Artifact GuideBrazilIncident Reporting to ANPD

Brazil LGPD Incident Reporting to ANPD

The controller must report a confirmed personal-data incident that may cause relevant risk or damage to data subjects.

Notify the ANPD and affected data subjects within three business days from the controller's knowledge that personal data was affected, unless specific law sets another period.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
4

Structured answer sets in this page tree.

Primary sources
6

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this guide to decide whether an incident must be reported to Brazil's Agência Nacional de Proteção de Dados () and affected data subjects, calculate the deadline, prepare complete or staged notices, and retain the evidence.

Section 1

What should teams decide about Incident Reporting to ANPD under the Brazil LGPD?

Report only when all three conditions are met: the event is a confirmed adverse event that compromises the confidentiality, integrity, availability, or authenticity of personal-data security; it involves personal data subject to the LGPD; and it may cause . A vulnerability without a confirmed adverse event is not an incident, and an event limited to effectively anonymised data is not reportable to the under this rule.

requires the potential to affect data subjects' fundamental interests and rights significantly and at least one listed factor: sensitive data; data about children, adolescents, or older people; financial data; system-authentication data; data protected by legal, judicial, or professional secrecy; or large-scale processing. Assess the context, people, nature and amount of data, possible material, moral, or reputational harm, protection against identification, and post-incident mitigation. The decides and files; an operator must notify the controller without unjustified delay and provide the facts needed for both notices.

  • Record when the event occurred, was detected, was reported by an operator, and became known to the as affecting personal data.
  • Document the reportability test with evidence and an approver, including a reasoned no-notify decision where applicable.
  • Start the and data-subject notice work before every technical fact is final; Resolution 15 permits a justified staged ANPD filing.
  • Check sector-specific reporting periods and small-processing-agent status before calculating the final due date.
Section 2

Who should own Incident Reporting to ANPD, and what evidence should prove the decision?

File with the and notify affected data subjects within three business days from the 's knowledge that the incident affected personal data, unless specific legislation sets another period. Qualifying small processing agents receive double time under Resolution 2/2022 as amended by Resolution 15/2024.

The filing should identify the incident, affected data and people, and operator, occurrence and knowledge dates, risks, technical and security measures, mitigation, communications, delay reasons, and contact route. The affected-person notice should state the nature and categories of affected data, technical and security measures subject to protected secrets, risks, the controller's knowledge date, delay reasons where applicable, mitigation or reversal measures, recommended protective action, and a contact route. Do not send the ANPD a list of affected people or their contact details merely to prove notice.

  • Assign the filing owner, technical fact owner, data-subject notice owner, approver, and substitute for absence.
  • Calculate business days in the applicable calendar and record the start fact, special statutory period, and small-agent conclusion.
  • Save the submitted form, attachments, protocol, data-subject notice, delivery evidence, and any correspondence.
  • Track other regulator, contractual, insurer, law-enforcement, and cross-border duties separately.
Section 3

What if the investigation is incomplete at the deadline?

A that lacks complete information may make a justified preliminary communication and provide the missing information within 20 business days from that communication. The supplement must be filed in the same process. A preliminary filing is not a completed Article 48 communication.

Notify data subjects directly and individually where possible, using simple language and a familiar channel. Indirect public communication is exceptional and requires justification. If the affected individuals cannot yet be distinguished, the may need to notify everyone whose personal data was in the affected dataset.

  • State what is unknown, why it is unavailable, who is investigating it, and when it will be supplied.
  • Do not delay the initial filing merely to improve precision when the threshold and deadline are already met.
  • Update affected people when later facts materially change the risk, mitigation, or protective action they should take.
  • Reassess a no-notify decision when forensics expands the affected data, people, duration, or possible harm.
Section 4

What record must the controller retain?

Keep a record of every security incident involving personal data for at least five years, including incidents that were not communicated. The file should reproduce the chronology, scope, risk assessment, reportability decision, communications, mitigation, and later corrections.

Close the reporting work only after required supplements are filed, data-subject notice is complete, delivery evidence is retained, follow-up is assigned, and the final facts are reflected in remediation, processing records, contracts, and relevant RIPDs.

  • Keep source logs and investigation reports, not only a summary drafted for the .
  • Link each risk conclusion to the affected data, people, protection, possible harm, and mitigation evidence.
  • Record copies and delivery proof for notices without sending unnecessary personal data to the .
  • Test the filing account, substitute owner, operator escalation clause, and notice channel after material changes.
Primary sources

References and citations

in.gov.br
Referenced sections
  • Binding regulation for the reportability threshold, controller and operator roles, three-business-day notices, staged filing, notice content, and five-year incident records.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Workflow Guide
Run an LGPD personal-data incident from confirmation and risk assessment through three-business-day notices, supplementation, mitigation, and records.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.