The controller must notify the ANPD and affected people when a confirmed incident involving LGPD-covered personal data may cause relevant risk or damage.
Resolution 15/2024 generally sets a three-business-day clock from the controller's knowledge, unless sector-specific law requires a shorter period.
Use three gates under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD): confirm that a occurred, confirm that it involves personal data subject to the LGPD, and assess whether it may cause . If all three are met, the controller must notify the Agência Nacional de Proteção de Dados (ANPD) and affected people. Start the clock when the controller knows that the incident affected personal data; an operator must inform the controller without unjustified delay and provide the information needed for the notices.
1
Section 1
What should teams decide about Breach Notification under the Brazil LGPD?
Resolution 15/2024 defines an incident as a confirmed adverse event that violates confidentiality, integrity, availability, or authenticity of personal-data security. A vulnerability without a confirmed adverse event is not by itself a reportable incident, and an event involving only data that is not personal data does not meet the LGPD gate.
requires a potential significant effect on fundamental interests and rights and, cumulatively, at least one listed factor: sensitive data; data about children, adolescents, or older people; financial data; system-authentication data; data protected by legal, judicial, or professional secrecy; or large-scale data.
Confirm the event, affected processing, personal-data categories, people, volume, systems, controller, operators, and whether the LGPD applies.
Assess likely material, moral, reputational, discriminatory, identity-theft, fraud, physical, or other effects, together with protective measures and post-incident mitigation.
Record the controller's knowledge date and the three-business-day calculation; identify any shorter sector-specific deadline.
Document the report or the reasoned no-report decision. The controller must keep incident records, including non-reportable incidents, for at least five years.
Who should own Breach Notification, and what evidence should prove the decision?
The controller owns the Article 48 decision and communication. Security investigates and contains the event; operators notify the controller and provide available information without delay; privacy or legal applies the reportability test; communications and support teams prepare clear, direct instructions for affected people.
Notify the ANPD and affected people within three business days, unless a shorter period applies. If justified information is unavailable, make a and provide the complement within 20 business days from the preliminary filing. A preliminary filing does not complete Article 48 by itself.
The ANPD filing should identify the incident, affected data and people, controller and operator, occurrence and knowledge dates, risks, technical and security measures, mitigation, data-subject communication, any delay, and the controller's contact route. The notice to affected people should explain the nature and categories of affected data, protection measures subject to protected secrets, risks, the controller's knowledge date, mitigation or reversal measures, recommended steps, delay where relevant, and a contact for questions.
Name one accountable owner and one reviewer for the Breach Notification workflow.
Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
Keep occurrence and knowledge times, affected systems and backups, data and people, controller and operator facts, risk analysis, containment, deadline calculation, filed forms, affected-person notice, supplements, remediation, and approval.
If notice is late, explain the reason. Preserve proof of the filing route and delivery to affected people.
Encryption, pseudonymisation, containment, or deletion by the recipient can reduce risk but does not automatically end the assessment. Consider whether the measures genuinely prevent identification or harmful use, the type and volume of data, vulnerable groups, likely consequences, and whether mitigation reached every affected copy.
A single event can involve several controllers. Each controller must assess its own Article 48 duty. An operator should not file as if it were the controller unless it is legally representing the controller through the accepted procedure.
Do not wait for complete forensic certainty if the notification gate and clock are already met; use the preliminary and complementary route where justified.
Do not notify only the ANPD when the same reportability test also requires notice to affected people.
Tailor the affected-person notice to the risks and mitigation they can use; avoid marketing language or a notice that hides the incident.
Check sector rules and eligible small-agent timing separately; use the shortest applicable period.
The output should be either a reasoned no-report decision or a matched ANPD and affected-person communication package. Update it if later facts change the risk assessment, population, data, or mitigation.
Exercise the workflow with incomplete facts so the team can use preliminary and complementary filings.
Pre-approve roles and contact routes, but draft the notice from the actual incident and risks.
Track promises made to affected people and verify that mitigation and follow-up are completed.
Reassess the control after an incident, near miss, vendor change, new data category, or ANPD procedure change.
Official explanation of the confirmed-incident, LGPD-data, and relevant-risk gates; risk factors; filing route; timing; phased communication; and records.