LGPD
Privacidade
Compliance
Brasil
Dados

LGPD two years later: what has really changed in Brazilian companies

Two years of active enforcement of the LGPD reveal that the majority of companies complied in appearance, not in structure.

LGPD two years later: what has really changed in Brazilian companies

The most comfortable assumption that circulated in the Brazilian market after LGPD took root was that companies, faced with the concrete threat of a fine, would do what needed to be done. Two years of active enforcement show that this assumption was wrong — not because companies are negligent, but because the compliance that most implemented was designed to appear sufficient, not to actually work.

What companies actually did

The most visible movement was superficial by definition. Cookie banners proliferated. Privacy policies were rewritten in language that few read and even fewer understood. Forms gained consent checkboxes. The DPO — a position required by law — was appointed, in many cases, as an additional role for an already overworked lawyer or an IT analyst who did not have specific training.

What didn't happen, on the same scale, was the invisible work that underpins any real privacy program: data mapping. Knowing what personal data the company collects, where it is stored, how long it is retained, who has access and with which third parties it is shared is the basis of everything. Without this inventory, any response to a principal request is an exercise in improvisation. Without it, responding to a security incident turns into chaos. The majority of medium-sized Brazilian companies reached 2026 without having completed this mapping.

What the ANPD revealed with its actions

The National Data Protection Authority did not arrive with the immediate rigor that some expected, which, paradoxically, fueled the minimum effort stance. The first sanctions were applied with pedagogical criteria — amounts below the legal ceiling, communications that prioritized guidance before punishment. This was interpreted by many companies as a sign that the window of impunity was long.

The ANPD's actions, however, revealed clear patterns of priority. Security incidents with a significant volume of personal data leaked received immediate attention. Companies in the financial and healthcare sectors — which deal with sensitive categories — were scrutinized more rigorously. The absence of a functional channel for requests from holders became a frequent trigger for investigation. What the authority did not pursue, at least not systematically, was the quality of consent or the completeness of treatment records — precisely what more companies neglected.

This selective focus created a perverse incentive: all it took was having a service channel that responded within the deadline and a cookie banner, and the immediate risk of sanctions dropped. Real compliance, which requires end-to-end data governance, became seen as overzealous.

What separates real compliance from cosmetic compliance

The companies that did the real work built three things that others don't have. First, an up-to-date record of processing operations—not a static document handed over for audit, but a living inventory that tracks changes to systems and data flows. Second, an operational process to respond to data subjects: when someone requests access, correction or deletion of their own data, there is a defined flow with SLA and person responsible, not a forgotten email box. Third, third-party management — contracts with suppliers that process personal data have been reviewed, DPA clauses have been included, and there is at least some level of periodic verification that these suppliers maintain adequate controls.

None of these three things appear on the company's website. None are visible to the end user. For this reason, they are the most honest criterion to distinguish those who have complied from those who have engaged in regulatory theater.

The weight that incidents will take

Brazil had significant leaks during this period. The 2021 mega-leak, with more than 220 million records, still had causes that were never fully publicly clarified. Other smaller incidents — at healthcare companies, on e-commerce platforms, on payroll systems — have shown that the attack vectors are not sophisticated: exposed credentials, databases without authentication, APIs without access control.

The cosmetic compliance bill will appear when the ANPD begins to investigate companies' response to these incidents, not just the incident itself. The law requires communication to the authority and affected holders within a reasonable time. It requires the company to know precisely what data has been compromised and who owns it. Without the data inventory that the majority did not carry out, this response is impossible to provide with quality — and the lack of quality in the response tends to aggravate, not mitigate, the regulatory situation.

What to do now, with what exists

For companies that recognize they are in the field of cosmetic compliance, the starting point isn't to redo everything — it's to prioritize honestly. Data mapping can start with the most critical systems and the highest risk treatments, not the entire company at once. The DPO needs real authority, access to leadership and minimum resources to function — if the person appointed does not have these conditions, the appointment is just bureaucratic.

Reviewing contracts with technology providers deserves particular attention because this is where the risk is often concentrated: cloud data processing, CRM systems, analytics platforms, marketing automation tools. Each of these providers is an operator within the meaning of the LGPD, and responsibility for what they do with the data lies with the controller.

What the market will demand in the coming years — from partners, suppliers, platforms — is evidence that compliance has substance. The pressure will come less from the ANPD and more from the supply chains themselves, as companies with international operations begin to demand concrete demonstrations of compliance. Whoever did the actual work will have this evidence. Those who only did the theater will need to do it for real, later and in more haste.

Also read