CiberLATAMbywhalemate

Brazil's ANPD reforms oversight

Brazil’s ANPD opened a public hearing and consultation to overhaul its oversight and sanctions rules, including precautionary measures.

Whalemate Labs · AI-assisted researchPublished:3 min read

Brazil’s ANPD has launched a new phase to revise its inspection and administrative sanction rules, starting with a public hearing and then a consultation on Brasil Participativo. The proposal includes differentiated procedures based on severity and the size of regulated entities, precautionary measures for imminent risks, and compliance tools for technology companies.

Brazil’s ANPD has moved ahead with a reform of its inspection rules and administrative sanction process, starting with a public hearing and then a consultation on the Brasil Participativo platform. The agency said 43 people registered to take part in the hearing, while the proposal already includes precautionary measures, differentiated procedures and compliance tools for technology companies.

What changed in ANPD’s regulatory agenda?

The proposal updates the Regulation of the Inspection Process and the Administrative Sanction Process, with more graduated enforcement criteria based on the severity of violations and the economic size of data controllers. ANPD said the review is part of a two-step process, first a public hearing and then a public consultation on Brasil Participativo.

The authority had announced the hearing to discuss the new rule, and later confirmed that 43 experts and public and private sector representatives signed up to speak. Specialized coverage said the discussion took place in a federal public hearing to debate Brazil’s inspection and administrative penalty rules.

What measures does the proposal include?

The reform includes precautionary measures, including the temporary suspension of specific algorithmic features when there are imminent risks to users’ physical or psychological integrity. It also opens the door to formalize conduct adjustment agreements and priority compliance plans to address structural vulnerabilities.

Portal do Holanda added that the proposal could require companies to disclose revenue or the number of Brazilian users, and could include daily fines of up to R$ 50 million for failing to comply with precautionary measures. According to that coverage, those mechanisms are still part of a proposal subject to change, not current rules.

Who would it apply to?

The proposed scope would include providers of technology products aimed at children and adolescents, digital platforms and companies with likely access to minors, as well as possible investigations into internet users’ rights and protection of women in digital spaces. R7 said ANPD plans to publish a guide with verification criteria and semiannual transparency reports for providers with more than one million child and teen users in Brazil.

At the same time, other reports showed how ANPD has already been using preventive powers in separate cases. O Globo reported that the agency denied a Discord request and kept its live streams suspended in Brazil because the platform did not provide enough evidence to justify the block. Metrópoles added that, in the Brazilian TikTok case, accounts of users under 16 should automatically adopt stricter privacy settings, changeable only with guardian authorization, along with stronger parental controls.

What does the TikTok/ByteDance case show?

The TikTok case appears to be a key precedent for understanding ANPD’s shift, although some of the data reported in the press has not been fully confirmed in the available official material. IAPP reported that, in its first decision in the inspection proceeding against TikTok, ANPD identified five LGPD violations tied to the lack of a valid legal basis for certain processing activities and to failures to comply with the principles of prevention and accountability.

The same source described a R$ 153.7 million fine against ByteDance as an August 2026 decision, but the available result does not link the official decision text or allow independent verification of the sanction calculation. TI Inside, also without full confirmation from the official material available, reported that the sanction would have included deletion of data allegedly collected improperly and the implementation of a compliance plan.

Sources

View all