CiberLATAMbywhalemate

Brazil's ANPD revises LGPD sanctions rules

Brazil’s ANPD is reviewing LGPD enforcement and sanctions rules as a new framework would raise fines starting in November 2026.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Brazil’s ANPD is keeping its LGPD enforcement and sanctions rules under review, and that process now intersects with a new legal framework that will expand its fining power starting in November 2026.

Update August 24, 2026: Brazil’s ANPD said its enforcement and sanctions rules will need to be updated starting in November 2026 to reflect a new legal framework with higher fines for economic groups in Brazil and foreign platforms. That change adds to the ongoing LGPD review and broadens the scope of the debate over oversight and penalties.

The ANPD said its review of the Enforcement Regulations and the Administrative Sanctions Regulations under the LGPD is still underway, as it published in August 2026 its 3rd Semiannual Monitoring and Execution Report on the 2025 2026 Regulatory Agenda, covering the first half of 2026. The document also ties that review to the regulatory sandbox for artificial intelligence and to other initiatives on information security and data subject rights.

What is the ANPD reviewing?

Brazil’s data protection authority is moving ahead with updates to two core parts of its enforcement framework, the enforcement rules and the administrative sanctions rules. According to the official report, that agenda is not advancing in isolation, but alongside monitoring of the AI sandbox and other regulatory initiatives related to implementing the LGPD.

The summary circulated by specialized media adds that the review is being prioritized alongside artificial intelligence, information security, and data subject rights. In that same context, tougher criteria are expected for assessing repeat offenses, severity, and the controller’s cooperation before fines and other measures are set.

What changes for companies operating in Brazil?

The practical effect is a stricter compliance regime, with more pressure on response times, internal documentation, and the ability to show cooperation to the ANPD. Recent analysis cited in the material notes that the authority can impose administrative sanctions ranging from warnings to fines of up to 2% of a company’s or group’s gross revenue in Brazil, capped at R$ 50 million per violation.

That sanctioning range is especially associated with cases involving unlawful retention of biometric data or exposure of records in security incidents. At the same time, compliance specialists say the ANPD can also act when an organization makes it harder for data subjects to exercise their rights, such as rectification, deletion, confirmation of processing, or portability, even when there is no data breach.

How do the incident reporting rules affect this?

Resolution CD/ANPD No. 15/2024 raised the operational bar for security incidents by requiring preliminary notice within up to 3 business days and obligating notification to both the ANPD and data subjects when there is a relevant risk or harm.

According to the analyses gathered, that threshold applies in cases involving sensitive data, children’s and older adults’ data, financial data, certain authentication credentials, information protected by legal or professional confidentiality, and large-scale processing. The resolution also structures communication in two stages, with later supplementation, aligned with impact analysis, mitigation measures, and actions to prevent repeat incidents.

The comparison with GDPR highlights another operational difference for multinationals: in Brazil the deadline is up to 3 business days, while Article 33 of the European rule uses 72 consecutive hours. For companies with regional operations, that means response playbooks have to match two different timelines.

In sectors such as health care, compliance consultancies warn that the 3-business-day window becomes a bottleneck for hospitals and clinics that do not have formal incident response plans, because without tested detection, classification, and reporting processes, the deadline is very hard to meet.

What is the ANPD testing with artificial intelligence?

The ANPD published its testing methodology for the Regulatory Sandbox on Artificial Intelligence and Data Protection and detailed that participants must follow specific supervision, monitoring, and solution assessment procedures, along with periodic technical reporting obligations.

That setup works as a compliance lab for testing criteria that can later inform enforcement and sanctions against AI systems that process personal data. In the semiannual report, the ANPD also links that experience to its review of control and sanction rules, suggesting both discussions are moving in parallel.

What new limit did the ANPD identify in the Discord case?

The ANPD acknowledged that it will have to update its rules starting in November 2026 to incorporate a new legal framework that changes the maximum penalties and expands its ability to sanction foreign platforms.

According to the article on its action against Discord, the new scheme provides for fines of up to 10% of an economic group’s revenue in Brazil or, if there is no local revenue, amounts between R$ 10 and R$ 1,000 per registered user, capped at R$ 50 million per violation. That change replaces the earlier reference to a general cap of 2% of gross revenue and moves the sanctions debate to a higher scale for global groups.

The development comes as the ANPD continues to assess how to apply its enforcement power to services that operate without a meaningful economic presence in the country. In that sense, the Discord case serves as an example of the current limits and the need to adapt the sanctions regime to better address large foreign platforms.

Sources

View all