Saying that your company is "compliant with LGPD" has become as cheap as saying that it is "customer focused". The declaration costs nothing, is rarely verified and almost never corresponds to operational reality. The difference between having a Privacy Policy document in the footer of the website and actually processing personal data with adequate controls is enormous — and this difference begins to take a toll. The National Data Protection Authority has left the learning period and is building the inspection record that will define the enforcement standard in Brazil for the coming years. Understanding where we are in 2026 is, first of all, understanding the distance between what was said and what was done.
What the ANPD has actually done so far
The ANPD began its sanctioning activities gradually, which generated a mistaken perception in the first years that the body would not have the strength to impose fines. This diagnosis was wrong, just early. Throughout 2024 and 2025, the Authority consolidated administrative sanctioning processes in sectors such as health, finance and digital retail, with fines that reached the level of R$50 million in more serious cases — the ceiling provided by law per infraction is 2% of revenue in Brazil, limited to R$50 million per infraction.
More relevant than the nominal value of the fines is the pattern of prioritized violations. The ANPD has not pursued specific oversights. The most serious cases involve the absence of a legal basis for processing, sharing of data without informed consent, and — especially — security incidents that were not reported within the 72 hours required by the incident regulation published in 2023. This last point deserves attention: the notification obligation exists, the deadline is known, and yet companies continue to report incidents weeks late or only when pressured by affected users.
Most exposed sectors and why
Health and finance lead the risk map, not by chance. These are the sectors that process sensitive data in volume, have broad user bases and have historically built data infrastructures with a focus on business, not governance. The combination of health data — a category especially protected by the LGPD — with legacy systems without adequate access controls created a risk profile that the ANPD identified early.
In digital retail, the problem is different. It's not so much the sensitivity of the data as the scale of processing and the chain of sharing with third parties — media platforms, CRM providers, analytics tools, affiliate networks. Each integration is a vector of risk, and most companies do not have up-to-date mapping of who receives what data. The Personal Data Protection Impact Report — the RIPD — that the law requires for high-risk treatments continues to be the most ignored document in Brazilian privacy compliance.
Startups and fintechs grew quickly and outsourced compliance to law firms that delivered documentation without transforming internal processes. The result is top-shelf compliance: well-written policies, named DPO on paper, and internal practices that haven't changed.
The gap between "we have the policy" and "we treat data appropriately"
Real compliance doesn’t start in the legal department. It starts with data inventory — knowing what the company collects, where it stores it, how long it retains it, who accesses it and who it shares it with. Most Brazilian companies have never carried out this mapping comprehensively. They did what was visible: updating the privacy notice, adding a cookie banner, appointing a DPO.
What was left behind is the technical work: implementing role-based access controls for databases with personal information, creating automatic deletion routines at the end of the retention period, ensuring that personal data access logs are maintained and monitored, building response flows to holder requests that work within the legal deadline of 15 days. These are engineering and operations processes, not communications — and they require technology teams to understand the law as well as legal.
Proof that the gap is real appears in the incidents reported to the ANPD: the majority involve systems that should have basic security controls but did not, because the company never treated personal data as an asset that requires specific management.
What's coming: automated decisions and international transfers
Two themes dominate the ANPD's regulatory agenda for 2026 and 2027. The first is the regulation of automated decisions — article 20 of the LGPD guarantees the holder the right to human review of decisions made exclusively by algorithms that affect their interests. The ANPD is developing specific standards on the topic, with a direct impact on credit granting, insurance pricing, selection of candidates in selection processes and content moderation on platforms. Companies operating in these models need to prepare documentation of the criteria used — not as a rhetorical exercise, but as an auditable process.
The second theme is suitability for international data transfers. Brazil does not yet have an adequacy decision recognized by the European Union, which limits the free movement of data between the two blocks. The ANPD is working on standard contractual clauses that will allow transfers to countries without a level of protection equivalent to Brazil's, and organizations that operate with subsidiaries or suppliers abroad will need to review their contracts as soon as the regulation is published. Postponing this analysis until after publication is guaranteeing unnecessary rush.
How to prepare what has not yet been done
Priority one: complete the data inventory if it does not exist or is out of date. It is not possible to manage what is not mapped, and the ANPD has required this document as the first step in any investigation. Priority two: review the chain of sub-operators and ensure that contracts with third parties that receive personal data include the clauses required by law. Priority three: test the processes for responding to holders — many companies have the contact channel, but have never simulated a portability or deletion request to check whether they can meet the deadline.
The distinction that will separate those who are well positioned from those who will suffer fines is not the presence of documents. It is the existence of processes that work in a repeatable and auditable way, with identified responsible parties and records that demonstrate compliance. This level of maturity takes time to build — which means the advantage of those who started early is real and growing.
Also read
- LGPD two years later: what has really changed in Brazilian companies
- Data dignity: the next step after privacy
- LGPD in Applications: Compliance Guide
- LGPD in Startups: Compliance and Data Protection Strategies
- Digital Compliance: Compliance Guide for Digital Products
- Digital Compliance: Comparative in Practice
