The controller must report a confirmed personal-data incident that may cause relevant risk or damage to data subjects.
Notify the ANPD and affected data subjects within three business days from the controller's knowledge that personal data was affected, unless specific law sets another period.
Use this guide to decide whether an incident must be reported to Brazil's Agência Nacional de Proteção de Dados () and affected data subjects, calculate the deadline, prepare complete or staged notices, and retain the evidence.
1
Section 1
What should teams decide about Incident Reporting to ANPD under the Brazil LGPD?
Report only when all three conditions are met: the event is a confirmed adverse event that compromises the confidentiality, integrity, availability, or authenticity of personal-data security; it involves personal data subject to the LGPD; and it may cause . A vulnerability without a confirmed adverse event is not an incident, and an event limited to effectively anonymised data is not reportable to the under this rule.
requires the potential to affect data subjects' fundamental interests and rights significantly and at least one listed factor: sensitive data; data about children, adolescents, or older people; financial data; system-authentication data; data protected by legal, judicial, or professional secrecy; or large-scale processing. Assess the context, people, nature and amount of data, possible material, moral, or reputational harm, protection against identification, and post-incident mitigation. The decides and files; an operator must notify the controller without unjustified delay and provide the facts needed for both notices.
Record when the event occurred, was detected, was reported by an operator, and became known to the as affecting personal data.
Document the reportability test with evidence and an approver, including a reasoned no-notify decision where applicable.
Start the and data-subject notice work before every technical fact is final; Resolution 15 permits a justified staged ANPD filing.
Check sector-specific reporting periods and small-processing-agent status before calculating the final due date.
Who should own Incident Reporting to ANPD, and what evidence should prove the decision?
File with the and notify affected data subjects within three business days from the 's knowledge that the incident affected personal data, unless specific legislation sets another period. Qualifying small processing agents receive double time under Resolution 2/2022 as amended by Resolution 15/2024.
The filing should identify the incident, affected data and people, and operator, occurrence and knowledge dates, risks, technical and security measures, mitigation, communications, delay reasons, and contact route. The affected-person notice should state the nature and categories of affected data, technical and security measures subject to protected secrets, risks, the controller's knowledge date, delay reasons where applicable, mitigation or reversal measures, recommended protective action, and a contact route. Do not send the ANPD a list of affected people or their contact details merely to prove notice.
Assign the filing owner, technical fact owner, data-subject notice owner, approver, and substitute for absence.
Calculate business days in the applicable calendar and record the start fact, special statutory period, and small-agent conclusion.
Save the submitted form, attachments, protocol, data-subject notice, delivery evidence, and any correspondence.
Track other regulator, contractual, insurer, law-enforcement, and cross-border duties separately.
What if the investigation is incomplete at the deadline?
A that lacks complete information may make a justified preliminary communication and provide the missing information within 20 business days from that communication. The supplement must be filed in the same process. A preliminary filing is not a completed Article 48 communication.
Notify data subjects directly and individually where possible, using simple language and a familiar channel. Indirect public communication is exceptional and requires justification. If the affected individuals cannot yet be distinguished, the may need to notify everyone whose personal data was in the affected dataset.
State what is unknown, why it is unavailable, who is investigating it, and when it will be supplied.
Do not delay the initial filing merely to improve precision when the threshold and deadline are already met.
Update affected people when later facts materially change the risk, mitigation, or protective action they should take.
Reassess a no-notify decision when forensics expands the affected data, people, duration, or possible harm.
Keep a record of every security incident involving personal data for at least five years, including incidents that were not communicated. The file should reproduce the chronology, scope, risk assessment, reportability decision, communications, mitigation, and later corrections.
Close the reporting work only after required supplements are filed, data-subject notice is complete, delivery evidence is retained, follow-up is assigned, and the final facts are reflected in remediation, processing records, contracts, and relevant RIPDs.
Keep source logs and investigation reports, not only a summary drafted for the .
Link each risk conclusion to the affected data, people, protection, possible harm, and mitigation evidence.
Record copies and delivery proof for notices without sending unnecessary personal data to the .
Test the filing account, substitute owner, operator escalation clause, and notice channel after material changes.
Binding regulation for the reportability threshold, controller and operator roles, three-business-day notices, staged filing, notice content, and five-year incident records.