Legal-Updates
2026-07-27 00:00 Legal-Updates

Data Protection Update in Brazil: Q3 2026

Brazil data protection 2026 has entered a more assertive phase. The Autoridade Nacional de Proteção de Dados (ANPD) - Brazil';s national data protection authority - has moved decisively from institution-building to active enforcement, issuing binding decisions, publishing new guidance and signalling higher penalties for non-compliance. For international businesses operating in Brazil or processing data of Brazilian residents, the stakes are now materially higher than in prior years. This guide covers the most significant regulatory and legislative developments of the current quarter, the enforcement cases shaping practice, and the concrete compliance steps that organisations should prioritise.

What is driving the current shift in Brazil data protection 2026

Brazil';s data protection framework is anchored in the Lei Geral de Proteção de Dados Pessoais (LGPD), Federal Law No. 13,709, which entered into force in recent years and established comprehensive rules for the processing of personal data by public and private entities. The LGPD was modelled in part on the European General Data Protection Regulation but contains several Brazil-specific features, including a distinct set of legal bases for processing, rules on the processing of sensitive data and a specific regime for international data transfers.

The ANPD was established as an independent federal authority with powers to regulate, inspect, apply sanctions and promote data protection culture. In its early phase, the ANPD focused on issuing guidance and building its institutional capacity. The current period marks a clear transition: the authority has published its updated enforcement strategy, expanded its technical staff and begun issuing fines that, while still below the LGPD';s statutory ceiling of two percent of a company';s Brazilian revenue, are large enough to attract serious board-level attention.

The ANPD';s regulatory agenda for the current cycle includes finalisation of rules on international data transfers, updated guidance on the legitimate interest legal basis, and a new framework for processing children';s and adolescents'; data. Each of these areas has direct operational implications for businesses across sectors.

A further driver is the Brazilian judiciary. Courts at federal and state level have been adjudicating LGPD-based claims with increasing frequency. Decisions have addressed the right of access, the right to deletion, liability for data breaches and the relationship between the LGPD and sector-specific legislation such as the consumer protection code (Código de Defesa do Consumidor, Law No. 8,078) and the banking secrecy law (Lei Complementar No. 105). The interaction between these legal regimes creates complexity that purely LGPD-focused compliance programmes may miss.

Recent ANPD regulatory actions and guidance

The ANPD has published several significant normative acts and guidance documents in the current period. Organisations should treat these as binding or near-binding depending on their form.

The authority';s updated regulation on international data transfers is among the most consequential recent developments. The ANPD has established a tiered mechanism: transfers to countries or international organisations that the ANPD has recognised as providing an adequate level of protection may proceed without additional safeguards. For transfers to non-adequate destinations, organisations must rely on standard contractual clauses approved by the ANPD, binding corporate rules, specific derogations or other mechanisms recognised under LGPD Article 33. The ANPD has published its own model standard contractual clauses, which differ in several respects from European equivalents. Organisations that have relied on European-style clauses without adaptation should review their transfer documentation.

The ANPD has also issued updated guidance on the legitimate interest legal basis under LGPD Article 10. The guidance clarifies that legitimate interest is not a residual catch-all and requires controllers to conduct and document a balancing test. The authority has indicated that it will scrutinise legitimate interest claims closely in enforcement proceedings, particularly where the processing involves large volumes of data or sensitive categories. In practice, organisations that have used legitimate interest broadly - for example, to justify marketing analytics or profiling - should revisit their legal basis assessments.

A third area of regulatory activity concerns the processing of children';s and adolescents'; data. The ANPD has published a draft regulation that would impose heightened requirements on controllers processing data of individuals under 18, including specific consent requirements, enhanced transparency obligations and restrictions on profiling. The draft is currently in a public consultation phase. Businesses in the education technology, gaming, social media and retail sectors should monitor this closely, as the final regulation is expected to impose significant operational changes.

The ANPD has also updated its guidance on data protection officers (DPOs). Under the LGPD, controllers and processors must designate a DPO (referred to in the statute as the "encarregado"). The updated guidance clarifies that the DPO may be an individual or a legal entity, may be internal or external, and must have genuine independence and resources. The ANPD has signalled that it will verify DPO designations as part of its inspection process, and that nominal or paper designations will not satisfy the requirement.

Enforcement trends and notable cases

Enforcement activity has accelerated. The ANPD has concluded several administrative proceedings and issued fines, public warnings and corrective orders. The cases decided in the current period illustrate the authority';s priorities and the practical risks for non-compliant organisations.

One significant case involved a financial services company that suffered a data breach affecting a large number of customers. The ANPD found violations of the LGPD';s security obligations under Article 46, which requires controllers and processors to adopt technical and administrative measures capable of protecting personal data from unauthorised access and accidental or unlawful situations. The authority also found a failure to notify the ANPD and affected data subjects within the required timeframe. The LGPD does not specify an exact notification deadline in hours, but the ANPD';s guidance indicates that notification should occur within a reasonable period, and the authority has treated delays of more than a few days as aggravating factors. The company received a fine and a public warning, both of which were published on the ANPD';s website.

A second notable case involved a data broker that was found to be processing personal data without a valid legal basis. The ANPD determined that the company';s reliance on legitimate interest was not supported by a documented balancing test and that the processing was disproportionate to any legitimate purpose. The authority ordered the company to cease processing and to delete the data in question, in addition to imposing a financial penalty. This case is significant because it demonstrates that the ANPD is willing to order operational disruption, not merely financial penalties.

A third area of enforcement activity concerns the rights of data subjects. The ANPD has received a significant volume of complaints from individuals asserting rights under the LGPD, including the right of access (Article 18(I)), the right to correction (Article 18(III)), the right to deletion (Article 18(VI)) and the right to data portability (Article 18(V)). The authority has issued decisions requiring organisations to respond to data subject requests within the statutory period and has treated systematic failures to respond as evidence of broader compliance deficiencies.

In practice, founders and compliance officers should consider that the ANPD';s published enforcement decisions function as a de facto guidance library. Each decision clarifies how the authority interprets specific LGPD provisions and what it expects from controllers and processors. Reviewing these decisions is an efficient way to identify compliance gaps.

If your organisation is navigating ANPD enforcement proceedings or reviewing its LGPD compliance programme, contact info@vlolawfirm.com. We can assist with documents and filings.

Practical compliance priorities for international businesses

International businesses operating in Brazil face a specific set of challenges. Many have compliance programmes designed around European or North American frameworks that do not map cleanly onto the LGPD. A common mistake is to assume that GDPR compliance is sufficient for Brazil. While the two frameworks share structural similarities, the LGPD has distinct legal bases, different rules on sensitive data, a different approach to international transfers and a separate enforcement authority with its own priorities.

The following areas represent the most pressing compliance priorities in the current period.

Legal basis review. Controllers should audit their processing activities and confirm that each activity is supported by a valid LGPD legal basis. The LGPD provides ten legal bases for processing general personal data and eight for sensitive personal data. Consent under the LGPD must be free, informed, unambiguous and specific to a purpose. Unlike the GDPR, the LGPD does not recognise a general "legitimate interests" basis for sensitive data processing. Organisations that have mapped their GDPR legal bases onto the LGPD without a Brazil-specific review are likely to have gaps.

International transfer documentation. Following the ANPD';s updated transfer regulation, organisations should confirm that all transfers of personal data outside Brazil are covered by an appropriate mechanism. This includes transfers to group companies, cloud service providers, analytics platforms and other processors located outside Brazil. The ANPD';s model standard contractual clauses should be used where applicable, and existing contracts should be reviewed for compatibility.

Data breach response procedures. The LGPD requires notification of the ANPD and affected data subjects in the event of a security incident that may cause risk or damage to data subjects. Organisations should have a documented incident response procedure that includes a clear escalation path, a process for assessing whether notification is required and a mechanism for notifying the ANPD. The ANPD';s notification form and guidance are available on its official portal.

Data subject rights management. Organisations should have a functioning process for receiving, logging and responding to data subject requests. The LGPD does not specify a response deadline in days in the same way as the GDPR';s 30-day rule, but the ANPD has indicated in guidance and enforcement decisions that responses should be provided promptly and that delays of more than 15 working days are likely to be treated as non-compliance.

Vendor and processor management. The LGPD imposes obligations on both controllers and processors. Controllers are responsible for ensuring that processors provide sufficient guarantees of compliance. Data processing agreements should be reviewed to confirm that they address the LGPD';s requirements, including the processor';s obligations on security, subcontracting and cooperation with the ANPD.

A non-obvious requirement is that the LGPD applies to processing carried out in Brazil, to processing aimed at offering goods or services to individuals located in Brazil, and to processing of data collected in Brazil - regardless of where the controller or processor is established. This extraterritorial scope means that foreign companies with no physical presence in Brazil may nonetheless be subject to the LGPD if they target Brazilian consumers or process data collected in Brazil.

Sector-specific developments

Several sectors are experiencing heightened regulatory attention in the current period.

Financial services. The intersection of the LGPD and Brazil';s open finance framework (Sistema Financeiro Aberto, regulated by the Banco Central do Brasil) continues to generate compliance complexity. Financial institutions must navigate both the LGPD';s consent and legal basis requirements and the specific rules on data sharing under the open finance regime. Recent ANPD guidance has clarified that consent obtained for open finance purposes must meet the LGPD';s standards and that financial institutions cannot rely on the open finance framework as a standalone legal basis for processing that goes beyond the specific purposes authorised by the customer.

Health and life sciences. Health data is classified as sensitive personal data under LGPD Article 11 and may only be processed on a limited set of legal bases, including explicit consent, the performance of a contract, compliance with a legal obligation, the protection of life, and specific public health purposes. The ANPD has indicated that it regards health data processing as a priority enforcement area. Pharmaceutical companies, health technology platforms and clinical research organisations should ensure that their legal basis assessments for health data processing are robust and documented.

E-commerce and retail. The ANPD has received a significant number of complaints from consumers in the retail sector, particularly relating to the use of personal data for targeted advertising and profiling. Retailers should review their cookie and tracking practices, their consent mechanisms and their privacy notices to ensure alignment with current ANPD guidance. A common mistake in this sector is to rely on pre-ticked consent boxes or bundled consent, both of which the ANPD has indicated are inconsistent with the LGPD';s requirements.

Technology and artificial intelligence. The use of artificial intelligence and automated decision-making is an emerging area of LGPD compliance. Article 20 of the LGPD gives data subjects the right to request a review of decisions made solely on the basis of automated processing that affect their interests. The ANPD has indicated that it is developing specific guidance on AI and automated decision-making, and that existing LGPD obligations - including transparency, purpose limitation and data minimisation - apply fully to AI systems. Organisations deploying AI in Brazil should begin mapping their automated decision-making processes against LGPD requirements now, rather than waiting for specific AI guidance.

Many underestimate the compliance burden associated with AI systems that process personal data. The combination of LGPD Article 20 rights, transparency obligations and the ANPD';s emerging AI agenda means that organisations deploying AI at scale in Brazil face a materially more complex compliance environment than in prior periods.

FAQ

What are the most significant practical risks for a foreign company processing data of Brazilian residents?

The primary risk is that the LGPD applies extraterritorially to any processing aimed at offering goods or services to individuals in Brazil or involving data collected in Brazil, regardless of where the company is established. Foreign companies that have not conducted a Brazil-specific LGPD assessment may be processing data without a valid legal basis, without adequate transfer mechanisms and without functioning data subject rights procedures. The ANPD has the power to impose fines, order data deletion and issue public warnings, all of which can have reputational and operational consequences. A further risk is that Brazilian consumers can bring LGPD-based claims before consumer protection bodies and courts, creating parallel litigation exposure alongside ANPD enforcement.

How long does it typically take to build a functional LGPD compliance programme, and what does it cost?

The timeline and cost depend heavily on the size and complexity of the organisation and the maturity of its existing privacy programme. For a mid-sized international company with moderate data processing activities, a baseline LGPD compliance programme - covering data mapping, legal basis assessment, privacy notices, data subject rights procedures, vendor contracts and a DPO designation - typically takes several months to implement properly. Organisations with complex data ecosystems, multiple legal entities or significant sensitive data processing should expect a longer timeline. Professional fees for legal and technical advisory work vary considerably; organisations should budget for both legal counsel and, where relevant, technical privacy engineering support. Ongoing compliance costs include DPO resourcing, periodic audits and training.

Should a company appoint an internal or external DPO for Brazil?

The LGPD permits both internal and external DPO appointments, and the ANPD';s updated guidance confirms that a legal entity may serve as DPO. The choice depends on the organisation';s size, the volume and sensitivity of its data processing, and its existing resources. An internal DPO provides closer integration with business operations and faster response times but requires investment in training and must have genuine independence from operational management. An external DPO - typically a law firm or specialist privacy consultancy - provides expertise and independence but may have less visibility into day-to-day processing activities. For smaller organisations or those entering the Brazilian market for the first time, an external DPO is often the more practical initial solution. Regardless of the model chosen, the DPO must be publicly identified and accessible to data subjects and the ANPD.

Conclusion

Brazil';s data protection environment has matured significantly. The ANPD is an active enforcement authority, the courts are adjudicating LGPD claims with greater frequency, and sector-specific regulatory developments are adding layers of complexity across financial services, health, retail and technology. International businesses that have not yet conducted a Brazil-specific LGPD compliance review face material legal and reputational risk. The practical priorities are clear: legal basis review, transfer documentation, breach response, data subject rights management and vendor oversight.

VLO Law Firms advises international clients on data protection matters in Brazil. We can assist with LGPD compliance assessments, DPO services, data transfer documentation, ANPD proceedings and privacy programme implementation. To request a consultation, contact: info@vlolawfirm.com