Artifact GuideBrazilBreach Notification

Brazil LGPD Breach Notification

The controller must notify the ANPD and affected people when a confirmed incident involving LGPD-covered personal data may cause relevant risk or damage.

Resolution 15/2024 generally sets a three-business-day clock from the controller's knowledge, unless sector-specific law requires a shorter period.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use three gates under Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD): confirm that a occurred, confirm that it involves personal data subject to the LGPD, and assess whether it may cause . If all three are met, the controller must notify the Agência Nacional de Proteção de Dados (ANPD) and affected people. Start the clock when the controller knows that the incident affected personal data; an operator must inform the controller without unjustified delay and provide the information needed for the notices.

Section 1

What should teams decide about Breach Notification under the Brazil LGPD?

Resolution 15/2024 defines an incident as a confirmed adverse event that violates confidentiality, integrity, availability, or authenticity of personal-data security. A vulnerability without a confirmed adverse event is not by itself a reportable incident, and an event involving only data that is not personal data does not meet the LGPD gate.

requires a potential significant effect on fundamental interests and rights and, cumulatively, at least one listed factor: sensitive data; data about children, adolescents, or older people; financial data; system-authentication data; data protected by legal, judicial, or professional secrecy; or large-scale data.

  • Confirm the event, affected processing, personal-data categories, people, volume, systems, controller, operators, and whether the LGPD applies.
  • Assess likely material, moral, reputational, discriminatory, identity-theft, fraud, physical, or other effects, together with protective measures and post-incident mitigation.
  • Record the controller's knowledge date and the three-business-day calculation; identify any shorter sector-specific deadline.
  • Document the report or the reasoned no-report decision. The controller must keep incident records, including non-reportable incidents, for at least five years.
Section 2

Who should own Breach Notification, and what evidence should prove the decision?

The controller owns the Article 48 decision and communication. Security investigates and contains the event; operators notify the controller and provide available information without delay; privacy or legal applies the reportability test; communications and support teams prepare clear, direct instructions for affected people.

Notify the ANPD and affected people within three business days, unless a shorter period applies. If justified information is unavailable, make a and provide the complement within 20 business days from the preliminary filing. A preliminary filing does not complete Article 48 by itself.

The ANPD filing should identify the incident, affected data and people, controller and operator, occurrence and knowledge dates, risks, technical and security measures, mitigation, data-subject communication, any delay, and the controller's contact route. The notice to affected people should explain the nature and categories of affected data, protection measures subject to protected secrets, risks, the controller's knowledge date, mitigation or reversal measures, recommended steps, delay where relevant, and a contact for questions.

  • Name one accountable owner and one reviewer for the Breach Notification workflow.
  • Keep source screenshots or source links, decision notes, implementation tickets, and approval records together.
  • Keep occurrence and knowledge times, affected systems and backups, data and people, controller and operator facts, risk analysis, containment, deadline calculation, filed forms, affected-person notice, supplements, remediation, and approval.
  • If notice is late, explain the reason. Preserve proof of the filing route and delivery to affected people.
Section 3

Which facts can change the notification decision?

Encryption, pseudonymisation, containment, or deletion by the recipient can reduce risk but does not automatically end the assessment. Consider whether the measures genuinely prevent identification or harmful use, the type and volume of data, vulnerable groups, likely consequences, and whether mitigation reached every affected copy.

A single event can involve several controllers. Each controller must assess its own Article 48 duty. An operator should not file as if it were the controller unless it is legally representing the controller through the accepted procedure.

  • Do not wait for complete forensic certainty if the notification gate and clock are already met; use the preliminary and complementary route where justified.
  • Do not notify only the ANPD when the same reportability test also requires notice to affected people.
  • Tailor the affected-person notice to the risks and mitigation they can use; avoid marketing language or a notice that hides the incident.
  • Check sector rules and eligible small-agent timing separately; use the shortest applicable period.
Section 4

What should the incident workflow produce?

Maintain a tested incident intake, controller knowledge timestamp, operator escalation clause, reportability worksheet, ANPD filing owner, affected-person notice path, 20-business-day complement tracker, five-year record, and remediation owner.

The output should be either a reasoned no-report decision or a matched ANPD and affected-person communication package. Update it if later facts change the risk assessment, population, data, or mitigation.

  • Exercise the workflow with incomplete facts so the team can use preliminary and complementary filings.
  • Pre-approve roles and contact routes, but draft the notice from the actual incident and risks.
  • Track promises made to affected people and verify that mitigation and follow-up are completed.
  • Reassess the control after an incident, near miss, vendor change, new data category, or ANPD procedure change.
Primary sources

References and citations

gov.br
Referenced sections
  • Official explanation of the confirmed-incident, LGPD-data, and relevant-risk gates; risk factors; filing route; timing; phased communication; and records.
planalto.gov.br
Referenced sections
  • Primary LGPD source for Article 48 breach-notification duties to the ANPD and affected data subjects when relevant risk or damage may occur.
"O controlador deverá comunicar à autoridade nacional e ao titular a ocorrência de incidente de segurança"
planalto.gov.br
Referenced sections
  • Binding Articles 46-48 for security measures, continuing confidentiality duties, reportability, and minimum communication content.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.