- ANPD incident guidance explains how Article 48 LGPD and Resolution 15/2024 apply to controller communications to ANPD and affected data subjects.
"prazo de três (3) dias úteis"
Incident Workflow decisions under the Brazil LGPD should be written in operational language: who is in scope, what must happen, what evidence proves it, and when escalation is needed.
Use this section to define scope, owner, evidence inputs, and the review outcome before execution.
Structured answer sets in this page tree.
Cited legal and guidance references.
This page explains how to handle a Brazil LGPD security incident from the first alert to the final communication and recordkeeping step. It is designed to help product, legal, privacy, security, and compliance teams decide when an incident must be escalated, when ANPD and affected data subjects must be informed, and what information the response record should capture.
Start by confirming whether the event is a security incident involving personal data and whether it may create risk or relevant harm to data subjects, as described in article 48 of the LGPD. If the event does not involve personal data or does not present that risk, document the assessment and close the workflow with the supporting evidence.
If the event is in scope, gather the facts needed for the ANPD communication: the nature of the affected data, the data subjects involved, the technical and security measures already in place, the risks linked to the incident, the reason for any delay, and the measures taken or planned to reduce the harm. The ANPD form also asks who discovered the incident, when it occurred, when the controller became aware of it, when it was reported to ANPD, and when data subjects were informed.
For incidents that still lack enough information, use a preliminary communication only as a temporary step and follow up with a complete or complementary communication when the facts are confirmed. The workflow should also record the internal owner, the DPO or privacy lead, the operator if one was involved, and any communication made to other authorities or to the affected data subjects.
A useful template captures role, purpose, lawful basis, data subject, category, transfer or incident trigger, owner, evidence, and ANPD/DPO escalation note.
Review the workflow after ANPD guidance, new vendors, new purposes, cross-border changes, incidents, complaints, or changes to data-subject channels.
This artifact page provides practical inputs, owner roles, required outputs, and evidence checkpoints for incident workflow.
Turn Incident Workflow into scoped questions, evidence fields, and review tasks.
Use Research Copilot to answer follow-up questions with cited source material.
Review scope, evidence, owners, and the next compliance actions with operational practice.
"prazo de três (3) dias úteis"
"Segurança da Informação para Agentes de Tratamento de Pequeno Porte"
"O controlador deverá comunicar à autoridade nacional e ao titular a ocorrência de incidente de segurança"
"processo de fiscalização e o processo administrativo sancionador"
"Esta Resolução CD/ANPD nº 4, de 24 de fevereiro de 2023, trata da aplicação de sanções administrativas e"