ANPD Enforcement in 2026: What Changed and Why Foreign Companies Should Pay Attention

Brazil's data protection authority became an autonomous regulator in 2026, with 75 planned enforcement actions and daily fines for non-compliance. Here's what changed and what foreign companies operating in Brazil need to do now.

7/21/20266 min read

judges gavel and open book on table
judges gavel and open book on table

Your company ran an Brazilian Data protection law (LGPD) compliance project three or four years ago. Someone drafted a privacy policy, updated a few contracts, and the topic moved off the priority list. If that describes your Brazilian operation today, the timing is worse than it looks.

For most of its existence, Brazil's data protection authority, the ANPD, operated mainly as an educator. It published guides, ran public consultations, and reserved sanctions for the clearest cases. As of 2026, that posture has changed structurally, not just rhetorically.

In February 2026, Law 15,352/2026 converted the ANPD from an agency tied to the federal executive branch into an autonomous regulatory body, with its own budget, an expanded staff, and reinforced investigative powers. The agency's own priority-setting instrument for the current period, the Mapa de Temas Prioritários 2026-2027, commits to 75 fiscalization actions over the two-year cycle, concentrated on biometric data, health data, financial data, children's and adolescents' data, and artificial intelligence. Complaints from data subjects are also climbing fast: the ANPD logged roughly 8,700 requerimentos from individuals in 2025 alone.

This article explains what actually changed in ANPD enforcement, what typically triggers a proceeding, and what a foreign company with operations, a subsidiary, or a data processing relationship in Brazil should do now that the guidance phase is ending.

The Precedent That Set the Pattern

The shift did not start in 2026. In December 2024, the ANPD opened simultaneous fiscalization proceedings against 20 large companies, including well-known names in technology, retail, and telecommunications, for failing to appoint a data protection officer or provide an adequate communication channel for data subjects, a basic requirement under LGPD article 41. Every one of those companies came into compliance rather than face escalation.

At the time, that sweep was notable mainly because it targeted private companies at all. Historically, ANPD sanctions concentrated on public sector entities, which cannot be fined under LGPD article 52, paragraph 3. The only private company formally penalized before this shift was a small telemarketing firm fined a modest R$14,400 in 2023. What the December 2024 sweep previewed, and what 2026 has now confirmed, is a move toward broad, sector-level enforcement rather than isolated complaints.

From Preview to Institutional Reality

Two developments in 2025 and 2026 turned that preview into a durable enforcement posture.

Daily fines for non-compliance. Deliberação CD-10/2025 introduced daily monetary penalties for companies that fail to comply with precautionary measures ordered by the agency, with the same statutory ceiling that applies to standard fines. This closes a gap that previously let companies delay compliance with little financial consequence while a proceeding was pending.

Structural independence. Law 15,352/2026 gave the ANPD administrative and financial autonomy, its own hiring track for specialized staff, and stronger authority to request documents and information from companies under investigation. An agency with a fixed budget and no dedicated enforcement staff investigates differently than one built to scale up caseload.

A recent proceeding illustrates the kind of gaps the ANPD is now scrutinizing in practice. In July 2026, the agency opened a sanctioning proceeding against a nonprofit organization that manages public health units across six Brazilian states, after a 2025 ransomware attack affected the records of roughly 500,000 patients, including tens of thousands of minors and elderly individuals. The organization had reported the incident to the ANPD, but the agency found the notification insufficient: it did not specify the date of the incident, the nature of the data and individuals affected, or the measures taken before and after the attack, all items required under LGPD article 48 and the ANPD's specific regulation on security incident communication. The agency also found no data protection officer contact information published on the organization's portal, and noted the entity had not produced technical evidence to substantiate the security measures it claimed to have implemented.

None of those three failures are unusual or specific to that case. They are exactly the gaps a routine LGPD audit is designed to catch, and they apply equally to private companies.

What the ANPD Is Actually Looking For

Across its proceedings to date, the ANPD's findings cluster around a small set of recurring failures.

Inadequate incident notification. A general announcement does not satisfy LGPD article 48. Notification to affected individuals and to the ANPD must specify the date of the incident, the nature of the data and the people involved, and what measures were taken before and after the breach. Under current ANPD regulation, initial notification is expected within three business days of discovery, with a more detailed follow-up allowed within 20 business days.

No visible data protection officer. LGPD article 41 requires companies to designate a data protection officer and make that person's contact information accessible, typically on the company's website. This is one of the most frequently cited violations because it is also one of the easiest for the ANPD to verify without opening a full investigation.

Insufficient documentation of security measures. When a company claims to have adequate technical and administrative safeguards, the ANPD expects evidence, not assertions. Proceedings have escalated specifically because companies could not substantiate what they said they had implemented.

Missing records of processing activities and impact assessments. Article 37 recordkeeping and article 38 impact assessments are treated as standalone obligations. A company can be found in violation for lacking this documentation even without an underlying incident.

For a foreign company, the practical takeaway is that Brazilian enforcement is not chasing sophisticated or novel violations. It is confirming whether the basics that most global privacy programs already assume are in place actually exist, and are documented in a form the ANPD recognizes under Brazilian law.

Why This Matters More for Foreign Companies Specifically

International groups often apply a global privacy framework and assume it covers Brazil by extension. Two gaps show up repeatedly when that assumption is tested locally.

The first is representation. LGPD requires companies without an establishment in Brazil that process data of individuals located in Brazil to appoint a local representative. A global privacy policy translated into Portuguese does not satisfy this requirement on its own.

The second is documentation formatted for Brazilian requirements specifically. A data protection officer listed in a US or European privacy notice is not the same as a data protection officer identified and reachable through the channels LGPD and ANPD regulations expect. The gap is usually not a lack of privacy governance. It is a lack of governance translated into the specific artifacts Brazilian regulators check for.

What to Do Before the ANPD Comes to You

A compliance review at this stage is considerably less expensive than responding to an active proceeding, especially with daily fines now available for non-compliance with agency orders. Four steps address most of what the ANPD has been checking in its recent enforcement activity:

  • Confirm that a data protection officer is formally designated and that their contact information is published where LGPD requires it, not buried in a global privacy policy.

  • Review whether your incident response plan meets Brazil's specific notification standard, including the three-business-day window for initial communication to the ANPD.

  • Verify that records of processing activities and any required impact assessments exist in a form that would survive a document request from the agency.

  • If your company operates without a Brazilian establishment, confirm that a local representative has been formally appointed, not just referenced informally.

If your operations touch health data, financial data, children's data, biometric data, or AI systems, treat compliance review as time-sensitive: these are the five categories the ANPD has explicitly named as fiscalization priorities for 2026-2027.

FAQ

Has the ANPD issued large fines against foreign companies?
Not yet in terms of monetary penalties. Total fines applied to date remain modest, and most sanctioned entities have been public sector bodies, which cannot be fined under LGPD article 52, paragraph 3. Private companies under investigation have generally corrected the underlying issues before a proceeding reached a monetary sanction. That track record does not reduce future exposure. LGPD authorizes fines of up to 2% of a company's revenue in Brazil, capped at R$50 million per violation, daily fines now apply to non-compliance with precautionary orders, and the agency's newly independent structure is built for a substantially higher volume of proceedings.

Does LGPD apply to a foreign company with no office in Brazil?
Yes. LGPD applies to any processing of personal data of individuals located in Brazil, regardless of where the company is headquartered, and requires companies without a Brazilian establishment to appoint a local representative.

What triggers an ANPD investigation?
Recent proceedings have originated from reported security incidents, sector-wide sweeps targeting a specific compliance gap such as missing data protection officers, and individual complaints from data subjects. With complaints rising sharply in 2025, companies do not need to be the subject of a major breach to be reviewed.

How long does a company have to respond once a sanctioning proceeding is opened?
Timelines are set case by case in the notice of infraction, but recent proceedings have given companies ten business days from notification to present a defense.

Is a privacy policy enough to demonstrate LGPD compliance?
No. The ANPD's enforcement pattern shows it expects documented evidence: records of processing activities, impact assessments, incident response protocols, and a formally designated data protection officer, not just a public-facing policy statement.

How Reis Araujo Advogados Can Help

Reis Araujo Advogados advises foreign companies and international counsel on LGPD compliance in Brazil, including data protection officer appointment, records of processing activities, incident response protocols aligned with Brazilian notification requirements, and local representative appointment for companies without a Brazilian establishment. If your company has not reviewed its Brazilian privacy program since the ANPD's enforcement posture shifted, contact our team to assess your current exposure.

© 2024 Reis Araujo Advogados
Email

contato@reisaraujo.com.br