Brazil's ANPD reviews LGPD sanctions rules
Brazil's ANPD is reviewing its LGPD enforcement and sanctions rules while moving ahead with its AI sandbox and new incident reporting rules.
Brazil's ANPD said in August 2026 that its review of the LGPD enforcement and administrative sanctions regulations is still under way, as part of its third semiannual monitoring report for the 2025-2026 regulatory agenda, covering the first half of 2026. The report also ties that review to the artificial intelligence sandbox and other regulatory efforts.
Brazil's ANPD said in August 2026 that it is still reviewing the regulations for enforcement and administrative sanctions under the LGPD, as it released its third semiannual monitoring report for the 2025-2026 regulatory agenda, covering the first half of 2026. The document also links that review to the regulatory sandbox for artificial intelligence and to other initiatives on information security and data subject rights.
What is the ANPD reviewing?
The Brazilian authority is keeping its update of two core parts of its oversight framework, the enforcement rules and the administrative sanctions rules, in progress. According to the official report, that agenda is not moving on its own, but alongside monitoring of the AI sandbox and other regulatory initiatives tied to LGPD implementation.
The summary circulated by specialized media adds that the review is being prioritized alongside artificial intelligence, information security and data subject rights. In that same framework, stricter criteria are expected for assessing repeat offenses, severity and the controller's cooperation before fines and other measures are set.
What changes for companies operating in Brazil?
The practical focus is a tougher compliance regime, with greater pressure on response times, internal documentation and the ability to show cooperation before the ANPD. Recent analyses cited in the material note that the authority can impose administrative sanctions ranging from warnings to fines of up to 2% of a company's or group's gross revenue in Brazil, capped at R$ 50 million per violation.
That sanction range appears especially tied to cases involving the improper retention of biometric data or exposure of records in security incidents. At the same time, compliance specialists say the ANPD can also act when an organization blocks data subjects from exercising their rights, such as correction, deletion, confirmation of processing or portability, even when there is no data breach.
How do the incident notification rules affect this?
Resolution CD/ANPD No. 15/2024 raised the operational standard for security incidents by setting a preliminary notification deadline of up to 3 business days and requiring notification to both the ANPD and affected individuals when there is relevant risk or harm.
According to the analyses compiled, that threshold applies in cases involving sensitive data, data from minors and older adults, financial data, certain authentication credentials, information protected by legal or professional confidentiality, and large-scale processing. The resolution also structures communication in two stages, with a later supplement, aligned with impact analysis, mitigation measures and steps to prevent repeat incidents.
The comparison with GDPR highlights another operational difference for multinationals: in Brazil, the deadline is up to 3 business days, while Article 33 of the European rule uses 72 calendar hours. For companies with regional operations, that means response playbooks must be adjusted to two different timelines.
In sectors such as healthcare, compliance consultants warn that the 3-business-day window becomes a bottleneck for hospitals and clinics without formal incident response plans, because without rehearsed detection, classification and reporting processes, the deadline is difficult to meet.
What is the ANPD testing with artificial intelligence?
The ANPD published the testing methodology for its Regulatory Sandbox on Artificial Intelligence and Data Protection, and said participants must follow specific supervision, monitoring and solution assessment procedures, along with periodic technical reporting duties.
That setup works as a compliance laboratory to test criteria that can later inform enforcement and sanctions against AI systems that process personal data. In the semiannual report, the ANPD also connects that experience with its review of enforcement and sanctions rules, suggesting both discussions are moving in parallel.
Sources
- ANPD publica relatório de acompanhamento e execução da agenda regulatória do 1º semestre deste anogov.br· Agência Nacional de Proteção de Dados (ANPD)
- Legislação sobre privacidade e proteção de dados pessoaisprodest.es.gov.br· Governo do Estado do Espírito Santo – PRODEST
- Materiais e Publicações – Guia Orientativo para Definições dos Agentes de Tratamento de Dados Pessoais e do Encarregadosedu.es.gov.br· Secretaria de Educação do Espírito Santo (SEDU)
- ANPD publishes 1st semester regulatory agenda report (2025–2026 agenda)rdprivacywatch.com· RD Privacy Watch
- ANPD realiza consulta multissetorial sobre Sandbox Regulatório de Inteligência Artificiallegismap.com.br· Legismap
- Privacidade e Verificação de Idade: O Limite da Lei e ANPDtecdiario.com.br· TecDiario
- Na mira da ANPD: os motivos por trás dos alvos e o risco de esconder seu canal de atendimentodponet.com.br· DPO4
- LATAM Pass sofre ataque cibernético e expõe dados de clientesminutodaseguranca.blog.br· Minuto da Segurança
- LGPD na saúde em 2026: o ano da virada regulatóriamedicinasa.com.br· Medicinasa
- Data privacy in Brazil: ANPD takes action against tech giantsmanageengine.com· ManageEngine Insights
- Custo de Vazamento de Dados no Brasil sob a LGPDnextguardinsurance.com· NextGuard Insurance
- Telecomunicações | Tecnologia, IA e Infraestruturas Críticas (junho e julho 2026)lefosse.com· Lefosse Advogados
- ANPD publica metodologia de testagem do Sandbox Regulatório em Inteligência Artificial e Proteção de Dadosgov.br· Agência Nacional de Proteção de Dados (ANPD)
- ANPD publica relatório de acompanhamento e execução da Agenda Regulatória no 1º semestre deste anogov.br· Agência Nacional de Proteção de Dados (ANPD)
- GDPR em Apps Móveis 2026: Bases Legais, SDKs e o mapeamento completo para a LGPDsecureprivacy.ai· SecurePrivacy.ai
- ANPD fiscaliza IA em 2026: sua empresa está exposta?nexusai.com.br· NexusAI
- Política de Privacidade (referencias a Resolução CD/ANPD nº 15/2024 y nº 18/2024)conneops.com· ConneOps



