🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
BR v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing32 sources retrieved model claude-sonnet-5 · 2026-08-03

Brazil

BR schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 64 claims · 40 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
64Claimsbaseline..claims[]
3Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 10 sub-modules are flagged red.

Jurisdiction brief

Latest update · 21 September 2026

Lead Signal

Brazil's data-protection regime crossed a structural threshold this cycle. In February 2026, the conversion of Provisional Measure 1.317/2025 into Law 15.352 gave the Autoridade Nacional de Proteção de Dados (ANPD) full functional, technical, decisional, administrative and financial autonomy as a regulatory agency, understood to end roughly five years of a largely educational enforcement posture. This institutional shift landed in the same window as Brazil's first-ever adequacy decision: following reciprocal decisions adopted 26 to 27 January 2026, personal data may now flow between Brazil and the EU/EEA, including Iceland, Liechtenstein and Norway, without additional transfer safeguards such as Standard Contractual Clauses. The European Commission's own adequacy decision, adopted 26 January 2026 under GDPR Article 45, found Brazil's LGPD-based framework essentially equivalent to EU protection. ANPD's reciprocal Resolução CD/ANPD 32/2026 recognises the EU under LGPD Article 33(I), subject to review every four years, with an explicit carve-out for public-security, national-defence and criminal-investigation transfers.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive omnibus statute in force since 2020 with an increasingly empowered, independent regulator; core scope/authority questions are settled.

Primary frameworkLei Geral de Proteção de Dados Pessoais (LGPD) — Law No. 13.709/2018, as amended by Law No. 13.853/2019 and Provisional Measure No. 1.317/2025
Traffic-light rationale — GreenComprehensive omnibus statute in force since 2020 with an increasingly empowered, independent regulator; core scope/authority questions are settled.

Sub-modules (5)

Regulator And AuthorityGreen

ANPD, created by LGPD Art. 55-A and structured by Decree 10.474/2020, was converted into an independent regulatory agency by Provisional Measure 1.317/2025, aligning it with other Brazilian regulatory agencies and granting police-style enforcement powers.

Claims (2):

  • Provisional Measure No. 1.317/2025 transformed ANPD into the National Data Protection Agency, guaranteeing functional, technical, decision-making, administrative and financial autonomy.
  • The provisional measure grants ANPD strengthened enforcement powers, including ordering establishments to cease operations, seizing goods, and requesting police assistance in cases of obstruction.

Act And InstrumentsGreen

The LGPD (65 articles) is the primary instrument, heavily influenced by GDPR, supplemented by numerous ANPD resolutions (DPO, breach notification, international transfers, dosimetry, small agents) and sector rules.

Claims (1):

  • The LGPD comprises 65 articles and was greatly influenced by the EU GDPR, providing legal bases authorizing personal data use across all economic sectors.

Material ScopeGreen

LGPD applies to processing of personal data by any natural or legal person, public or private, online or offline, with limited exceptions (journalistic/artistic/academic purposes, public safety, national defense, criminal investigation).

Claims (1):

  • LGPD applicability is not limited by business size; exceptions apply only to journalistic, artistic, academic, public-safety and national-defense purposes.

Territorial ScopeGreen

Article 3 gives the LGPD extraterritorial reach: any processing carried out in Brazil, or aimed at offering goods/services to individuals in Brazil, triggers applicability regardless of the controller's country of establishment.

Claims (1):

  • Under Article 3, a personal data processor is subject to the LGPD when data are collected or processed in Brazil, or processed to offer goods/services to individuals in Brazil, irrespective of where the controller is headquartered.

Regulator Registration And FilingAmber

There is no general controller-registration regime, but ANPD Resolution 02/2022 (small-scale agents) and a simplified ROPA template create lighter-touch filing/record obligations for small processing agents.

Claims (1):

  • ANPD developed a simplified ROPA (record of processing activities) template for small-scale processing agents under the small-agents regulation approved by Resolution CD/ANPD No. 02/2022.
Category narrative64 words

Brazil's data protection framework is anchored in the LGPD (Law 13.709/2018, as amended by Law 13.853/2019), enforced by ANPD, which in September 2025 was upgraded from a transitional federal-administration body into an autonomous 'National Data Protection Agency' via Provisional Measure 1.317/2025, gaining functional, technical, decision-making, administrative and financial autonomy. The law applies extraterritorially and covers virtually all sectors and processing operations with narrow carve-outs.

Periodic update · new data 2026-09-21

Regulator & Framework

Brazil's data-protection regulator underwent a structural institutional change this cycle. The February 2026 conversion of Provisional Measure 1.317/2025 into Law 15.352 gave the Autoridade Nacional de Proteção de Dados full functional, technical, decisional, administrative and financial autonomy as a regulatory agency. This is understood, per secondary legal-press reporting, to end approximately five years during which ANPD's enforcement posture had been largely educational rather than punitive in character. The finding is assessed at probable confidence: no gov.br or planalto.gov.br primary text of Law 15.352 was reached this cycle, and sourcing rests on legal-press coverage rather than the statute itself.

The practical significance of this conversion is that it removes structural constraints, tied to ANPD's prior status, that had limited its capacity to act with full regulatory independence, including budgetary and administrative autonomy from the broader federal executive structure. This institutional change sits alongside, and plausibly helps explain, the marked escalation in enforcement activity landing in the same period, including the large children's-data fine and the newly opened Claro/Serasa proceeding described elsewhere in this cycle's findings.

Outlook

The clearest indicator to watch is whether ANPD's enforcement tempo, evident in the fines and proceedings recorded this cycle, continues at pace now that the institutional-autonomy conversion is complete, and whether a primary-source text of Law 15.352 becomes available to confirm the specific scope of the new autonomy.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (6)
  1. ConfirmedIAPP — Provisional Measure No. 1.317/2025 transformed ANPD into the National Data Protection Agency, guaranteeing functional, technical, decision-making, administrative and financial autonomy.observed
  2. ConfirmedIAPP — The provisional measure grants ANPD strengthened enforcement powers, including ordering establishments to cease operations, seizing goods, and requesting police assistance in cases of obstruction.observed
  3. ConfirmedIAPP — The LGPD comprises 65 articles and was greatly influenced by the EU GDPR, providing legal bases authorizing personal data use across all economic sectors.observed
  4. ConfirmedIAPP — LGPD applicability is not limited by business size; exceptions apply only to journalistic, artistic, academic, public-safety and national-defense purposes.observed
  5. ConfirmedIAPP — Under Article 3, a personal data processor is subject to the LGPD when data are collected or processed in Brazil, or processed to offer goods/services to individuals in Brazil, irrespective of where the controller is headquartered.observed
  6. ProbableOneTrust DataGuidance — ANPD developed a simplified ROPA (record of processing activities) template for small-scale processing agents under the small-agents regulation approved by Resolution CD/ANPD No. 02/2022.observed

#

Legal basis and sensitive-data regimes are well-settled statutory provisions with several years of ANPD/court interpretation.

Primary frameworkLGPD Arts. 7–13
Traffic-light rationale — GreenLegal basis and sensitive-data regimes are well-settled statutory provisions with several years of ANPD/court interpretation.

Sub-modules (4)

Lawful BasesGreen

Ten legal bases exist for general personal data, including consent and legitimate interest; a distinct 'protection of credit' basis (Art. 7 X) is unique to Brazil and important for financial/credit-bureau processing.

Claims (2):

  • The LGPD restricts processing of personal data to enumerated legal bases in Article 7, similar to GDPR Article 6, including consent and legitimate interest.
  • A distinctive 'protection of credit' legal basis (Art. 7 X) allows financial institutions and credit bureaus to process personal data for credit risk analysis and credit-history consultation.

Special CategoriesGreen

Sensitive personal data (Art. 5 II) includes racial/ethnic origin, religion, political opinion, union/religious/philosophical organisation membership, health, sex life, and genetic or biometric data; processing is restricted to the enumerated grounds of Article 11.

Claims (2):

  • Sensitive personal data includes racial/ethnic origin, religious belief, political opinion, union/religious/philosophical organisation membership, health or sex life, and genetic or biometric data.
  • Processing of sensitive personal data is restricted to the situations enumerated in Article 11, including specific/distinct consent or, without consent, compliance with a legal obligation, public-policy execution, research (with anonymisation where possible), exercise of rights, life/safety protection, health protection, or fraud prevention.

Pseudonymisation And AnonymisationAmber

Anonymised data (using reasonable technical/cost means at the time of processing) falls outside LGPD scope, except where the anonymisation is reversible or the data is used to build an identified individual's behavioral profile.

Claims (1):

  • Anonymised data can be treated as personal data under the LGPD when it is used to formulate a behavioural profile of a particular natural person who is identified.
Category narrative70 words

The LGPD provides ten enumerated legal bases (Art. 7 and 11), including consent, legitimate interest, contract necessity and a distinctive 'protection of credit' basis. Sensitive/special-category data (racial/ethnic origin, religion, political opinion, union membership, health, sex life, genetic and biometric data) is subject to a stricter, separately enumerated set of bases under Article 11. Anonymisation and pseudonymisation are defined but ANPD has flagged that re-identifiable/behavioral-profiling data can fall back within scope.

Sources and claims (6)
  1. ConfirmedIAPP — The LGPD restricts processing of personal data to enumerated legal bases in Article 7, similar to GDPR Article 6, including consent and legitimate interest.observed
  2. ConfirmedOneTrust DataGuidance — A distinctive 'protection of credit' legal basis (Art. 7 X) allows financial institutions and credit bureaus to process personal data for credit risk analysis and credit-history consultation.observed
  3. ConfirmedIAPP — Consent must be given for particular purposes and the burden of proof is on the controller to demonstrate valid consent; consent may be revoked at any time free of charge.observed
  4. ConfirmedIAPP — Sensitive personal data includes racial/ethnic origin, religious belief, political opinion, union/religious/philosophical organisation membership, health or sex life, and genetic or biometric data.observed
  5. ConfirmedIAPP — Processing of sensitive personal data is restricted to the situations enumerated in Article 11, including specific/distinct consent or, without consent, compliance with a legal obligation, public-policy execution, research (with anonymisation where possible), exercise of rights, life/safety protection, health protection, or fraud prevention.observed
  6. ProbableOneTrust DataGuidance — Anonymised data can be treated as personal data under the LGPD when it is used to formulate a behavioural profile of a particular natural person who is identified.observed

#

Rights catalogue is comprehensive and in force, though some response-timeline specifics are left to case-by-case ANPD regulation.

Primary frameworkLGPD Arts. 9, 18–20
Traffic-light rationale — GreenRights catalogue is comprehensive and in force, though some response-timeline specifics are left to case-by-case ANPD regulation.

Sub-modules (5)

Access RightGreen

Data subjects have the right to confirmation of the existence of processing and facilitated access to their data (Arts. 9, 19).

Claims (1):

  • Data subjects have the right to facilitated access to information about the processing of their data, to be made available in a clear, adequate and ostensible manner.

Rectification And ErasureGreen

Article 18 grants rights to correct incomplete/inaccurate/outdated data and to anonymise, block, or delete unnecessary, excessive, or unlawfully processed data.

Claims (1):

  • Article 18 rights include correcting incomplete, inaccurate or out-of-date data, and anonymising, blocking or deleting unnecessary or excessive data or data processed in noncompliance with the law.

Restriction And ObjectionGreen

Data subjects may petition against the controller before ANPD, and may oppose processing carried out under a consent-waiver ground if the LGPD is not being complied with.

Claims (1):

  • The data subject has the right to petition regarding her/his data against the controller before the national authority, and may oppose processing carried out under a consent-waiver ground if there is noncompliance with the LGPD.

Data PortabilityAmber

Article 18(V) grants a right to data portability; sectoral implementation (e.g., Central Bank open-banking/open-finance rules) has been used to operationalise portability in the financial sector ahead of general ANPD guidance.

Claims (1):

  • The Central Bank and Monetary Council's open banking regulation implemented consent-based data portability among financial institutions ahead of general ANPD portability guidance.

Deadlines And Response WindowsAmber

Where immediate compliance with a rights request is impossible, the controller must respond indicating either that it is not the processing agent or the factual/legal reasons preventing immediate action (Art. 19 §4); a fixed 15-day deadline applies specifically to requests for the text of international-transfer contractual instruments.

Claims (1):

  • Upon a data subject's request for the full text of contractual instruments used in an international transfer, controllers have 15 days to provide it, excluding trade secrets.
Category narrative42 words

Article 18 grants a GDPR-like bundle of rights (confirmation/access, correction, anonymisation/blocking/deletion, portability, information about sharing and about consequences of refusing consent, and review of automated decisions under Article 20). Rights must first be exercised directly against the controller before escalation to ANPD.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedDataGuidance — Data subjects have the right to facilitated access to information about the processing of their data, to be made available in a clear, adequate and ostensible manner.observed
  2. ConfirmedIAPP — Article 18 rights include correcting incomplete, inaccurate or out-of-date data, and anonymising, blocking or deleting unnecessary or excessive data or data processed in noncompliance with the law.observed
  3. ConfirmedIAPP — The data subject has the right to petition regarding her/his data against the controller before the national authority, and may oppose processing carried out under a consent-waiver ground if there is noncompliance with the LGPD.observed
  4. ProbableOneTrust DataGuidance — The Central Bank and Monetary Council's open banking regulation implemented consent-based data portability among financial institutions ahead of general ANPD portability guidance.observed
  5. ConfirmedIAPP — Upon a data subject's request for the full text of contractual instruments used in an international transfer, controllers have 15 days to provide it, excluding trade secrets.observed

#

Core duties are legislated and increasingly detailed by ANPD resolutions (DPO, breach, dosimetry), but explicit statutory retention/disposal timelines remain unresolved and enforcement of Art. 48/49 duties shows continuing public-sector immaturity.

Primary frameworkLGPD Arts. 37–50; ANPD Resolutions CD/ANPD 15/2024, 18/2024, 02/2022
Traffic-light rationale — AmberCore duties are legislated and increasingly detailed by ANPD resolutions (DPO, breach, dosimetry), but explicit statutory retention/disposal timelines remain unresolved and enforcement of Art. 48/49 duties shows continuing public-sector immaturity.

Sub-modules (7)

Accountability And DpiaGreen

DPIAs ('relatório de impacto') are expressly contemplated when processing relies on legitimate interest (Art. 10 §3) or involves sensitive data (Art. 38); the Digital Government Secretariat (SGD) guideline also recommends DPIAs for location tracking, profiling, automated decision-making with legal effects, and processing involving children/teenagers.

Claims (1):

  • The LGPD expressly contemplates DPIAs where processing is based on legitimate interest or involves sensitive data, and ANPD may at any time request a DPIA from the controller in those instances.

Dpo RequirementsGreen

Resolution CD/ANPD No. 18/2024 requires all controllers to designate a DPO via a formal written act, grant technical autonomy, and ensure Portuguese-language communication; small-scale controllers are exempt but must maintain a data-subject communication channel; processors are not required to appoint a DPO.

Claims (2):

  • Under ANPD Resolution CD/ANPD No. 18/2024, all organisations acting as a controller must designate a DPO through a formal written, dated and signed act; exemptions are granted only for small-scale controllers, which must instead maintain a channel for data-subject requests.
  • The DPO must be able to communicate with ANPD and data subjects in Portuguese and is not personally liable for the controller's processing of personal information.

Ropa RequirementsAmber

A simplified ROPA template for small processing agents was developed under Resolution CD/ANPD 02/2022 following public consultation.

Claims (1):

  • ANPD developed a draft simplified ROPA (record of processing activities) template specifically for small processing agents under Resolution CD/ANPD No. 02/2022.

Joint Controller ArrangementsGreen

Controllers and processors can be jointly and severally liable for security incidents and unauthorized/improper data use; a processor's liability may be limited to its contractual and security obligations if it does not itself violate LGPD rules.

Claims (1):

  • Controllers and processors can be jointly and severally liable for information-security incidents and improper/unauthorized data use, though a processor's liability may be limited to its contractual and security obligations.

Security MeasuresAmber

Article 49 requires security in systems operationalising personal data processing; three of ANPD's early sanctioning decisions concerned Article 49 security violations.

Claims (1):

  • Three of ANPD's published sanctioning decisions to date have dealt with Article 49 violations relating to ensuring security in systems operationalising personal data processing.

Breach NotificationGreen

Article 48 requires notification of security incidents to ANPD within a reasonable timeframe depending on severity, potentially triggering data-subject notification and public disclosure; Resolution CD/ANPD 15/2024 (April 2024) defines incidents and clarifies criteria, timeline and methods for notification.

Claims (2):

  • Article 48 of the LGPD requires mandatory data-breach notification to ANPD within a reasonable timeframe, which may, depending on severity, require notifying affected data subjects and public disclosure of the incident.
  • ANPD Resolution CD/ANPD No. 15 of 24 April 2024 defines security incidents and clarifies the criteria, timeline and methods for breach notification.

Retention And DisposalRed

No specific statutory retention-period schedule was identified in this research pass beyond the general purpose-limitation principle; ANPD has not published a dedicated retention/disposal regulation comparable to its DPO or breach-notification resolutions.

Category narrative57 words

Controllers must appoint a DPO (Resolution CD/ANPD 18/2024) unless qualifying as a small-scale controller; ROPA obligations apply with a simplified template for small agents; DPIAs are recommended/required for legitimate-interest and sensitive-data processing and for profiling/tracking/children's-data scenarios; breach notification to ANPD is mandatory within a reasonable timeframe under Resolution CD/ANPD 15/2024; joint controller/processor liability follows a GDPR-like split.

Sources and claims (8)
  1. ConfirmedIAPP — The LGPD expressly contemplates DPIAs where processing is based on legitimate interest or involves sensitive data, and ANPD may at any time request a DPIA from the controller in those instances.observed
  2. ConfirmedIAPP — Under ANPD Resolution CD/ANPD No. 18/2024, all organisations acting as a controller must designate a DPO through a formal written, dated and signed act; exemptions are granted only for small-scale controllers, which must instead maintain a channel for data-subject requests.observed
  3. ConfirmedIAPP — The DPO must be able to communicate with ANPD and data subjects in Portuguese and is not personally liable for the controller's processing of personal information.observed
  4. ProbableOneTrust DataGuidance — ANPD developed a draft simplified ROPA (record of processing activities) template specifically for small processing agents under Resolution CD/ANPD No. 02/2022.observed
  5. ConfirmedIAPP — Controllers and processors can be jointly and severally liable for information-security incidents and improper/unauthorized data use, though a processor's liability may be limited to its contractual and security obligations.observed
  6. ConfirmedIAPP — Three of ANPD's published sanctioning decisions to date have dealt with Article 49 violations relating to ensuring security in systems operationalising personal data processing.observed
  7. ConfirmedIAPP — Article 48 of the LGPD requires mandatory data-breach notification to ANPD within a reasonable timeframe, which may, depending on severity, require notifying affected data subjects and public disclosure of the incident.observed
  8. ConfirmedIAPP — ANPD Resolution CD/ANPD No. 15 of 24 April 2024 defines security incidents and clarifies the criteria, timeline and methods for breach notification.observed

#

A full transfer-mechanism toolkit is now operative and the landmark 2026 mutual adequacy determination substantially de-risks EU-Brazil data flows, though SCC/BCR implementation details remain partly unresolved.

Primary frameworkLGPD Arts. 33–36; ANPD International Data Transfer Regulation (Aug. 2024); Resolution No. 32/2026
Traffic-light rationale — GreenA full transfer-mechanism toolkit is now operative and the landmark 2026 mutual adequacy determination substantially de-risks EU-Brazil data flows, though SCC/BCR implementation details remain partly unresolved.

Sub-modules (6)

Transfer MechanismsGreen

Article 33 lists exhaustive grounds for international transfers: adequacy, contractual/BCR guarantees, international cooperation agreements, life/safety protection, ANPD prior authorization, public-policy execution, consent, legal/regulatory compliance, contractual necessity, and exercise of rights.

Claims (1):

  • Article 33 of the LGPD provides an exhaustive list of grounds authorising international data transfers, including adequacy, contractual instruments, ANPD-authorised specific clauses, international cooperation agreements, and data-subject consent.

Adequacy ReceivedGreen

The European Commission's Implementing Decision 2026/179 (January 2026) recognises that Brazil ensures an adequate level of protection for personal data transferred from the EU under GDPR Article 45.

Claims (1):

  • For the purpose of Article 45 of Regulation (EU) 2016/679, Brazil ensures an adequate level of protection for personal data transferred from the European Union to controllers and processors in Brazil subject to the LGPD.

Adequacy GrantedGreen

ANPD's Resolution No. 32/2026 reciprocally recognised the EU as an international organisation providing an adequate level of protection for international transfers under the LGPD.

Claims (1):

  • In Resolution No. 32/2026, ANPD recognized the EU as an international organization providing an adequate level of protection for purposes of international data transfers under the LGPD.

Sccs And BcrsAmber

ANPD introduced a rigid standard-contractual-clause model (inspired by EU, UK, New Zealand and Singapore frameworks) divided into general information, mandatory clauses, security measures, and additional clauses/annexes; BCRs require prior ANPD assessment and evidence of a data-privacy governance program.

Claims (2):

  • ANPD's SCCs can form a stand-alone contract or be attached to a broader agreement, are divided into general information, mandatory clauses, security measures, and additional clauses/annexes, and unlike EU clauses do not feature modules but customizable fields.
  • Use of BCRs for intragroup international transfers requires prior ANPD assessment, with data controllers demonstrating compliance including implementation of a data privacy governance program.

Transfer Impact AssessmentAmber

The LGPD does not impose a discrete, Schrems-II-style per-transfer impact assessment; adequacy equivalence is instead assessed by ANPD at the country level, though commentators note open questions about whether additional safeguards for SCCs may eventually be required.

Claims (1):

  • There will inevitably be discussions about the adequacy of SCCs and whether additional measures are necessary, mirroring concerns raised in the EU under Schrems II.

Data LocalisationAmber

Brazil does not impose a general data-localisation mandate; however, discussions of a 'sovereign cloud' as part of Brazil's Artificial Intelligence Plan aim to keep government data stored within national borders.

Claims (1):

  • Publication of the ANPD international-transfer regulation coincided with discussions of creating a 'sovereign cloud' under Brazil's Artificial Intelligence Plan, aiming to keep government data stored within national borders.
Category narrative72 words

Article 33 provides an exhaustive list of transfer mechanisms (adequacy, standard contractual clauses, BCRs, consent, legal-obligation, contract necessity, and other named grounds). ANPD published its long-awaited International Data Transfer Regulation (August 2024) and, in January 2026, mutual EU-Brazil adequacy was achieved: the European Commission adopted Implementing Decision 2026/179 recognising Brazil as adequate under GDPR Art. 45, and ANPD's Resolution No. 32/2026 reciprocally recognised the EU as providing adequate protection under the LGPD.

Periodic update · new data 2026-09-21

Cross-Border & Adequacy

Brazil received its first-ever adequacy decision this cycle. Following reciprocal decisions adopted 26 to 27 January 2026, personal data may flow between Brazil and the EU/EEA, including Iceland, Liechtenstein and Norway, without additional transfer safeguards such as Standard Contractual Clauses or Binding Corporate Rules. This is a confirmed, high-materiality development affecting the transfer mechanism landscape in both directions.

On the EU side, the European Commission adopted its adequacy decision on 26 January 2026 under GDPR Article 45, finding Brazil's LGPD-based framework essentially equivalent to EU data protection, and permitting EU-to-Brazil transfers without additional safeguards. On the Brazilian side, ANPD's Resolução CD/ANPD 32/2026, adopted 26 to 27 January 2026, formally recognises the European Union, covering all Member States plus Iceland, Liechtenstein and Norway, as providing adequate personal-data protection under LGPD Article 33(I). This recognition is subject to review every four years from the adoption date, and carries an explicit carve-out preserving the need for additional safeguards on transfers related to public security, national defence, or criminal investigation.

This reciprocal pairing of decisions is a structural, not episodic, development: it establishes for the first time a bilateral adequacy relationship that eliminates the routine transfer-mechanism burden for the large volume of EU-Brazil personal-data flows, while preserving a defined and narrow carve-out for security-sensitive categories.

Outlook

The adequacy decisions are due for review every four years from the January 2026 adoption date, placing the first formal review point in 2030. In the nearer term, watch for any sector-specific guidance clarifying how the public-security and criminal-investigation carve-out will be applied in practice.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ConfirmedIAPP — Article 33 of the LGPD provides an exhaustive list of grounds authorising international data transfers, including adequacy, contractual instruments, ANPD-authorised specific clauses, international cooperation agreements, and data-subject consent.observed
  2. ConfirmedEUR-Lex — For the purpose of Article 45 of Regulation (EU) 2016/679, Brazil ensures an adequate level of protection for personal data transferred from the European Union to controllers and processors in Brazil subject to the LGPD.observed
  3. ConfirmedIAPP — In Resolution No. 32/2026, ANPD recognized the EU as an international organization providing an adequate level of protection for purposes of international data transfers under the LGPD.observed
  4. ConfirmedIAPP — ANPD's SCCs can form a stand-alone contract or be attached to a broader agreement, are divided into general information, mandatory clauses, security measures, and additional clauses/annexes, and unlike EU clauses do not feature modules but customizable fields.observed
  5. ConfirmedIAPP — Use of BCRs for intragroup international transfers requires prior ANPD assessment, with data controllers demonstrating compliance including implementation of a data privacy governance program.observed
  6. UncertainIAPP — There will inevitably be discussions about the adequacy of SCCs and whether additional measures are necessary, mirroring concerns raised in the EU under Schrems II.observed
  7. UncertainIAPP — Publication of the ANPD international-transfer regulation coincided with discussions of creating a 'sovereign cloud' under Brazil's Artificial Intelligence Plan, aiming to keep government data stored within national borders.observed

#

Financial and health overlays are documented and active; telecoms/ePrivacy, education and insurance sub-areas lack dedicated sectoral DP instruments in the sources reviewed.

Primary frameworkLGPD (general) plus BACEN/CMN Open Finance regulation and FEBRABAN self-regulation (financial sector)
Traffic-light rationale — AmberFinancial and health overlays are documented and active; telecoms/ePrivacy, education and insurance sub-areas lack dedicated sectoral DP instruments in the sources reviewed.

Sub-modules (7)

Financial Sector OverlayGreen

BACEN and the Monetary Council's Open Finance regulation establishes consent as the sole legal ground for data transfers within open banking; FEBRABAN's CARB Standard 21/2022 reiterates and supplements LGPD requirements for banks.

Claims (2):

  • The Central Bank and Monetary Council's open banking regulation establishes consent as the unique legal ground for data transfers within the scope of open banking, excluding sensitive data, credit scores/ratings and login/access credentials from the transferable dataset.
  • FEBRABAN's CARB Standard 21/2022 reiterates and adds to LGPD requirements, prompting financial institutions toward international standards and better data-protection governance.

Health Sector OverlayAmber

ANPD sanctioned the Instituto de Assistência Médica ao Servidor Público Estadual (IAMSPE) for failing to safeguard public employees' health data and for an untimely Article 48 breach notification.

Claims (1):

  • ANPD determined that the government health system IAMSPE violated the LGPD by failing to safeguard public employees' personal health data and by not producing a data-breach notification within a reasonable period.

Telecoms And EprivacyRed

No dedicated telecoms/ePrivacy-specific data-protection overlay (comparable to the EU ePrivacy Directive) was identified for Brazil in this research pass; cookie-specific guidance exists as ANPD soft-law rather than a distinct statute.

Claims (1):

  • No distinct telecoms/ePrivacy statute analogous to the EU ePrivacy Directive was located for Brazil; ANPD has issued a Guide on Cookies and Data Protection as soft-law guidance rather than binding sector legislation.

Employment DataAmber

Employment-related sensitive health data has been subject to ANPD enforcement in the public sector (IAMSPE case involving public employees' health data), but no dedicated private-sector employment-data statute was identified.

Claims (1):

  • ANPD determined that the government health system IAMSPE violated the LGPD by failing to safeguard public employees' personal health data and by not producing a data-breach notification within a reasonable period.

Credit And ScoringAmber

The 'protection of credit' legal basis (Art. 7 X) underpins credit-bureau and scoring activity; Brazilian courts have restricted processing of data such as voter registration number, mother's name, lifestyle, social class, schooling, marginal propensity to consume and georeferencing for credit-protection purposes as not necessary.

Claims (1):

  • Brazilian courts have restricted the processing of data such as voter registration number, mother's name, lifestyle, social class, schooling, marginal propensity to consume and georeferencing for credit-protection purposes as not necessary.

EducationRed

No education-sector-specific data-protection instrument was identified in this research pass beyond general LGPD applicability and DPIA guidance touching on children's data in digital products.

InsuranceRed

No insurance-sector-specific data-protection instrument was identified in this research pass beyond general LGPD applicability.

Category narrative92 words

Financial-sector data flows are shaped by BACEN/Monetary Council open-banking (Open Finance) rules layered atop the LGPD, plus bank self-regulation (FEBRABAN's CARB Standard 21/2022). Health-sector enforcement so far centres on ANPD sanctions against a public health-insurance entity for failing to safeguard employees' health data and for a late Article 48 breach notification. Credit/scoring processing is governed by a bespoke 'protection of credit' legal basis, with courts restricting non-necessary data (e.g., voter registration, marginal propensity to consume) in credit-protection scoring. No comprehensive telecoms/ePrivacy-specific overlay, education-sector, or insurance-sector regime was identified in this research pass.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidance — The Central Bank and Monetary Council's open banking regulation establishes consent as the unique legal ground for data transfers within the scope of open banking, excluding sensitive data, credit scores/ratings and login/access credentials from the transferable dataset.observed
  2. ProbableOneTrust DataGuidance — FEBRABAN's CARB Standard 21/2022 reiterates and adds to LGPD requirements, prompting financial institutions toward international standards and better data-protection governance.observed
  3. ConfirmedIAPP — ANPD determined that the government health system IAMSPE violated the LGPD by failing to safeguard public employees' personal health data and by not producing a data-breach notification within a reasonable period.observed
  4. UncertainEUR-Lex — No distinct telecoms/ePrivacy statute analogous to the EU ePrivacy Directive was located for Brazil; ANPD has issued a Guide on Cookies and Data Protection as soft-law guidance rather than binding sector legislation.observed
  5. ProbableEUR-Lex — Brazilian courts have restricted the processing of data such as voter registration number, mother's name, lifestyle, social class, schooling, marginal propensity to consume and georeferencing for credit-protection purposes as not necessary.observed

#

One concrete enforcement precedent (Meta AI-training suspension) exists, but most adtech sub-areas lack dedicated Brazilian instruments identified in this pass.

Primary frameworkLGPD general provisions (Arts. 7, 18, 20) plus ANPD enforcement practice; no dedicated adtech statute identified
Traffic-light rationale — AmberOne concrete enforcement precedent (Meta AI-training suspension) exists, but most adtech sub-areas lack dedicated Brazilian instruments identified in this pass.

Sub-modules (6)

Cookies And TrackersAmber

ANPD has published a Guide on Cookies and Data Protection referenced in the EU's adequacy assessment, but this is soft-law guidance rather than a binding ePrivacy-style cookie consent statute.

Claims (1):

  • ANPD has issued a Guide on Cookies and Data Protection, referenced as an official ANPD guidance document in the European Commission's Brazil adequacy assessment.

Dark PatternsRed

No Brazil-specific dark-pattern prohibition distinct from general LGPD transparency/consent principles was identified in this research pass.

Opt Out SignalsRed

No evidence was found of Brazil recognising standardized opt-out signals (e.g., Global Privacy Control) analogous to US state regimes.

Clean Rooms And DcrRed

No clean-room or data-collaboration-room-specific guidance was identified for Brazil in this research pass.

Cross Context AdvertisingAmber

ANPD ordered Meta to suspend processing of personal data for AI-model training under penalty of a daily fine of BRL50,000; the order was later suspended conditional on Meta's compliance with a monitored plan facilitating the right to object.

Claims (2):

  • The ANPD ordered Meta to suspend the processing of personal data for AI training, under penalty of a daily fine of BRL 50,000.
  • The Meta suspension order was lifted conditional on compliance with a plan monitored by ANPD, including facilitating the exercise of the right to object.

Direct MarketingRed

No Brazil-specific direct-marketing suppression/consent regime distinct from general LGPD consent and objection rights was identified in this research pass.

Category narrative80 words

Commercial/adtech-specific DP rules in Brazil remain comparatively underdeveloped relative to cookie/consent regimes seen in the EU or certain US states. The clearest enforcement data point is ANPD's order suspending Meta's processing of personal data for AI-model training (subject to a daily fine), conditioned on facilitating the right to object. ANPD has referenced a Guide on Cookies and Data Protection, but dark-pattern-specific prohibitions, opt-out signal recognition (e.g., GPC), clean-room/data-collaboration rules, and direct-marketing-specific suppression regimes were not located in this research pass.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (3)
  1. ProbableEUR-Lex — ANPD has issued a Guide on Cookies and Data Protection, referenced as an official ANPD guidance document in the European Commission's Brazil adequacy assessment.observed
  2. ConfirmedIAPP — The ANPD ordered Meta to suspend the processing of personal data for AI training, under penalty of a daily fine of BRL 50,000.observed
  3. ConfirmedIAPP — The Meta suspension order was lifted conditional on compliance with a plan monitored by ANPD, including facilitating the exercise of the right to object.observed

#

ADM transparency right is in force but implementation guidance is nascent; the horizontal AI statute remains unconfirmed as fully enacted; state-surveillance carve-outs are statutorily defined but ANPD's practical oversight role there is limited.

Primary frameworkLGPD Art. 20 (ADM); LGPD Art. 4 §3 (state-surveillance carve-out); Brazilian AI Bill (PL 2338/2023, status uncertain)
Traffic-light rationale — AmberADM transparency right is in force but implementation guidance is nascent; the horizontal AI statute remains unconfirmed as fully enacted; state-surveillance carve-outs are statutorily defined but ANPD's practical oversight role there is limited.

Sub-modules (6)

Profiling RestrictionsAmber

The SGD's DPIA guideline recommends impact assessments where processing involves location tracking, behavioral profiling, or automated decision-making with legal effects on a person's personal, professional, consumer or credit profile.

Claims (1):

  • The SGD DPIA guideline suggests a DPIA where processing involves tracking data subjects' location, formation of a behavioral profile, or automated decision-making with legal effects on personal, professional, consumer or credit profiles, or involving children and teenagers.

Automated Decision Making TransparencyAmber

Article 20 of the LGPD guarantees individuals the right to request review of decisions made solely through automated processing of personal data; ANPD's Technical Note 12/2025 (May 2025) summarised public input on AI/ADM to inform future regulation.

Claims (1):

  • Article 20 of the LGPD guarantees individuals the right to request a review of decisions made solely through automated processing of personal data.

Ai Risk AssessmentsAmber

The Brazilian AI Bill (PL 2338/2023), a risk-based framework drawing on the EU AI Act, passed the Senate in December 2024 and was under Chamber of Deputies discussion; separate sector-specific AI bills (e.g., AI-based domestic-violence-offender monitoring, Bill 750/2026) are also in progress. Final enactment status of PL 2338/2023 could not be confirmed as of this research pass.

Claims (2):

  • The Brazilian Artificial Intelligence Bill (PL 2338/2023) had its wording approved by the Senate in December 2024 and draws parallels with the EU AI Act's risk-based approach.
  • Bill No. 750/2026, before the Chamber of Deputies, would establish a National Program for Monitoring Aggressors Using Artificial Intelligence, combining electronic monitoring, behavioral analytics and real-time alerts.

Biometric RegimeAmber

Biometric data is classified as sensitive personal data under Art. 5 II and subject to Art. 11 processing restrictions; age-verification mechanisms under the Digital ECA increasingly rely on soft-biometric signals (e.g., typing patterns, device position), raising fresh biometric-processing questions.

Claims (1):

  • Age-verification approaches evolving under Brazil's Digital ECA framework increasingly draw on soft biometrics such as typing patterns and device position to assess probable user age.

Genetic DataGreen

Genetic data is expressly listed among sensitive personal data categories under Art. 5 II, subject to the same Art. 11 restrictions as other special categories.

Claims (1):

  • Genetic and biometric data are expressly included within the LGPD's definition of sensitive personal data under Article 5 II.

State Surveillance CarveoutsAmber

The LGPD does not apply to processing for public security, national defense, state security, or investigation/prosecution of criminal offenses, but ANPD retains authority to issue technical opinions, recommendations, and to request a DPIA from controllers even in these carve-out scenarios.

Claims (1):

  • For public security, national defense, state security, or investigation/prosecution of criminal offenses, the LGPD is not applicable, but ANPD retains the attribution of issuing technical opinions, recommendations and requesting a DPIA from controllers (Art. 4 §3).
Category narrative109 words

Article 20 gives data subjects the right to request review of decisions made solely through automated processing; ANPD's Technical Note 12/2025 explores implementation as AI use grows. A dedicated Brazilian AI Bill (PL 2338/2023), risk-based and modeled on the EU AI Act, passed the Senate in December 2024 but its enactment status in the Chamber of Deputies could not be confirmed as final in this research pass. Biometric and genetic data are protected as sensitive categories under Art. 5 II/Art. 11. Public-security, national-defense, state-security and criminal-investigation processing fall outside LGPD's substantive scope, though ANPD retains power to issue technical opinions, recommendations, and request DPIAs even in those carve-out cases.

Periodic update · new data 2026-09-21

Algorithmic, Biometric & Surveillance Governance

Two distinct developments define this module's material content this cycle. First, ANPD published a Report on Generative AI, understood to analyse the implications, risks and challenges associated with generative-AI technologies, representing the regulator's move into active engagement with AI-specific governance questions ahead of any dedicated AI-processing rule.

Second, and providing important enforcement-precedent context, in 2025 ANPD issued a preliminary order prohibiting Tools for Humanity, the operator of Worldcoin, from collecting iris scans in exchange for cryptocurrency in Brazil, backed by a daily fine of R$50,000 for non-compliance. This action is understood to demonstrate ANPD's willingness to halt biometric-data operations at a preliminary, pre-merits stage where mass-impact risk is present, notably occurring ahead of any dedicated biometric-data regulation, which remains a later-phase item on ANPD's 2025-2026 Regulatory Agenda, following data subject rights, DPIAs, government data-sharing and minors' data in the agenda's sequencing.

Read together, the generative-AI report and the Worldcoin biometric enforcement precedent indicate that ANPD is building governance capacity and enforcement precedent in the algorithmic and biometric space ahead of, rather than through, dedicated statutory rules specific to those categories.

Outlook

Dedicated biometric-data regulation remains a later-phase Regulatory Agenda item with an expected multi-year horizon; watch for whether the Worldcoin enforcement precedent is followed by further preliminary orders against other biometric-data operations pending that dedicated rule.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (7)
  1. ProbableIAPP — The SGD DPIA guideline suggests a DPIA where processing involves tracking data subjects' location, formation of a behavioral profile, or automated decision-making with legal effects on personal, professional, consumer or credit profiles, or involving children and teenagers.observed
  2. ConfirmedIAPP — Article 20 of the LGPD guarantees individuals the right to request a review of decisions made solely through automated processing of personal data.observed
  3. UncertainOneTrust DataGuidance — The Brazilian Artificial Intelligence Bill (PL 2338/2023) had its wording approved by the Senate in December 2024 and draws parallels with the EU AI Act's risk-based approach.observed
  4. ConfirmedIAPP — Bill No. 750/2026, before the Chamber of Deputies, would establish a National Program for Monitoring Aggressors Using Artificial Intelligence, combining electronic monitoring, behavioral analytics and real-time alerts.observed
  5. ProbableIAPP — Age-verification approaches evolving under Brazil's Digital ECA framework increasingly draw on soft biometrics such as typing patterns and device position to assess probable user age.observed
  6. ConfirmedIAPP — Genetic and biometric data are expressly included within the LGPD's definition of sensitive personal data under Article 5 II.observed
  7. ConfirmedIAPP — For public security, national defense, state security, or investigation/prosecution of criminal offenses, the LGPD is not applicable, but ANPD retains the attribution of issuing technical opinions, recommendations and requesting a DPIA from controllers (Art. 4 §3).observed

#

Statutory protection is strong and rapidly maturing (Digital ECA now in force), but implementing age-verification technical standards remain under active public consultation as of mid-2026.

Primary frameworkLGPD Art. 14; Digital Child and Adolescent Statute (Law No. 15.211/2025) and Decree No. 12.881/2026
Traffic-light rationale — AmberStatutory protection is strong and rapidly maturing (Digital ECA now in force), but implementing age-verification technical standards remain under active public consultation as of mid-2026.

Sub-modules (5)

Age VerificationAmber

The Digital ECA (Law 15.211/2025), in force since 17 March 2026, requires providers of digital products/services directed at or likely accessed by children/adolescents to implement robust age-verification mechanisms; ANPD's Radar Tecnológico and 2026 public consultations are developing detailed technical guidance.

Claims (3):

  • Law No. 15.211/2025, the Digital Child and Adolescent Statute ('Digital ECA'), establishes a substantive framework for protecting children and adolescents in digital environments, with Decree No. 12.881/2026 operationalising preventive measures, risk management and accountability requirements.
  • The Digital ECA applies to any product, service, or platform directed to, or likely to be accessed by, children (under 12) and adolescents (12-18) in Brazil.
  • ANPD's Radar Tecnológico #5 and a May 2026 call for contributions are developing an Age Verification Mechanisms Guide to implement the Digital ECA, updating preliminary guidelines first published in March 2026.

Minor Profiling BansAmber

The SGD DPIA guideline recommends a DPIA whenever processing involves children and teenagers, reflecting heightened scrutiny of profiling activities affecting minors rather than an outright statutory profiling ban.

Claims (1):

  • The SGD's DPIA guideline recommends a data protection impact assessment whenever processing involves children and teenagers.

Education SettingsRed

No education-sector-specific children's-data provision distinct from the general Digital ECA/LGPD children's-data framework was identified in this research pass.

Dependent AdultsRed

No Brazil-specific statutory provisions for dependent/incapacitated adults distinct from general Civil Code representation rules were identified in this research pass.

Category narrative131 words

The LGPD (Art. 14) requires specific/highlighted parental or guardian consent for children's data processing as the general rule, subject to exceptions (contacting parents, protection, one-time non-stored use), while ANPD's Statement 1/2023 clarified that other legal bases may apply provided the child's best interest is observed. This framework has been substantially overlaid by the new Digital Child and Adolescent Statute ('Digital ECA', Law 15.211/2025, in force since March 2026 with Decree 12.881/2026), which mandates robust age verification, content restrictions, parental-supervision tools, and anti-exploitation measures for any digital product/service directed at or accessible to children (under 12) and adolescents (12-18). ANPD is the enforcing authority for the Digital ECA and has been running public consultations (its 2025-26 Regulatory Agenda, Radar Tecnológico #5, and a May 2026 call for contributions) on age-verification mechanism guidance.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedIAPP — Law No. 15.211/2025, the Digital Child and Adolescent Statute ('Digital ECA'), establishes a substantive framework for protecting children and adolescents in digital environments, with Decree No. 12.881/2026 operationalising preventive measures, risk management and accountability requirements.observed
  2. ConfirmedIAPP — The Digital ECA applies to any product, service, or platform directed to, or likely to be accessed by, children (under 12) and adolescents (12-18) in Brazil.observed
  3. ConfirmedIAPP — ANPD's Radar Tecnológico #5 and a May 2026 call for contributions are developing an Age Verification Mechanisms Guide to implement the Digital ECA, updating preliminary guidelines first published in March 2026.observed
  4. ConfirmedDataGuidance — Children's personal data may only be processed with specific and highlighted consent from a parent or legal representative, except where collection is necessary to contact the parents/representative, is used a single time without storage, or is for the child's protection.observed
  5. ConfirmedIAPP — ANPD's Statement No. 1/2023 clarified that processing of children's data may rely on any legal basis under the LGPD, provided the best interests of the child prevail in the specific case, moving away from consent as the sole compliance anchor.observed
  6. ProbableIAPP — The SGD's DPIA guideline recommends a data protection impact assessment whenever processing involves children and teenagers.observed

#

Statutory penalty and powers framework is robust and has just been substantially strengthened, but actual enforcement volume remains modest and concentrated in the public sector, and ANPD's historic capacity constraints are only now being addressed.

Primary frameworkLGPD Arts. 52, 55-A to 55-L; Provisional Measure No. 1.317/2025; ANPD Dosimetry Regulation (Resolution of 27 Feb. 2023)
Traffic-light rationale — AmberStatutory penalty and powers framework is robust and has just been substantially strengthened, but actual enforcement volume remains modest and concentrated in the public sector, and ANPD's historic capacity constraints are only now being addressed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

ANPD has sole responsibility for LGPD sanctions (Art. 55-K), which include warnings, fines up to 2% of Brazilian revenue capped at BRL 50 million per infraction, daily fines, publicization, data blocking/deletion, and processing/database suspension up to 12 months; the 2025 reform added cease-operation, seizure and police-assistance powers.

Claims (2):

  • ANPD has sole responsibility for applying LGPD sanctions (Art. 55-K), including fines of up to 2% of a company's Brazil-derived revenue for the prior fiscal year, excluding taxes, capped at BRL 50 million per infraction, plus daily fines subject to the same cap.
  • Provisional Measure 1.317/2025 makes clear that ANPD can now order establishments to cease operations, seize goods, and request police assistance in cases of obstruction of its functions.

Enforcement Activity IndexAmber

Of ANPD's seven to eight published sanctioning decisions, most target the public sector; five concerned Article 48 breach-notification violations and three concerned Article 49 security violations, alongside the Meta AI-training suspension order (BRL 50,000 daily fine).

Claims (2):

  • Of ANPD's seven sanctioning decisions published to date, most target the public sector, with five dealing with Article 48 breach-communication violations.
  • Among ANPD's first eight sanctioning procedures, seven were issued against public entities.

Regulator Funding And CapacityAmber

ANPD historically operated with a small technical and administrative staff limiting its scope of action; the September 2025 transformation into an autonomous agency (with tenured technical staff positions) is expected to substantially increase structural and budgetary capacity.

Claims (2):

  • ANPD's actions in relation to public entities have historically been predominantly pedagogical and limited in scope, aggravated by the authority's small technical and administrative staff.
  • ANPD's transformation into a regulatory agency is expected to bring greater structural and budgetary robustness, with increased staff and technical resources and enhanced operational independence.

Collective Redress And Class ActionsGreen

Individual and class suits are possible independent of ANPD's administrative process, and fines collected by ANPD are allocated to Diffuse Rights Defense Funds.

Claims (1):

  • The sum of fines collected by ANPD is allocated to the Diffuse Rights Defense Funds referred to in Law No. 7.347/1985 and Law No. 9.008/1995.

Private Right Of ActionGreen

Brazil's Constitution gives all citizens both a private right of action and a public right of action via the Public Prosecutors' Office, enabling enforcement by individuals, consumer-protection organisations, and prosecutors independent of ANPD sanctions.

Claims (1):

  • Brazil's Constitution gives all citizens a private right of action and a public right of action to the Brazil Public Prosecutors' Office, enabling individual and class suits regardless of ANPD's administrative sanction status.

Recent Developments 180DGreen

Within the last 180 days (Feb.-Aug. 2026): the EU-Brazil mutual adequacy regime took effect (EU Implementing Decision 2026/179 and ANPD Resolution 32/2026, Jan. 2026); the Digital ECA Decree 12.881/2026 operationalised the Digital ECA which took force 17 March 2026; and ANPD opened a May 2026 public consultation to update its Age Verification Mechanisms Guide.

Claims (3):

  • In January 2026, the European Commission recognized that Brazil ensures an adequate level of protection for personal data transferred from the EU under the GDPR.
  • Brazil's Digital ECA (Law 15.211/2025) took effect 17 March 2026, alongside Decree 12.881/2026 operationalizing its preventive-measures and accountability requirements, with ANPD empowered as enforcer.
  • On 22 May 2026, ANPD opened a call for contributions on its Age Verification Mechanisms Guide, updating preliminary guidelines published in March 2026 to implement the Digital ECA.
Category narrative111 words

ANPD has sole administrative sanctioning authority under Article 55-K, with penalties (Art. 52) ranging from warnings to fines of up to 2% of Brazil-derived revenue (capped at BRL 50 million per infraction), daily fines, public disclosure, data blocking/deletion, and processing/database suspension of up to twelve months. The September 2025 transformation into an autonomous agency added cease-operation, seizure, and police-assistance powers. To date, ANPD's sanctioning track record (seven to eight published decisions) skews heavily toward public-sector entities, mostly for Article 48 (breach notification) and Article 49 (security) violations, alongside the high-profile Meta AI-training suspension order. Independent of ANPD, individuals, public prosecutors, and consumer-protection bodies retain constitutional rights of private and collective action.

Periodic update · new data 2026-09-21

Enforcement & Redress

ANPD's enforcement activity escalated markedly this cycle across two concurrent matters. ANPD opened a supervisory proceeding against Claro, with Serasa notified for a parallel proceeding, alleging LGPD violations arising from the transfer of more than one hundred pieces of customer information per partnership. A potential fine of up to R$50 million, or 2 percent of the company's Brazilian revenue for the prior fiscal year, whichever is applicable, is in prospect, consistent with ANPD's standing statutory penalty ceiling under LGPD Article 52; the proceeding remains at a proposed, unresolved stage this cycle.

This proceeding lands alongside the separately reported R$153.77 million fine against a social-media platform for children's-data violations, described under Children & Vulnerable Groups, and both sit against the backdrop of ANPD's February 2026 conversion to full institutional autonomy under Law 15.352. ANPD's standing statutory powers include the ability to impose fines of up to 2 percent of Brazilian revenue capped at R$50 million per infraction, and to block databases, delete data, publicise violations, and suspend or prohibit processing activities; these powers pre-date this cycle but provide the statutory basis against which the newly opened Claro/Serasa proceeding and the sanctioned children's-data case should be read.

The concurrence of a large resolved fine and a newly opened, unresolved proceeding of comparable potential magnitude is itself a signal of a regulator operating at a materially higher enforcement tempo than in prior periods.

Outlook

The Claro/Serasa proceeding's resolution, whether by settlement, sanction, or dismissal, is the clearest near-term indicator of ANPD's post-autonomy enforcement trajectory; watch for its outcome and for the eventual fine amount relative to the R$50 million or 2 percent statutory ceiling.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (11)
  1. ConfirmedIAPP — ANPD has sole responsibility for applying LGPD sanctions (Art. 55-K), including fines of up to 2% of a company's Brazil-derived revenue for the prior fiscal year, excluding taxes, capped at BRL 50 million per infraction, plus daily fines subject to the same cap.observed
  2. ConfirmedIAPP — Provisional Measure 1.317/2025 makes clear that ANPD can now order establishments to cease operations, seize goods, and request police assistance in cases of obstruction of its functions.observed
  3. ConfirmedIAPP — Of ANPD's seven sanctioning decisions published to date, most target the public sector, with five dealing with Article 48 breach-communication violations.observed
  4. ConfirmedIAPP — Among ANPD's first eight sanctioning procedures, seven were issued against public entities.observed
  5. ConfirmedIAPP — ANPD's actions in relation to public entities have historically been predominantly pedagogical and limited in scope, aggravated by the authority's small technical and administrative staff.observed
  6. ProbableIAPP — ANPD's transformation into a regulatory agency is expected to bring greater structural and budgetary robustness, with increased staff and technical resources and enhanced operational independence.observed
  7. ConfirmedIAPP — The sum of fines collected by ANPD is allocated to the Diffuse Rights Defense Funds referred to in Law No. 7.347/1985 and Law No. 9.008/1995.observed
  8. ConfirmedIAPP — Brazil's Constitution gives all citizens a private right of action and a public right of action to the Brazil Public Prosecutors' Office, enabling individual and class suits regardless of ANPD's administrative sanction status.observed
  9. ConfirmedIAPP — In January 2026, the European Commission recognized that Brazil ensures an adequate level of protection for personal data transferred from the EU under the GDPR.observed
  10. ConfirmedIAPP — Brazil's Digital ECA (Law 15.211/2025) took effect 17 March 2026, alongside Decree 12.881/2026 operationalizing its preventive-measures and accountability requirements, with ANPD empowered as enforcer.observed
  11. ConfirmedIAPP — On 22 May 2026, ANPD opened a call for contributions on its Age Verification Mechanisms Guide, updating preliminary guidelines published in March 2026 to implement the Digital ECA.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct78.12
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Brazil
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 64 claim(s) (64 category placement(s)), 40 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsrectification and erasure
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrectification and erasure
Art. 19Data Subject Rightsdeadlines and response windows
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiessecurity measures
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

All 10 modules populated with T1 (LGPD statutory text, EU adequacy Implementing Decision 2026/179) and T2 (IAPP analysis, ANPD regulation summaries) sources as primary grounding, supplemented by T3 (DataGuidance opinion/news) for financial-sector and AI-bill context. regulator_and_framework, lawful_processing_and_special_data, data_subject_rights, cross_border_and_adequacy, children_and_vulnerable_groups, and enforcement_and_redress modules rest on strong T1/T2 evidence. controller_processor_duties is well-evidenced except retention_and_disposal, which carries only a narrative absent_field_provenance (no dedicated ANPD retention-schedule regulation located). sectoral_watch is strong for financial and health overlays but red/absent for telecoms/ePrivacy, education and insurance sub-modules. adtech_and_commercial_privacy relies mainly on a single enforcement precedent (Meta AI-training order) and ANPD's cookie guide reference, with dark-patterns, opt-out signals, clean rooms and direct-marketing sub-modules carrying absent_field_provenance. algorithmic_biometric_and_surveillance_governance's ai_risk_assessments sub-module carries Uncertain confidence because the final enactment status of PL 2338/2023 (Brazilian AI Bill) could not be confirmed as of the research date.

Unresolved questions (5):

  • Has the Brazilian AI Bill (PL 2338/2023) been enacted into law, and if so, under what final title/number and effective date?
  • Does ANPD have or plan a dedicated data-retention/disposal regulation comparable to its DPO and breach-notification resolutions?
  • Is there a Brazil-specific telecoms/ePrivacy cookie-consent statute distinct from ANPD's soft-law Cookie Guide?
  • What is the current operative status/version of ANPD's Age Verification Mechanisms Guide following the May 2026 consultation round?
  • Are there Brazil-specific opt-out-signal (e.g., Global Privacy Control equivalent), dark-pattern, or clean-room regulations not captured in this pass?

Escalate to primary-source review: yes