Artifact GuideBrazilIncident Workflow

Brazil LGPD Incident Workflow

Confirm whether personal data was affected, record when the controller learned that fact, and assess whether the incident may cause relevant risk or damage.

When the reporting threshold is met, the controller must notify the ANPD and affected data subjects within three business days, unless sector-specific law sets another period.

Author
Sorena AI
Published
May 9, 2026
Updated
Jul 24, 2026
Sections
3

Structured answer sets in this page tree.

Primary sources
5

Cited legal and guidance references.

Publication metadata
Sorena AI
Published May 9, 2026
Updated Jul 24, 2026
Overview

Use this workflow to handle a Brazil LGPD from the first alert through risk assessment, ANPD and data-subject notices, mitigation, supplementation, and final records.

Section 1

How should a Brazil LGPD incident workflow run?

Open the privacy incident workflow when an event may have affected the confidentiality, integrity, availability, or authenticity of personal data. A vulnerability with no confirmed adverse event is not itself an incident, and an event involving only effectively anonymized data does not require an LGPD incident notice. Preserve logs and evidence while security contains the event.

The notification test has three cumulative parts: the incident is confirmed, it involves personal data subject to the LGPD, and it may cause relevant risk or damage to data subjects. Assess the processing context, categories and number of people, nature and amount of data, possible material, moral, or reputational harm, effective protection such as encryption, mitigation already completed, large-scale effects, sensitive data, and vulnerable groups.

Treat compromise of authentication credentials, financial or payment data, protected secrets, sensitive data, or data about children and other vulnerable people as a strong risk indicator, especially at scale or where fraud, identity theft, discrimination, physical harm, or denial of a service is plausible. The category alone does not replace the case-specific threshold assessment; record how exposure, protection, duration, recoverability, and completed mitigation change the likely harm.

The owns the reportability decision and notifications. An must inform the controller without unjustified delay and supply the information needed for the assessment and notices. Contractual escalation periods should be short enough for the controller to meet the legal clock.

  • Record occurrence, detection, notice, and -knowledge times separately; do not reconstruct the clock after the decision.
  • Contain the event without destroying evidence, identify affected systems and data flows, and preserve the reasoning behind every scope estimate.
  • Issue a documented no-notify decision when the cumulative threshold is not met, with a named approver and facts that would reopen the assessment.
  • If the threshold is met, prepare ANPD and data-subject notices in parallel with containment and remediation.
Section 2

What happens once the incident is reportable?

Notify the ANPD and affected data subjects within three business days from the 's knowledge that the incident affected personal data, unless specific legislation sets another period. Resolution 2/2022 gives qualifying small processing agents double time under the incident regulation. A team should confirm that status before relying on the extension.

If complete information is unavailable, submit a justified preliminary ANPD communication and supplement it within 20 business days from that communication. A preliminary filing does not complete the Article 48 duty. Data-subject notices should be direct, individual, in simple language, and sent through a customary channel where possible; indirect public notice is exceptional and must be justified.

  • ANPD filing: and identities, incident description, affected data and people, occurrence and knowledge dates, risks, security measures, mitigation, notices, delay reason, and contact details.
  • Data-subject notice: affected data categories, relevant protection measures, likely impacts, delay reason if late, mitigation already taken or planned, knowledge date, and a contact route including the encarregado when applicable.
  • Supplement tracker: unknown fact, owner, investigation step, expected date, 20-business-day due date, same-process filing reference, and final submission proof.
  • Parallel duties: record any sector regulator, contractual, law-enforcement, insurer, or cross-border notification separately; an ANPD filing does not replace another applicable duty.
Section 3

What evidence closes the workflow?

Resolution 15/2024 requires the to keep a record of security incidents involving personal data for at least five years, including incidents that were not communicated. The record should let a reviewer reproduce the threshold decision, clock calculation, notices, mitigation, and follow-up without relying on memory.

Close the incident only after containment and recovery are verified, required communications and supplements are complete, corrective actions have owners and dates, and the records whether the RIPD, processing inventory, contracts, security measures, retention rules, or data-subject guidance must change.

  • Retain the incident chronology, evidence sources, affected-data analysis, risk assessment, reportability decision, approvals, notices, delivery proof, ANPD protocol, supplements, and remediation evidence.
  • Record why encryption, anonymization, containment, or another control did or did not reduce relevant risk; naming a control is not enough.
  • For a non-reportable event, retain the missing threshold element, supporting facts, approver, and reopening trigger. For a reportable event, retain the three-business-day calculation from knowledge and explain any delay.
  • Test the escalation path and notice templates after material system, vendor, or contact-channel changes.
  • Reopen the assessment if later forensics expand the people, data, duration, or harm involved.
Primary sources

References and citations

gov.br
Referenced sections
  • Current ANPD instructions for the three-business-day period, preliminary and complementary filings, and direct data-subject communication.
in.gov.br
Referenced sections
  • Binding regulation for the reportability test, controller and operator duties, three-business-day notices, staged communication, and incident records.
Related guides

Explore more topics

Brazil LGPD ANPD Enforcement and Fines Guide
How ANPD investigates LGPD infringements, classifies severity, selects sanctions, calculates fines, and weighs aggravating and mitigating evidence.
Brazil LGPD Applicability Test Guide
Apply LGPD Articles 3 and 4 to a processing activity, including foreign organisations, Brazil collection, targeting, exclusions, and the evidence to retain.
Brazil LGPD Breach Notification Guide
Apply Brazil's LGPD incident notification test, three-business-day clock, notice content, phased filing, affected-person communication, and five-year records.
Brazil LGPD Checklist
An evidence-based Brazil LGPD checklist for scope, roles, legal bases, notices, rights, vendors, security incidents, transfers, retention, and governance.
Brazil LGPD Compliance Guide
Build an LGPD compliance program from processing records, legal bases, transparency, rights, security, vendors, transfers, incidents, and accountable evidence.
Brazil LGPD Controller Operator and DPO Roles Guide
Classify LGPD controller, operator, sub-operator, and encarregado roles from actual decisions, instructions, processing facts, and Resolution 18 duties.
Brazil LGPD Data Subject Rights Guide
Brazil LGPD rights guide covering confirmation, access, correction, restriction, deletion, portability, consent, sharing, objection, and automated decisions.
Brazil LGPD Deadlines and Compliance Calendar Guide
Track Brazil LGPD commencement dates, data-access responses, incident notices, international-transfer clauses, and ANPD fine-payment deadlines.
Brazil LGPD DSAR Response Template Guide
Build an LGPD data-subject response that identifies the right, applies the correct timing, records the decision, protects third parties, and proves delivery.
Brazil LGPD DSAR Workflow Guide
Run an LGPD data-subject request from intake and identity checks through rights analysis, response timing, evidence, exceptions, and escalation.
Brazil LGPD Incident Reporting to ANPD Guide
Decide whether an LGPD incident is reportable, calculate the ANPD deadline, prepare complete or staged notices, and keep the required five-year record.
Brazil LGPD International Transfer Mechanisms Guide
Compare LGPD international-transfer mechanisms: adequacy, ANPD standard clauses, approved specific clauses, global corporate rules, consent, and other Article 33 routes.
Brazil LGPD International Transfers Guide
Brazil LGPD international-transfer guide for identifying transfers, selecting Article 33 mechanisms, applying ANPD clauses, EU adequacy, and transparency.
Brazil LGPD Lawful Bases Guide
Compare LGPD Article 7 bases for ordinary personal data and Article 11 bases for sensitive data, with consent, necessity, evidence, and edge cases.
Brazil LGPD Legal Bases and Legitimate Interest Balancing Guide
Apply LGPD legitimate interest through purpose, necessity, balancing, reasonable expectations, safeguards, children, sensitive-data limits, and records.
Brazil LGPD Penalties and Fines Guide
Understand every ANPD administrative sanction under LGPD Article 52, the fine ceilings, non-monetary penalties, and public-body limits.
Brazil LGPD Privacy Law FAQ
Answers to common Brazil LGPD questions about scope, roles, legal bases, rights, incidents, transfers, impact reports, small agents, and enforcement.
Brazil LGPD Requirements Guide
Reference guide to Brazil LGPD scope, principles, legal bases, transparency, rights, roles, security, incidents, transfers, records, and ANPD oversight.
Brazil LGPD RIPD and DPIA Evidence Guide
Build an LGPD RIPD evidence file that proves the processing scope, high-risk screen, necessity, safeguards, residual risk, approval, and later review.
Brazil LGPD RIPD Workflow Guide
Decide when to prepare an LGPD RIPD, apply the ANPD high-risk screen, document required evidence and mitigation, approve residual risk, and review changes.
Brazil LGPD Small Processing Agents Guide
Check whether an organization qualifies for Brazil's small-processing-agent regime, which flexibilities apply, and which LGPD duties remain unchanged.
Brazil LGPD Templates Guide
Choose and maintain LGPD templates for processing records, data-subject requests, incidents, RIPDs, transfers, and controller-operator role evidence.
Brazil LGPD Transfer Workflow Guide
Classify an LGPD international transfer, confirm the processing legal basis and transfer mechanism, document onward transfers, and approve the evidence before launch.
LGPD vs CCPA: Key Differences for Privacy Teams
Compare Brazil's LGPD and California's CCPA by scope, legal bases, consumer rights, sale and sharing rules, deadlines, transfers, and enforcement.
LGPD vs GDPR: Key Differences for Privacy Teams
Compare Brazil's LGPD and the EU GDPR by scope, legal bases, roles, rights deadlines, impact assessments, incidents, transfers, and enforcement.
What should teams do about Children's Data under the Brazil LGPD?
Apply LGPD Article 14 to children's and adolescents' data: age categories, best interests, legal bases, parental consent, limited collection, notices, and evidence.
What should teams do about Controller Operator and DPO Roles under the Brazil LGPD?
Brazil LGPD guidance for Controller Operator and DPO Roles, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Cookies under the Brazil LGPD?
Brazil LGPD guidance for Cookies, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Incident Reporting To ANPD under the Brazil LGPD?
Brazil LGPD guidance for Incident Reporting To ANPD, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about International Transfer Mechanisms under the Brazil LGPD?
Brazil LGPD guidance for International Transfer Mechanisms, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legal Bases under the Brazil LGPD?
Brazil LGPD guidance for Legal Bases, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Legitimate Interest Balancing under the Brazil LGPD?
Brazil LGPD guidance for Legitimate Interest Balancing, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about RIPD and DPIA under the Brazil LGPD?
Brazil LGPD guidance for RIPD and DPIA, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Sanctions Methodology under the Brazil LGPD?
Brazil LGPD guidance for Sanctions Methodology, with practical decisions, evidence, edge cases, and external source citations.
What should teams do about Small Processing Agents under the Brazil LGPD?
Brazil LGPD guidance for Small Processing Agents, with practical decisions, evidence, edge cases, and external source citations.