WorldPrivacyAtlas
Laws by country

Data Security & Breach Notification

Lei Geral de Protecao de Dados Pessoais — communication of security incidents

LGPD Art. 48

Brazil · September 18, 2020 (Art. 48); Resolution CD/ANPD No. 15 published April 26, 2024

Art. 48 required communicating security incidents that may create relevant risk or damage to data subjects, but left 'reasonable time' undefined until ANPD's Resolution No. 15/2024 fixed it: three business days from becoming aware, to both the ANPD and the affected data subjects. That is one of the shortest windows in this dataset — shorter in practice than GDPR's 72 hours, because business days exclude weekends only on the running side while the assessment burden is the same, and because Brazil requires notifying individuals on the same clock as the regulator rather than on a separate high-risk trigger. Failure to notify is itself a standalone infraction, sanctionable without proof of damage. The Resolution also supplies the definitions and content requirements Art. 48 lacked.

Lei no 13.709/2018, Art. 48; Resolution CD/ANPD No. 15 of April 24, 2024Read regulation →

This is a general reference, not legal advice or a determination that this law applies to your specific business. Run the full questionnaire to check against your actual presence, activities, and data types.