Brazil's ANPD revises LGPD sanctions rules
Brazil’s ANPD is reviewing LGPD enforcement and sanctions rules as a new framework would raise fines starting in November 2026.
Brazil’s ANPD is keeping its LGPD enforcement and sanctions rules under review, and that process now intersects with a new legal framework that will expand its fining power starting in November 2026.
Update August 24, 2026: Brazil’s ANPD said its enforcement and sanctions rules will need to be updated starting in November 2026 to reflect a new legal framework with higher fines for economic groups in Brazil and foreign platforms. That change adds to the ongoing LGPD review and broadens the scope of the debate over oversight and penalties.
The ANPD said its review of the Enforcement Regulations and the Administrative Sanctions Regulations under the LGPD is still underway, as it published in August 2026 its 3rd Semiannual Monitoring and Execution Report on the 2025 2026 Regulatory Agenda, covering the first half of 2026. The document also ties that review to the regulatory sandbox for artificial intelligence and to other initiatives on information security and data subject rights.
What is the ANPD reviewing?
Brazil’s data protection authority is moving ahead with updates to two core parts of its enforcement framework, the enforcement rules and the administrative sanctions rules. According to the official report, that agenda is not advancing in isolation, but alongside monitoring of the AI sandbox and other regulatory initiatives related to implementing the LGPD.
The summary circulated by specialized media adds that the review is being prioritized alongside artificial intelligence, information security, and data subject rights. In that same context, tougher criteria are expected for assessing repeat offenses, severity, and the controller’s cooperation before fines and other measures are set.
What changes for companies operating in Brazil?
The practical effect is a stricter compliance regime, with more pressure on response times, internal documentation, and the ability to show cooperation to the ANPD. Recent analysis cited in the material notes that the authority can impose administrative sanctions ranging from warnings to fines of up to 2% of a company’s or group’s gross revenue in Brazil, capped at R$ 50 million per violation.
That sanctioning range is especially associated with cases involving unlawful retention of biometric data or exposure of records in security incidents. At the same time, compliance specialists say the ANPD can also act when an organization makes it harder for data subjects to exercise their rights, such as rectification, deletion, confirmation of processing, or portability, even when there is no data breach.
How do the incident reporting rules affect this?
Resolution CD/ANPD No. 15/2024 raised the operational bar for security incidents by requiring preliminary notice within up to 3 business days and obligating notification to both the ANPD and data subjects when there is a relevant risk or harm.
According to the analyses gathered, that threshold applies in cases involving sensitive data, children’s and older adults’ data, financial data, certain authentication credentials, information protected by legal or professional confidentiality, and large-scale processing. The resolution also structures communication in two stages, with later supplementation, aligned with impact analysis, mitigation measures, and actions to prevent repeat incidents.
The comparison with GDPR highlights another operational difference for multinationals: in Brazil the deadline is up to 3 business days, while Article 33 of the European rule uses 72 consecutive hours. For companies with regional operations, that means response playbooks have to match two different timelines.
In sectors such as health care, compliance consultancies warn that the 3-business-day window becomes a bottleneck for hospitals and clinics that do not have formal incident response plans, because without tested detection, classification, and reporting processes, the deadline is very hard to meet.
What is the ANPD testing with artificial intelligence?
The ANPD published its testing methodology for the Regulatory Sandbox on Artificial Intelligence and Data Protection and detailed that participants must follow specific supervision, monitoring, and solution assessment procedures, along with periodic technical reporting obligations.
That setup works as a compliance lab for testing criteria that can later inform enforcement and sanctions against AI systems that process personal data. In the semiannual report, the ANPD also links that experience to its review of control and sanction rules, suggesting both discussions are moving in parallel.
What new limit did the ANPD identify in the Discord case?
The ANPD acknowledged that it will have to update its rules starting in November 2026 to incorporate a new legal framework that changes the maximum penalties and expands its ability to sanction foreign platforms.
According to the article on its action against Discord, the new scheme provides for fines of up to 10% of an economic group’s revenue in Brazil or, if there is no local revenue, amounts between R$ 10 and R$ 1,000 per registered user, capped at R$ 50 million per violation. That change replaces the earlier reference to a general cap of 2% of gross revenue and moves the sanctions debate to a higher scale for global groups.
The development comes as the ANPD continues to assess how to apply its enforcement power to services that operate without a meaningful economic presence in the country. In that sense, the Discord case serves as an example of the current limits and the need to adapt the sanctions regime to better address large foreign platforms.
Sources
- Guia Definitivo da LGPD nas Empresas: Passo a passo para adequação completa em 2026dponet.com.br· DPO Net
- ANPD enfrenta limites na aplicação de sanções ao Discord no Brasil em meio a debate sobre responsabilidade de plataformas estrangeirasjmvnews.com· JMV News
- Legislação sobre privacidade e proteção de dados pessoaisprodest.es.gov.br· Governo do Estado do Espírito Santo – PRODEST
- Materiais e Publicações – Guia Orientativo para Definições dos Agentes de Tratamento de Dados Pessoais e do Encarregadosedu.es.gov.br· Secretaria de Educação do Espírito Santo (SEDU)
- ANPD publishes 1st semester regulatory agenda report (2025–2026 agenda)rdprivacywatch.com· RD Privacy Watch
- ANPD realiza consulta multissetorial sobre Sandbox Regulatório de Inteligência Artificiallegismap.com.br· Legismap
- Privacidade e Verificação de Idade: O Limite da Lei e ANPDtecdiario.com.br· TecDiario
- Na mira da ANPD: os motivos por trás dos alvos e o risco de esconder seu canal de atendimentodponet.com.br· DPO4
- LATAM Pass sofre ataque cibernético e expõe dados de clientesminutodaseguranca.blog.br· Minuto da Segurança
- LGPD na saúde em 2026: o ano da virada regulatóriamedicinasa.com.br· Medicinasa
- Custo de Vazamento de Dados no Brasil sob a LGPDnextguardinsurance.com· NextGuard Insurance
- Telecomunicações | Tecnologia, IA e Infraestruturas Críticas (junho e julho 2026)lefosse.com· Lefosse Advogados
- ANPD publica metodologia de testagem do Sandbox Regulatório em Inteligência Artificial e Proteção de Dadosgov.br· Agência Nacional de Proteção de Dados (ANPD)
- ANPD publica relatório de acompanhamento e execução da Agenda Regulatória no 1º semestre deste anogov.br· Agência Nacional de Proteção de Dados (ANPD)
- ANPD fiscaliza IA em 2026: sua empresa está exposta?nexusai.com.br· NexusAI
- Brazil's ANPD emerges as a powerful enforcer of data privacymanageengine.com· ManageEngine Insights
- Latam Pass Data Breach: Exposed BIN Data Creates Fraud Risk Beyond Partial Card Claimstechtimes.com· TechTimes
- Política de Privacidade (referencias a Resolução CD/ANPD nº 15/2024 y nº 18/2024)conneops.com· ConneOps
- Vazamento de Dados da Empresa - Responsabilidadejoaocoelho.adv.br· João Coelho Advogados
- ANPD publica relatório de acompanhamento e execução da agenda regulatória do 1º semestre deste anogov.br· Agência Nacional de Proteção de Dados (ANPD)
- Latam Pass sofre vazamento de dados e aciona a ANPDpainelpolitico.com· Painel Político
- A fiscalização da ANPD e os desafios de conformidade à LGPD para as empresasbsaadvogados.com.br· BSA Advogados
- Falha de Segurança Expõe Dados de Clientes em Programa de Fidelidade do Setor Aéreodponet.com.br· DPO Net
- Data privacy in Brazil: ANPD takes action against tech giantsmanageengine.com· ManageEngine Insights
- GDPR em Apps Móveis 2026: Bases Legais, SDKs e o mapeamento completo para a LGPDsecureprivacy.ai· SecurePrivacy.ai



