Quick Answer: When must an LGPD security incident be reported?
Under Article 48 of the LGPD and ANPD Resolution CD/ANPD No. 15/2024, a controller must communicate a security incident to ANPD and affected data subjects when the incident can cause relevant risk or damage. ANPD's current guidance says the reporting test is cumulative: the incident must be confirmed, involve personal data subject to the LGPD, and be capable of causing relevant risk or damage to data subjects. When notification is required, the ordinary deadline is three business days, subject to a different deadline in specific legislation. Qualifying small processing agents benefit from the current double-deadline rule under Resolution No. 2/2022.
Key Takeaways
- Not every cybersecurity event is reportable. A vulnerability alone is not automatically a security incident.
- Not every confirmed incident must be reported. The controller must assess whether it can cause relevant risk or damage.
- The controller owns the legal notification duty. The operator must escalate without unjustified delay and support the controller.
- The ordinary deadline is three business days. It applies to communication to ANPD and affected data subjects when the threshold is met.
- Qualifying small agents have double time. Under the current consolidated rule, this generally means six business days.
- Incomplete facts do not justify silence. ANPD allows preliminary and complementary communications in justified cases.
- Even non-reportable incidents must be taken seriously. Resolution 15/2024 requires the controller to maintain incident records—including non-reported incidents—for at least five years.
“Data breach” is useful international shorthand, but Brazil's regulation uses the broader concept of a security incident involving personal data. That matters because the problem is not limited to public leaks. Loss of availability, unauthorized alteration, accidental disclosure, compromised authenticity, and other adverse events can also fall within incident-response analysis.
ANPD's glossary defines a security incident as a confirmed adverse event related to violation of the confidentiality, integrity, availability or authenticity of personal-data security.
Which Incidents Must Be Reported to ANPD?
ANPD's current incident page gives a useful three-part test. A security incident needs to be communicated when the following criteria are met cumulatively:
A suspected vulnerability, alert or anomaly should be investigated. Reporting is not triggered merely because a weakness exists.
An information-security event involving no personal data, or only data that is genuinely anonymized and no longer relates to identifiable people, does not follow the same Article 48 path.
The controller must assess the likely impact on data subjects using the incident context, data, scale, affected groups, protections and mitigation.
Article 48 places the notification obligation on the controller where a security incident can create relevant risk or damage to data subjects. It requires communication to both the national data-protection authority and the affected data subjects and identifies minimum information categories for the communication.
A vulnerability is not automatically an incident
ANPD expressly distinguishes a vulnerability from an incident. A vulnerability is a weakness. If it has not been exploited and no confirmed adverse event involving personal-data security has occurred, the organization may be dealing with a security weakness rather than a reportable incident.
That does not mean the weakness can be ignored. Article 46 requires technical and administrative security measures, and prevention is one of the LGPD's core principles. The distinction simply prevents vulnerability management from being confused with Article 48 notification.
What Does “Relevant Risk or Damage” Mean?
This is the core decision in many incidents. ANPD says the controller should assess factors including:
- the context of the processing activity;
- the categories and number of affected data subjects;
- the nature, categories and quantity of affected data;
- potential material, moral or reputational harm;
- whether affected data was protected so that identification of the data subjects was prevented; and
- whether post-incident mitigation measures were sufficient.
ANPD specifically identifies concerns such as discrimination, identity theft, financial fraud and other material or moral harms, with particular attention to incidents involving large-scale data, sensitive data and vulnerable groups such as children, adolescents or older persons.
| Risk factor | Questions to ask | Example signal |
|---|---|---|
| Data sensitivity | Does the event involve health, biometric, genetic, religious, political, sexual-life or other sensitive information? | Exposed medical records or biometric templates. |
| Financial / authentication data | Could the data facilitate account takeover, fraud or unauthorized transactions? | Passwords, tokens, payment-related records or banking information. |
| Vulnerable groups | Are children, adolescents, older persons or other vulnerable populations affected? | School, health or social-benefit database exposure. |
| Scale | How many people and how much data are affected? How geographically broad is the impact? | Large customer database or long-running exposure. |
| Protection | Was the data encrypted or otherwise protected in a way that made it unintelligible to unauthorized third parties? | Encrypted stolen device with strong key protection versus readable customer files. |
| Potential harm | Could the event cause fraud, discrimination, identity misuse, reputational harm, physical risk or loss of rights? | Identity-document exposure combined with financial data. |
| Mitigation | Did containment materially reduce the remaining risk? | Rapid credential reset, token revocation or confirmed deletion by an unintended recipient. |
The Current LGPD Incident Deadline: Three Business Days
Resolution CD/ANPD No. 15/2024 is currently listed by ANPD as in force. Under the current rule, communication to ANPD and affected data subjects generally must be made within three business days when the incident can cause relevant risk or damage, unless specific legislation applicable to the organization provides another notification deadline.
Qualifying small processing agents: double deadline
A valuable 2026 nuance is that the consolidated small-processing-agent regulation still provides a double deadline for qualifying small processing agents when communicating a reportable security incident to ANPD and data subjects under Resolution 15/2024.
Applied to the ordinary three-business-day period, that generally means six business days for an agent that validly qualifies for the differentiated regime.
What if you do not have all the facts by the deadline?
ANPD expressly provides for phased reporting in exceptional cases. If complete information is not yet available, the controller can submit a preliminary communication, explain why it is incomplete, and later provide complementary information in a reasoned manner.
ANPD's current guidance says the complementary information may be provided within 20 business days from the initial communication.
That makes one incident-response habit particularly dangerous: waiting for perfect forensic certainty before deciding whether the regulatory clock matters.
Controller vs Operator: Who Must Notify?
The legal notification duty belongs to the controller.
Article 48 places the duty to communicate the incident to ANPD and affected data subjects on the controller. ANPD's current guidance repeats this point.
The operator still has a critical duty: when an incident occurs, it must inform the controller without unjustified delay and provide the information the controller needs for risk assessment and notification.
This distinction is especially important for SaaS, cloud, payroll, marketing, e-commerce and outsourced-service providers. A processor/operator contract that says “vendor will notify customer within applicable legal deadlines” can be operationally useless if the controller has only three business days and the operator itself waits two or three days before escalating.
ANPD recommends that incident-communication obligations between controllers and operators be established contractually so the process can move quickly and risks to data subjects can be reduced.
| Activity | Controller | Operator |
|---|---|---|
| Contain and investigate | Coordinates its environment and decision-making. | Investigates and contains its affected service/environment. |
| Determine LGPD applicability | Must assess the controller's affected processing and obligations. | Provides facts about the processing it performs for the controller. |
| Risk assessment | Makes the reportability decision for its incident obligations. | Provides data, scope, chronology, protections and mitigation information. |
| Notify ANPD | Legal duty belongs to controller. | Supports controller; does not replace the controller's Article 48 duty merely by being the operator. |
| Notify data subjects | Legal duty belongs to controller when threshold is met. | Supports with affected-user identification and incident facts. |
| Contractual escalation | Should set a timeline short enough to preserve regulatory response time. | Must escalate without unjustified delay and according to contract. |
For a deeper role analysis, see our LGPD for SaaS Companies guide.
What Should the Controller Communicate to ANPD?
Article 48 lists minimum subject matter, and Resolution 15/2024 creates the current operational communication process. A controller should be prepared to assemble, at minimum, information around:
ANPD currently receives incident communications through electronic petitioning in the SEI!ANPD system. The communication is made by the encarregado or a legally constituted representative of the controller.
How Must Affected Data Subjects Be Notified?
ANPD says communication should happen as quickly as possible once the controller concludes that the incident can create relevant risk or damage. It should be direct and individualized whenever possible.
Communication channels can include:
- email;
- SMS;
- letter;
- electronic message; or
- preferably, another channel the organization already normally uses to communicate with the data subject.
If affected individuals cannot be individually identified despite confirmation of the incident, broader communication may be necessary. ANPD says indirect public communication can be used exceptionally and with justification, using a channel capable of reaching the greatest possible number of affected individuals and giving the notice appropriate prominence.
What should the data-subject notice contain?
According to ANPD's current incident page, the notice should use simple, easy-to-understand language and include at least:
- the nature and categories of personal data affected;
- the technical and security measures used to protect the data, respecting commercial and industrial secrecy;
- the risks and possible impacts for data subjects;
- the reason for delay if the notice was late;
- measures already taken or planned to reverse or mitigate the effects;
- the date the organization learned of the incident; and
- a contact for further information and, where applicable, the encarregado's contact details.
Incident Records: The Five-Year Requirement
One of the most important but less-discussed requirements of Resolution 15/2024 is the incident register. The controller must maintain a record of security incidents—including incidents that were not communicated to ANPD or affected individuals—for at least five years from the date of the record, unless another obligation requires a longer period.
A defensible incident record should include at least:
- date the incident became known;
- general description of the circumstances;
- nature and category of affected data;
- number of affected data subjects;
- risk assessment and possible harm;
- correction and mitigation measures;
- form and content of communication where notification occurred; and
- the reasons for not communicating when the incident was determined to be non-reportable.
A 12-Step LGPD Security Incident Response Workflow
Detect and preserve evidence
Record the alert source, timestamps, systems, logs and initial facts. Avoid destroying evidence while trying to contain the incident.
Contain the active threat
Revoke credentials, isolate systems, disable exposed endpoints, remove public access, reset secrets or take other measures appropriate to the event.
Confirm whether a security incident occurred
Separate a vulnerability or false positive from a confirmed adverse event affecting confidentiality, integrity, availability or authenticity of personal data.
Identify the affected personal data and LGPD scope
Determine which datasets, data subjects, systems and processing activities are affected and whether the personal data is subject to the LGPD.
Identify controller and operator roles
Establish who holds the Article 48 controller duty and which operators/suboperators must urgently provide facts.
Run the relevant-risk or damage assessment
Evaluate data sensitivity, affected groups, scale, possible fraud or identity misuse, reputational or physical harm, existing protections, duration of exposure and mitigation.
Start the regulatory clock workflow immediately
Do not wait until the final reportability decision to assemble notification facts. The ordinary reportable-incident period is three business days, and qualifying small agents may have double time.
Prepare ANPD communication
Assemble the known incident facts, risks, security measures, chronology, affected-data information and mitigation. Use preliminary reporting if complete information is genuinely unavailable and justify the staged approach.
Prepare the data-subject notice
Use direct, individualized communication whenever possible and explain the incident in plain language, including risks, mitigations and practical contact information.
Coordinate other legal and contractual notifications
Sector regulators, customers, insurers, law enforcement, contractual partners or authorities in other jurisdictions may have separate rules. Build one incident timeline that tracks each obligation independently.
Complement, mitigate and test
Submit any justified complementary information, complete remediation, monitor abuse/fraud indicators, and verify that the affected system and control changes work as intended.
Close with a five-year incident record and lessons learned
Preserve the incident register, reportability rationale, communications and remediation evidence. Feed lessons back into security design, vendor management, training and future incident tabletop exercises.
Common LGPD Incident-Response Mistakes
“We will decide whether to notify after forensics is complete.”
That can be dangerous. The regulatory period is short. Investigation and notification preparation should run in parallel, with preliminary reporting available where facts remain incomplete and the incident is reportable.
“Our vendor will notify ANPD for us.”
A vendor may help operationally, but Article 48 places the legal communication duty on the controller. Make sure the controller owns the reportability decision and filing process.
“No notification means no documentation.”
Incorrect. The incident register includes incidents not communicated to ANPD or data subjects, and the reasons for non-notification should be recorded.
“Encrypted data means the incident can never be reportable.”
Encryption can materially reduce risk and Article 48 says ANPD can consider whether technical measures made affected data unintelligible to unauthorized third parties. But the controller should assess the actual encryption, key exposure and incident facts, not rely on the word “encrypted” alone.
“A website press release is enough.”
Not when affected individuals can be identified and contacted. ANPD's preferred model is direct and individualized communication whenever possible.
Want to connect incident response to the rest of your LGPD program?
Use our 25-point LGPD Compliance Checklist to review security, vendors, roles, international transfers, rights, retention and governance alongside breach response.
What Should Be Tested Before an Incident?
| Readiness test | Question | Success evidence |
|---|---|---|
| Detection | Can the organization detect unauthorized access, disclosure, loss, alteration or availability events? | Monitoring, alerts, logging and escalation tests. |
| Ownership | Who can declare a personal-data incident and who decides reportability? | Named incident/privacy decision owners. |
| Vendor escalation | Can critical operators notify the controller quickly enough? | Contract terms, tested contacts and after-hours procedure. |
| Data map | Can the team identify affected personal-data categories and people quickly? | Current data map / ROPA and system ownership. |
| ANPD filing | Can an authorized person access and use the current electronic filing process? | Documented procedure and authorized representative. |
| Subject contact | Can the business reach affected people directly? | Communication channels, templates and tested delivery process. |
| Recordkeeping | Can the organization preserve the required incident record for five years? | Controlled incident register and retention rule. |
Turn Incident Response Into a Documented Compliance Process
The Brazil LGPD Compliance Playbook — 2026 Edition includes a Security Incident Assessment worksheet, Data Mapping Worksheet, Processing Inventory / ROPA, Vendor Privacy and Security Review, International Transfer Review, Data-Subject Request tools, a 100-point compliance audit, and a 30-day implementation roadmap.
Frequently Asked Questions
What is the LGPD data breach notification deadline?
Under Resolution 15/2024, when a security incident can cause relevant risk or damage to data subjects, the controller generally must notify ANPD and affected data subjects within three business days, unless specific legislation establishes another deadline.
Does every security incident have to be reported?
No. ANPD says the incident must cumulatively be confirmed, involve personal data subject to the LGPD, and be capable of causing relevant risk or damage to affected data subjects.
Who must notify ANPD: the controller or operator?
The legal duty to communicate the incident to ANPD and affected data subjects belongs to the controller. The operator must inform the controller without unjustified delay and provide the necessary incident information.
What if we do not have all the information within three business days?
ANPD permits a justified staged approach in exceptional cases. A preliminary communication can be submitted and complementary information can be provided, in a reasoned manner, within twenty business days from the initial communication.
How long must incident records be kept?
Resolution 15/2024 requires the controller to keep the incident record—including incidents not communicated to ANPD or data subjects—for at least five years from the record date, unless another obligation requires a longer period.
Do qualifying small processing agents get more time?
Yes. The current consolidated Resolution 2/2022 provides double time for qualifying small processing agents for incident communication to ANPD and data subjects under Resolution 15/2024. Applied to the ordinary three-business-day period, this generally means six business days for agents that validly qualify for the differentiated regime.
Does a vulnerability have to be reported?
Not merely because it exists. ANPD distinguishes a vulnerability from a confirmed security incident. If exploitation results in an adverse event affecting personal-data confidentiality, integrity, availability or authenticity, the organization should then assess the incident under the reporting criteria.
Can encryption mean an incident is non-reportable?
Strong protection that makes data unintelligible to unauthorized third parties can reduce the risk assessment, and Article 48 expressly allows ANPD to consider such technical measures. The conclusion still depends on the actual incident, encryption implementation, key exposure, affected data and potential harm.
How should data subjects be informed?
ANPD says communication should be direct and individualized whenever possible, use simple and understandable language, and explain the affected data, security measures, risks, mitigation, date of knowledge and an information contact.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary source for Articles 46–49, security duties, controller notification and incident severity considerations.
- ANPD — Security Incident Communication Current operational guidance on reportability, risk assessment, three-business-day communication, phased reporting, operator duties, data-subject communications and electronic filing.
- ANPD — Current Regulations Official regulatory index confirming Resolution CD/ANPD No. 15/2024 remains in force as of the review date.
- ANPD Resolution CD/ANPD No. 2/2022 — Small Processing Agents Current consolidated source for the double-deadline rule applicable to qualifying small processing agents and the eligibility restrictions for the differentiated regime.