What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
LGPD Article 48 creates the binding notification duty, and ANPD Resolution 15/2024 defines the current threshold, content, procedure, and deadlines. A vulnerability without a confirmed event, an incident that does not involve personal data subject to the LGPD, or an incident that cannot cause does not meet all three reporting criteria. Keep the assessment even when the outcome is non-reportable.
Assess the nature and sensitivity of the data, the processing context, the number and vulnerability of affected people, possible material or moral effects, and safeguards already effective at the time of the event. For example, the theft of strongly encrypted data may present a different risk from theft of the same readable data, but encryption is evidence to assess rather than an automatic exemption.
The three-business-day period starts when the controller learns that the incident affected personal data, not when the investigation closes or the threshold assessment is complete. The duty to notify still applies only if the incident may cause . Record the occurrence, detection, operator notice, controller knowledge, facts available for the threshold decision, and any shorter or different sector-specific deadline.
The controller owns the reportability decision and both required communications. The operator should alert the controller without unjustified delay and provide logs, affected systems and data, containment actions, and other facts required by contract or instruction. The encarregado or a legal representative may submit the ANPD filing, but that does not transfer the controller's accountability.
- Identify the controller for each affected dataset; one organization may be controller for one purpose and operator for another, and an operator's customer notice does not replace the controller's notices.
- Check banking, health, telecommunications, consumer, contractual, and other incident regimes in parallel. A specific legal deadline can displace the Resolution 15/2024 period, while contractual or insurance notices do not.
- If required information is unavailable, file a on time, justify what is missing, and submit the complementary information within twenty business days of that filing unless ANPD sets another period.
- Tell affected people directly, in simple language, about the nature and category of data, risks and possible effects, measures taken or recommended, incident date if known, and a controller or encarregado contact. If direct and individualized notice is infeasible or affected people cannot be identified, Resolution 15/2024 requires a prominent notice through available communication channels for at least three months.
ANPD's incident communication page supports the FAQ's reporting workflow by identifying controller responsibility, SEI filing, reportable incident criteria, and the three-business-day communication period.
The incident-communication regulation is the primary rule for when and how controllers communicate security incidents to ANPD and affected data subjects.
ANPD's binding dosimetry regulation governs administrative sanctions for established LGPD infringements.