LGPD, security incident notification
Lei nº 13.709, de 2018 (LGPD), art. 48 (security incident notification)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 18 September 2020.
A breach notification rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Notify the ANPD and the affected data subjects of a security incident that may create relevant risk or harm to data subjects, within the reasonable period the ANPD sets by regulation, and state the reasons for the delay when the notice is not immediate.
- Describe in the notification the nature of the personal data affected, the data subjects involved, the technical and security measures used, the risks related to the incident, and the measures taken or planned to reverse or mitigate its effects.
- Expect the ANPD to assess the incident's severity, and comply if it orders wide publicity of the incident or measures to reverse or mitigate its effects.
What it reaches
Obligation class
Breach notice, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 48 requires the controller to notify the ANPD and the data subject of a security incident that may create relevant risk or harm to data subjects.
The notification runs on a reasonable period the ANPD itself defines by regulation rather than a fixed number of hours or days stated in the LGPD, and paragraph 1 requires it to describe, at minimum, the nature of the personal data affected, information about the data subjects involved, the technical and security measures used, the risks related to the incident, the reasons for any delay, and the measures taken or planned to reverse or mitigate the harm.
Paragraph 2 lets the ANPD assess the incident's gravity and order the controller to give the incident wide publicity in the media or to adopt measures reversing or mitigating its effects, and paragraph 3 lets the ANPD weigh, in that assessment, whether the controller had already rendered the affected data unintelligible to unauthorized third parties.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
Official compiled text of Lei nº 13.709/2018, Presidência da República
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.