2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD Security & Incidents

LGPD Data Breach Notification: When and How Companies Must Respond

Brazil does not require every cybersecurity event to be reported to ANPD. The critical questions are whether the event is a confirmed security incident involving personal data subject to the LGPD, whether it can cause relevant risk or damage to data subjects, who is the controller, and whether the organization can investigate and communicate within the current regulatory timetable.

Published: Last reviewed: Reading time: ~20 minutes By LGPD Brazil Editorial Team

Quick Answer: When must an LGPD security incident be reported?

Under Article 48 of the LGPD and ANPD Resolution CD/ANPD No. 15/2024, a controller must communicate a security incident to ANPD and affected data subjects when the incident can cause relevant risk or damage. ANPD's current guidance says the reporting test is cumulative: the incident must be confirmed, involve personal data subject to the LGPD, and be capable of causing relevant risk or damage to data subjects. When notification is required, the ordinary deadline is three business days, subject to a different deadline in specific legislation. Qualifying small processing agents benefit from the current double-deadline rule under Resolution No. 2/2022.

Key Takeaways

  • Not every cybersecurity event is reportable. A vulnerability alone is not automatically a security incident.
  • Not every confirmed incident must be reported. The controller must assess whether it can cause relevant risk or damage.
  • The controller owns the legal notification duty. The operator must escalate without unjustified delay and support the controller.
  • The ordinary deadline is three business days. It applies to communication to ANPD and affected data subjects when the threshold is met.
  • Qualifying small agents have double time. Under the current consolidated rule, this generally means six business days.
  • Incomplete facts do not justify silence. ANPD allows preliminary and complementary communications in justified cases.
  • Even non-reportable incidents must be taken seriously. Resolution 15/2024 requires the controller to maintain incident records—including non-reported incidents—for at least five years.

“Data breach” is useful international shorthand, but Brazil's regulation uses the broader concept of a security incident involving personal data. That matters because the problem is not limited to public leaks. Loss of availability, unauthorized alteration, accidental disclosure, compromised authenticity, and other adverse events can also fall within incident-response analysis.

ANPD's glossary defines a security incident as a confirmed adverse event related to violation of the confidentiality, integrity, availability or authenticity of personal-data security.

Which Incidents Must Be Reported to ANPD?

ANPD's current incident page gives a useful three-part test. A security incident needs to be communicated when the following criteria are met cumulatively:

Test 1 The incident is confirmed

A suspected vulnerability, alert or anomaly should be investigated. Reporting is not triggered merely because a weakness exists.

Test 2 It involves personal data subject to LGPD

An information-security event involving no personal data, or only data that is genuinely anonymized and no longer relates to identifiable people, does not follow the same Article 48 path.

Test 3 Relevant risk or damage is possible

The controller must assess the likely impact on data subjects using the incident context, data, scale, affected groups, protections and mitigation.

Article 48 of the LGPD

Article 48 places the notification obligation on the controller where a security incident can create relevant risk or damage to data subjects. It requires communication to both the national data-protection authority and the affected data subjects and identifies minimum information categories for the communication.

Read the official compiled LGPD .

A vulnerability is not automatically an incident

ANPD expressly distinguishes a vulnerability from an incident. A vulnerability is a weakness. If it has not been exploited and no confirmed adverse event involving personal-data security has occurred, the organization may be dealing with a security weakness rather than a reportable incident.

That does not mean the weakness can be ignored. Article 46 requires technical and administrative security measures, and prevention is one of the LGPD's core principles. The distinction simply prevents vulnerability management from being confused with Article 48 notification.

What Does “Relevant Risk or Damage” Mean?

This is the core decision in many incidents. ANPD says the controller should assess factors including:

  • the context of the processing activity;
  • the categories and number of affected data subjects;
  • the nature, categories and quantity of affected data;
  • potential material, moral or reputational harm;
  • whether affected data was protected so that identification of the data subjects was prevented; and
  • whether post-incident mitigation measures were sufficient.

ANPD specifically identifies concerns such as discrimination, identity theft, financial fraud and other material or moral harms, with particular attention to incidents involving large-scale data, sensitive data and vulnerable groups such as children, adolescents or older persons.

Risk factor Questions to ask Example signal
Data sensitivity Does the event involve health, biometric, genetic, religious, political, sexual-life or other sensitive information? Exposed medical records or biometric templates.
Financial / authentication data Could the data facilitate account takeover, fraud or unauthorized transactions? Passwords, tokens, payment-related records or banking information.
Vulnerable groups Are children, adolescents, older persons or other vulnerable populations affected? School, health or social-benefit database exposure.
Scale How many people and how much data are affected? How geographically broad is the impact? Large customer database or long-running exposure.
Protection Was the data encrypted or otherwise protected in a way that made it unintelligible to unauthorized third parties? Encrypted stolen device with strong key protection versus readable customer files.
Potential harm Could the event cause fraud, discrimination, identity misuse, reputational harm, physical risk or loss of rights? Identity-document exposure combined with financial data.
Mitigation Did containment materially reduce the remaining risk? Rapid credential reset, token revocation or confirmed deletion by an unintended recipient.
Do not use a single-factor rule. Encryption, number of affected people, type of data and mitigation should be assessed together. ANPD notes that the same type of event can be relevant in one context and non-relevant in another.

The Current LGPD Incident Deadline: Three Business Days

Resolution CD/ANPD No. 15/2024 is currently listed by ANPD as in force. Under the current rule, communication to ANPD and affected data subjects generally must be made within three business days when the incident can cause relevant risk or damage, unless specific legislation applicable to the organization provides another notification deadline.

Detect Security alert, user report, vendor notice, log anomaly, mistaken disclosure or other signal.
Confirm & assess Determine whether a personal-data security incident occurred and whether the relevant-risk threshold is met.
Within 3 business days Ordinary deadline for controller communication to ANPD and affected data subjects when reportable.
Up to 20 business days Reasoned complementary information may follow a justified preliminary ANPD communication.

Qualifying small processing agents: double deadline

A valuable 2026 nuance is that the consolidated small-processing-agent regulation still provides a double deadline for qualifying small processing agents when communicating a reportable security incident to ANPD and data subjects under Resolution 15/2024.

Applied to the ordinary three-business-day period, that generally means six business days for an agent that validly qualifies for the differentiated regime.

Do not claim six business days merely because the company is “small.” Resolution 2/2022 has eligibility limits. Agents performing high-risk processing or exceeding applicable revenue/group thresholds, among other restrictions, may not benefit from the differentiated framework.

What if you do not have all the facts by the deadline?

ANPD expressly provides for phased reporting in exceptional cases. If complete information is not yet available, the controller can submit a preliminary communication, explain why it is incomplete, and later provide complementary information in a reasoned manner.

ANPD's current guidance says the complementary information may be provided within 20 business days from the initial communication.

That makes one incident-response habit particularly dangerous: waiting for perfect forensic certainty before deciding whether the regulatory clock matters.

Controller vs Operator: Who Must Notify?

The legal notification duty belongs to the controller.

Article 48 places the duty to communicate the incident to ANPD and affected data subjects on the controller. ANPD's current guidance repeats this point.

The operator still has a critical duty: when an incident occurs, it must inform the controller without unjustified delay and provide the information the controller needs for risk assessment and notification.

This distinction is especially important for SaaS, cloud, payroll, marketing, e-commerce and outsourced-service providers. A processor/operator contract that says “vendor will notify customer within applicable legal deadlines” can be operationally useless if the controller has only three business days and the operator itself waits two or three days before escalating.

ANPD recommends that incident-communication obligations between controllers and operators be established contractually so the process can move quickly and risks to data subjects can be reduced.

Activity Controller Operator
Contain and investigateCoordinates its environment and decision-making.Investigates and contains its affected service/environment.
Determine LGPD applicabilityMust assess the controller's affected processing and obligations.Provides facts about the processing it performs for the controller.
Risk assessmentMakes the reportability decision for its incident obligations.Provides data, scope, chronology, protections and mitigation information.
Notify ANPDLegal duty belongs to controller.Supports controller; does not replace the controller's Article 48 duty merely by being the operator.
Notify data subjectsLegal duty belongs to controller when threshold is met.Supports with affected-user identification and incident facts.
Contractual escalationShould set a timeline short enough to preserve regulatory response time.Must escalate without unjustified delay and according to contract.

For a deeper role analysis, see our LGPD for SaaS Companies guide.

What Should the Controller Communicate to ANPD?

Article 48 lists minimum subject matter, and Resolution 15/2024 creates the current operational communication process. A controller should be prepared to assemble, at minimum, information around:

Nature and category of affected personal dataWhat types of data were affected and how sensitive are they?
Affected data subjectsWho was affected and, where known, approximately how many people?
Security measuresWhich technical and security measures protected the data, subject to commercial and industrial secrecy?
Incident risksWhat relevant risks and possible impacts can the incident create for individuals?
Chronology and awarenessWhen did the organization become aware of the incident and what happened next?
MitigationWhat measures have been or will be taken to reverse or reduce the effects?
Delay explanationIf communication was late, why?
Controller / representative informationKeep the formal notifying-party and representation information ready for ANPD's electronic procedure.

ANPD currently receives incident communications through electronic petitioning in the SEI!ANPD system. The communication is made by the encarregado or a legally constituted representative of the controller.

Prepare SEI!ANPD access before an incident. The middle of a three-business-day notification window is a poor time to discover that the relevant people do not know the filing process or lack the documentation and authority needed to submit the communication.

How Must Affected Data Subjects Be Notified?

ANPD says communication should happen as quickly as possible once the controller concludes that the incident can create relevant risk or damage. It should be direct and individualized whenever possible.

Communication channels can include:

  • email;
  • SMS;
  • letter;
  • electronic message; or
  • preferably, another channel the organization already normally uses to communicate with the data subject.

If affected individuals cannot be individually identified despite confirmation of the incident, broader communication may be necessary. ANPD says indirect public communication can be used exceptionally and with justification, using a channel capable of reaching the greatest possible number of affected individuals and giving the notice appropriate prominence.

What should the data-subject notice contain?

According to ANPD's current incident page, the notice should use simple, easy-to-understand language and include at least:

  1. the nature and categories of personal data affected;
  2. the technical and security measures used to protect the data, respecting commercial and industrial secrecy;
  3. the risks and possible impacts for data subjects;
  4. the reason for delay if the notice was late;
  5. measures already taken or planned to reverse or mitigate the effects;
  6. the date the organization learned of the incident; and
  7. a contact for further information and, where applicable, the encarregado's contact details.
A public statement is not automatically a valid individual notice. ANPD says communication should be direct and individualized whenever identification is possible. A press release or website banner should not be chosen merely because it is easier for the organization.

Incident Records: The Five-Year Requirement

One of the most important but less-discussed requirements of Resolution 15/2024 is the incident register. The controller must maintain a record of security incidents—including incidents that were not communicated to ANPD or affected individuals—for at least five years from the date of the record, unless another obligation requires a longer period.

A defensible incident record should include at least:

  • date the incident became known;
  • general description of the circumstances;
  • nature and category of affected data;
  • number of affected data subjects;
  • risk assessment and possible harm;
  • correction and mitigation measures;
  • form and content of communication where notification occurred; and
  • the reasons for not communicating when the incident was determined to be non-reportable.
This changes the meaning of “not reportable.” The decision should not disappear into a Slack conversation or an email chain. If the controller concludes that no notification is required, the reason for that conclusion should itself be documented.

A 12-Step LGPD Security Incident Response Workflow

1

Detect and preserve evidence

Record the alert source, timestamps, systems, logs and initial facts. Avoid destroying evidence while trying to contain the incident.

Evidence: alert, ticket, logs, forensic snapshot, user/vendor report.
2

Contain the active threat

Revoke credentials, isolate systems, disable exposed endpoints, remove public access, reset secrets or take other measures appropriate to the event.

Evidence: containment actions, timestamps, responsible team and validation.
3

Confirm whether a security incident occurred

Separate a vulnerability or false positive from a confirmed adverse event affecting confidentiality, integrity, availability or authenticity of personal data.

Evidence: incident confirmation memo and technical findings.
4

Identify the affected personal data and LGPD scope

Determine which datasets, data subjects, systems and processing activities are affected and whether the personal data is subject to the LGPD.

Evidence: affected-data inventory, systems, data subjects, processing owner.
5

Identify controller and operator roles

Establish who holds the Article 48 controller duty and which operators/suboperators must urgently provide facts.

Evidence: contract/DPA, role matrix, escalation contacts.
6

Run the relevant-risk or damage assessment

Evaluate data sensitivity, affected groups, scale, possible fraud or identity misuse, reputational or physical harm, existing protections, duration of exposure and mitigation.

Evidence: written risk assessment with facts, assumptions and decision owner.
7

Start the regulatory clock workflow immediately

Do not wait until the final reportability decision to assemble notification facts. The ordinary reportable-incident period is three business days, and qualifying small agents may have double time.

Evidence: incident clock, decision deadline and owner.
8

Prepare ANPD communication

Assemble the known incident facts, risks, security measures, chronology, affected-data information and mitigation. Use preliminary reporting if complete information is genuinely unavailable and justify the staged approach.

Evidence: draft/submitted CIS, SEI protocol and representation documents.
9

Prepare the data-subject notice

Use direct, individualized communication whenever possible and explain the incident in plain language, including risks, mitigations and practical contact information.

Evidence: final notice, recipient logic, delivery records and copy of public notice if exceptional indirect publication is used.
10

Coordinate other legal and contractual notifications

Sector regulators, customers, insurers, law enforcement, contractual partners or authorities in other jurisdictions may have separate rules. Build one incident timeline that tracks each obligation independently.

Evidence: jurisdiction/contract notification matrix and filing records.
11

Complement, mitigate and test

Submit any justified complementary information, complete remediation, monitor abuse/fraud indicators, and verify that the affected system and control changes work as intended.

Evidence: complementary filing, remediation tickets, test results, post-incident monitoring.
12

Close with a five-year incident record and lessons learned

Preserve the incident register, reportability rationale, communications and remediation evidence. Feed lessons back into security design, vendor management, training and future incident tabletop exercises.

Evidence: final incident report, five-year record, lessons learned, remediation tracker and governance review.

Common LGPD Incident-Response Mistakes

“We will decide whether to notify after forensics is complete.”

That can be dangerous. The regulatory period is short. Investigation and notification preparation should run in parallel, with preliminary reporting available where facts remain incomplete and the incident is reportable.

“Our vendor will notify ANPD for us.”

A vendor may help operationally, but Article 48 places the legal communication duty on the controller. Make sure the controller owns the reportability decision and filing process.

“No notification means no documentation.”

Incorrect. The incident register includes incidents not communicated to ANPD or data subjects, and the reasons for non-notification should be recorded.

“Encrypted data means the incident can never be reportable.”

Encryption can materially reduce risk and Article 48 says ANPD can consider whether technical measures made affected data unintelligible to unauthorized third parties. But the controller should assess the actual encryption, key exposure and incident facts, not rely on the word “encrypted” alone.

“A website press release is enough.”

Not when affected individuals can be identified and contacted. ANPD's preferred model is direct and individualized communication whenever possible.

Want to connect incident response to the rest of your LGPD program?

Use our 25-point LGPD Compliance Checklist to review security, vendors, roles, international transfers, rights, retention and governance alongside breach response.

What Should Be Tested Before an Incident?

Readiness test Question Success evidence
DetectionCan the organization detect unauthorized access, disclosure, loss, alteration or availability events?Monitoring, alerts, logging and escalation tests.
OwnershipWho can declare a personal-data incident and who decides reportability?Named incident/privacy decision owners.
Vendor escalationCan critical operators notify the controller quickly enough?Contract terms, tested contacts and after-hours procedure.
Data mapCan the team identify affected personal-data categories and people quickly?Current data map / ROPA and system ownership.
ANPD filingCan an authorized person access and use the current electronic filing process?Documented procedure and authorized representative.
Subject contactCan the business reach affected people directly?Communication channels, templates and tested delivery process.
RecordkeepingCan the organization preserve the required incident record for five years?Controlled incident register and retention rule.

Turn Incident Response Into a Documented Compliance Process

The Brazil LGPD Compliance Playbook — 2026 Edition includes a Security Incident Assessment worksheet, Data Mapping Worksheet, Processing Inventory / ROPA, Vendor Privacy and Security Review, International Transfer Review, Data-Subject Request tools, a 100-point compliance audit, and a 30-day implementation roadmap.

Security Incident Assessment Vendor Review 100-point compliance audit 16 implementation tools
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

What is the LGPD data breach notification deadline?

Under Resolution 15/2024, when a security incident can cause relevant risk or damage to data subjects, the controller generally must notify ANPD and affected data subjects within three business days, unless specific legislation establishes another deadline.

Does every security incident have to be reported?

No. ANPD says the incident must cumulatively be confirmed, involve personal data subject to the LGPD, and be capable of causing relevant risk or damage to affected data subjects.

Who must notify ANPD: the controller or operator?

The legal duty to communicate the incident to ANPD and affected data subjects belongs to the controller. The operator must inform the controller without unjustified delay and provide the necessary incident information.

What if we do not have all the information within three business days?

ANPD permits a justified staged approach in exceptional cases. A preliminary communication can be submitted and complementary information can be provided, in a reasoned manner, within twenty business days from the initial communication.

How long must incident records be kept?

Resolution 15/2024 requires the controller to keep the incident record—including incidents not communicated to ANPD or data subjects—for at least five years from the record date, unless another obligation requires a longer period.

Do qualifying small processing agents get more time?

Yes. The current consolidated Resolution 2/2022 provides double time for qualifying small processing agents for incident communication to ANPD and data subjects under Resolution 15/2024. Applied to the ordinary three-business-day period, this generally means six business days for agents that validly qualify for the differentiated regime.

Does a vulnerability have to be reported?

Not merely because it exists. ANPD distinguishes a vulnerability from a confirmed security incident. If exploitation results in an adverse event affecting personal-data confidentiality, integrity, availability or authenticity, the organization should then assess the incident under the reporting criteria.

Can encryption mean an incident is non-reportable?

Strong protection that makes data unintelligible to unauthorized third parties can reduce the risk assessment, and Article 48 expressly allows ANPD to consider such technical measures. The conclusion still depends on the actual incident, encryption implementation, key exposure, affected data and potential harm.

How should data subjects be informed?

ANPD says communication should be direct and individualized whenever possible, use simple and understandable language, and explain the affected data, security measures, risks, mitigation, date of knowledge and an information contact.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD, Resolution CD/ANPD No. 15/2024, the consolidated Resolution CD/ANPD No. 2/2022 and official ANPD incident guidance available on August 19, 2026. Incident reportability is highly fact-specific and can also be affected by sector-specific laws, contracts, regulators and foreign notification requirements. During a live incident, obtain qualified Brazilian legal, privacy and cybersecurity assistance appropriate to the circumstances.