CiberLATAMbywhalemate

Brazil's ANPD tightens breach notice rules

Brazil’s ANPD set short breach-reporting deadlines and stepped up oversight of data officers, with a focus on financial, biometric and health data.

Whalemate Labs · AI-assisted researchPublished:3 min read

Brazil’s ANPD has set short deadlines for incident reporting, stepped up oversight of data protection officers and prioritized financial, biometric and health data. That framework has direct implications for regional companies processing Peruvian users’ data from Brazil, including firms revising policies after the LATAM Pass case.

Brazil’s ANPD is tightening oversight of security incidents and LGPD compliance obligations, with direct effects on regional companies that process Peruvian users’ data from Brazil. Recent analyses and privacy policies reviewed in August point to short notification deadlines, closer scrutiny of data protection officers, reviews of impact assessments and a growing focus on financial and biometric data.

What does the ANPD incident ruling require?

The ANPD’s Resolution CD/ANPD No. 15/2024 requires that when a controller confirms a security incident affecting personal data and creating relevant risk or harm, it notify the ANPD and the affected data subjects within a maximum of three business days from the moment it becomes aware of the breach. That standard appears in analyses by TechTimes, Minuto da Segurança and ManageEngine, as well as in Mira’s privacy policy.

TechTimes’ analysis of LATAM Pass links that obligation to the exposed-data case and underscores that the regulatory scope extends to Peruvian users whose data is processed under Brazil’s LGPD. Minuto da Segurança added that, based on the public information available, it is not possible to conclude whether LATAM missed any deadlines or regulatory duties, a clarification that tempers more categorical readings of the incident.

DPO Net, in an analysis of security failures in airline loyalty programs, also noted that the initial notice cannot wait until the investigation is closed and that unjustified delay is a separate violation. The same text said the notice must include the nature of the data affected, the technical measures adopted and the associated risks.

What data is under the closest scrutiny?

The ANPD is giving priority to financial data, biometric data, health data and processing involving children and adolescents, along with certain sensitive or high-risk categories under the LGPD. That combination raises the compliance bar for regional operations managing Peruvian customers’ information from Brazil.

TechTimes said the 2026 2027 Priority Topics Map includes financial data among the four enforcement priorities, alongside biometrics, health and data processing involving children and adolescents. At the same time, ManageEngine stressed that the duty to report breaches under Article 48 of the LGPD and Resolution CD/ANPD No. 15/2024 also covers incidents involving financial data, data of children and older adults, certain authentication data, data protected by professional or legal privilege and large-scale processing.

The ANPD’s order to stop the use of facial recognition for school attendance monitoring in Paraná, reported by Biometric Update, shows how intense that enforcement can be. In that case, the authority gave the state government ten days from notification to prove it had stopped biometric data processing across all involved systems and schools.

How is the market reacting?

Several companies are already explicitly incorporating the LGPD ANPD standard into their privacy policies and incident response protocols. Mira’s policy, for example, calls for notifying the ANPD and affected data subjects within a maximum of three business days from the moment it becomes aware of a personal data incident, and for sending additional information within up to 20 business days.

That kind of wording shows how operators with regional services are adapting their compliance mechanisms to Brazil’s framework, with an impact that also reaches Peruvian users whose data is processed in Brazil. BSA Advogados added that the ANPD disclosed in July 2026 the results of a first phase of monitoring proceedings on the obligation to appoint a data protection officer, a requirement that also applies to Brazilian subsidiaries of groups with a parent company or presence in Peru.

Legismap, meanwhile, reported that the authority has been using short deadlines in its monitoring proceedings for digital platforms, requiring responses to regulatory questionnaires within ten business days of notification. Taken together, those moves increase pressure on companies operating between Brazil and Peru, which must maintain standards compatible with the LGPD and Law 29733.

Sources

View all