracts with processors, the decision on whether to notify — remains human work.
Official sources
Every article, deadline and figure cited here was checked against the official text:
- Law No. 13,709/2018 (LGPD) — Planalto
- Law No. 15,352/2026 — establishing the Agência Nacional de Proteção de Dados (Article 55-A of the LGPD)
- ANPD Board Resolution No. 15/2024 — Security Incident Notification Regulation (Official Gazette)
- ANPD Board Resolution No. 18/2024 — Regulation on the role of the Encarregado (Official Gazette)
- ANPD Board Resolution No. 2/2022 — Regulation for small-scale processing agents (Official Gazette)
- ANPD Board Resolution No. 4/2023 — Regulation on sanction calibration and the application of administrative sanctions
- ANPD — Security Incident Notification (procedure and FAQ)
- ANPD — Guidance note on information security for small-scale processing agents
- ANPD — Guidance note on the role of the Encarregado
- ANPD — Published regulations (official list)