Company Partners Our Teams Contact Blog
Services
Industries
Talk to an expert

LGPD dosimetry: how Brazil's ANPD calculates fines and sanctions

· 7 min read · Network Secure

Brazil's LGPD provides for fines of up to 2% of revenue, capped at R$ 50 million per violation, but the actual amount of a penalty is not guesswork. The ANPD calculates it under the Regulation on Dosimetry and Application of Administrative Sanctions, approved by CD/ANPD Resolution No. 4 of February 24, 2023. Understanding that calculation shows, quite precisely, what actually reduces a company's exposure.

The sanctions in Article 52 of the LGPD

Article 52 of Law No. 13,709/2018 lists the administrative sanctions the ANPD may impose on processing agents, always after an administrative proceeding with full right of defense:

  • Warning. With a deadline to adopt corrective measures.
  • Simple fine. Up to 2% of the revenue of the private legal entity, group or conglomerate in Brazil in its last fiscal year, net of taxes, capped at R$ 50 million per violation.
  • Daily fine. Used to compel compliance with an obligation, subject to the same total cap per violation.
  • Publicizing the violation. Disclosure by the offender itself, once the violation has been investigated and confirmed.
  • Blocking of personal data. Temporary suspension of processing of the data involved until the situation is remedied.
  • Deletion of personal data. Erasure of the data related to the violation.
  • Suspension and prohibition. Partial suspension of the database or of the processing activity for up to six months, renewable once for the same period, and partial or total prohibition of processing activities.

The most severe sanctions (suspensions and prohibition) may only be applied after at least one of the fine, publicizing, blocking or deletion sanctions has already been imposed in the same case. Public bodies and entities are not subject to fines, but may receive warnings, publicizing, blocking, deletion, suspensions and prohibition.

How the ANPD classifies a violation

The starting point of the dosimetry is the classification of the violation, set out in Article 8 of the regulation:

  • Minor. When none of the medium or serious scenarios apply.
  • Medium. When it may significantly affect data subjects' interests and fundamental rights, for example by preventing or limiting the exercise of rights or the use of a service, or by causing material or moral harm such as discrimination, financial fraud or identity misuse.
  • Serious. When, in addition to being medium, it involves at least one aggravating context: large-scale processing, economic advantage for the offender, risk to life, sensitive data or data of children, adolescents and the elderly, processing without a legal basis, unlawful discriminatory effects or systematic irregular practices. Obstructing an inspection is also, on its own, a serious violation.

The classification sets the path. A warning applies to minor or medium violations without specific recidivism, or when corrective measures need to be imposed. A simple fine applies when the violation is serious, when the offender has failed to comply with preventive or corrective measures, or when no other sanction is appropriate.

From base amount to final fine

The base amount of the simple fine is calculated per violation, using the methodology in Appendix I of the regulation, from three elements: the classification of the violation, the offender's revenue in the line of business where it occurred (in the last available fiscal year, net of taxes) and the degree of harm.

Aggravating and mitigating factors are then applied to the base amount, added up as percentages (Articles 12 and 13):

Aggravating factors

  • Specific recidivism. 10% per case, up to 40%.
  • Generic recidivism. 5% per case, up to 20%.
  • Guidance or preventive measure not complied with. 20% per measure, up to 80%.
  • Corrective measure not complied with. 30% per measure, up to 90%.

Mitigating factors

  • Ending the violation. 75% if it happens before the ANPD opens a preliminary procedure; 50% if after that and before the sanctioning proceeding; 30% if during the proceeding and before the first-instance decision.
  • Governance. 20% for implementing a good practices and governance policy, or for the repeated and demonstrated adoption of internal mechanisms capable of minimizing harm to data subjects, up to the first-instance decision.
  • Mitigating the effects. 20% for measures that reverse or mitigate the effects on data subjects before any ANPD procedure; 10% if after the preliminary procedure and before the sanctioning proceeding.
  • Cooperation or good faith. 5%.

The result cannot fall below the minimums in Appendix II, except when the economic advantage obtained can be estimated (in which case twice that amount applies), and it remains capped at 2% of revenue or R$ 50 million. An offender that expressly waives its right to appeal and pays on time gets a 25% reduction.

The detail that matters most. Ending the violation and mitigating its effects only count as mitigating factors when they do not result from merely complying with an administrative or court order, and the burden of proving each requirement lies with the offender. Acting early and documenting it is worth more than reacting once the inspection arrives.

What the first cases showed

The first sanction against a private company, published in Brazil's Official Gazette on July 6, 2023, targeted a micro-enterprise that sold lists of WhatsApp contacts for sending election advertising. It received a warning for not having appointed a data protection officer and two simple fines, one for processing data without a legal basis and another for failing to respond to the inspection's requests, totaling R$ 14,400. The amount is small in reais, but each violation generated its own fine.

In another case, a state public servants' healthcare institute received a warning for security failures, such as the lack of adequate controls and access logging, and for not reporting an incident to the ANPD and to data subjects. As a public body it could not be fined, but it was ordered to take corrective action. In both cases, size kept no one off the radar.

Incident reporting: three business days

CD/ANPD Resolution No. 15 of April 24, 2024 approved the Security Incident Reporting Regulation. When an incident may result in relevant risk or harm to data subjects, the controller must report it to the ANPD and to the data subjects within three business days of learning that the incident affected personal data (the deadline is doubled for small processing agents). The risk is considered relevant when the incident may significantly affect data subjects' rights and involves, for example, sensitive, financial or authentication data, data of children, adolescents or the elderly, or data at large scale.

Every incident, reported or not, must be recorded, and the record kept for at least five years.

What reduces exposure in practice

  1. Data mapping. An inventory of processing activities with a defined legal basis for each one. Processing without a legal basis is one of the triggers for a serious violation.
  2. Data protection officer and service channel. A formally appointed DPO able to respond to data subjects and to the ANPD within the deadlines.
  3. A documented governance program. Policies, records and evidence that it works, which support the 20% mitigating factor and lower the chance of the violation being classified as systematic.
  4. Technical controls and risk management. Gap analysis against ISO/IEC 27001, vulnerability management and logging of access to systems holding personal data.
  5. Incident response plan. Criteria to assess relevant risk, a reporting template and a decision flow that fit within three business days.

Frequently asked questions

What is the maximum LGPD fine?

The simple fine is up to 2% of the revenue of the company, group or conglomerate in Brazil in its last fiscal year, net of taxes, capped at R$ 50 million per violation. Because the cap applies per violation, a single proceeding can result in more than one fine.

Does a privacy governance program reduce the fine?

Yes. Implementing a good practices and governance policy, or demonstrated internal mechanisms to minimize harm, is a 20% mitigating factor if proven up to the first-instance decision.

What is the deadline to report an incident to the ANPD?

Three business days from learning that the incident affected personal data, when it may result in relevant risk or harm to data subjects, unless specific legislation sets a different deadline. Small processing agents get twice the time.

Sources consulted: Law No. 13,709/2018 (LGPD), Articles 52 and 53, on the Brazilian Presidency's legislation portal; CD/ANPD Resolution No. 4 of February 24, 2023 (Regulation on Dosimetry and Application of Administrative Sanctions) and CD/ANPD Resolution No. 15 of April 24, 2024 (Security Incident Reporting Regulation), both in Brazil's Official Gazette; ANPD guidance on incident reporting at gov.br/anpd. This article is educational and does not constitute legal advice; for specific cases, consult the official texts and a specialized lawyer.

Official references

Read next