Back to the blog
Guide11 min readUpdated

Data Breach in Brazil: LGPD Fines and How to Avoid Them

Customer data leaked at your SaaS or fintech in Brazil? LGPD fines go up to 2% of revenue (R$ 50M cap). What the law requires and when to notify the ANPD.

Diego Melo, author
Diego Melo

Security researcher and founder of No Vuln

Data Breach in Brazil: LGPD Fines and How to Avoid Them

Your company collects customer data — names, emails, CPF numbers (Brazil's individual taxpayer ID), addresses, cards, bank details. You know that. What you may not know: if your company operates in Brazil or serves users there, Brazil's General Data Protection Law (LGPD) applies — and if any of that data leaks, you can be fined up to 2% of your revenue in Brazil (capped at R$ 50 million per violation). And that's still the cheapest part of the bill.

This article explains three things in plain English:

  • What the law requires before a breach (prevention)
  • What the law requires after a breach (response)
  • How to avoid all of it without becoming an LGPD expert

What counts as a “data breach” under the law

The LGPD (Law 13,709/2018) calls it a security incident: any situation in which personal data was accessed, altered or disclosed by someone who shouldn't have. That includes:

  • A database breached by a hacker (the classic)
  • An employee accessing data they shouldn't
  • An email containing personal data sent to the wrong recipients
  • Customer A being able to see customer B's data in the system (a bug)
  • A database backup sitting in a public S3 bucket or Drive folder, no password
  • Customer data in a file lost in transit
  • Social engineering that fooled an employee

Notice: not every breach involves a hacker. Many of the public cases came down to a misconfiguration, a software bug or a careless employee. You don't need to be targeted by a criminal mastermind — a server left with an insecure default configuration is enough.

What a breach actually costs

The ANPD fine

The ANPD — Brazil's National Data Protection Authority — can impose:

  • A warning (the lightest)
  • A simple fine — up to 2% of revenue in Brazil, capped at R$ 50 million per violation
  • A daily fine — for ongoing non-compliance
  • Public disclosure of the violation — your company named in a public ANPD notice
  • Blocking of the personal data until the issue is fixed
  • Deletion of the personal data
  • Partial suspension of the database — up to 6 months
  • Suspension of the data processing activity — up to 6 months
  • A partial or total ban on data processing activities

But the fine isn't the worst part

CostTypical range (Brazil)
ANPD fineR$ 0 to 2% of revenue
Individual damages (courts)R$ 3,000 to R$ 15,000 per affected customer
Forensic investigation + emergency pentestR$ 30,000 to R$ 150,000
Customer notification + PRR$ 10,000 to R$ 100,000
Legal feesR$ 50,000 to R$ 500,000+
Churn (lost customers)15% to 40% over the next 90 days
Cost of capital in the next round+30% to +60% (investors price in the risk)

Add up the items above and the typical total impact of a mid-sized breach at a Brazilian SaaS or e-commerce company lands between R$ 500,000 and R$ 5 million — depending on the volume of data, the nature of the exposed data and the size of the customer base.

What the law requires from your company BEFORE any breach

The LGPD doesn't require perfection. It requires that you've adopted reasonable protective measures. Article 46 explicitly calls for “technical and administrative measures capable of protecting personal data.” In an ANPD inspection, this is what carries weight:

  • A recent, documented pentest (last 12 months) — concrete proof of an active technical measure
  • A published, up-to-date privacy policy
  • A formally appointed Data Protection Officer (DPO) — the “encarregado” in the LGPD
  • A personal data inventory maintained by the company
  • Contracts with processors (Vercel, AWS, Stripe, etc.) that include a data protection clause
  • A written incident response plan
  • Audit trails (logs) with minimum retention

Companies that had all of these in place before the incident get drastically smaller fines — in some cases, just a warning. Companies that didn't are treated as negligent — maximum fine.

What the law requires from your company AFTER a breach

This is where the clock starts.

Notify the ANPD

LGPD Article 48: the controller must notify the ANPD within a reasonable time of any incident that may create “relevant risk or harm” to data subjects. Under Resolution CD/ANPD No. 15/2024, the deadline is 3 business days. Delays make the fine worse. (If the breach also involves data covered by another law, notify that authority within its own deadline too — 72 hours under the GDPR.)

The notification must include:

  • The nature of the affected data
  • The approximate number of data subjects
  • The risks involved
  • The measures already taken
  • The timeline for notifying data subjects

Notify the affected customers

The law requires direct notice to the data subjects whose data was affected. No hedging. In plain language. Through an appropriate channel (email, push notification, or a public announcement if individual notice isn't feasible).

Hiding it doesn't work. The ANPD now receives a growing volume of complaints from customers. Many breaches are first uncovered by the press, before the company has a chance to report them officially — and in those cases the penalty is at its maximum.

Document everything

All of it. When you found out, how you found out, who decided what, at what time, on what basis. That record is the company's defense in any administrative proceeding.

The path most companies take (and why it fails)

The typical reaction of a business owner who learns they “have to comply with the LGPD” is:

  1. Hire a lawyer to write the privacy policy
  2. Appoint a DPO (usually the CFO or an outside lawyer)
  3. Build a data inventory in a spreadsheet
  4. Train the team in a 2-hour workshop
  5. Call it done: “we're compliant”

That process covers the paperwork side of the LGPD. But it ignores the riskiest part: the technical side of your system. If the system has a bug that allows a breach, all that legal work is window dressing — because the breach will happen anyway, and the ANPD will ask: “what technical measures did you adopt to prevent this?”

And this is the part nobody tells you before the incident.

The missing layer: independent technical validation

Getting LGPD-compliant on paper is the easy part. Making sure the system actually protects the data is the part that truly protects the company. That second part can only be done by an independent technical third party — someone trained to try to break into your platform and show you what's vulnerable.

That process is called a pentest (penetration test). It's done under contract and NDA, with a defined scope. The result is a technical report showing:

  • Which specific bugs allow personal data to leak right now
  • How each bug can be exploited (with proof)
  • How to fix each bug
  • Validation after the fix

A documented pentest isn't “accepted” or certified by the ANPD — the authority doesn't validate third-party reports. But it is concrete evidence of an adopted technical measure (Art. 46), useful in an inspection, a customer's due diligence process, or an incident response. Having that document ready changes the conversation: instead of claiming you protected the data, you show it.

Doing it right vs. paying for the breach

ScenarioTotal cost, year 1 (Brazil)
Paperwork compliance + annual pentest + light ongoing testingR$ 25,000 to R$ 60,000
Average breach at a Brazilian SaaS (no prevention)R$ 500,000 to R$ 5,000,000

The math: prevention costs 1% to 5% of what a breach costs. Plus an intangible gain — you sleep at night.

What to do now (practical steps)

Legal steps (you or your lawyer)

  1. Publish a clear privacy policy at /privacy
  2. Publish terms of service at /terms
  3. Formally appoint a DPO (letter, contract, board minutes)
  4. Build a personal data inventory in a spreadsheet
  5. Review your processor contracts (data protection clause)
  6. Write a 2–3 page incident response plan

Technical steps (requires a specialized firm)

  1. A formal pentest scoped around personal data
  2. A technical + executive report formatted for the LGPD
  3. A prioritized remediation plan
  4. A retest after the fixes
  5. Consider ongoing testing for continuous monitoring

Where No Vuln comes in

No Vuln handles the technical side. Pentesting with a report formatted as LGPD evidence: an executive summary aligned with Article 46, a map of findings × type of personal data affected, calibrated severity (technical + LGPD impact), a 30/60/90-day remediation plan, retest included.

For international clients, No Vuln prices the LGPD pentest in USD. Small company (one system, basic data): Sprint (25h) package, US$ 3,750 to US$ 6,250. Mid-sized company (multiple systems + integrations): Deep Dive (50h), US$ 7,500 to US$ 12,500. Large company or sensitive data: Full Scope (100h+), from US$ 15,000. The hourly rate ranges from US$ 150 to US$ 250 depending on stack, testing mode and timeline — larger packages have a lower hourly rate. Invoiced in USD via Wise or international wire transfer: 50% at kickoff, 50% on delivery.

For the moderate investment this path represents, you move from “waiting for it to happen” to “we have documented evidence that the system is protected.” When an inspection or a customer audit comes around, the difference is literally an order of magnitude.

Book a call with No Vuln. In 30 minutes we'll assess what makes sense for your company and send you a formal proposal within 3 business days. Mutual NDA before any technical conversation.

Share

WhatsAppLinkedInX

Next step

Want to apply this to your system?

No Vuln runs in-depth penetration tests with the same methodology described in this article. Request a proposal: mutual NDA within 24h, scope defined on a technical call.