CiberLATAMbywhalemate

Brazil’s ANPD tightens LGPD enforcement

ANPD is updating its sanctions rulebook, keeping an enforcement draft open for comment and expanding guidance on DPOs, IT

Whalemate Labs · AI-assisted researchPublished:3 min read

Brazil’s ANPD expanded its enforcement and sanctions powers under the LGPD in 2025 and 2026, with a public consultation open on its sanctions rulebook, a guide for IT providers tied to the ECA Digital, and criteria now covering security incidents, international transfers and AI training.

Brazil’s data protection authority, the ANPD, deepened its shift toward more active LGPD enforcement in 2025 and 2026. The agency is keeping its updated inspection and administrative sanctions rulebook open for public comment through Oct. 26, while moving forward with a guide for IT providers tied to the ECA Digital and sharpening criteria that already cover security incidents, international transfers and AI system training.

What changed in ANPD enforcement?

The ANPD has moved from a mostly advisory posture to one that actively imposes sanctions under the LGPD, according to compliance practice analysis cited in the source material. That shift is tied to its transformation into an independent regulatory agency, which expanded its authority to levy fines, issue certification rules and coordinate with sector regulators.

The agency has also said publicly that it follows a responsive enforcement model and uses strictly technical criteria to bring data handlers into compliance. That position came in response to criticism over alleged censorship and overreach in social media regulation.

What does the sanctions rulebook under consultation provide?

The ANPD’s sanctions framework includes aggravating and mitigating factors that can significantly change the final amount of a fine. According to the material, specific or general recidivism and failure to comply with preventive or corrective orders can increase the amount by 5% to 90% from the initial value, while governance mechanisms and corrective measures can reduce it by 5% to 75%.

The public consultation on the updated Regulamento de Fiscalização e do Processo Administrativo Sancionador will remain open until Oct. 26. That process will affect how the agency supervises and penalizes LGPD violations.

What other guidance and areas has ANPD opened up?

The ANPD is preparing a Guia de fornecedores de produtos ou serviços de TI, escopo e obrigações gerais do ECA Digital, which is now in the consolidation stage for feedback. The document will define obligations for IT providers in protecting the data of children and adolescents, alongside the duties already established under the LGPD.

One year after the ECA Digital took effect, the agency formally said that, after Decree No. 12.622/2025 and its conversion into a federal regulatory agency under Law No. 15.352, enforcing that statute became a core responsibility. Folha de S.Paulo also reported practical tensions in that enforcement, citing the Aug. 12 order to suspend live streams and other video features on Discord, a measure that was carried out and later challenged in court.

How is ANPD applying the LGPD to AI, breaches and transfers?

The compliance agenda now reaches the use of data for AI training, security incidents and international transfers. According to recent legal analysis, the ANPD has already sanctioned the use of personal data to train AI models without waiting for a specific framework, applying purpose, necessity and legal-basis principles to machine learning projects.

At the same time, a bill is under discussion that would amend the LGPD to set criteria for using personal data to train and improve AI systems. The material also says the authority requires personal data security incidents to be reported within three business days and oversees international transfers from three angles, notice to the data subject, documentation of the data flow and response to incidents.

Are the new rules already being used in the public sector?

Yes. Administrative acts by local governments in Brazil are already applying Resolução CD/ANPD No. 18/2024 to appoint data protection officers, based on provisions covering designation, characteristics, duties and conflicts of interest. The case shows that the rulebook has already entered public-sector practice, not just private companies.

Sources

View all