The Autoridade Nacional de Proteção de Dados (ANPD) is Brazil’s national data protection authority. Created by the LGPD (Lei Geral de Proteção de Dados) in 2018 and operational since 2021, the ANPD became a fully independent regulatory agency in February 2026 with the enactment of Law 15.352. Enforcement has escalated sharply through 2024 and 2025, with the ANPD moving from an educational stance to active sanctioning. The EU granted Brazil adequacy status in January 2026, cementing the LGPD as one of the reference privacy frameworks in Latin America.
Autoridade Nacional de Proteção de Dados (ANPD) · Created by LGPD Law 13.709/2018; operational since 2021; full regulatory agency status since February 2026 under Law 15.352 · Chair Waldemar Gonçalves Ortunho Jr since November 2022 (5-year term) · Directive Board (Conselho Diretor) of 5 members · Based in Brasília; linked to the Ministry of Justice since January 2023, now fully autonomous · Enforces LGPD, coordinates with the Consumer Defense Code (CDC) framework and sector regulators (BACEN, ANATEL, CVM) · Max fine: 2% of Brazilian annual revenue per infraction, capped at BRL 50 million per infraction.
Role and powers
The ANPD combines three functional vectors under the LGPD. Its Directive Board of five members holds decision-making power over investigations, sanctions, and general orders. The full regulatory agency status granted in February 2026 removed the previous procedural constraints tied to the Presidency of the Republic and gave the ANPD explicit financial and technical autonomy.
- Enforcement. Investigations, corrective orders, and administrative penalties up to 2% of Brazilian revenue per infraction, capped at BRL 50 million. The Resolution CD/ANPD nº 4/2023 sets the graduated penalty methodology, applied consistently since 2024.
- Regulation. The ANPD publishes binding resolutions, guides, and technical notes on LGPD interpretation. Its 2025-2026 Regulatory Agenda covers data subject rights, DPIAs, biometric data, and high-risk processing.
- Individual complaints. Through the ANPD’s public complaint channel, data subjects can file petitions that feed into monitoring cycles. Public bodies and sector regulators (BACEN for finance, ANATEL for telecom) coordinate parallel enforcement.
- Adequacy and transfers. The ANPD approves standard contractual clauses, binding corporate rules, and adequacy decisions with third countries. The EU-Brazil adequacy decision (January 2026) is the reference case for outbound transfers from Europe.
Recent enforcement highlights
Other recent notable actions include the TikTok/ByteDance investigations opened in December 2024, sanctions against the Santa Catarina State Health Secretariat (2025) for leaking sensitive patient data, and sector-wide sweeps targeting biometric-data processors and health-data controllers. The ANPD’s public case tracker currently references active reviews against 21+ organisations across public and private sectors.
2026 enforcement priorities
Priority Topics Map 2026-2027 published. Four fronts drive proactive enforcement: (1) biometric data, following the Worldcoin precedent; (2) health data, sensitive category with heightened LGPD protection; (3) financial data, in coordination with BACEN sector regulation; (4) data of children and adolescents, aligned with the Digital ECA (Estatuto da Criança e do Adolescente) and age-verification requirements. The ANPD’s stated strategy for 2026 is transition from educational enforcement toward active sanctioning across all sectors, with sector-wide sweeps supplementing individual complaints. Generative AI is under active study; a formal Report on Generative AI was published in 2025 and enforcement follow-up is expected.
How to file a complaint
- Submit a petição (petition) via the ANPD’s online channel at gov.br/anpd. Complaints in Portuguese; supporting documents accepted in English or Spanish.
- Prior contact with the data controller is not required, but the ANPD encourages first raising the issue with the controller’s Data Protection Officer (DPO / Encarregado).
- Complaints against controllers established outside Brazil but processing Brazilian residents’ data are accepted directly. The LGPD applies extraterritorially under Article 3, similar to GDPR Article 3(2).
- For consumer-facing marketing violations, parallel action through the Department of Consumer Protection and Defense (SENACON) and state-level Procon offices remains available. The Public Prosecutor’s Office (Ministério Público) also has standing.
- Decisions are published at gov.br/anpd (in Portuguese; English summaries provided for major cross-border cases). Compliance Week and international law firm alerts translate significant decisions.
Common misconceptions
“LGPD is just GDPR translated.” Substantially similar principles but with meaningful differences: 10 legal bases (vs 6 in GDPR), broader definition of sensitive data including trade-union membership and philosophical views, mandatory Encarregado (DPO) for most controllers regardless of size, and interplay with the Consumer Defense Code that has no direct GDPR equivalent.
“Fines are still theoretical.” No. The ANPD issued its first sanction in July 2023 and has issued multiple sanctions in 2024-2025 including significant daily fines against Meta and Worldcoin. Resolution CD/ANPD nº 4/2023 codifies the graduated penalty methodology. Enforcement volume is escalating quarter over quarter.
“Foreign senders do not need to comply.” No. LGPD Article 3 applies extraterritorially to any organisation offering goods or services to Brazilian residents or processing personal data collected in Brazil. Server location is irrelevant. The EU adequacy decision (January 2026) is bidirectional and imposes obligations on EU controllers as well.
“Consent is the only legal basis for marketing.” Not necessarily. LGPD Article 7 lists 10 legal bases with no hierarchy. Legitimate interest (Article 7, IX) is available for direct marketing to existing customers, subject to a documented balancing test and clear opt-out. Sensitive data always requires consent.
Frequently asked questions
What did Law 15.352 change in February 2026?
Law 15.352 (converted from Provisional Measure 1.317/2025) transformed the ANPD from an entity associated with the Ministry of Justice into a fully independent regulatory agency with functional, technical, decisional, administrative, and financial autonomy. In practical terms: the ANPD’s budget is now fixed by law rather than executive discretion, its regulations no longer require external ratification, and its enforcement decisions cannot be reversed on political grounds.
How does the EU adequacy decision affect senders?
The European Commission’s adequacy decision (January 2026) allows personal data to flow freely from the EU to Brazil without additional safeguards, and enables Brazilian controllers to receive EU personal data under LGPD without SCCs or transfer impact assessments. In practice this significantly simplifies cross-border marketing operations between the EU and Brazil for both EU exporters and Brazilian importers.
Does LGPD require an Encarregado (DPO) for foreign senders?
Yes when personal data is processed in Brazil or on Brazilian residents. The Encarregado must be identified in the controller’s privacy notice, act as the point of contact for the ANPD and data subjects, and have direct access to top management. Small businesses can rely on a shared or outsourced Encarregado, but the role cannot be omitted.
What is Resolution CD/ANPD nº 4/2023?
The graduated-penalty methodology applied to all administrative fines under the LGPD. It classifies violations by severity (light, medium, high) and factors in the number of affected data subjects, controller compliance history, mitigation efforts, and cooperation with the investigation. The methodology has been applied consistently since 2024 and produces predictable fine calculations.
Where can I find current ANPD decisions in English?
The ANPD publishes some English summaries at gov.br/anpd/en. Full decisions remain in Portuguese. Third-party sources including Baker McKenzie’s Global Data and Cyber Handbook, ICLG’s annual Data Protection Laws report, and Compliance Week track significant decisions with English translations.
Where to go next
- GDPR compliance guide — the EU framework, now adequacy-linked with Brazil since January 2026
- Email unsubscribe laws worldwide — global overview including Brazilian LGPD obligations
- PDPC (Singapore) — comparable Asia-Pacific privacy authority with active enforcement
- PPC (Japan) — APPI enforcer and reference for East Asia data protection
Sending marketing email into Brazil? Pre-validating recipient addresses with SMTPing before you press send catches disposables, catch-alls, and dead mailboxes that generate ANPD complaints. Thirteen validation types, twenty-five free checks daily, no card required. Try SMTPing free.
About the Author

Alaa · LinkedIn
Email infrastructure specialist with 8+ years of hands-on experience in SMTP, deliverability, and email verification. I’ve configured and troubleshot mail systems across Postfix, Exchange, and cloud relays, managed IP reputation and warmup campaigns, and built verification pipelines processing millions of addresses. My work spans DNS authentication (SPF, DKIM, DMARC, BIMI), bounce handling, blocklist monitoring, and compliance frameworks including CAN-SPAM and GDPR. I write every article on SMTPedia to give email professionals, developers, and marketers the accurate, RFC-grounded reference they need.
About SMTPedia
SMTPedia is an independent email industry reference covering SMTP, IMAP, POP3, email deliverability, marketing platforms, DNS authentication, and email verification. Every article is researched from official provider documentation, IETF RFCs, and industry best practices. Settings and configurations are verified quarterly.
We are cited as a source by ChatGPT, Microsoft Copilot, and thousands of email professionals worldwide. Learn more about our editorial process.

