
Brazil’s LGPD Breach Rule Turns ‘Reasonable Time’ Into Three Business Days
Brazil’s data-protection authority has replaced an open-ended breach-notification standard with a defined three-business-day clock and a detailed test for deciding which incidents must be reported.
Brazil’s Lei Geral de Proteção de Dados, or LGPD, has always required controllers to communicate security incidents capable of causing relevant risk or damage. For several years, however, the law’s reference to reporting within a “reasonable time” left organisations without a settled operational deadline.
Resolution CD/ANPD No. 15, published on 26 April 2024, changed that. A controller must generally notify the National Data Protection Authority and affected individuals within three business days when a confirmed incident involves personal data subject to the LGPD and may cause relevant risk or damage.
That is not much time. The rule makes incident classification, controller-processor coordination and communication capability part of routine security engineering.
Not every security event is reportable
The reporting test is cumulative. An event must be confirmed, involve personal data covered by the LGPD and be capable of causing relevant risk or damage to individuals.
The assessment is contextual. Organisations should consider the nature and volume of data, the number and characteristics of affected people, the likely material or moral harm, and whether protections such as strong encryption make identification impracticable. Large-scale data, sensitive data and information concerning vulnerable groups increase the likelihood of relevant risk.
Availability and integrity matter as well as confidentiality. A ransomware incident that makes patient information unavailable can be reportable even if the attacker did not publish the database. An accidental alteration or destruction of data can also affect individuals’ rights.
The controller owns the external clock
The obligation to communicate to the ANPD and affected individuals sits with the controller. A processor must provide the controller with the necessary incident information without unjustified delay.
That distinction must be reflected in supplier agreements. If a cloud provider takes two days to decide whether an event is worth escalating, the controller may receive the facts too late to assess the threshold, prepare the notice and obtain approval within three business days.
Contracts should specify immediate escalation triggers, minimum incident fields, secure evidence exchange and named decision contacts. A generic promise to “cooperate” is not an incident workflow.
An incomplete investigation is not a reason to remain silent
The regulation permits staged reporting when complete information is unavailable. The controller can submit a preliminary notification and provide a justified supplement, generally within 20 business days after the initial communication.
That option should not become an excuse for a content-free notice. The first report still needs the known nature of the incident, the affected data and people, potential consequences, mitigation measures and contact information. Teams need to distinguish information that is essential for the initial decision from details that can follow after forensic work.
Communication to individuals should be direct and individualised where possible, use plain language and explain what happened, which data categories were affected, the relevant risks and what people can do. The ANPD may require corrections or wider publicity if the chosen communication is inadequate.
Build the reporting decision into the incident process
An organisation subject to the LGPD should be able to answer five questions during the first incident meeting:
- Has a security incident actually been confirmed?
- Does it involve identifiable people and processing covered by the LGPD?
- Who is the controller for each affected dataset?
- Could the event create relevant risk or damage?
- When did the three-business-day period begin?
The answers should be recorded even when the decision is not to notify. A defensible incident register needs the facts considered, the risk assessment, responsible decision-makers, mitigation and communications. That evidence is important if the ANPD later learns about the event from an individual, supplier or public report.
The practical control set
- Update incident-severity criteria to include harm to individuals, not only technical or business impact.
- Require processors to alert controllers without unjustified delay.
- Maintain templates for ANPD and data-subject communications in Portuguese.
- Identify who can approve a notification during weekends, holidays and executive absence.
- Test staged reporting in tabletop exercises.
- Preserve the decision record and supporting evidence for regulatory review.
The regulation makes the breach clock predictable. It also removes the comfort of waiting for a perfect forensic narrative. Organisations need enough information to make and explain a risk decision quickly, then improve the account as the investigation develops.
Official sources
- Brazilian ANPD: Security Incident Communication procedure and guidance
- Brazilian ANPD: Resolution CD/ANPD No. 15 of 24 April 2024
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index



