Quick Answer: How much can a company be fined under the LGPD?
Under Article 52 of Brazil's LGPD, a private legal entity, group or conglomerate can receive a simple administrative fine of up to 2% of its revenue in Brazil in the previous fiscal year, excluding taxes, subject to a maximum of R$50 million per infraction. A daily fine is subject to the same total cap per infraction. But fines are only part of the sanction framework. ANPD can also issue warnings, publicize a confirmed infraction, block or delete personal data, suspend a database or processing activity, or partially or totally prohibit personal-data processing activities. The actual sanction must follow an administrative proceeding and the dosimetry criteria in Resolution CD/ANPD No. 4/2023.
Key Takeaways
- R$50 million is not an automatic fine. It is the statutory maximum per infraction for the simple fine.
- The percentage is 2% of Brazil revenue, not global turnover. The statutory text refers to revenue in Brazil for a private legal entity, group or conglomerate, excluding taxes.
- One case can involve multiple infractions. Separate violations can generate separate sanctions, subject to the applicable rules.
- Operational sanctions can be more disruptive than money. Blocking, deletion, suspension or prohibition can affect the ability to use data in the business.
- Severity is structured. Resolution 4/2023 classifies infractions as light, medium or serious.
- Cooperation and remediation matter. Governance, early correction, mitigation and cooperation can operate as mitigating factors.
- Ignoring ANPD can make the situation worse. Obstruction of supervision is itself treated as a serious infraction under the dosimetry regulation.
The Maximum LGPD Fine: 2% of Brazil Revenue, Capped at R$50 Million Per Infraction
The simple-fine ceiling is tied to the revenue of the private legal entity, group or conglomerate in Brazil in the previous fiscal year, excluding taxes.
Even when the 2% calculation would be higher, the simple administrative fine is capped at R$50 million for each infraction.
The daily fine is also subject to the total limit associated with Article 52(II). Resolution 4/2023 says daily fines accumulate until the obligation is fulfilled, up to R$50 million per infraction.
Is R$50 million the maximum total legal exposure?
No. Article 52(2) expressly says the administrative sanctions in the LGPD do not replace administrative, civil or criminal sanctions available under Brazil's Consumer Protection Code or other specific legislation.
The LGPD also contains civil-liability provisions. A controller or operator that causes material, moral, individual or collective damage through unlawful processing may face a duty to repair the damage under the conditions set out in the law.
The Nine Administrative Sanctions in ANPD's Current Dosimetry Regulation
Resolution 4/2023 organizes the sanction framework into nine categories. The sanctions can be applied gradually, individually or cumulatively depending on the case.
Warning
A warning can be used for a light or medium infraction that does not involve specific recidivism, or when corrective measures need to be imposed.
Simple Fine
ANPD can apply a simple fine when preventive or corrective measures were not complied with, when the infraction is classified as serious, or when another sanction would not be adequate given the nature of the violation, processing activity, data and circumstances.
Daily Fine
A daily fine can be used to compel compliance with a non-monetary sanction or ANPD determination. It can also be used where irregularities remain uncorrected, supervision is obstructed or a permanent infraction continues.
Publicization of the Infraction
ANPD can require the infractor to publicly disclose the violation after it has been properly investigated and confirmed. The Agency determines the content, medium, duration and compliance period.
Blocking of Personal Data
Blocking temporarily suspends processing of the personal data connected to the infraction until the conduct is regularized. The infractor must also notify processing agents with whom the data was shared so they can repeat the blocking, subject to the regulation's exceptions.
Deletion of Personal Data
ANPD can require deletion of the personal data connected to the infraction. The regulation also requires communication to other processing agents that received the data so they can repeat the procedure, unless that communication is demonstrably impossible or disproportionately burdensome.
Partial Suspension of a Database
ANPD can partially suspend operation of the database related to the infraction for up to six months, extendable once for an equal period, until the processing is regularized.
Suspension of the Processing Activity
ANPD can suspend the personal-data processing activity connected to the infraction for up to six months, extendable once for the same period.
Partial or Total Prohibition of Personal-Data Processing Activities
The regulation permits partial or total prohibition in specified serious circumstances, including certain recidivism situations, unlawful-purpose processing or processing without a legal basis, or loss/failure of the technical and operational conditions needed for adequate processing.
The three most restrictive operational sanctions—partial database suspension, processing-activity suspension and prohibition— are subject to escalation rules. Resolution 4/2023 says they generally follow at least one of the sanctions specified in the regulation for the same concrete case.
How ANPD Calculates and Selects a Sanction
Resolution CD/ANPD No. 4/2023 is the central dosimetry rule. It does not treat every LGPD violation as a flat fine.
For a simple fine, the regulation considers the classification of the infraction, the relevant revenue from the last available fiscal year before the sanction, and the degree of harm. Depending on the facts and the available financial information, ANPD can use revenue from the affected business branch or other regulatory fallbacks.
The regulation also says the final sanction must respect proportionality. ANPD can depart from the fine methodology or replace a sanction with another one where necessary to avoid disproportion between the seriousness of the violation and the intensity of the sanction, but the decision must be reasoned.
Light, Medium and Serious LGPD Infractions
Light
An infraction is classified as light when it does not meet the regulatory tests for medium or serious.
Medium
A medium infraction is one capable of significantly affecting the interests and fundamental rights of data subjects— for example, significantly limiting rights or access to a service, or causing material or moral harms such as discrimination, violation of physical integrity, image/reputation harm, financial fraud or identity misuse—provided it is not classified as serious.
Serious
A medium-level impact becomes serious when combined with at least one of the additional circumstances listed in Resolution 4/2023, including:
- large-scale processing;
- obtaining or seeking economic advantage from the violation;
- risk to the life of data subjects;
- sensitive data or data relating to children, adolescents or older persons;
- processing without a legal basis under the LGPD;
- unlawful or abusive discriminatory effects; or
- systematic irregular practices.
The regulation separately says that obstruction of ANPD's supervisory activity is a serious infraction.
What Can Increase or Reduce an LGPD Fine?
Resolution 4/2023 contains explicit aggravating and mitigating factors. This is one of the strongest reasons to maintain evidence of governance, remediation and cooperation before a regulatory problem occurs.
| Aggravating factor | Regulatory adjustment | What it means operationally |
|---|---|---|
| Specific recidivism | +10% per case, up to +40% | Repeated violation of the same legal/regulatory provision can materially increase the fine. |
| General recidivism | +5% per case, up to +20% | Previous final ANPD sanctions for other violations can also matter. |
| Failure to comply with guidance/preventive measures | +20% per measure, up to +80% | Ignoring early ANPD intervention can sharply increase monetary exposure. |
| Failure to comply with corrective measures | +30% per measure, up to +90% | Failure to remediate after a formal corrective measure is especially damaging. |
| Mitigating factor | Potential reduction | What it rewards |
|---|---|---|
| Violation stopped before preparatory proceeding | -75% | Very early self-correction before ANPD has formally escalated the matter. |
| Stopped after preparatory proceeding but before PAS | -50% | Prompt remediation after early regulatory engagement. |
| Stopped after PAS but before first-instance decision | -30% | Later remediation still has value, but less than early correction. |
| Good-practice/governance policy or demonstrated internal safeguards | -20% | Documented privacy governance and repeatable controls can count. |
| Mitigation/reversal of effects before preparatory proceeding or PAS | -20% | Early action to reduce harm to affected data subjects. |
| Mitigation after preparatory proceeding but before PAS | -10% | Remediation after regulatory attention but before sanction proceedings. |
| Cooperation or good faith | -5% | Constructive engagement and credible evidence matter. |
Payment and appeal
Under Resolution 4/2023, a fine is generally payable within 20 business days from official notice of the sanction decision. Qualifying small processing agents receive double time for payment.
The regulation also allows a 25% reduction when the infractor expressly waives the right to appeal the first-instance decision and pays within the applicable payment period.
Can Public Authorities Be Fined Under the LGPD?
Article 52 treats public bodies differently. Paragraph 3 says the following sanctions can be applied to public entities and bodies:
- warning;
- publicization of the infraction;
- blocking of the affected personal data;
- deletion of the affected personal data;
- partial suspension of the relevant database;
- suspension of the relevant processing activity; and
- partial or total prohibition of personal-data processing activities.
The simple and daily monetary-fine provisions are not included in Article 52(3)'s public-entity list.
ANPD Enforcement in Practice: What 2026 Shows
2026 signal: ANPD is using monitoring, remediation and sanction proceedings together
In July 2026, ANPD reported the result of monitoring 56 controllers regarding encarregado appointments and communication channels for data subjects. According to the Agency, 27 organizations fully complied with its requests, eight still had pending corrections and 21 did not respond; the non-responsive cases were sent to the sanctions area for analysis.
This is important because it shows that enforcement is not limited to issuing headline fines. ANPD's model includes monitoring, requests for adequacy, remediation opportunities and escalation when organizations fail to respond.
2026 sanction proceeding involving sensitive health data
In July 2026, ANPD announced that it had opened an administrative sanction proceeding against Instituto Saúde e Cidadania (Isac) following a 2025 ransomware incident affecting approximately 500,000 patient records.
The Agency said the investigation concerned alleged failures related to security measures, communication to affected people, publication of encarregado information, prevention, accountability and cooperation/evidence. The case involves sensitive health data and records relating to children, adolescents and older persons.
No final sanction should be inferred merely from the opening of the proceeding. ANPD itself states that any sanction will be defined only after the case is analyzed under the dosimetry regulation.
The first LGPD fine: a useful lesson in proportionality
ANPD's first announced fine in 2023 involved Telekall Infoservice. The Agency imposed a warning and two simple fines of R$7,200 each, totaling R$14,400. One fine concerned processing without a legal basis, and the other concerned failure to respond to ANPD requests during the investigation.
The case is useful because it corrects two misconceptions at once:
- Small businesses are not immune from enforcement.
- The maximum statutory fine is not the normal starting point. Dosimetry and proportionality matter.
ANPD's case summary also stated that obstruction of supervision was treated as serious and that the company's microenterprise status affected the financial limit applied to the fine.
What Triggers ANPD Attention?
There is no one public checklist saying that a particular event automatically causes a sanction proceeding. ANPD's enforcement framework includes monitoring, guidance, prevention and repression.
In practice, organizations should treat the following as important escalation signals:
- unresolved data-subject complaints or petitions;
- failure to answer ANPD information requests;
- security incidents involving relevant risk or damage;
- processing without a documented legal basis;
- large-scale, sensitive or vulnerable-person processing;
- failure to implement required governance or encarregado obligations;
- failure to comply with preventive or corrective measures;
- systematic irregular processing; and
- recidivism.
That does not mean every one of these situations results in a fine. It means they are exactly the types of facts that can matter to severity, supervision and dosimetry under the current framework.
Want to find the gaps before ANPD does?
Use our 25-point LGPD Compliance Checklist to review scope, data mapping, legal bases, rights, vendors, transfers, security, incident response and governance.
How Companies Can Reduce LGPD Enforcement Risk
No compliance program can guarantee that a company will never receive a complaint, incident or ANPD inquiry. The goal is to make the organization capable of demonstrating that it understood the processing, implemented reasonable controls, responded quickly, cooperated and corrected problems.
Why Governance Can Affect the Fine
This is one of the most commercially important lessons in the entire sanction regulation. Privacy governance is not only a best-practice concept.
Resolution 4/2023 expressly recognizes, as a mitigating factor, implementation of a good-practice and governance policy or the repeated and demonstrated adoption of internal mechanisms and procedures capable of minimizing harm and supporting secure and appropriate processing.
That does not mean a privacy policy automatically earns a reduction. The organization has to prove the relevant conditions.
Strong evidence can include:
- current data inventories;
- documented legal-basis decisions;
- vendor security reviews;
- international-transfer records;
- incident-response exercises;
- rights-request logs;
- training records;
- privacy-by-design reviews;
- risk assessments and RIPDs where appropriate; and
- documented remediation after identified gaps.
LGPD Fine Examples: What You Should and Should Not Calculate
It is tempting to take a company's Brazil revenue, multiply it by 2% and call that the expected fine. That is not how Resolution 4/2023 works.
The 2% figure is a statutory ceiling, not a universal fine rate. ANPD first evaluates the infraction and applies the dosimetry methodology, including severity, relevant revenue, degree of harm, aggravating and mitigating factors and applicable minimum/maximum limits.
| Statement | Accurate? | Better explanation |
|---|---|---|
| “Every LGPD violation costs 2% of revenue.” | No | 2% is the ceiling for the simple fine; dosimetry determines the actual sanction and amount. |
| “The maximum penalty is R$50 million total.” | No | R$50 million is the cap per infraction for the simple fine and total daily fine; other sanctions and liabilities can coexist. |
| “Only data breaches create fines.” | No | Any violation of LGPD or ANPD regulations can enter the enforcement framework, depending on the facts. |
| “If no one suffered proven financial loss, there can be no sanction.” | No | Degree of harm matters, but sanctions can address unlawful processing, obstruction, governance failures and other violations. |
| “Cooperation after a problem does not matter.” | No | Cooperation, early cessation, mitigation and governance are expressly recognized in the dosimetry regulation. |
Reduce Enforcement Risk by Building the Evidence Before You Need It
The Brazil LGPD Compliance Playbook — 2026 Edition includes a 100-point compliance audit, a 30-day implementation roadmap and 16 practical tools for data mapping, processing records, legal bases, legitimate interest, vendors, cookies, rights requests, incidents, international transfers, privacy notices, DPAs, retention and ongoing governance.
Frequently Asked Questions
What is the maximum LGPD fine?
For a simple administrative fine, Article 52 allows up to 2% of the revenue of a private legal entity, group or conglomerate in Brazil in the previous fiscal year, excluding taxes, capped at R$50 million per infraction. Daily fines are subject to the same total cap per infraction.
Is the LGPD fine based on global revenue?
Article 52 refers to revenue in Brazil, not global worldwide turnover. Resolution 4/2023 contains more detailed revenue rules for calculating the base amount, including the affected business branch and regulatory fallbacks when information is unavailable or incomplete.
Is R$50 million the maximum total legal exposure?
No. It is the statutory cap per infraction for the ANPD simple fine and the total cap for a daily fine per infraction. The LGPD also provides non-monetary sanctions, and Article 52 says those administrative sanctions do not replace separate administrative, civil or criminal sanctions available under consumer law or specific legislation.
Can ANPD impose penalties other than fines?
Yes. The current framework includes warning, publicization, blocking and deletion of personal data, partial suspension of a database, suspension of a processing activity and partial or total prohibition of personal-data processing activities.
How does ANPD calculate a fine?
Resolution 4/2023 classifies the infraction as light, medium or serious and considers relevant revenue and degree of harm. The fine is then adjusted for aggravating and mitigating circumstances and checked against regulatory minimum and maximum limits.
What makes an LGPD infraction serious?
Serious classification can arise where medium-level impacts are combined with factors such as large-scale processing, economic advantage, risk to life, sensitive data, data of children/adolescents/older persons, processing without a legal basis, discriminatory effects or systematic irregular practices. Obstruction of ANPD supervision is separately classified as serious.
Can cooperation reduce an LGPD fine?
Yes. Resolution 4/2023 includes mitigation for early cessation, documented governance/internal safeguards, measures that mitigate or reverse effects, and cooperation or good faith.
Can ANPD reduce the fine if the company fixes the problem quickly?
Yes. The regulation provides much larger reductions for cessation before regulatory escalation than for correction later in a sanction proceeding. The exact reduction depends on the stage and the conditions proven by the infractor.
Can public authorities receive LGPD fines?
Article 52 paragraph 3 identifies non-monetary sanctions that can be applied to public entities and bodies. The simple and daily monetary-fine provisions are not included in that list. Public companies and mixed-capital companies can require a separate Article 24 analysis depending on whether they operate competitively or execute public policy.
Was a company ever actually fined under the LGPD?
Yes. ANPD announced its first fine in 2023 against Telekall Infoservice. The case included a warning and two simple fines of R$7,200, totaling R$14,400. The case involved processing without a legal basis and failure to respond to ANPD requests during the investigation.
Can a company get a discount for not appealing an ANPD fine?
Resolution 4/2023 provides a 25% reduction where the infractor expressly waives the right to appeal the first-instance decision and pays within the applicable payment deadline.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary statutory source for Article 52 sanctions, the 2% / R$50 million rule, public-sector treatment, additional liability and the sanction criteria.
- ANPD — Administrative Sanctions Current official page connecting the sanction framework to Resolution 1/2021 and Resolution 4/2023.
- ANPD Resolution CD/ANPD No. 4/2023 — Dosimetry and Administrative Sanctions Primary regulatory source for severity classes, selection of sanctions, fine methodology, aggravating and mitigating factors, daily fines, payment and operational sanctions.
- ANPD — First LGPD Fine (Telekall Infoservice) Official case summary showing warning plus two R$7,200 simple fines and the role of non-cooperation in the investigation.
- ANPD — 2026 Monitoring of Encarregado and Data-Subject Channels Current enforcement example showing remediation, unresolved deficiencies and referral of non-responsive organizations for sanctions analysis.
- ANPD — 2026 Isac Administrative Sanction Proceeding Current example involving alleged security, notification, governance and accountability failures after a ransomware incident affecting sensitive health data.