07/05/2025
In the world of data protection, the updates never stop! Recently, the National Data Protection Authority (ANPD) concluded a supervisory process that affected 20 companies across various sectors. Below, we share the main aspects of the ANPD’s actions and how compliance with the Brazilian General Data Protection Law (LGPD) can be demonstrated.
What happened?
In December 2024, the ANPD began an inspection process focused on companies that had failed to appoint a Data Protection Officer (DPO) and/or provide effective communication channels for data subjects. The aim of this investigation was to ensure that these companies comply with the obligations laid down in the LGPD.
Which companies were inspected?
The process included personal data controllers from private entities. These controllers were selected by the ANPD based on the following indications: a) failure to appoint a DPO; b) absence/deficiency of a contact channel with the data subject; and c) demands forwarded to the National Data Protection Authority (ANPD) and not duly answered. The ANPD also considered other criteria for selecting the controllers to be inspected, such as size, volume of data processed and geographical scope, prioritizing large entities with national operations, in order to maximize the results of the inspections.
Why is this important?
The LGPD establishes that every company that processes personal data must appoint a DPO and provide clear and efficient communication channels so that data subjects can exercise their rights. The absence of these elements hinders transparency and control over personal data, harming both data subjects and the ANPD itself.
The outcome?
All 20 companies that were inspected ended up implementing the necessary measures to comply with the LGPD. The ANPD has published the results of this action, reinforcing the importance of companies paying attention to their obligations.
What’s next?
According to the ANPD, these companies will be monitored for six months to ensure that they remain in compliance with the LGPD. If new irregularities or a high number of complaints are identified, the ANPD may reopen the cases and initiate administrative sanctioning proceedings, which could certainly have more critical consequences for repeat offenders.
What do you need to know?
The ANPD’s enforcement action serves as a warning to all companies to adapt their practices to the LGPD guidelines. It is essential that your company:
- Appoint a Data Protection Officer (DPO): This person will be responsible for overseeing data protection and acting as a point of contact between the company, data subjects and the ANPD.
- Create efficient communication channels: Ensure that data subjects can exercise their rights easily and quickly, such as access, correction, deletion and data portability.
- Keep up to date: The LGPD and ANPD regulations are constantly evolving. Keep up with what is new and adapt your practices to ensure ongoing compliance.
Our Privacy and Data Protection team is on hand to help with all stages of LGPD compliance.
Coauthored by:Esther Jerussalmy Cunha and Denise de Araujo Berzin Reupke