Artifact GuideBrazilANPD Enforcement and Fines

Brazil LGPD ANPD Enforcement and Fines

An LGPD infringement does not produce an automatic fine. The ANPD must use an administrative proceeding, allow defense and contradiction, classify the infringement, and justify the sanction under the LGPD and Resolution 4/2023.

Use the alleged infringement, procedural notice, severity factors, remediation record, and verified revenue data to plan the response.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
3

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

When the ANPD opens an enforcement matter, first preserve the notice and underlying records, identify each alleged LGPD or ANPD-rule infringement, calendar the deadline stated in the proceeding, and stop or correct any continuing unlawful processing. Then build the response around the facts, defense, affected rights, harm, cooperation, governance, mitigation, recurrence history, and financial inputs. Resolution 4/2023 controls sanction selection and the calculation of a ; it does not replace the defense rights and procedure required by the LGPD.

Section 1

How does an ANPD enforcement matter move from allegation to sanction?

Resolution 4/2023 says the ANPD applies sanctions only after an administrative proceeding and a reasoned decision, with full defense, contradiction, and due process. The decision must identify the facts and legal grounds and, when it imposes a sanction, state the relevant action, deadline, payment amount, or daily-fine terms.

The ANPD may use monitoring, orientation, prevention, and repression within its inspection framework, as well as preventive or corrective measures and Article 52 sanctions. Failure to comply with a preventive measure can aggravate a later sanction, while failure to comply with a sanction or regularize the conduct can lead the ANPD to escalate its response. Treat every official request, measure, and deadline as a separate obligation rather than waiting for a fine decision.

Keep the stages distinct: an information request or inspection finding is not a final infringement decision, and a corrective measure is not automatically a monetary sanction. The notice and current procedural record control what response is due, when it is due, and which review or appeal route is available.

  • Create an allegation table: cited provision, alleged act or omission, affected processing, factual response, supporting record, remediation, owner, and procedural date.
  • Preserve the original records and decision history. Do not create or backdate compliance evidence after the notice.
  • Identify whether the matter concerns the controller, an operator, or both; contracts do not override the ANPD's case-specific assessment of actual roles and conduct.
  • Keep ANPD administrative exposure separate from civil, consumer, labor, criminal, contractual, and sector-regulator exposure.
Section 2

How does the ANPD classify an infringement and choose a sanction?

Resolution 4/2023 classifies an infringement as light, medium, or serious. A medium infringement can significantly affect data subjects' fundamental interests and rights by materially limiting a right or service or causing material or moral harm, unless it meets the serious test. A serious infringement meets the medium test plus a listed factor, such as large-scale processing, economic advantage, risk to life, sensitive or children's data, processing without a legal basis, unlawful or abusive discrimination, or systematic irregular practices. Obstruction of ANPD supervision is also serious.

A warning may be used for a light or medium infringement without specific recidivism, or when corrective measures are needed. A applies when the infringer fails to meet preventive or corrective measures, the infringement is serious, or another sanction is unsuitable in light of the conduct, processing, data, and case circumstances. The ANPD must still justify its choice.

  • Map the affected data categories, number and vulnerability of data subjects, processing scale, purpose, legal basis, and effect on rights or access to a service.
  • Document whether the conduct continues and whether the organization has complied with every preventive or corrective measure.
  • Check the previous five years for final ANPD decisions relevant to specific or generic recidivism under Resolution 4/2023.
  • Do not label a case light, medium, or serious from one fact alone; apply the complete Article 8 test to the actual processing and affected rights.
Section 3

How does ANPD calculate and adjust a simple fine?

The ANPD calculates a value base for each infringement from its classification, the degree of harm, and the infringer's revenue in the business activity affected. If reliable activity-specific revenue is unavailable, Resolution 4/2023 provides alternatives, including total Brazil revenue in defined circumstances. The statutory basis is not worldwide group turnover.

The ANPD then applies aggravating and mitigating factors. Specific recidivism adds 10% per case up to 40%; generic recidivism adds 5% per case up to 20%; failure to meet orientation or preventive measures adds 20% per measure up to 80%; and failure to meet corrective measures adds 30% per measure up to 90%. Mitigation can reduce the amount for timely cessation, implemented governance and damage-minimization controls, timely measures that reverse or mitigate effects, and cooperation or good faith. The infringer bears the burden of proving the mitigating conditions.

  • Validate the legal entity, group or conglomerate, affected business activity, revenue period, exclusions, and source documents before giving the ANPD financial inputs.
  • Separate remediation adopted voluntarily and on time from action taken only to comply with an administrative or judicial order; the latter does not earn the cessation or mitigation reductions in Article 13.
  • Preserve evidence of when processing stopped, when mitigation began, which data subjects were protected, and how the measure reduced or reversed harm.
  • Check both statutory ceilings: the cannot exceed 2% of the applicable Brazil revenue basis, excluding taxes, or R$50 million per infringement.
  • After a final monetary decision, calendar the payment terms in the decision. Resolution 4/2023 allows up to 20 business days from official notice, doubles that period for qualifying small processing agents, and provides a 25% reduction only when the infringer waives the appeal and pays within the stated period.
Section 4

What evidence should the response team assemble?

Legal or regulatory affairs should coordinate the proceeding. Privacy, security, product, operations, finance, and the relevant controller or operator should supply verified evidence within their remit. The response should connect every factual assertion to a contemporaneous record and every remedial claim to a dated outcome.

Keep a single chronology from the processing decision or incident through notice, investigation, containment, data-subject communications, remediation, ANPD submissions, and final action. Record disputed facts and legal positions clearly; cooperation does not require conceding an unsupported allegation.

  • Proceeding record: notice, service date, deadlines, submissions, requests, decisions, and proof of compliance with each measure.
  • Processing record: actual roles, purposes, legal bases, data categories, data subjects, systems, recipients, transfers, retention, and responsible decision-makers.
  • Control record: policies, training, access controls, assessments, monitoring, incident response, rights handling, contracts, audits, and evidence that each control operated in practice.
  • Impact and remediation record: affected rights, harm analysis, containment, cessation, corrections, communications, mitigation, verification, and recurrence prevention.
  • Dosimetry record: prior final ANPD matters, governance and cooperation evidence, affected-activity revenue, tax exclusions, and finance approval of submitted figures.
Primary sources

References and citations

gov.br
Referenced sections
  • The ANPD's inspection and sanctioning-process regulation governs regulated-agent duties, records, information requests, audits, procedural measures, and sanctioning proceedings, as amended.
Related guides

Explore more topics

Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.