Brazil data protection 2026 has entered a more demanding phase. The country';s data protection authority, the Autoridade Nacional de Proteção de Dados (ANPD), has accelerated its enforcement agenda, issued new guidance, and opened formal proceedings against organisations across multiple sectors. For foreign businesses operating in Brazil or processing the personal data of Brazilian residents, the compliance stakes are higher than at any point since the Lei Geral de Proteção de Dados Pessoais (LGPD) came into force. This guide covers the key regulatory developments of the first quarter, their practical implications, and the steps organisations should take to stay compliant.
What changed in Brazilian data protection law in Q1
The first quarter brought several notable regulatory moves. The ANPD published updated guidance on international data transfers, clarifying the conditions under which personal data may be sent to countries or organisations that do not offer an equivalent level of protection to that guaranteed by the LGPD. The guidance builds on the transfer mechanisms already established under the LGPD - standard contractual clauses, binding corporate rules, and adequacy decisions - and introduces more specific documentation requirements for each mechanism.
Separately, the ANPD issued a resolution addressing the processing of sensitive personal data, a category that under Article 11 of the LGPD includes health data, biometric data, racial or ethnic origin, and political opinions. The resolution tightens the conditions under which consent can be used as a legal basis for processing sensitive data, and it places new obligations on data controllers to maintain detailed records of their processing activities in this category. Organisations that rely on consent for health-related processing - a common situation in the insurtech and healthtech sectors - will need to review their consent mechanisms.
A third development concerns the ANPD';s regulatory agenda for data protection officers (DPOs), referred to in the LGPD as the Encarregado. The authority signalled its intention to formalise qualification requirements for DPOs, moving toward a model where the Encarregado must demonstrate specific competencies. While the formal rule has not yet been enacted, organisations should treat this as a near-term compliance requirement and audit their current DPO arrangements.
ANPD enforcement actions: key cases and patterns
Enforcement activity increased noticeably in the first quarter. The ANPD concluded several administrative proceedings and issued fines and corrective orders against organisations in the financial services, retail, and telecommunications sectors. While the ANPD does not always publish the full text of its decisions immediately, the patterns that emerge from publicly available summaries are instructive.
The most common violations cited in recent proceedings include:
- Failure to appoint a DPO or to make the DPO';s contact details publicly available, as required by Article 41 of the LGPD.
- Processing personal data without a valid legal basis under Article 7 of the LGPD.
- Inadequate response to data subject access requests within the statutory timeframe.
- Failure to notify the ANPD and affected data subjects of a personal data breach within a reasonable period.
The ANPD has made clear that it will treat repeat violations and failures to cooperate with investigations as aggravating factors when calculating sanctions. Under the LGPD, fines can reach up to two percent of a company';s revenue in Brazil in the preceding financial year, capped at a significant ceiling per infraction. In practice, the authority has so far imposed fines at the lower end of the available range for first-time violations, but the trajectory is toward more substantial penalties as enforcement matures.
A common mistake among foreign companies is to assume that because their servers are located outside Brazil, they fall outside the LGPD';s territorial scope. Article 3 of the LGPD applies the law to any processing operation carried out in Brazil, to any processing of data collected in Brazil, and to any processing aimed at offering goods or services to individuals in Brazil. The location of the data controller';s headquarters is irrelevant.
International data transfers: updated requirements for cross-border flows
One of the most practically significant developments of the quarter concerns international data transfers. The ANPD';s updated guidance operationalises the transfer mechanisms set out in Articles 33 to 36 of the LGPD and introduces a clearer procedural framework for each.
For transfers based on standard contractual clauses, the guidance specifies that the clauses must be executed before the transfer begins, must cover the full chain of sub-processors, and must be retained and made available to the ANPD on request. Organisations that have been relying on informal arrangements or on clauses drafted for other jurisdictions - such as the EU';s standard contractual clauses - should note that the ANPD has indicated it will publish Brazil-specific model clauses. Until those are available, organisations should document their transfer arrangements carefully and be prepared to justify their approach.
For transfers within corporate groups, binding corporate rules remain an option, but the ANPD';s approval process is resource-intensive and the authority has processed only a limited number of applications to date. In practice, most multinational groups operating in Brazil are using standard contractual clauses or relying on the specific derogations in Article 33, such as transfers necessary for the performance of a contract with the data subject.
A non-obvious requirement that surfaces in the ANPD';s guidance is the obligation to conduct a transfer impact assessment before relying on standard contractual clauses for transfers to certain destinations. This mirrors the approach taken in the EU following the Schrems II ruling, and organisations familiar with EU practice will recognise the framework, but the Brazilian version has its own procedural specifics that must be followed.
In practice, founders and compliance teams should consider mapping all data flows out of Brazil at the outset of any new product or service launch, rather than retrofitting transfer mechanisms after the fact. Retroactive compliance is significantly more expensive and time-consuming.
If your organisation processes personal data of Brazilian residents and transfers that data internationally, contact info@vlolawfirm.com. We can help structure the setup correctly the first time.
Sensitive data and consent: what the new resolution means in practice
The ANPD';s resolution on sensitive personal data has direct implications for a wide range of businesses. Health data is the most commercially significant category. Insurers, health platforms, telemedicine providers, and employers who collect health information from employees are all affected.
Under the LGPD, sensitive personal data may only be processed on the basis of specific legal grounds listed in Article 11. Consent is one of those grounds, but it must be specific, informed, and freely given. The new resolution clarifies that consent for sensitive data processing must be granular - a single blanket consent covering multiple processing purposes is not sufficient. Each distinct purpose must be consented to separately.
The resolution also addresses the processing of biometric data, which has become increasingly common in access control systems, payment authentication, and identity verification. Organisations using biometric data must now maintain a specific record of the legal basis for each biometric processing activity, the retention period, and the security measures applied. This record must be kept separately from the general records of processing activities and must be available for inspection.
For employers, the resolution has implications for workplace monitoring and health screening programmes. Processing employee health data is permissible under the LGPD in certain circumstances - for example, where required by occupational health legislation - but the resolution makes clear that the employer cannot rely on consent as the legal basis where there is a power imbalance between employer and employee that makes consent genuinely free. This is consistent with the approach taken by data protection authorities in other jurisdictions and should prompt HR and legal teams to review the legal bases they are using for employee data processing.
A practical scenario: a multinational company operating a wellness programme in Brazil that collects health data from employees and shares it with a third-party wellness provider will need to identify a legal basis other than consent for that processing, or restructure the programme so that participation is genuinely voluntary and consent is freely given. The distinction between the two scenarios is not always obvious and requires careful legal analysis.
Data breach notification: timelines, obligations, and common failures
Data breach notification remains one of the most operationally challenging areas of LGPD compliance. Article 48 of the LGPD requires data controllers to notify the ANPD and affected data subjects of a security incident that may result in relevant risk or damage to data subjects. The ANPD has issued guidance specifying that notification should occur within a reasonable period, which the authority has interpreted as 72 hours from the moment the controller becomes aware of the incident - a standard that aligns with the EU General Data Protection Regulation but that many organisations in Brazil have not yet operationalised.
The enforcement cases from the first quarter reveal a consistent pattern: organisations are notifying the ANPD, but they are doing so late, and the notifications often lack the information required by the ANPD';s guidance. A compliant notification must include a description of the nature of the incident, the categories and approximate number of data subjects affected, the categories and approximate number of personal data records concerned, the likely consequences of the breach, and the measures taken or proposed to address it.
Many underestimate the internal coordination required to produce a compliant notification within 72 hours. In practice, this requires a pre-existing incident response plan, clear internal escalation procedures, and a designated team with authority to make decisions quickly. Organisations that have not yet developed an incident response plan should treat this as a priority.
A second practical scenario: a Brazilian e-commerce company suffers a ransomware attack that encrypts customer data. The company';s IT team spends the first 48 hours attempting to restore systems without informing the legal or compliance team. By the time the DPO is notified, the 72-hour window has already closed. The ANPD treats the late notification as an aggravating factor in any subsequent proceeding. This scenario is not hypothetical - it reflects the pattern seen in several of the ANPD';s recent enforcement decisions.
Practical steps for organisations operating in Brazil
The developments of the first quarter point to a clear set of priorities for organisations that process personal data in Brazil or that are subject to the LGPD on the basis of their activities targeting Brazilian residents.
The first priority is a legal basis audit. Organisations should map every processing activity against the legal bases available under Article 7 (for general personal data) and Article 11 (for sensitive personal data) of the LGPD, and confirm that each activity has a documented, defensible legal basis. Where consent is being used, organisations should assess whether it meets the LGPD';s standards for specificity and freedom.
The second priority is DPO compliance. The Encarregado must be appointed, must have the competencies to perform the role effectively, and must be publicly identified - typically on the organisation';s website and in its privacy policy. The ANPD has indicated that it will scrutinise DPO arrangements more closely as it moves toward formalising qualification requirements.
The third priority is international transfer documentation. Any organisation transferring personal data out of Brazil should have a documented transfer mechanism in place, a record of that mechanism, and - where required - a transfer impact assessment. Relying on informal arrangements or on transfer mechanisms designed for other jurisdictions is a compliance risk.
The fourth priority is incident response readiness. Organisations should have a written incident response plan that covers the 72-hour notification requirement, designates a response team, and includes template notifications for the ANPD and for data subjects.
The fifth priority is records of processing activities. The LGPD requires data controllers and processors to maintain records of their processing activities. The ANPD has made clear that it will request these records as a standard part of any investigation, and that incomplete or absent records will be treated as a compliance failure in their own right.
To discuss how these requirements apply to your specific operations in Brazil, contact info@vlolawfirm.com. We can assist with documents and filings.
FAQ
What is the ANPD';s current approach to fines for first-time LGPD violations?
The ANPD has the authority to impose fines of up to two percent of a company';s revenue in Brazil in the preceding financial year, subject to a statutory cap per infraction. In practice, the authority has applied fines at the lower end of the available range for first-time violations, particularly where the organisation cooperated with the investigation and took corrective action promptly. However, the ANPD has signalled that it will increase the severity of sanctions as enforcement matures and as organisations have had sufficient time to achieve compliance. Repeat violations, failure to cooperate, and evidence of deliberate non-compliance are treated as aggravating factors. Organisations should not rely on the current relatively modest fine levels as a guide to future enforcement.
How quickly must a Brazilian data breach be reported, and what does the notification need to include?
The ANPD has interpreted the LGPD';s "reasonable period" notification requirement as 72 hours from the moment the data controller becomes aware of a security incident that may cause relevant risk or damage to data subjects. The notification must describe the nature of the incident, the categories and approximate number of affected data subjects and records, the likely consequences, and the measures taken or proposed. If all required information is not available within 72 hours, the organisation should submit an initial notification with the information available and follow up with a supplementary notification as soon as the remaining information is confirmed. Late or incomplete notifications have been cited as aggravating factors in ANPD enforcement proceedings.
Does the LGPD apply to a foreign company that has no legal entity in Brazil?
Yes. The LGPD applies on the basis of three alternative territorial triggers set out in Article 3: the processing operation takes place in Brazil; the processing involves data collected in Brazil; or the processing is carried out for the purpose of offering goods or services to individuals located in Brazil. A foreign company with no Brazilian subsidiary but with a website that accepts orders from Brazilian consumers, or a software-as-a-service provider whose Brazilian customers upload personal data to the platform, will typically be subject to the LGPD. The location of servers, the nationality of the company, and the absence of a local legal entity are not determinative. Foreign companies in this position should appoint a DPO and consider whether they need a local representative to facilitate communication with the ANPD.
Conclusion
The first quarter has confirmed that Brazil';s data protection framework is moving from a period of regulatory construction into one of active enforcement. The ANPD is issuing more specific guidance, opening more proceedings, and signalling higher expectations for compliance. Organisations that have treated LGPD compliance as a background task should treat these developments as a prompt to reassess their programmes.
VLO Law Firms advises international clients on data protection matters in Brazil. We can assist with LGPD compliance audits, DPO arrangements, international data transfer documentation, incident response planning, and engagement with the ANPD. To request a consultation, contact: info@vlolawfirm.com