2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
LGPD Enforcement & Sanctions

LGPD Fines and Penalties: How Much Can Companies Be Fined in Brazil?

The headline number—“R$50 million”—is only part of the story. Brazil's LGPD allows ANPD to impose warnings, simple and daily fines, publicize an infraction, block or delete personal data, suspend databases or processing activities, and in serious cases prohibit personal-data processing activities. Resolution No. 4/2023 determines how ANPD evaluates severity, damage, revenue, cooperation, governance, remediation and recurrence.

Published: Last reviewed: Reading time: ~21 minutes By LGPD Brazil Editorial Team

Quick Answer: How much can a company be fined under the LGPD?

Under Article 52 of Brazil's LGPD, a private legal entity, group or conglomerate can receive a simple administrative fine of up to 2% of its revenue in Brazil in the previous fiscal year, excluding taxes, subject to a maximum of R$50 million per infraction. A daily fine is subject to the same total cap per infraction. But fines are only part of the sanction framework. ANPD can also issue warnings, publicize a confirmed infraction, block or delete personal data, suspend a database or processing activity, or partially or totally prohibit personal-data processing activities. The actual sanction must follow an administrative proceeding and the dosimetry criteria in Resolution CD/ANPD No. 4/2023.

Key Takeaways

  • R$50 million is not an automatic fine. It is the statutory maximum per infraction for the simple fine.
  • The percentage is 2% of Brazil revenue, not global turnover. The statutory text refers to revenue in Brazil for a private legal entity, group or conglomerate, excluding taxes.
  • One case can involve multiple infractions. Separate violations can generate separate sanctions, subject to the applicable rules.
  • Operational sanctions can be more disruptive than money. Blocking, deletion, suspension or prohibition can affect the ability to use data in the business.
  • Severity is structured. Resolution 4/2023 classifies infractions as light, medium or serious.
  • Cooperation and remediation matter. Governance, early correction, mitigation and cooperation can operate as mitigating factors.
  • Ignoring ANPD can make the situation worse. Obstruction of supervision is itself treated as a serious infraction under the dosimetry regulation.

The Maximum LGPD Fine: 2% of Brazil Revenue, Capped at R$50 Million Per Infraction

Up to 2%
Revenue in Brazil

The simple-fine ceiling is tied to the revenue of the private legal entity, group or conglomerate in Brazil in the previous fiscal year, excluding taxes.

R$50M
Maximum per infraction

Even when the 2% calculation would be higher, the simple administrative fine is capped at R$50 million for each infraction.

The phrase “per infraction” matters. The R$50 million amount is not a universal ceiling for every possible LGPD consequence arising from one business problem. A case may involve more than one proven infraction, and non-monetary sanctions can also be imposed under Article 52.

The daily fine is also subject to the total limit associated with Article 52(II). Resolution 4/2023 says daily fines accumulate until the obligation is fulfilled, up to R$50 million per infraction.

Is R$50 million the maximum total legal exposure?

No. Article 52(2) expressly says the administrative sanctions in the LGPD do not replace administrative, civil or criminal sanctions available under Brazil's Consumer Protection Code or other specific legislation.

The LGPD also contains civil-liability provisions. A controller or operator that causes material, moral, individual or collective damage through unlawful processing may face a duty to repair the damage under the conditions set out in the law.

Do not tell management “our maximum LGPD exposure is R$50 million.” A better statement is: “The ANPD simple-fine cap is R$50 million per infraction, but the law also provides daily fines, operational sanctions and potentially separate civil, consumer, sector-specific or other legal consequences.”

The Nine Administrative Sanctions in ANPD's Current Dosimetry Regulation

Resolution 4/2023 organizes the sanction framework into nine categories. The sanctions can be applied gradually, individually or cumulatively depending on the case.

1

Warning

A warning can be used for a light or medium infraction that does not involve specific recidivism, or when corrective measures need to be imposed.

Business impact: formal regulatory finding plus a deadline and concrete remediation obligations.
2

Simple Fine

ANPD can apply a simple fine when preventive or corrective measures were not complied with, when the infraction is classified as serious, or when another sanction would not be adequate given the nature of the violation, processing activity, data and circumstances.

Ceiling: up to 2% of qualifying Brazil revenue, capped at R$50 million per infraction.
3

Daily Fine

A daily fine can be used to compel compliance with a non-monetary sanction or ANPD determination. It can also be used where irregularities remain uncorrected, supervision is obstructed or a permanent infraction continues.

Ceiling: cumulative total up to R$50 million per infraction.
4

Publicization of the Infraction

ANPD can require the infractor to publicly disclose the violation after it has been properly investigated and confirmed. The Agency determines the content, medium, duration and compliance period.

Business impact: reputational consequences can exceed the direct monetary cost of a fine.
5

Blocking of Personal Data

Blocking temporarily suspends processing of the personal data connected to the infraction until the conduct is regularized. The infractor must also notify processing agents with whom the data was shared so they can repeat the blocking, subject to the regulation's exceptions.

Business impact: affected data can become operationally unavailable for sales, analytics, profiling, service delivery or other uses.
6

Deletion of Personal Data

ANPD can require deletion of the personal data connected to the infraction. The regulation also requires communication to other processing agents that received the data so they can repeat the procedure, unless that communication is demonstrably impossible or disproportionately burdensome.

Business impact: unlawful datasets, models, audience lists or customer information may have to be removed rather than merely documented.
7

Partial Suspension of a Database

ANPD can partially suspend operation of the database related to the infraction for up to six months, extendable once for an equal period, until the processing is regularized.

Business impact: a core database may become unusable for the affected processing activity.
8

Suspension of the Processing Activity

ANPD can suspend the personal-data processing activity connected to the infraction for up to six months, extendable once for the same period.

Business impact: a product feature, marketing operation, profiling process or other data-dependent activity can be halted.
9

Partial or Total Prohibition of Personal-Data Processing Activities

The regulation permits partial or total prohibition in specified serious circumstances, including certain recidivism situations, unlawful-purpose processing or processing without a legal basis, or loss/failure of the technical and operational conditions needed for adequate processing.

Business impact: for a data-driven company, this can threaten the viability of a product or business model.

The three most restrictive operational sanctions—partial database suspension, processing-activity suspension and prohibition— are subject to escalation rules. Resolution 4/2023 says they generally follow at least one of the sanctions specified in the regulation for the same concrete case.

How ANPD Calculates and Selects a Sanction

Resolution CD/ANPD No. 4/2023 is the central dosimetry rule. It does not treat every LGPD violation as a flat fine.

1. Identify infractionWhich LGPD or ANPD rule was violated?
2. Classify severityLight, medium or serious.
3. Determine baseRevenue context, infraction class and degree of harm.
4. AdjustAggravating and mitigating circumstances.
5. Apply limitsMinimums, 2% ceiling, R$50m cap and proportionality.

For a simple fine, the regulation considers the classification of the infraction, the relevant revenue from the last available fiscal year before the sanction, and the degree of harm. Depending on the facts and the available financial information, ANPD can use revenue from the affected business branch or other regulatory fallbacks.

The regulation also says the final sanction must respect proportionality. ANPD can depart from the fine methodology or replace a sanction with another one where necessary to avoid disproportion between the seriousness of the violation and the intensity of the sanction, but the decision must be reasoned.

Light, Medium and Serious LGPD Infractions

Light

An infraction is classified as light when it does not meet the regulatory tests for medium or serious.

Medium

A medium infraction is one capable of significantly affecting the interests and fundamental rights of data subjects— for example, significantly limiting rights or access to a service, or causing material or moral harms such as discrimination, violation of physical integrity, image/reputation harm, financial fraud or identity misuse—provided it is not classified as serious.

Serious

A medium-level impact becomes serious when combined with at least one of the additional circumstances listed in Resolution 4/2023, including:

  • large-scale processing;
  • obtaining or seeking economic advantage from the violation;
  • risk to the life of data subjects;
  • sensitive data or data relating to children, adolescents or older persons;
  • processing without a legal basis under the LGPD;
  • unlawful or abusive discriminatory effects; or
  • systematic irregular practices.

The regulation separately says that obstruction of ANPD's supervisory activity is a serious infraction.

This is why “we will answer the regulator later” is a bad compliance strategy. Failure to cooperate is not simply poor process management. Under the dosimetry regulation, obstruction itself can become a serious violation.

What Can Increase or Reduce an LGPD Fine?

Resolution 4/2023 contains explicit aggravating and mitigating factors. This is one of the strongest reasons to maintain evidence of governance, remediation and cooperation before a regulatory problem occurs.

Aggravating factor Regulatory adjustment What it means operationally
Specific recidivism +10% per case, up to +40% Repeated violation of the same legal/regulatory provision can materially increase the fine.
General recidivism +5% per case, up to +20% Previous final ANPD sanctions for other violations can also matter.
Failure to comply with guidance/preventive measures +20% per measure, up to +80% Ignoring early ANPD intervention can sharply increase monetary exposure.
Failure to comply with corrective measures +30% per measure, up to +90% Failure to remediate after a formal corrective measure is especially damaging.
Mitigating factor Potential reduction What it rewards
Violation stopped before preparatory proceeding -75% Very early self-correction before ANPD has formally escalated the matter.
Stopped after preparatory proceeding but before PAS -50% Prompt remediation after early regulatory engagement.
Stopped after PAS but before first-instance decision -30% Later remediation still has value, but less than early correction.
Good-practice/governance policy or demonstrated internal safeguards -20% Documented privacy governance and repeatable controls can count.
Mitigation/reversal of effects before preparatory proceeding or PAS -20% Early action to reduce harm to affected data subjects.
Mitigation after preparatory proceeding but before PAS -10% Remediation after regulatory attention but before sanction proceedings.
Cooperation or good faith -5% Constructive engagement and credible evidence matter.
Evidence is critical. The regulation places the burden on the infractor to prove that the conditions for the mitigating factors were met. A governance program that exists only in slides is much weaker than dated records, audits, procedures, remediation tickets, training evidence and documented decision-making.

Payment and appeal

Under Resolution 4/2023, a fine is generally payable within 20 business days from official notice of the sanction decision. Qualifying small processing agents receive double time for payment.

The regulation also allows a 25% reduction when the infractor expressly waives the right to appeal the first-instance decision and pays within the applicable payment period.

Can Public Authorities Be Fined Under the LGPD?

Article 52 treats public bodies differently. Paragraph 3 says the following sanctions can be applied to public entities and bodies:

  • warning;
  • publicization of the infraction;
  • blocking of the affected personal data;
  • deletion of the affected personal data;
  • partial suspension of the relevant database;
  • suspension of the relevant processing activity; and
  • partial or total prohibition of personal-data processing activities.

The simple and daily monetary-fine provisions are not included in Article 52(3)'s public-entity list.

Public-sector analysis still needs nuance. Article 24 says public companies and mixed-capital companies operating under a competitive regime receive the same LGPD treatment as private legal entities, while the same organizations executing public policies receive public-sector treatment for those activities.

ANPD Enforcement in Practice: What 2026 Shows

2026 signal: ANPD is using monitoring, remediation and sanction proceedings together

In July 2026, ANPD reported the result of monitoring 56 controllers regarding encarregado appointments and communication channels for data subjects. According to the Agency, 27 organizations fully complied with its requests, eight still had pending corrections and 21 did not respond; the non-responsive cases were sent to the sanctions area for analysis.

This is important because it shows that enforcement is not limited to issuing headline fines. ANPD's model includes monitoring, requests for adequacy, remediation opportunities and escalation when organizations fail to respond.

Read ANPD's July 2026 monitoring update .

2026 sanction proceeding involving sensitive health data

In July 2026, ANPD announced that it had opened an administrative sanction proceeding against Instituto Saúde e Cidadania (Isac) following a 2025 ransomware incident affecting approximately 500,000 patient records.

The Agency said the investigation concerned alleged failures related to security measures, communication to affected people, publication of encarregado information, prevention, accountability and cooperation/evidence. The case involves sensitive health data and records relating to children, adolescents and older persons.

No final sanction should be inferred merely from the opening of the proceeding. ANPD itself states that any sanction will be defined only after the case is analyzed under the dosimetry regulation.

The first LGPD fine: a useful lesson in proportionality

ANPD's first announced fine in 2023 involved Telekall Infoservice. The Agency imposed a warning and two simple fines of R$7,200 each, totaling R$14,400. One fine concerned processing without a legal basis, and the other concerned failure to respond to ANPD requests during the investigation.

The case is useful because it corrects two misconceptions at once:

  1. Small businesses are not immune from enforcement.
  2. The maximum statutory fine is not the normal starting point. Dosimetry and proportionality matter.

ANPD's case summary also stated that obstruction of supervision was treated as serious and that the company's microenterprise status affected the financial limit applied to the fine.

What Triggers ANPD Attention?

There is no one public checklist saying that a particular event automatically causes a sanction proceeding. ANPD's enforcement framework includes monitoring, guidance, prevention and repression.

In practice, organizations should treat the following as important escalation signals:

  • unresolved data-subject complaints or petitions;
  • failure to answer ANPD information requests;
  • security incidents involving relevant risk or damage;
  • processing without a documented legal basis;
  • large-scale, sensitive or vulnerable-person processing;
  • failure to implement required governance or encarregado obligations;
  • failure to comply with preventive or corrective measures;
  • systematic irregular processing; and
  • recidivism.

That does not mean every one of these situations results in a fine. It means they are exactly the types of facts that can matter to severity, supervision and dosimetry under the current framework.

Want to find the gaps before ANPD does?

Use our 25-point LGPD Compliance Checklist to review scope, data mapping, legal bases, rights, vendors, transfers, security, incident response and governance.

How Companies Can Reduce LGPD Enforcement Risk

No compliance program can guarantee that a company will never receive a complaint, incident or ANPD inquiry. The goal is to make the organization capable of demonstrating that it understood the processing, implemented reasonable controls, responded quickly, cooperated and corrected problems.

1. Map LGPD applicabilityKnow which Brazil-facing processing activities fall within the law and which entity acts as controller/operator.
2. Maintain a real processing inventoryRecord purposes, legal bases, systems, vendors, transfers, retention and owners.
3. Document legal basesProcessing without a valid legal basis is expressly relevant to serious-infraction classification.
4. Test rights-request channelsA privacy mailbox or web form should actually reach an accountable team and generate a trackable workflow.
5. Keep encarregado governance currentWhere required, maintain the formal appointment, public identity/contact information and substitute coverage.
6. Review vendors and contractsKnow which processors/subprocessors hold Brazilian personal data and how incidents, rights and deletion are escalated.
7. Review international transfersMap destinations, remote access, onward transfers and the applicable Article 33 mechanism.
8. Maintain security evidenceAccess controls, secure development, patching, logs, backups, vendor security and incident readiness should be demonstrable.
9. Respond to incidents promptlyRun a documented risk assessment and meet the current notification framework where relevant.
10. Cooperate with ANPDDo not let requests expire. Preserve a record of what was supplied, when and by whom.
11. Remediate earlyResolution 4/2023 rewards early cessation and mitigation much more strongly than late correction.
12. Preserve governance evidencePolicies, ROPA, assessments, audit logs, training, decisions and remediation tickets can support accountability and mitigating factors.

Why Governance Can Affect the Fine

This is one of the most commercially important lessons in the entire sanction regulation. Privacy governance is not only a best-practice concept.

Resolution 4/2023 expressly recognizes, as a mitigating factor, implementation of a good-practice and governance policy or the repeated and demonstrated adoption of internal mechanisms and procedures capable of minimizing harm and supporting secure and appropriate processing.

That does not mean a privacy policy automatically earns a reduction. The organization has to prove the relevant conditions.

Strong evidence can include:

  • current data inventories;
  • documented legal-basis decisions;
  • vendor security reviews;
  • international-transfer records;
  • incident-response exercises;
  • rights-request logs;
  • training records;
  • privacy-by-design reviews;
  • risk assessments and RIPDs where appropriate; and
  • documented remediation after identified gaps.
This is why “we are compliant” is weak evidence. A regulator can evaluate what the company actually documented, implemented, tested, corrected and supplied during supervision.

LGPD Fine Examples: What You Should and Should Not Calculate

It is tempting to take a company's Brazil revenue, multiply it by 2% and call that the expected fine. That is not how Resolution 4/2023 works.

The 2% figure is a statutory ceiling, not a universal fine rate. ANPD first evaluates the infraction and applies the dosimetry methodology, including severity, relevant revenue, degree of harm, aggravating and mitigating factors and applicable minimum/maximum limits.

Statement Accurate? Better explanation
“Every LGPD violation costs 2% of revenue.”No2% is the ceiling for the simple fine; dosimetry determines the actual sanction and amount.
“The maximum penalty is R$50 million total.”NoR$50 million is the cap per infraction for the simple fine and total daily fine; other sanctions and liabilities can coexist.
“Only data breaches create fines.”NoAny violation of LGPD or ANPD regulations can enter the enforcement framework, depending on the facts.
“If no one suffered proven financial loss, there can be no sanction.”NoDegree of harm matters, but sanctions can address unlawful processing, obstruction, governance failures and other violations.
“Cooperation after a problem does not matter.”NoCooperation, early cessation, mitigation and governance are expressly recognized in the dosimetry regulation.

Reduce Enforcement Risk by Building the Evidence Before You Need It

The Brazil LGPD Compliance Playbook — 2026 Edition includes a 100-point compliance audit, a 30-day implementation roadmap and 16 practical tools for data mapping, processing records, legal bases, legitimate interest, vendors, cookies, rights requests, incidents, international transfers, privacy notices, DPAs, retention and ongoing governance.

100-point compliance audit 16 implementation tools 30-day action plan Governance evidence
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

What is the maximum LGPD fine?

For a simple administrative fine, Article 52 allows up to 2% of the revenue of a private legal entity, group or conglomerate in Brazil in the previous fiscal year, excluding taxes, capped at R$50 million per infraction. Daily fines are subject to the same total cap per infraction.

Is the LGPD fine based on global revenue?

Article 52 refers to revenue in Brazil, not global worldwide turnover. Resolution 4/2023 contains more detailed revenue rules for calculating the base amount, including the affected business branch and regulatory fallbacks when information is unavailable or incomplete.

Is R$50 million the maximum total legal exposure?

No. It is the statutory cap per infraction for the ANPD simple fine and the total cap for a daily fine per infraction. The LGPD also provides non-monetary sanctions, and Article 52 says those administrative sanctions do not replace separate administrative, civil or criminal sanctions available under consumer law or specific legislation.

Can ANPD impose penalties other than fines?

Yes. The current framework includes warning, publicization, blocking and deletion of personal data, partial suspension of a database, suspension of a processing activity and partial or total prohibition of personal-data processing activities.

How does ANPD calculate a fine?

Resolution 4/2023 classifies the infraction as light, medium or serious and considers relevant revenue and degree of harm. The fine is then adjusted for aggravating and mitigating circumstances and checked against regulatory minimum and maximum limits.

What makes an LGPD infraction serious?

Serious classification can arise where medium-level impacts are combined with factors such as large-scale processing, economic advantage, risk to life, sensitive data, data of children/adolescents/older persons, processing without a legal basis, discriminatory effects or systematic irregular practices. Obstruction of ANPD supervision is separately classified as serious.

Can cooperation reduce an LGPD fine?

Yes. Resolution 4/2023 includes mitigation for early cessation, documented governance/internal safeguards, measures that mitigate or reverse effects, and cooperation or good faith.

Can ANPD reduce the fine if the company fixes the problem quickly?

Yes. The regulation provides much larger reductions for cessation before regulatory escalation than for correction later in a sanction proceeding. The exact reduction depends on the stage and the conditions proven by the infractor.

Can public authorities receive LGPD fines?

Article 52 paragraph 3 identifies non-monetary sanctions that can be applied to public entities and bodies. The simple and daily monetary-fine provisions are not included in that list. Public companies and mixed-capital companies can require a separate Article 24 analysis depending on whether they operate competitively or execute public policy.

Was a company ever actually fined under the LGPD?

Yes. ANPD announced its first fine in 2023 against Telekall Infoservice. The case included a warning and two simple fines of R$7,200, totaling R$14,400. The case involved processing without a legal basis and failure to respond to ANPD requests during the investigation.

Can a company get a discount for not appealing an ANPD fine?

Resolution 4/2023 provides a 25% reduction where the infractor expressly waives the right to appeal the first-instance decision and pays within the applicable payment deadline.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against the current compiled LGPD, Resolution CD/ANPD No. 4/2023 and official ANPD enforcement materials available on August 19, 2026. An opened investigation or administrative sanction proceeding does not itself establish a final violation or final sanction. Fine calculations and sanction selection are fact-specific and depend on the applicable revenue evidence, severity, harm, aggravating/mitigating factors, procedural history and other law. Verify current official ANPD sources and obtain qualified Brazilian legal advice for an actual enforcement matter.