Artifact GuideBrazilIncident Reporting To ANPD

Brazil LGPD Incident Reporting To ANPD

A controller must notify the ANPD and affected people when a personal-data security incident may cause relevant risk or harm.

When the reporting threshold is met, Resolution 15/2024 gives the controller three business days to notify the ANPD and affected people, counted from when the controller learns that the incident affected personal data, unless specific law sets another period.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 25, 2026
Questions
3

Structured answer sets in this page tree.

Primary sources
4

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 25, 2026
Overview

Contain the and preserve evidence while the controller applies three cumulative checks: confirm that an incident occurred, confirm that it involves personal data subject to the LGPD, and decide whether it may cause . If all three are met, notify the ANPD and affected people within three business days, counted from when the controller learns that the incident affected personal data, unless specific law sets another deadline. An operator should notify the controller promptly and supply the facts needed for that decision.

Search this module

Find a question or answer quickly

3 of 3 questions
Question 1

What should teams do about Incident Reporting To ANPD under the Brazil LGPD?

LGPD Article 48 creates the binding notification duty, and ANPD Resolution 15/2024 defines the current threshold, content, procedure, and deadlines. A vulnerability without a confirmed event, an incident that does not involve personal data subject to the LGPD, or an incident that cannot cause does not meet all three reporting criteria. Keep the assessment even when the outcome is non-reportable.

Assess the nature and sensitivity of the data, the processing context, the number and vulnerability of affected people, possible material or moral effects, and safeguards already effective at the time of the event. For example, the theft of strongly encrypted data may present a different risk from theft of the same readable data, but encryption is evidence to assess rather than an automatic exemption.

The three-business-day period starts when the controller learns that the incident affected personal data, not when the investigation closes or the threshold assessment is complete. The duty to notify still applies only if the incident may cause . Record the occurrence, detection, operator notice, controller knowledge, facts available for the threshold decision, and any shorter or different sector-specific deadline.

The controller owns the reportability decision and both required communications. The operator should alert the controller without unjustified delay and provide logs, affected systems and data, containment actions, and other facts required by contract or instruction. The encarregado or a legal representative may submit the ANPD filing, but that does not transfer the controller's accountability.

  • Identify the controller for each affected dataset; one organization may be controller for one purpose and operator for another, and an operator's customer notice does not replace the controller's notices.
  • Check banking, health, telecommunications, consumer, contractual, and other incident regimes in parallel. A specific legal deadline can displace the Resolution 15/2024 period, while contractual or insurance notices do not.
  • If required information is unavailable, file a on time, justify what is missing, and submit the complementary information within twenty business days of that filing unless ANPD sets another period.
  • Tell affected people directly, in simple language, about the nature and category of data, risks and possible effects, measures taken or recommended, incident date if known, and a controller or encarregado contact. If direct and individualized notice is infeasible or affected people cannot be identified, Resolution 15/2024 requires a prominent notice through available communication channels for at least three months.
Citations
ANPD - Comunicação de Incidente de Segurança

ANPD's incident communication page supports the FAQ's reporting workflow by identifying controller responsibility, SEI filing, reportable incident criteria, and the three-business-day communication period.

Question 2

What evidence should teams keep for Incident Reporting To ANPD under the Brazil LGPD?

Keep a decision record for every confirmed incident, including those assessed as non-reportable. It should connect the chronology and technical evidence to each reporting criterion and show who made the controller decision. Resolution 15/2024 requires the controller to keep the incident record for at least five years from the record date, unless another rule requires longer retention; public bodies and entities must also observe the archival periods in the legislation that governs them.

  • Chronology: occurrence if known, detection, containment, operator escalation, controller knowledge that personal data was affected, threshold decision, filing, affected-person notice, supplements, and closure.
  • Scope and threshold: controller and operator roles, systems and locations, categories and approximate volume of data and people, vulnerable groups, likely effects, and safeguards such as effective encryption.
  • Response: preserved logs, investigation findings, containment and recovery steps, measures offered to affected people, ANPD form and receipt, notice text and delivery evidence, delay explanation, and corrections.
  • Governance: decision owner, legal and security review, sector-regulator notices, processor cooperation, lessons learned, control changes, and the next reassessment date.
Citations
LEI Nº 13.709, DE 14 DE AGOSTO DE 2018

Official source supporting the FAQ answer because LGPD Article 48 requires controllers to communicate security incidents that may create relevant risk or harm to data subjects.

Question 3

Which mistakes create risk when handling Incident Reporting To ANPD under the Brazil LGPD?

Do not rely on the LGPD's general 'reasonable time' wording without applying Resolution 15/2024. A is not complete compliance: investigate, mitigate, notify affected people, and supply the justified missing information within the complementary period. ANPD may require corrections, broader disclosure, additional mitigation, or other measures after reviewing the case.

  • Do not start the clock only when a forensic report is final or the threshold assessment is complete; start from the controller's knowledge that the incident affected personal data.
  • Do not wait for proof of actual harm, complaints, fraud, or publication; the test is whether may result.
  • Do not let contractual, insurance, law-enforcement, or other regulator workflows delay the LGPD communication, and do not assume one filing satisfies every regime.
  • If filing late, explain the cause, record the chronology, and state the measures taken to reduce harm. A delay explanation does not erase the missed deadline.
Citations
Primary sources

References and citations

gov.br
Referenced sections
  • Official source supporting the risk and boundary notes in this FAQ because ANPD lists the cumulative criteria for incidents that must be communicated.
"Possa acarretar risco ou dano relevante aos titulares dos dados"
planalto.gov.br
Referenced sections
  • Official source supporting the risk and boundary notes in this FAQ because LGPD Article 48 frames incident reporting around risk or relevant harm to data subjects.
"risco ou dano relevante aos titulares"
dspace.mj.gov.br
Referenced sections
  • Official source supporting the risk and boundary notes in this FAQ because the regulation defines the communication process and ANPD follow-up for relevant-risk incidents.
"Regulamento de Comunicação de Incidente de Segurança"
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.