Private civil liability and damages — Articles 42–44 LGPD
Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD) creates a direct private right of action for data subjects to sue controllers and processors in civil court for damages caused by unlawful processing. This enforcement pathway operates independently of ANPD's administrative sanctioning power under Article 52, and is the primary mechanism Brazilian data subjects have used to seek compensation for data breaches and privacy violations.
Strict liability standard — Article 42. Article 42 of the LGPD establishes that a controller or processor that, when performing personal-data-processing activities, causes pecuniary, moral, individual, or collective damage to others in violation of data-protection legislation shall be required to compensate for such damage. The statute does not require proof of fault or negligence; liability arises from the violation itself and the resulting damage. The language "dano patrimonial, moral, individual ou coletivo" encompasses both economic loss (lost wages, identity-theft costs, credit-monitoring expenses) and non-economic harm (emotional distress, reputational injury, loss of privacy itself), and permits both individual and collective claims.
Joint and several liability — Article 42, § 1. To ensure effective compensation to data subjects, Article 42, § 1 imposes joint and several liability in two scenarios. First, a processor is jointly liable for damages caused by processing when it (i) fails to comply with LGPD obligations or (ii) does not follow lawful instructions from the controller, in which case the processor is deemed equivalent to a controller. Second, multiple controllers directly involved in the same processing activity that caused damage to the data subject are jointly liable. In both cases, liability is subject to the exclusion defenses in Article 43.
Defenses — Article 43. Processing agents (controllers and processors, collectively) will not be held liable if they prove any one of three defenses: (i) they did not perform the personal-data processing attributed to them; (ii) although they performed the processing attributed to them, there was no violation of data-protection legislation; or (iii) the damage resulted from the exclusive fault of the data subject or a third party. The burden of proof lies with the processing agent; the plaintiff data subject need only demonstrate the processing, the violation, and the damage.
Burden-shifting — Article 42, § 2. In civil proceedings, the judge may shift the burden of proof in favor of the data subject when, in the judge's view, the allegation is plausible, the data subject is unable to produce evidence for reasons of insufficient resources, or producing the evidence would impose an excessive burden on the data subject. This procedural mechanism, borrowed from Brazil's Consumer Protection Code (Law No. 8,078/1990, Article 6, VIII), reflects the recognition that controllers and processors hold the technical records and processing logs necessary to defend against liability claims, while data subjects typically lack visibility into backend processing operations.
Unlawful processing — Article 44. Processing of personal data is considered irregular (and therefore a violation triggering Article 42 liability) when it fails to comply with the LGPD or when it does not provide the security the data subject can reasonably expect. Article 44 lists relevant circumstances to assess the security expectation, including the purposes of the processing, the data subject's reasonable expectations at the time of processing, and the data-processing techniques available at the time the processing occurred. The sole paragraph of Article 44 specifies that a controller or processor who fails to adopt the security measures required by Article 46 of the LGPD and thereby causes damage is liable for damages resulting from the security-breach violation.
Collective actions — Article 42, § 3. Actions for collective damages under Article 42 may be brought collectively in court, in accordance with the applicable procedural legislation. Brazil's Consumer Protection Code, Article 81, and Law No. 7,347 of July 24, 1985 (Public Civil Action Law) establish that collective actions for homogeneous individual rights may be filed by the Public Prosecutor's Office (Ministério Público), consumer-protection agencies (including PROCON), legally constituted associations, and the Public Defender's Office. Collective data-breach litigation in Brazil has followed this model, permitting a single judicial action to obtain compensation on behalf of a defined class of affected data subjects.
Relationship to ANPD enforcement. Article 42–44 civil liability is independent of ANPD's Article 52 administrative sanctions. A data subject may file a civil suit for damages without waiting for ANPD to open an administrative proceeding, and a controller or processor may face both an ANPD fine and a civil judgment for the same underlying violation. In practice, ANPD enforcement decisions and dosimetry resolutions (Resolution CD/ANPD No. 4 of February 24, 2023) serve as persuasive evidence in civil proceedings, but civil courts apply their own analysis of violation, causation, and quantum of damages under the Brazilian Civil Code and LGPD Articles 42–44.
Statute of limitations. The LGPD does not specify a limitations period for Article 42 civil actions. Brazilian courts have applied the general tort statute of limitations in the Civil Code (Law No. 10,406 of January 10, 2002), Article 206, § 3, V: three years from the date the data subject became aware of the damage and its author. For latent data breaches where the harm is not immediately apparent (e.g., credential stuffing attacks exploiting data stolen months earlier), the three-year clock begins when the data subject discovers the breach and the identity of the controller or processor responsible.
Source: Law No. 13,709 of August 14, 2018 (LGPD), Articles 42–44; ANPD official English translation of LGPD
Criminal prosecution and concurrent enforcement under general criminal law — LGPD Article 45 and Criminal Code Article 154-A
The Lei Geral de Proteção de Dados Pessoais (LGPD) itself does not create criminal offenses or authorize criminal prosecution for data-protection violations. However, LGPD Article 45 expressly preserves the application of concurrent criminal liability under other Brazilian statutes, and data controllers, processors, and individual employees face potential criminal exposure under Brazil's general criminal law for conduct that also constitutes an LGPD violation. Understanding this enforcement layering is critical for risk assessment: a single unlawful-processing incident may trigger ANPD's administrative sanctioning process (Articles 52–54 LGPD), civil damages liability (Articles 42–44 LGPD), and criminal investigation and prosecution under the Brazilian Criminal Code (Código Penal, Decree-Law No. 2,848 of December 7, 1940, as amended) or sectoral criminal statutes.
LGPD Article 45 — preservation of concurrent enforcement. Article 45 of the LGPD provides that violations of the data subject's rights that occur within the context of consumer relations remain subject to the liability rules provided in the relevant legislation. Article 52, § 2 (as renumbered and added by Law No. 13,853/2019) states that the administrative sanctions provisions of LGPD do not replace the application of administrative, civil, or criminal sanctions provided in the Consumer Protection Code (Law No. 8,078 of September 11, 1990, Article 7, VI; Articles 61–80) and in specific legislation. This language confirms that LGPD enforcement by ANPD operates in parallel with, rather than preempting, criminal prosecution by the Public Prosecutor's Office (Ministério Público) and police authorities.
Criminal Code Article 154-A — unauthorized computer-device invasion. The most frequently invoked criminal statute for data-protection violations is Article 154-A of the Brazilian Criminal Code, added by Law No. 12,737 of November 30, 2012 (popularly known as the "Carolina Dieckmann Law" after a high-profile celebrity data breach). Article 154-A criminalizes invading another person's computer device (dispositivo informático alheio), whether or not connected to a computer network, by improperly violating a security mechanism, with the purpose of obtaining, altering, or destroying data or information without the express or tacit authorization of the device's owner, or installing vulnerabilities to obtain unlawful advantage. The base penalty is detention from three months to one year plus a fine.
Enhanced penalties — Article 154-A, §§ 1–5. Article 154-A, § 1 applies the same penalty to anyone who produces, offers, distributes, sells, or disseminates a computer device or program with the intent to permit commission of the invasion conduct described in the main provision. Article 154-A, § 2 increases the penalty by one-sixth to one-third if the invasion results in economic loss. Article 154-A, § 3 substantially enhances the penalty — **imprisonment (reclusão) from six months to two years plus a fine — if the invasion results in obtaining the content of private electronic communications, commercial or industrial secrets, or confidential information as defined by law, or if it results in unauthorized control of the invaded device remotely. Article 154-A, § 4 doubles the penalty (one to four years imprisonment plus fine) for qualified invasion that results in any of the Article 154-A, § 3 harms and** the conduct is committed against the President of the Republic, state governors, the Federal District governor, or mayors; against a public administration entity or a financial services provider, payment institution, or credit-card issuer; or for purposes of commercial or industrial advantage. Article 154-A, § 5 specifies that criminal action (ação penal) for the basic Article 154-A offense (main provision, §§ 1–3) is conditioned on a complaint by the victim (ação penal privada), whereas the qualified offenses under Article 154-A, § 4 are prosecuted as public criminal actions (ação penal pública incondicionada) — the Public Prosecutor may prosecute without the victim's complaint.
Application to LGPD violations. A data-processing activity that violates the LGPD can also satisfy the elements of Article 154-A if it involved (a) unauthorized access to a computer device or database (b) by circumventing a security mechanism (c) with the purpose of obtaining, altering, or destroying personal data without authorization. For example, an employee of a data processor who accesses a customer database beyond the scope of the controller's instructions and exfiltrates personal data for resale satisfies both LGPD Article 42, § 1, item I (processor liability for failure to follow lawful controller instructions) and Criminal Code Article 154-A, § 3 or § 4 (unauthorized invasion to obtain confidential information). The same facts support an ANPD administrative sanction against the processor entity, a civil damages claim by affected data subjects under LGPD Article 42, and criminal prosecution of the individual employee (and potentially the company's officers under criminal-law complicity or corporate-liability doctrines).
Other applicable criminal statutes. Depending on the nature of the unlawful processing and the resulting harm, prosecutors may also charge violations under other Criminal Code provisions: Article 153 (unauthorized disclosure of secrets, violação de segredo profissional); Article 325 (violation of functional secrecy by a public official, violação de sigilo funcional); Articles 171–179 (fraud and related property crimes, if the processing was part of a scheme to defraud); or Article 7, X of Law No. 8,078/1990 (crimes against consumer relations for failure to safeguard consumer data under the Consumer Protection Code). The Consumer Protection Code's criminal provisions (Articles 61–80) include imprisonment from six months to two years for placing in the market a product or service in conditions known to be dangerous to health or safety (Article 63), and the federal courts have recognized data-breach exposure can constitute a "dangerous service" under this standard when the controller or processor knew of systemic security deficiencies.
Institutional roles — ANPD does not prosecute crimes. ANPD's authority under Article 55-J of the LGPD is limited to administrative enforcement — investigation of administrative infractions and application of Article 52 sanctions (warnings, fines, blocking, deletion, suspension, prohibition). ANPD expressly states on its public website that it "does not conduct criminal investigations" (não realiza especificamente investigação de crimes); criminal investigation is the jurisdiction of the state and federal police forces (Polícia Civil and Polícia Federal) and prosecution by the Public Prosecutor's Office (Ministério Público). However, ANPD may refer cases involving apparent criminal conduct to the appropriate police or prosecutorial authorities, and prosecutors may use ANPD administrative-proceeding findings and evidence as a basis for initiating criminal investigation. The two tracks operate independently: ANPD may close an administrative proceeding with a fine or warning, and the same facts may still be the subject of an ongoing criminal prosecution.
Statute of limitations — criminal versus administrative. Criminal-law statutes of limitations under Criminal Code Article 109 apply to Article 154-A prosecutions: for the base offense (three months to one year detention), the limitation period is three years from the date of the offense (Article 109, VI); for the qualified offense under Article 154-A, § 4 (one to four years imprisonment), the limitation period is eight years (Article 109, IV). ANPD administrative sanctions under LGPD Article 52 are subject to a five-year statute of limitations from the date ANPD became aware of the violation (Lei No. 9,873 of November 23, 1999, Article 1), which begins running when ANPD receives a complaint or otherwise acquires knowledge of the facts. A controller or processor may thus face administrative sanctions from ANPD even when the parallel criminal investigation has been time-barred, or vice versa.
Corporate criminal liability. Under Brazilian criminal law, legal entities (companies) can be held criminally liable in limited circumstances — most notably environmental crimes under Law No. 9,605 of February 12, 1998, Article 3. For data-protection and cybercrime violations under Article 154-A, current criminal-law doctrine treats criminal liability as personal to the individual perpetrator (the employee, officer, or director who committed the invasion or instructed it). However, corporate officers and directors may face personal criminal exposure under theories of co-authorship (coautoria) or participation (participação) if they ordered, directed, or knowingly permitted the unlawful processing, and companies face collateral consequences including administrative fines, contractual liability, and reputational damage even when they cannot be directly charged with a crime.
Source: Law No. 13,709 of August 14, 2018 (LGPD), Article 45 and Article 52, § 2; Law No. 12,737 of November 30, 2012 (Cybercrime Law — Carolina Dieckmann Law), adding Article 154-A to the Criminal Code; ANPD official English translation of LGPD
ANPD enforcement record and published sanctions decisions — 2023–2025 practice
Brazil's Autoridade Nacional de Proteção de Dados (ANPD) transitioned from regulatory development to active enforcement starting in 2023, following the February 24, 2023 publication of Resolution CD/ANPD No. 4, the Regulation on Dosimetry and Application of Administrative Sanctions (Regulamento de Dosimetria e Aplicação de Sanções Administrativas). This dosimetry regulation satisfied the Article 53 LGPD precondition that ANPD issue methodology guidance before imposing fines, and enforcement actions accelerated immediately thereafter. Understanding ANPD's published decisions—the violations targeted, the sanctions imposed, and the dosimetry applied in practice—is essential for compliance prioritization and risk assessment.
First monetary sanction — Telekall Infoservice (July 2023). On July 6, 2023, ANPD published its first-ever monetary sanction in the Diário Oficial da União: a total fine of R$ 14,400 against Telekall Infoservice Ltda., a micro-enterprise telemarketing company (process No. 261.000489/2022-62, initiated March 10, 2022). The Coordenação-Geral de Fiscalização (CGF, ANPD's Inspection and Enforcement Directorate) found three violations:
- Violation of Article 7 LGPD (absence of a lawful basis for processing personal data) — fine of R$ 7,200 (approximately USD $1,480 at July 2023 exchange rates);
- Violation of Article 41 LGPD (failure to appoint a Data Protection Officer / encarregado de dados pessoais) — warning (advertência) without corrective measures, as Telekall did not demonstrate that it performed only low-risk processing that would exempt it from the DPO requirement;
- Violation of Article 5 of Resolution CD/ANPD No. 1/2021 (failure to cooperate with ANPD information requests during the investigation) — fine of R$ 7,200.
Telekall is classified as a microempresa under Brazilian law (annual revenue up to R$ 360,000, approximately USD $74,000), and ANPD applied the Article 52 dosimetry factors—particularly the economic condition of the offender—to cap each fine at 2 percent of the company's gross revenue. The decision remains subject to administrative appeal to ANPD's Conselho Diretor (Board of Directors) under Resolution CD/ANPD No. 1/2021, Article 61. The Telekall decision is significant as a signal that ANPD will enforce against small businesses and that even modest revenue thresholds do not insulate controllers from LGPD obligations, although economic condition is a mitigating dosimetry factor that substantially reduces fine amounts for micro and small enterprises.
First public-sector sanctions — IAMSPE (October 2023). On October 6, 2023, ANPD published its first sanctions decision against a government entity: the Instituto de Assistência Médica ao Servidor Público Estadual de São Paulo (IAMSPE), a São Paulo state public health-assistance agency (process No. 00261.001969/2022-41, initiated September 30, 2022). CGF concluded that IAMSPE violated Article 48 LGPD (duty to communicate security incidents to ANPD and to affected data subjects) and Article 49 LGPD (duty to maintain technical and administrative security measures appropriate to the nature of the processing) in connection with a data breach affecting approximately 1.5 million public servants and their dependents who are beneficiaries of IAMSPE health services. The agency delayed notification to affected data subjects by approximately three months after discovering the breach (August–September 2022) and failed to maintain adequate security controls.
ANPD imposed non-monetary corrective sanctions only—warnings and mandatory corrective measures including timely breach notification and security upgrades—because Article 52, § 5 of the LGPD (as added by Law No. 13,853/2019) prohibits the imposition of monetary fines on public-sector entities (órgãos e entidades públicas). This statutory carve-out creates an asymmetry: private controllers face fines up to the Article 52 cap (R$ 50 million per violation), while public-sector controllers and processors are subject only to warnings, publication of the infraction, blocking, deletion, suspension, and prohibition measures—powerful operational sanctions, but no direct financial penalty. IAMSPE was entitled to appeal the CGF decision to the Conselho Diretor within ten business days of receiving the intimation.
Santa Catarina Health Department (October 2023). On October 18, 2023, ANPD sanctioned the Secretaria de Estado da Saúde de Santa Catarina (SES-SC, the Santa Catarina State Department of Health) (process No. 00261.001886/2022-51, initiated September 14, 2022) for four LGPD violations: (1) failure to present a required data-protection impact assessment (DPIA / relatório de impacto à proteção de dados pessoais, Article 38 LGPD); (2) inadequate security measures for storing and processing personal data (Article 49 LGPD); (3) delayed notification of a security breach to ANPD and to affected individuals (Article 48 LGPD); and (4) failure to respond to ANPD information requests (Article 18, § 8 and Article 5 of Resolution CD/ANPD No. 1/2021). ANPD imposed four warnings and corrective measures, including mandatory breach notifications and security improvements. SES-SC had ten days to appeal. As a public entity, SES-SC faced no monetary fine. The decision illustrates ANPD's emphasis on foundational compliance obligations—DPIAs for high-risk processing, proactive security, timely breach reporting, and cooperation with supervisory-authority investigations—across both private and public sectors.
Enforcement against public entities — Ministry of Health and INSS (2024). ANPD's published enforcement-decision list includes concluded processes against major federal public entities, including two Ministry of Health (Ministério da Saúde) processes (No. 00261.000456/2022-12, initiated March 7, 2022, concluded 2024; and No. 00261.001882/2022-73, initiated September 12, 2022, with appeal under review by the Conselho Diretor as of 2024) and the Instituto Nacional do Seguro Social (INSS, Brazil's National Social Security Institute) (process No. 00261.001888/2023-21, appeal decided by the Conselho Diretor in Circuito Deliberativo No. 15/2024, process concluded). The Ministry of Health processes investigated failures to respond to ANPD information requests, absence of a designated DPO (encarregado), and failure to notify ANPD of security incidents. The INSS case involved a data breach affecting INSS beneficiaries between August and September 2022 and resulted in corrective sanctions after administrative appeal. These decisions confirm that federal agencies—including those processing massive volumes of sensitive personal data (health, social security)—are active targets of ANPD enforcement, although monetary fines remain unavailable under the Article 52, § 5 public-sector exemption.
Preventive measures and daily fines — Meta (July–August 2024). In July 2024, ANPD issued a preventive measure (medida preventiva, Article 30 of Resolution CD/ANPD No. 1/2021) suspending Meta Platforms' privacy policy update titled "Facebook Online Services of Brazil," which would have permitted Meta to process personal data from Facebook, Instagram, and Messenger for training generative-AI systems. ANPD found four violations: (1) inadequate disclosure to data subjects about AI training purposes; (2) failure to implement safeguards for processing children's data; (3) absence of accessible opt-out mechanisms; and (4) failure to respect the legitimate expectations of Brazilian users under Article 6, VI LGPD (processing must respect the reasonable expectations of the data subject). ANPD did not impose a final sanction but threatened a daily fine (multa diária) of R$ 50,000 per day (approximately USD $10,000/day at 2024 exchange rates) if Meta failed to comply with the preventive measure. Meta responded by updating its privacy policy to provide clearer notices, obtain consent for AI training, permit opt-outs, and commit to not processing children's data for AI training; ANPD lifted the preventive measure on August 30, 2024. The Meta intervention illustrates ANPD's use of interim enforcement tools—preventive measures with daily-fine threats under Article 52, III LGPD—to halt ongoing processing violations without waiting for a full administrative sanctioning process (processo administrativo sancionador), and signals ANPD's enforcement priority on AI/generative-AI data processing and transparency obligations.
Preventive measure — Havan (May 2025). In May 2025, ANPD imposed a preventive measure (medida preventiva) against Havan, a major Brazilian retailer, to halt the public dissemination of surveillance videos showing individuals accused of theft in its stores. The measure was issued under Article 30 of Resolution CD/ANPD No. 1/2021, following concerns that the practice violated the principles of transparency, minimization, and security established in the LGPD. The order required Havan to immediately cease publishing such videos on social media or other public channels while the investigation proceeded. No monetary sanction was imposed at this stage, and the matter illustrates ANPD's willingness to intervene promptly to prevent potential rights violations and reputational harm. As of June 2025, the final sanctioning decision in this case had not yet been published, but the interim measure demonstrates the agency's readiness to use its preventive powers to address high-profile data-protection risks.
Enforcement trends and priorities — 2023–2025. As of mid-2025, ANPD has published dozens of concluded and ongoing administrative sanctioning processes, with enforcement concentrated in four violation categories:
- Breach notification failures (Article 48 LGPD and Resolution CD/ANPD No. 15 of April 2024, which establishes that controllers must notify ANPD within three business days of learning of a security incident involving risk or harm to sensitive personal data, children's or elderly data, financial data, authentication data, professional-secrecy-protected data, or large-scale data);
- Inadequate security measures (Article 49 LGPD, particularly failures to encrypt sensitive data, inadequate access controls, and absence of breach-response plans);
- Absence of a designated DPO (Article 41 LGPD, with ANPD strictly enforcing the DPO requirement except for demonstrated low-risk processing under Resolution CD/ANPD No. 18 of August 2024);
- Failure to cooperate with ANPD investigations (Article 18, § 8 and Article 5 of Resolution CD/ANPD No. 1/2021, including ignoring information requests and obstructing inspections).
ANPD has imposed sanctions across private micro-enterprises, large technology platforms, and federal/state public entities, and has made clear that organizational size and public/private status do not exempt controllers from core LGPD obligations. However, monetary fines remain modest compared to EU GDPR enforcement: as of early 2025, reported ANPD fines total approximately R$ 98 million (approximately USD $20 million) across all concluded processes from 2023–2025, with individual fines ranging from R$ 7,200 (Telekall, micro-enterprise) to fines in the millions of reais for large-scale breach and security failures. The R$ 50 million per-violation statutory cap (Article 52, II) has not yet been reached in any published decision. ANPD follows a responsive regulation model prioritizing guidance, preventive measures, and warnings before punitive fines, and the dosimetry regulation (Resolution CD/ANPD No. 4/2023) weights mitigating factors—good faith, cooperation, prompt corrective action, economic condition—heavily in fine calculation. Controllers that engage transparently with ANPD during investigations, adopt corrective measures promptly, and demonstrate compliance programs receive substantially reduced sanctions.
Published decision repository and transparency. ANPD publishes concluded sanctioning-decision reports (Relatórios de Instrução) on its official website at gov.br/anpd/pt-br/centrais-de-conteudo/decisoes-em-processos-sancionadores-1, organized by year and process number. These reports include the factual findings, legal analysis, dosimetry calculation, and the sanctions imposed. ANPD also publishes a list of ongoing (not yet concluded) administrative sanctioning processes at gov.br/anpd/pt-br/assuntos/noticias/anpd-divulga-lista-de-processos-sancionatorios, identifying the entity under investigation, the alleged violations, the investigation phase, and the process number. Final sanctions are additionally published on the federal government's Transparency Portal (Portal da Transparência), where entities sanctioned by ANPD appear in the National Registry of Punished Companies (CNEP, Cadastro Nacional de Empresas Punidas). This multi-channel transparency reflects ANPD's implementation of the Article 52, IV LGPD sanction of publication of the infraction (publicização da infração), which serves both a punitive and a deterrent function by publicly associating the controller's name with the LGPD violation.
Source: ANPD — Decisões em Processos Sancionadores (Official repository of concluded enforcement decisions); ANPD — First fine announcement (Telekall, July 2023); ANPD — IAMSPE sanctions decision (October 2023); ANPD — Sanções Administrativas (Administrative sanctions page); ANPD — Preventive measure against Havan (May 2025)
ANPD enforcement practice and precedent — responsive regulation posture, first sanctions imposed, and enforcement priorities
Since the LGPD sanctions provisions took effect on August 1, 2021, Brazil's Autoridade Nacional de Proteção de Dados (ANPD) has pursued a responsive regulation model that prioritizes orientation, prevention, and cooperation before punitive enforcement. This is grounded in ANPD's enforcement-process regulation (Resolution CD/ANPD No. 1 of October 28, 2021, as amended by Resolution CD/ANPD No. 4 of February 24, 2023) and distinguishes monitoring, guidance, preventive activities, and repressive enforcement. Repressive action (the processo administrativo sancionador, or administrative sanctioning process) is reserved for cases involving coercive measures to interrupt harm or risk, restore compliance, and punish violators through Article 52 sanctions.
First sanctions imposed — Telekall Infoservice (July 2023). ANPD applied its first administrative sanctions in July 2023 (private sector) and October 2023 (public sector). These early cases establish ANPD’s current practice: initial orientation and information requests, escalation to a sanctioning process when requests are ignored/non-remediated, then warnings and non-pecuniary mandates for public bodies and monetary penalties for private entities. Details and precedent-setting decisions are published in the ANPD’s official repository.
Ongoing themes and enforcement priorities. In November 2023, ANPD’s Monitoring Cycle Report and subsequent public statements highlighted key enforcement axes: failure to respond to ANPD requisitions (especially unfulfilled data protection officer/contact requirements), breach-notification failures, data-security deficiencies, and focus on children’s data and ed-tech platforms. The sanctioning cycle for 2024–2025 continued these priorities, including monitoring large private-sector controllers for DPO/contact compliance and rapid intervention against breach-notification and recurring non-responsiveness.
New Priority Topics Map for the 2026–2027 biennium. ANPD published a formal Priority Enforcement Topics Map for 2026–2027 ("Mapa de Temas Prioritários 2026–2027"), reflecting both experience from the first years of enforcement and alignment with public and legislative priorities. The revised map targets:
- Data subjects’ rights (with an emphasis on the effectiveness of mechanisms for access, rectification, and deletion);
- Protection of children and adolescents (including forthcoming regulatory action on ECA Digital age-verification mechanisms, scheduled for enforcement starting in 2027);
- Public sector data processing (particularly security and transparency failures in large public databases);
- Artificial intelligence and emerging technologies (including regulatory guidance and enforcement on the application of the LGPD to AI systems and automated decision-making, a new stated thematic axis).
This update marks an explicit deepening of the agency's program beyond reactive casework, with prospective sector-wide enforcement campaigns and proactive regulatory development. Thematic priorities and related workstreams are scheduled for ongoing public reporting and regulatory consultation rounds throughout 2026.
Escalation pathway and compliance signals ANPD rewards. ANPD's enforcement practice has consistently followed a graduated response: monitoring/orientation; preventive measures; administrative sanction process; and, where warranted, publication of sanction or operational restrictions. The Dosimetry Regulation (Resolution CD/ANPD No. 4/2023) continues to govern sanction calculation—cooperation, adoption of good governance, and prompt remediation remain major mitigating factors. Monetary sanctions remain targeted and proportionate.
Transparency and public access. The ANPD maintains a public repository of concluded sanctioning processes with links to instruction reports and publishes enforcement statistics, with new dashboards and thematic summary reports planned for the 2026–2027 period. Case details from ongoing processes generally remain confidential, except when sanctions require publication.
No criminal jurisdiction; referral to prosecutors. ANPD does not investigate crimes, but may refer apparent criminal conduct to police or prosecutors. Administrative and criminal proceedings are independent.
Source: ANPD Press Release — First Fine (Telekall), July 7, 2023; ANPD Press Release — IAMSPE Sanctioning Decision, October 6, 2023; ANPD — Decisions in Sanctioning Processes (published instruction reports); ANPD — Monitoring Cycle Report 2023 (PDF, enforcement statistics and case summaries); ANPD Priority Topics Map 2026–2027 announcement; ANPD Press Release — Monitoring 20 Companies for Encarregado / DPO Violations, December 13, 2024
Prohibition on monetary fines for public entities — Article 52, § 5 LGPD and enforcement asymmetry
Prohibition on ANPD monetary fines against public entities — Article 52, § 5 LGPD
Brazil’s Lei Geral de Proteção de Dados Pessoais (LGPD) draws a sharp distinction between the sanctioning of private-sector and public-sector entities by the Autoridade Nacional de Proteção de Dados (ANPD). Article 52, § 5 of LGPD, as amended by Law No. 13,853/2019, expressly prohibits the imposition of monetary fines (both the “simple fine” and “daily fine” administrative sanctions) on "organs and entities of the public administration.”
The provision states: “The sanctions provided for in items II and III of the caput of this article [simple fine and daily fine] shall not apply to organs and entities of the public administration.” (Art. 52, § 5 LGPD; items II and III refer to fines up to 2% of revenue or R$ 50 million per infraction.) Public authorities remain exposed to the full range of non-monetary sanctions: warning, publication of the infraction, blocking or deletion of personal data, suspension or prohibition of processing activities. These sanctions can have a significant operational impact, especially when affecting core public services, but do not include direct financial penalties. The legislative rationale, as reflected in the parliamentary debates, was to avoid shifting public resources—ultimately taxpayer funds—to a penalty regime, but the result creates a pronounced enforcement asymmetry between private and public data-processing.
Enforcement in practice:
ANPD’s published decisions in cases involving the Instituto de Assistência Médica ao Servidor Público Estadual de São Paulo (IAMSPE), the Secretaria de Estado da Saúde de Santa Catarina, the Instituto Nacional do Seguro Social (INSS), and the Ministério da Saúde demonstrate how this limitation affects sanctioning. In these cases, ANPD applied warnings, mandatory corrective measures, and (where warranted) public disclosure of the infraction, but never a monetary fine, even for significant breaches exposing sensitive data of millions of Brazilians.
Practical implications and criticism:
This structure means that, while private-sector entities face potentially severe financial liability, public entities are shielded from direct monetary consequences—even for identical factual violations. The result, as noted by privacy advocates and in the annual Enforcement Monitoring Cycle reports, is a "two-track" system where operational but not financial risk deters noncompliance by public bodies. However, as a counterbalance, ANPD has emphasized public transparency, mandatory improvement plans, and, in serious cases, the reputational effects of published sanction decisions.
Ongoing discussions:
The restriction has been debated in the National Congress and by ANPD itself, with proposals that would allow moderate monetary penalties on public bodies for gross negligence or repeated violations, but as of June 2026, the ban in Article 52, § 5 remains in force.
Source: LGPD (Art. 52, § 5) — Planalto.gov.br; ANPD — IAMSPE Sanction Decision; ANPD Decisions — Sanctioned Public Entities
ANPD administrative enforcement procedure — investigation, defense rights, and appeals under Resolution CD/ANPD No. 1/2021 as amended
Brazil’s Autoridade Nacional de Proteção de Dados (ANPD) enforces the LGPD (Lei Geral de Proteção de Dados Pessoais) through a formal administrative process detailed in Resolution CD/ANPD No. 1 of October 28, 2021, as amended by Resolution CD/ANPD No. 4 of February 24, 2023. Understanding this process is crucial for any controller or processor facing investigation or potential sanctions.
Opening and phases of the process. ANPD differentiates between monitoring (informal requests for information), preventive measures (corrective demands without sanctions), and repressive enforcement. A formal processo administrativo sancionador (administrative sanctioning process) begins with an Auto de Infração (Notice of Infraction) issued by the Coordenação-Geral de Fiscalização (CGF) when credible evidence of an LGPD violation exists, whether through proactive monitoring or following a complaint or incident notification (arts. 4–6).
Defense rights and procedural guarantees. After notification, the accused party has:
- The right to present a written defense within at least 10 business days (art. 56).
- The right to access the case file, present evidence, and request production of documents, expert reports, or witnesses (arts. 54, 58–59, 63).
- The right to propose a Term of Commitment to Adjustment (Termo de Compromisso de Ajustamento) at any time, which may suspend or conclude the proceedings if accepted (arts. 74–80).
The process progresses through notification, defense, evidence production, and issuance of an Instruction Report (Relatório de Instrução). The Board of Directors (Conselho Diretor) adopts the final decision (arts. 64–70). The controller or processor may file an administrative appeal within 10 business days of the decision, and appeal generally suspends the sanction’s enforceability until decided (art. 72).
Publication, fine accrual, and legal representation. Final decisions, including sanctions, are published on ANPD’s website (arts. 71–72), both for transparency and to comply with LGPD Article 52(IV). Daily fines imposed only begin accruing from the date specified in the sanctioning decision (arts. 40–43). Legal entities must act through formally authorized representatives. Failure to participate or respond allows the process to continue in absentia (art. 67, §1). The principles of adversarial process, full defense, motivation, and proportionality (mirroring Law No. 9,784/1999) apply throughout.
Settlement and judicial remedies. Settlement (including the Term of Commitment to Adjustment) may be proposed at any stage. ANPD publishes a summary of accepted agreements. While administrative remedies should generally be exhausted before recourse to the courts, the regulations do not expressly bar judicial action on constitutional or urgent grounds—the statute is silent.
Procedural updates and current application. Resolution CD/ANPD No. 4 of February 24, 2023, amended certain dosimetry, aggravation/mitigation, and sanction-calculation factors and clarified that these changes supplement, but do not fundamentally alter, the procedural stages above. The most up-to-date procedural guarantees remain in the as-amended text of Resolution CD/ANPD No. 1/2021. Timelines for proceedings in practice are not set in Regulation and must be confirmed from official case reports if needed.
Source: Resolution CD/ANPD No. 1 of October 28, 2021 — Processual regulation, updated URL; Resolution CD/ANPD No. 4 of February 24, 2023 — Dosimetry Regulation
Statute of limitations for LGPD enforcement actions and civil claims — Articles 52, 42–44 LGPD and Lei No. 9,873/1999
Statute of limitations for administrative, civil, and criminal enforcement under the LGPD
The LGPD (Lei Geral de Proteção de Dados Pessoais) does not set a specific statute of limitations for enforcement actions by the Autoridade Nacional de Proteção de Dados (ANPD) or for civil claims brought by data subjects. Practitioners must therefore look to related federal statutes and enforcement practice to determine the relevant time limits.
Administrative sanctions — five-year limitation (Law No. 9,873/1999). For administrative procedures led by the ANPD, Law No. 9,873 of 23 November 1999 governs: Article 1 imposes a five-year limitation period for the application of administrative sanctions by federal authorities. This period is counted from the date when ANPD gains “knowledge of the occurrence of the infraction”—typically through complaint, incident notice, or discovery during supervision. Interruption or suspension of the period follows Articles 2 and 3: formal acts such as the opening of an investigation, delivery of a notice of infraction, acknowledgment of liability, or the filing of judicial appeals will halt or restart the running of prescription. ANPD sanctioning decisions and internal reports confirm that this five-year period applies to LGPD enforcement.
Civil actions by data subjects — three-year period (Brazilian Civil Code, Article 206, § 3, V). For data-subject lawsuits seeking damages under Articles 42–44 LGPD, the Brazilian Civil Code (Law No. 10,406/2002) at Article 206, § 3, V sets a three-year period. The clock runs from when the data subject becomes aware of both the damage and the party responsible. This rule governs both patrimonial (economic) and moral (non-economic) damages, including class actions brought under the Public Civil Action Law (Lei No. 7,347/1985). Courts apply this discovery rule even for latent or delayed harms, so the starting date may be well after the incident itself.
Criminal prosecution — periods under the Criminal Code. Where LGPD-violative conduct is also prosecuted under Criminal Code Article 154-A (unauthorized computer-device invasion), statute of limitations are defined by Criminal Code Article 109: three years for the basic offense (three months to one year detention) and eight years for the qualified crime (one to four years' imprisonment).
Suspension, interruption, and current practice. Initiating a formal ANPD administrative procedure or court action suspends the running of the relevant prescription under Law No. 9,873/1999 and procedural codes. As of June 2026, there are no unique ANPD regulations or higher court guidelines creating different limitation periods for LGPD cases.
Source: Lei No. 13,709/2018 (LGPD); Law No. 9,873/1999 (statute of limitations for administrative sanctions); Brazilian Civil Code — Law No. 10,406/2002, Article 206, §3, V
Voluntary settlement and Termo de Compromisso de Ajustamento in ANPD enforcement — Resolution CD/ANPD No. 1/2021, Articles 74–80
A controller or processor subject to an administrative sanctioning process by Brazil’s Autoridade Nacional de Proteção de Dados (ANPD) may propose a voluntary settlement known as a Termo de Compromisso de Ajustamento (TAC, Commitment to Adjustment Term). The TAC mechanism, codified in Articles 74 to 80 of Resolution CD/ANPD No. 1/2021, provides a formal path to suspend or resolve enforcement by agreeing to correct noncompliance under ANPD supervision.
Who may propose and timing: Any party under investigation in a sanctioning process may propose a TAC at any stage—even before the instruction report (Relatório de Instrução) is issued, during the evidence phase, or on appeal to the Board of Directors (Art. 74, § 1). ANPD has discretion to accept or reject a proposed TAC, considering the seriousness of the violation and the adequacy of the commitments offered.
Required content and terms: Articles 75–77 require that a TAC lay out specific obligations to remediate the infraction, establish deadlines for compliance, and define how progress will be demonstrated. The agreement can include technical, administrative, or organizational measures (such as new security safeguards, staff training, or revised procedures). It must specify what constitutes fulfillment, and include mechanisms for monitoring compliance. ANPD is empowered to set reporting requirements and request evidence of performance. The TAC must stipulate penalties or consequences for breach—such as resumption of the administrative process and possible additional sanctions (Art. 78).
Legal effects and publication: Once a TAC is approved by ANPD, any ongoing sanctioning process is suspended for the covered conduct. Fulfillment of the agreed commitments leads to closure of the process without formal administrative penalty for the same facts (Art. 74, § 2). If the commitments are not fulfilled, the process resumes from the point of suspension, and the failure itself may weigh against the party in subsequent sanctions. For transparency, a summary of every concluded TAC is published by ANPD on its official website (Art. 80).
Articles 74–80 provide a regulatory alternative to contested enforcement and reflect a preventive, compliance-oriented posture, but do not determine the frequency or specific practice of TAC acceptance. The substantive requirements and legal consequences are defined strictly by the cited regulation.
Source: Resolution CD/ANPD No. 1/2021, Articles 74–80 (official, HTML page)
Complaints to ANPD and whistleblower protections — LGPD and Resolution CD/ANPD No. 1/2021 Articles 29–31
Initiating complaints to ANPD Brazil’s Lei Geral de Proteção de Dados (LGPD) grants every data subject the right to file a complaint (petição) with the Autoridade Nacional de Proteção de Dados (ANPD) for violations of LGPD (Article 18, §1). Resolution CD/ANPD No. 1/2021 formalizes the process: any individual or legal entity may present a complaint to ANPD regarding non-compliance, provided they first attempt to resolve the issue with the controller (Art. 29). Complaints can be filed through ANPD’s official online portal or by mail and must include supporting information and evidence if available. Anonymous submissions are accepted if justified (Art. 30, §1), especially where disclosure of identity could result in reprisals.
Whistleblower identity and confidentiality Resolution CD/ANPD No. 1/2021 places particular emphasis on protecting the identity of complainants and whistleblowers. Article 30, §3 establishes that ANPD must preserve the whistleblower's confidentiality when requested, except in legal or procedural situations where disclosure is strictly necessary; in such cases, ANPD informs the whistleblower of the disclosure prior to action. This aligns with broader federal administrative law protecting good-faith whistleblowers against retaliation and guarantees non-punishment for reporting in good faith (cf. Federal Law No. 13,608/2018, Art. 4).
Anonymous and confidential complaints Complainants who fear retaliation (especially employees or service providers disclosing internal LGPD violations) may request full confidentiality or file anonymously. ANPD will process and investigate such complaints, weighing their substance as in any standard submission. ANPD also recognizes, per Art. 30, §2, that anonymous or confidential complaints may have evidentiary limitations but does not require any greater burden of proof than for named complainants.
Prohibition on retaliation and general legal protections While the LGPD itself does not have an explicit anti-retaliation article, multiple federal laws—most notably Law No. 13,608/2018—prohibit and criminalize acts of retaliation (including dismissal, demotion, or harassment) against employees or individuals reporting good-faith suspicions of regulatory violations to a competent authority. ANPD guidance references these statutes as applicable for whistleblower protection in the LGPD enforcement context.
Process and follow-up Once a complaint is filed, ANPD may gather information, request clarifications, or open a formal monitoring or enforcement proceeding. Complainants (including whistleblowers) are notified of investigation phases and outcomes consistent with the procedural guarantees of Art. 32 of the Resolution and Art. 55-J of LGPD. Complainants may supplement their submissions or request progress updates through the same portal.
2026 currency As of June 2026, ANPD accepts whistleblower reports both from data subjects and internal actors, with protections for anonymity and anti-retaliation rooted in Resolution CD/ANPD No. 1/2021 and Federal Law No. 13,608/2018. There is not yet a published ANPD enforcement record specifically sanctioning organizations for whistleblower retaliation, but the statutory duty to protect complainants is clear.
Source: Resolution CD/ANPD No. 1/2021, Articles 29–32 (procedures for complaints, whistleblower confidentiality); Lei No. 13,608/2018, Art. 4 (federal whistleblower law)
Judicial review of ANPD administrative sanctions — right to challenge and court process under Brazilian law
Any controller or processor sanctioned by Brazil's Autoridade Nacional de Proteção de Dados (ANPD) has the right to seek judicial review of ANPD's final administrative enforcement decisions. While the Lei Geral de Proteção de Dados Pessoais (LGPD, Law No. 13,709/2018) itself does not create a bespoke judicial-appeal procedure, constitutional guarantees of due process (Article 5, XXXV of the Federal Constitution — “the law shall not exclude from judicial review any injury or threat to a right”) ensure that all affected parties may challenge ANPD sanctions in federal court once the administrative process is exhausted.
Precondition — exhaustion of administrative remedies. Under general principles of Brazilian administrative law, challenged entities must exhaust ANPD's internal remedies before resorting to the judiciary. LGPD Article 55-J, XIII vests ANPD with authority to judge administrative appeals, and Article 72 of Resolution CD/ANPD No. 1/2021 (Processual Regulation) specifies that sanctioned parties may appeal to ANPD's Board of Directors (Conselho Diretor) within 10 business days of the decision. During the pendency of an administrative appeal, enforcement of the sanction is typically suspended (Resolution No. 1/2021, Art. 72), unless an urgent preventive measure has been imposed.
Judicial review pathway and effect. Once ANPD's internal appeals are exhausted, the sanctioned party may file a court action—typically a suit to annul the administrative act (ação anulatória de ato administrativo) or a writ of mandamus (mandado de segurança)—before the federal courts (Justiça Federal). The competent court is generally the Federal Court of the defendant’s domicile or of the Federal District (Código de Processo Civil, Art. 46, I; Law No. 13,105/2015). Judicial review is available both for alleged legal/constitutional violations and, in practice, for factual disputes or questions of proportionality in sanctioning.
Under the head of ANPD's Board of Directors, the agency defends its decisions in court as a federal public authority. Courts may grant interim relief (injunction; tutela de urgência or liminar) suspending the ANPD sanction if the challenger demonstrates risk of irreparable harm or clear unlawfulness. The judicial process is governed by the Brazilian Civil Procedure Code (Law No. 13,105/2015). There is no statutorily fixed time limit for filing the judicial challenge; the general deadline is five years for annulment actions (Decree-Law No. 20,910/1932, Art. 1), but much shorter terms apply to writs of mandamus (120 days).
Case law and practical outcomes. As of June 2026, published ANPD enforcement records and federal docket search show that judicial review of ANPD sanctions has been limited in number, as most challenged entities opt for voluntary settlement (TAC) or succeed in administrative appeal. Early judicial decisions confirm that courts will review both substantive and procedural fairness of ANPD’s acts, and may suspend or annul LGPD sanctions found to violate due process or proportionality principles.
Source: LGPD (Lei No. 13,709/2018); Resolution CD/ANPD No. 1/2021, Articles 71–72 (Processual Regulation, official HTML); Federal Constitution, Article 5, XXXV
Dosimetry methodology for ANPD fines — Resolution CD/ANPD No. 4/2023 calculation factors and reduction criteria
How ANPD calculates administrative fines: base amount, mitigation, and aggravation factors under the Dosimetry Regulation (Resolution CD/ANPD No. 4/2023)
Brazil's Autoridade Nacional de Proteção de Dados (ANPD) is required by Article 53 of the LGPD to set out transparent rules for calculating administrative sanctions, especially monetary fines. Resolution CD/ANPD No. 4 of February 24, 2023 (the “Dosimetry Regulation”) establishes the methodology the agency must follow in all sanctioning processes.
Base fine calculation
- The base amount is set with reference to the gravity and nature of the infraction, the economic condition of the controller or processor, and the economic advantage obtained (arts. 5–9, Resolution No. 4/2023).
- For “simple fines,” the Dosimetry Regulation provides a table that links seriousness level (mild, moderate, severe), company size, and revenue to a percentage—up to the statutory cap of 2% of revenue in Brazil, capped at R$50 million per violation (Art. 52, II LGPD).
- ANPD must justify its finding of the infraction’s gravity in the formal decision.
Mitigating and aggravating factors Article 10 (and Annex I) lists factors that must reduce or may increase the fine:
- Mitigating: Good faith, prompt correction, adoption of governance programs (Art. 50 LGPD), cooperation with ANPD, demonstration of technical/security measures, absence of previous violations, and non-benefit from the infraction.
- Aggravating: Recidivism (generic or specific), obstruction of investigation, non-cooperation, economic benefit from the infraction, large scale or sensitive data impact, failure to comply with preventive/adaptation measures.
- Each factor adjusts the base fine by a preset percentage (see Annex II tables).
Specific rules for micro and small entities Articles 17–20 set additional reductions for microenterprises and small businesses, reflecting their limited economic condition and capacity.
Daily fines calculation Articles 14–16 set out a multiplier method for daily fines, linked to duration, the gravity of ongoing harm, and the capacity of the controller.
Transparent process and publication Every ANPD sanction decision must include a rationale describing which factors were applied in mitigation or aggravation, and the calculation under the rules, and must be published online per Art. 71, Resolution No. 1/2021.
Currency as of June 2026: The Dosimetry Regulation is the controlling methodology for all ANPD fine calculations as of 2026; there are no later comprehensive amendments.
Publication of infraction as a sanction — Article 52(IV) LGPD: scope, implementation, and effect
Statutory scope — Article 52(IV) LGPD
Article 52(IV) of Brazil’s Lei Geral de Proteção de Dados Pessoais (LGPD, Law No. 13,709/2018) authorizes the Autoridade Nacional de Proteção de Dados (ANPD) to impose “publication of the infraction” (publicização da infração) as an administrative sanction for violations of the LGPD. This measure may be ordered independently or alongside other sanctions such as warnings, fines, blocking or deletion of personal data, and suspension or prohibition of processing. For public entities, where monetary fines are prohibited (Art. 52, § 5), publication is one of the principal operational penalties available.
Publication of the infraction requires making public the final administrative decision—including the legal findings, nature of violation, and sanction imposed—after exhaustion of internal ANPD appeals. Article 52(IV) requires that publication occur only after the administrative process is concluded, and the law delegates to the ANPD the authority to determine the form and duration of publication for each case.
Implementation — ANPD regulation and procedural requirements
Resolution CD/ANPD No. 1/2021 (Processual Regulation) further details the mechanics. Article 71 obligates ANPD to publish all final sanction decisions on its official website. Where the publication sanction is imposed under Article 52(IV), the sanctioned party must also display the decision in a prominent place on its own website or, if it does not maintain a site, by another method prescribed by ANPD, to ensure public awareness (Article 71, sole paragraph). The precise format and length of publication are determined by ANPD on a case-by-case basis in the formal sanction decision and may be tailored to the scale and risk profile of the infraction.
Practical effect
The publication sanction serves both punitive and deterrent purposes: public association of an organization’s name with a confirmed LGPD violation can have reputational and operational impacts, especially in regulated sectors or when public trust is at issue. For public-sector bodies—which cannot be fined—the requirement to publicize the infraction serves as a primary legal consequence. Sanctioned entities must comply with the publication order as directed, and ANPD monitors and publicly records compliance with this obligation in its repository of enforcement decisions.
For practitioners or organizations seeking recent published examples, ANPD maintains an official online repository of sanctioning decisions and instructions, where each case imposing a publication sanction is recorded and can be referenced for detail on form and duration. The content of publication and specific requirements will vary based on the sanction decision and are not fixed by statute or regulation beyond what is stated above.
Source: LGPD (Law No. 13,709/2018), Art. 52(IV); Resolution CD/ANPD No. 1/2021, Art. 71; ANPD repository — published sanctions
Preventive measures (medidas preventivas) in ANPD enforcement — legal basis and process under updated Resolution CD/ANPD No. 1/2021 (as amended by Resolution CD/ANPD No. 4/2023)
The Autoridade Nacional de Proteção de Dados (ANPD) has authority to order preventive measures (medidas preventivas) as an interim enforcement tool at any stage of its monitoring, investigation, or sanctioning functions. The original framework for these measures is set out in Articles 29–32 of Resolution CD/ANPD No. 1, of 28 October 2021. However, significant amendments to this framework were promulgated by Resolution CD/ANPD No. 4, of 24 February 2023, which is now the controlling authority for ANPD’s procedures on preventive actions and their legal effect.
Legal basis and updated prerequisites. Resolution CD/ANPD No. 1/2021, as most recently amended, affirms that ANPD may impose a preventive measure when there is evidence of an infraction or an imminent risk to data subjects’ rights or the proper functioning of data processing. Article 30 now emphasizes that the preventive measure must be urgent, proportional to the risk, and founded on an explicit justification in the decision. Orders can include suspending processing activities, mandating technical or administrative steps, or other interventions necessary to halt or limit ongoing or imminent harm. The resolutions build in proportionality, necessity, and written motivation as required elements for valid preventive measures.
Issuance, notification, and review. The decision is to be reasoned in writing, specifying content, rationale, and deadline for compliance. The monitored party (controller or processor) must comply immediately upon notification, but has the right to present supporting evidence or request review within the administrative process. ANPD may amend, lift, or confirm the measure in response to such a request, and the preventive measure remains effective either until a contrary decision is rendered or until the related sanctioning process concludes (Article 32, as amended).
Consequences and compliance. A significant update in the amended Resolution is the procedure for escalation. If the party fails to comply with a preventive measure, ANPD may escalate directly to repressive enforcement (processo administrativo sancionador), and the failure may be considered as an aggravating factor in the calculation of administrative penalties under the Dosimetry Regulation (Resolution CD/ANPD No. 4/2023). Notably, recent ANPD enforcement records—such as the 2024 preventive measure against Meta and the 2025 Havan case—demonstrate the practical deployment of these interim measures, including the imposition of daily fines for non-compliance and the public reporting of ANPD's orders.
Current through 2026. As of June 2026, preventive measures in ANPD enforcement are governed by Articles 29–32 of Resolution CD/ANPD No. 1/2021, as amended by Resolution CD/ANPD No. 4/2023. All official ANPD references and recent sanction orders cite the revised regulatory text for legal basis and compliance standards.
Finality and appeals of ANPD enforcement sanctions — deadlines, suspensive effect, and enforceability under Resolution CD/ANPD No. 1/2021
Finality and appeals in ANPD administrative enforcement: when are sanctions enforceable, and what is the effect of an appeal?
When the Autoridade Nacional de Proteção de Dados (ANPD) imposes an administrative sanction (warning, fine, publication of infraction, blocking, deletion, suspension, or prohibition), the procedural rules for appeal and finality are set out in Resolution CD/ANPD No. 1 of October 28, 2021 (Processual Regulation), Articles 64–72. This process governs both when the sanction “becomes final” (trânsito em julgado administrativo) and when it can be enforced or published (including entry of a fine in the active debt register).
Appeal deadlines and suspensive effect
- The sanctioned party (controller or processor) has 10 business days from notification of the sanctioning decision to file an administrative appeal with ANPD's Board of Directors (Conselho Diretor) (Art. 72, caput and sole paragraph).
- Filing an administrative appeal suspends the enforceability of the sanction until the Board of Directors issues a final decision on the appeal (Art. 72, § 2; see also Art. 71 on publication of decisions).
- If no internal appeal is filed within the deadline, the decision becomes administratively final, and ANPD proceeds immediately to enforce the sanction (including fine collection, publication, or other operational measures).
- The Board of Directors’ decision on the appeal is final within the administrative sphere, and the sanction becomes enforceable on the date of notification of that decision to the affected party (Art. 72, § 3).
Effect of finality — implementation and publication
- Only administratively final decisions ("trânsito em julgado administrativo") are published on ANPD's official portal as required by LGPD Article 52(IV) and Resolution CD/ANPD No. 1/2021, Art. 71.
- Sanctions that require action by the controller—such as the publication of infraction on their own website, deletion of data, or payment of fines—are only enforceable after finality, unless an urgent preventive measure has been imposed separately under Articles 29–32.
Currency and ANPD practice (2026)
- As of June 2026, all published ANPD sanctions follow this model, and there are no later regulations altering the process. Failure to appeal within the 10-day window results in loss of administrative remedies. Administrative finality does not preclude judicial review: sanctioned parties retain the right to seek annulment in federal court after internal appeals are exhausted (see section on Judicial Review).
Source: Resolution CD/ANPD No. 1 of October 28, 2021 (official PDF, processual regulation, Articles 64–72)