CiberLATAMbywhalemate

Brazil's ANPD reviews LGPD sanctions rules

Brazil's ANPD is reviewing its LGPD enforcement and sanctions rules while moving ahead with its AI sandbox and new incident reporting rules.

Whalemate Labs · AI-assisted researchPublished:3 min read

Brazil's ANPD said in August 2026 that its review of the LGPD enforcement and administrative sanctions regulations is still under way, as part of its third semiannual monitoring report for the 2025-2026 regulatory agenda, covering the first half of 2026. The report also ties that review to the artificial intelligence sandbox and other regulatory efforts.

Brazil's ANPD said in August 2026 that it is still reviewing the regulations for enforcement and administrative sanctions under the LGPD, as it released its third semiannual monitoring report for the 2025-2026 regulatory agenda, covering the first half of 2026. The document also links that review to the regulatory sandbox for artificial intelligence and to other initiatives on information security and data subject rights.

What is the ANPD reviewing?

The Brazilian authority is keeping its update of two core parts of its oversight framework, the enforcement rules and the administrative sanctions rules, in progress. According to the official report, that agenda is not moving on its own, but alongside monitoring of the AI sandbox and other regulatory initiatives tied to LGPD implementation.

The summary circulated by specialized media adds that the review is being prioritized alongside artificial intelligence, information security and data subject rights. In that same framework, stricter criteria are expected for assessing repeat offenses, severity and the controller's cooperation before fines and other measures are set.

What changes for companies operating in Brazil?

The practical focus is a tougher compliance regime, with greater pressure on response times, internal documentation and the ability to show cooperation before the ANPD. Recent analyses cited in the material note that the authority can impose administrative sanctions ranging from warnings to fines of up to 2% of a company's or group's gross revenue in Brazil, capped at R$ 50 million per violation.

That sanction range appears especially tied to cases involving the improper retention of biometric data or exposure of records in security incidents. At the same time, compliance specialists say the ANPD can also act when an organization blocks data subjects from exercising their rights, such as correction, deletion, confirmation of processing or portability, even when there is no data breach.

How do the incident notification rules affect this?

Resolution CD/ANPD No. 15/2024 raised the operational standard for security incidents by setting a preliminary notification deadline of up to 3 business days and requiring notification to both the ANPD and affected individuals when there is relevant risk or harm.

According to the analyses compiled, that threshold applies in cases involving sensitive data, data from minors and older adults, financial data, certain authentication credentials, information protected by legal or professional confidentiality, and large-scale processing. The resolution also structures communication in two stages, with a later supplement, aligned with impact analysis, mitigation measures and steps to prevent repeat incidents.

The comparison with GDPR highlights another operational difference for multinationals: in Brazil, the deadline is up to 3 business days, while Article 33 of the European rule uses 72 calendar hours. For companies with regional operations, that means response playbooks must be adjusted to two different timelines.

In sectors such as healthcare, compliance consultants warn that the 3-business-day window becomes a bottleneck for hospitals and clinics without formal incident response plans, because without rehearsed detection, classification and reporting processes, the deadline is difficult to meet.

What is the ANPD testing with artificial intelligence?

The ANPD published the testing methodology for its Regulatory Sandbox on Artificial Intelligence and Data Protection, and said participants must follow specific supervision, monitoring and solution assessment procedures, along with periodic technical reporting duties.

That setup works as a compliance laboratory to test criteria that can later inform enforcement and sanctions against AI systems that process personal data. In the semiannual report, the ANPD also connects that experience with its review of enforcement and sanctions rules, suggesting both discussions are moving in parallel.

Sources

View all