Don’t do SECURITY. Do business SECURELY.

Brazil’s ANPD sets three-day breach notification rule

Brazil’s data protection authority adopts Resolution 15/2024, requiring notification of relevant security incidents within three working days.

Brazil’s national data protection authority (ANPD) today approves Resolution CD/ANPD No. 15/2024, the Regulation on Security Incident Communication under the LGPD.

Key points

  • Incidents that may cause relevant risk or damage to data subjects must be notified to the ANPD and data subjects within three working days.
  • Deadlines are doubled for small processing agents.
  • Notifications must include specified information on the nature, data and individuals affected, and measures taken.
  • Controllers must keep a record of all security incidents for at least five years.

UK organisations subject to the LGPD should update incident response plans for Brazil’s three-working-day deadline, which is tighter than the UK GDPR’s 72-hour window in some cases.

Source: Resolução CD/ANPD nº 15/2024 (Ministério da Justiça, Brazil)

Need help understanding what this change means for your organisation? Get in touch for a pragmatic, no-obligation conversation.

More insights