When a security incident involves personal data, the first 72 hours determine both the extent of the damage and the company’s legal standing before the ANPD (Autoridade Nacional de Proteção de Dados — Brazil’s National Data Protection Authority).
How the company responds in those first hours — documenting correctly and notifying within the deadline — is what allows it to demonstrate good faith in any administrative proceeding that may follow. Resolution CD/ANPD No. 4/2023 treats the adoption of good response practices as a mitigating factor when the authority calculates sanctions.
This article details what to do in the first 72 hours after confirming a personal data incident.
TL;DR
- An incident triggering a notification duty is one that may cause relevant risk or harm to data subjects — Resolution CD/ANPD No. 4/2023 sets out the criteria.
- The 72-hour clock starts running from the moment the controller becomes aware of the incident — not from the date it actually occurred.
- Notification to the ANPD is submitted through the electronic form on the authority’s website; it can be preliminary (with the information available at the time) and supplemented later.
- Notifying data subjects is mandatory when there is relevant risk or harm to them — the format and timing follow what is “reasonable” under the ANPD’s guidance.
- Document everything from the first moment: who knew, when they knew, what was done, and by whom. This documentation is the main form of evidence in any administrative proceeding.
- What not to do: wait to see if the problem “goes away,” alter or delete logs, or issue public statements that haven’t been coordinated with legal counsel and the DPO.
Table of Contents
- The incident that started on a Friday night
- What qualifies as an incident with a notification duty
- Containment: the first technical and legal actions
- The duty to notify the ANPD: deadline, format, and content
- Notifying data subjects: when it’s mandatory and how to do it
- What to document (and why it matters later)
- Frequently asked questions
1. The incident that started on a Friday night
A fintech startup with roughly 40,000 active users received a message from a security researcher on a Friday afternoon: an S3 bucket had been configured as public. The exposed data included bank statements, CPFs (Brazilian individual taxpayer IDs), and transaction history for approximately 12,000 customers — and the bucket had been accessible for at least 11 days.
The engineering team fixed the configuration in under an hour. But the question that followed had no technical answer: now what?
Who knew, and when? Is there an obligation to notify the ANPD? Within what timeframe? What should customers be told? What needs to be documented to avoid making things worse if an administrative proceeding follows?
These questions demand fast answers — and getting the wrong answers in those first hours has a direct impact on the company’s legal exposure.
2. What qualifies as an incident with a notification duty
Law 13,709/2018 (the LGPD — Brazil’s General Data Protection Law), in Article 48, establishes the controller’s duty to notify the ANPD and data subjects when a security incident occurs that may create relevant risk or harm to data subjects.
Resolution CD/ANPD No. 4/2023 regulated the criteria and procedure for this notification. It defines a security incident as:
any confirmed adverse event related to a breach in the security of personal data, such as unauthorized, accidental, or unlawful access resulting in destruction, loss, alteration, leakage, or any other form of inadequate or unlawful processing of data, that may pose a risk to the rights and freedoms of the data subject.
Not every security problem triggers a duty to notify. The obligation arises when the incident may cause relevant risk or harm to data subjects. Resolution CD/ANPD No. 4/2023 lists factors to weigh in that assessment:
| Factor | Examples |
|---|---|
| Nature of the data | Sensitive data (health, financial, biometric) carries greater weight |
| Number of data subjects affected | The larger the number, the greater the risk |
| Ease of identification | Data that allows the person to be directly identified |
| Potential harm | Discrimination, financial fraud, exposure of a vulnerability |
| Profile of data subjects | Children, adolescents, the elderly — groups with enhanced protection |
If the internal assessment indicates the incident may cause relevant risk or harm, notification is mandatory. Doubt — especially in incidents of significant scale involving financial data — should be resolved in favor of notifying.
Controller vs. processor: if your company is a processor (operador — processing data on behalf of another company), the duty to notify the ANPD lies with the controller. The processor must report the incident to the controller immediately so the controller can assess it and take the appropriate steps. Check the DPA (Data Processing Agreement, or Acordo de Tratamento de Dados) with the controller — it usually sets a deadline for this internal communication.
3. Containment: the first technical and legal actions
Containment is the set of immediate actions taken to stop unauthorized access, preserve evidence, and prevent the incident from expanding.
Immediate technical actions:
- Isolate the affected system or data — without deleting logs. Altering or erasing access records after the incident is discovered can be interpreted as concealment and worsens the company’s position.
- Identify the access vector — how did the incident happen? Compromised credentials, misconfiguration, exploited vulnerability?
- Revoke compromised access — tokens, API keys, credentials that may have been exposed.
- Preserve evidence — access logs, timestamps, screenshots of the affected environment before any changes are made.
Immediate legal and organizational actions:
- Notify the DPO (Data Protection Officer, Encarregado de Proteção de Dados) — Article 41 of the LGPD requires the controller to appoint a DPO. In startups without a formally designated DPO, notify whoever is internally responsible for privacy or the legal advisory team.
- Document the moment of awareness — who knew, how, and when. This is critical: the 72-hour clock starts running from the controller’s awareness, not from the date the incident occurred.
- Carry out an initial risk triage — how many data subjects were affected? What data? What is the potential risk to each data subject?
- Do not communicate externally without coordination — spontaneous statements on social media or to the press, made without legal alignment, can heighten exposure and conflict with the formal notification to the ANPD.
4. The duty to notify the ANPD: deadline, format, and content
Deadline:
Resolution CD/ANPD No. 4/2023 sets a deadline of 3 business days (not calendar days) from the moment the controller becomes aware of the incident to notify the ANPD — provided the internal assessment indicates the incident may cause relevant risk or harm.
The commonly cited “72-hour” deadline is a colloquial reference to this 3-business-day period — and the distinction matters: an incident discovered on a Friday afternoon may have its deadline extending to the following Wednesday, depending on how the count is done. The conservative approach is to treat it as 72 calendar hours for planning purposes.
Preliminary vs. supplementary notification:
Resolution CD/ANPD No. 4/2023 allows notification in two stages:
- Preliminary notification: submitted within the 3-business-day deadline, with the information available at that time. It may be incomplete — what matters is meeting the deadline.
- Supplementary notification: adds to the preliminary notification any information that was not available initially. It should be submitted as soon as the additional information is gathered.
How to notify:
Notification is submitted through the electronic form available on the ANPD’s website (anpd.gov.br). The system accepts the preliminary notification and allows for later supplementation.
Minimum content of the notification:
- Description of the incident (what happened, how, when it was discovered)
- Personal data affected (categories, estimated number of data subjects)
- Technical and organizational measures adopted to contain the incident
- Potential risks to data subjects
- Measures adopted or planned to mitigate the risks
- Identification of the DPO or contact information for the controller
Consequences of failing to notify:
The LGPD (Article 52) provides for administrative sanctions including a warning, a fine of up to 2% of the corporate group’s revenue in Brazil in the last fiscal year (capped at R$50 million per infraction), and blocking or deletion of the personal data involved. Failure to notify a relevant incident is itself a standalone infraction subject to sanction — regardless of any proven damage.
5. Notifying data subjects: when it’s mandatory and how to do it
Notifying affected data subjects is mandatory when the incident may cause them relevant risk or harm (LGPD, Article 48, §1). Resolution CD/ANPD No. 4/2023 states that this notification must be made within a reasonable timeframe and in a manner that is clear and appropriate for the data subject.
When to notify:
- The potential risk or harm justifies notification — financial data, identity documents, and health data carry greater weight.
- Notification can help the data subject take protective measures (canceling a card, monitoring transactions, changing a password).
- The ANPD may order notification even if the controller assesses that it is not necessary.
When notification may be mitigated:
- The exposed data was robustly encrypted and cannot be deciphered by whoever accessed it.
- The data was no longer under unauthorized access at the time of notification (though this does not eliminate the duty to notify the ANPD).
How to notify data subjects:
The notification to data subjects should:
- Be direct and clear — without euphemisms that obscure what happened.
- Describe the data affected and the associated risk.
- Inform data subjects of the measures the company has already taken to contain the incident.
- Guide the data subject on what they can do to protect themselves.
- Provide a contact channel for questions.
The notification does not need to — and generally should not — include information that could compromise ongoing investigations or reveal technical details that would facilitate further attacks.
Record-keeping: keep a record of every notification sent, the date it was sent, and the channel used. This is evidence of compliance with the obligation in any subsequent administrative proceeding.
6. What to document (and why it matters later)
Documentation of the incident is the company’s main line of defense in an ANPD administrative proceeding or in a lawsuit brought by affected data subjects.
What to document from the first moment:
| What | How |
|---|---|
| Moment of awareness | A timestamped record (email, ticket, system log) of when someone at the company first learned of the incident |
| Initial triage | A written assessment by whoever performed the triage, based on the criteria in Resolution CD/ANPD No. 4/2023 |
| Containment actions | A record of each technical action: what was done, by whom, and when |
| Preserved evidence | An inventory of the logs and records preserved |
| Internal communications | Emails, Slack/Teams messages among those involved in managing the incident |
| Decisions made and justifications | A record of each relevant decision (whether to notify, whether to communicate, and why) |
| Notifications sent | Copies of the notifications to the ANPD and the communications to data subjects, with dates |
| Forensic investigation | A technical report on the attack vector, extent of access, and data affected |
Why documentation matters:
In a sanctioning proceeding, the ANPD assesses not just the incident itself, but the company’s response to it. Resolution CD/ANPD No. 4/2023 treats the adoption of good governance practices, cooperation with the ANPD, and the immediate adoption of mitigation measures as mitigating factors. Consistent documentation is the evidence of that response.
Companies that fail to document properly cannot demonstrate what they did — even if they acted correctly.
Retention: keep incident documentation for a period consistent with the statute of limitations for related claims. A claim for moral damages, for example, has a 3-year statute of limitations (Civil Code, Article 206, §3, V).
7. Frequently asked questions
Does the 72-hour clock start when the incident occurred or when we discovered it?
The clock starts when the controller becomes aware of the incident — not when it occurred. Resolution CD/ANPD No. 4/2023 is clear on this point: the 3-business-day period counts from the moment the company (the controller) becomes aware that an incident occurred that may cause relevant risk or harm to data subjects. This means that an incident that went on for 11 days before being discovered does not have its clock counted from day one of the exposure — but from the day someone at the company found out. Hence the importance of precisely documenting the exact moment awareness reached the company. Internally, it’s also necessary to define what counts as the “controller’s awareness”: the security team’s ticket? The email to the DPO? The automated monitoring system alert? This definition should be part of the company’s incident response plan, put in place before any incident occurs.
This is general information and does not replace consulting a lawyer to analyze your specific case.
We’re a processor, not a controller. Are we required to notify the ANPD?
The duty to notify the ANPD lies with the controller — the company that defines the purpose and means of processing the data. The processor (which processes data on behalf of the controller) does not notify the ANPD directly, but is obligated to report the incident to the controller immediately, so the controller can meet its own notification deadline. The timeframe and format of this internal communication (processor → controller) should be set out in the data processing agreement or DPA between the parties. In the absence of a contractual deadline, the communication should be made as soon as possible — any delay that undermines the controller’s ability to meet its deadline may create contractual liability for the processor. SaaS companies, payment processors, and cloud service providers that process data on behalf of their clients (the controllers) are generally in the position of processors and need clear incident-communication workflows with each controller they serve.
This is general information and does not replace consulting a lawyer to analyze your specific case.
What’s the risk of not notifying the ANPD about a relevant incident?
Failure to notify a relevant incident is a standalone infraction under the LGPD (Law 13,709/2018), regardless of any harm to data subjects. The sanctions set out in Article 52 of the LGPD include a warning (with a deadline to adopt corrective measures), a fine of up to 2% of the corporate group’s revenue in Brazil in the last fiscal year — capped at R$50 million per infraction —, blocking or deletion of the personal data involved in the infraction, and public disclosure of the infraction after it has been investigated and confirmed. Beyond the ANPD’s administrative sanctions, the company may face civil liability toward affected data subjects for moral or material damages arising from the incident. A court may treat the absence of notification as evidence of bad faith in the company’s response to the incident. The risk of failing to notify, therefore, is greater than the risk of notifying with preliminary information and supplementing it later — which is exactly what Resolution CD/ANPD No. 4/2023 allows.
This is general information and does not replace consulting a lawyer to analyze your specific case.
Disclaimer and next steps
The information in this article is general and educational in nature. It does not constitute legal advice for any specific situation and does not replace a lawyer’s analysis of your particular case. The ANPD’s regulations are still evolving — always check the current status and any updates to Resolution CD/ANPD No. 4/2023 and the authority’s guidance as of the date of application.
If your company has experienced a data incident and needs to assess its notification obligations, or if you want to put an incident response plan in place before an event happens, the starting point is a conversation with a lawyer and the responsible DPO.
Alessandra De Paula Souza — OAB/PR 31.133 Practice focused on LGPD, data protection, and legal advisory services for startups and SMEs.