Back to the blog
Compliance11 min readUpdated

LGPD Article 46: 7 Technical Measures the ANPD Expects

What Brazil's ANPD treats as adequate technical measures under LGPD Art. 46 in 2026: 7 controls SaaS, fintech and e-commerce must prove to avoid fines.

Diego Melo, author
Diego Melo

Security researcher and founder of No Vuln

LGPD Article 46: 7 Technical Measures the ANPD Expects

Article 46 of the LGPD — Brazil's General Data Protection Law — requires “technical and administrative security measures capable of protecting personal data.” The law doesn't list which specific measures; each company defines them based on the risk of its own processing. Based on that article and on the enforcement cases made public so far, you can map out 7 technical measures that work as concrete evidence the company took security seriously. Without them, your defense is weaker. With them, you have something to show if the ANPD asks.

This article lists all 7, with references to the legal text and what you need to prove for each one — as evidence of an adequate technical measure in an eventual inspection, due diligence process or incident response, not as ANPD certification (the ANPD doesn't certify or “accept” third-party reports).

Why it matters: what enforcement has looked like so far

The LGPD allows sanctions ranging from a warning to a fine of up to 2% of revenue in Brazil (capped at R$ 50 million per violation). So far the ANPD has issued few fines, but enforcement is ramping up:

  • 2023: the ANPD's first fine against a private company — Telekall Infoservice, two fines of R$ 7,200 each (R$ 14,400 total), for selling WhatsApp contact lists for a political campaign without a legal basis ( source: ANPD)
  • 2024: no fines against private companies — only sanctions against public agencies
  • December 2024: the ANPD opened inspections against 20 large companies for lacking a Data Protection Officer (DPO) and a channel for data subjects — all of them came into compliance by April 2025

In every case, the ANPD asked for the same thing before closing the matter: documentary evidence of the technical and organizational measures adopted. Those who had it resolved things quickly. Those who didn't were treated as negligent.

1. A recent, documented pentest

What it is: a penetration test performed by an independent technical third party, with a formal report, within the last 12 months.

Why inspectors ask for it: it's the only concrete way to show that the company actually tested the security of the systems that process personal data — rather than just claiming it did.

What the report needs to include:

  • A clear scope (which systems, which endpoints)
  • The methodology used
  • A list of findings with severity and impact
  • A remediation plan
  • A formal compliance statement aligned with Art. 46
  • A retest after the fixes (strengthens the evidence)

2. Personal data inventory

What it is: a map of which personal data the company collects, where it stores it, how it shares it, on what legal basis, and how long it keeps it.

Legal reference: Art. 37 (record of processing operations) + Art. 7 (legal bases).

How to prove it: a formal document (spreadsheet, in-house system, specialized tool) with at least these columns:

  • Data type (Brazilian CPF taxpayer ID, email, geolocation, etc.)
  • Category (registration, behavioral, sensitive)
  • Source (form, API, partner)
  • Storage system (database X, system Y)
  • Legal basis (Art. 7, Art. 11)
  • Sharing with processors
  • Retention period

3. A clear, up-to-date privacy policy

What it is: a public document, written in language data subjects understand, describing how the company processes personal data.

Legal reference: Art. 9 (data subjects' right to easy access to information about the processing) + Art. 18 (data subject rights).

Common mistakes inspectors flag:

  • A policy copied from another country (LGPD ≠ GDPR ≠ CCPA)
  • Last updated in 2018 or earlier
  • Vague terms like “legitimate interest” with no justification
  • No clear channel for exercising rights
  • Missing the name or contact of the DPO (the “encarregado” in the LGPD)

4. An appointed, active Data Protection Officer (DPO)

What it is: an individual or legal entity formally appointed as the point of contact between the company, the ANPD and data subjects (Art. 41).

How to prove it:

  • A documented formal appointment (letter, contract, board minutes)
  • Name published in the privacy policy
  • A working, dedicated email address (usually [email protected])
  • A log of requests from data subjects (even if empty, it proves the channel is open)

Small businesses (under the ANPD's simplified regime for small processing agents) may be exempt from appointing a formal DPO, but they need to be able to justify it.

5. Documented, auditable access control

What it is: evidence that only authorized people access personal data, with an audit trail.

How to prove it:

  • RBAC or ABAC implemented in the systems that process personal data
  • Mandatory MFA on admin panels
  • Access logs retained for at least 6 months
  • A formal access management policy (provisioning, quarterly review, removal)
  • Least privilege applied

In a pentest, this translates into coverage of BOLA, BFLA and BOPLA — authorization flaws that allow improper access to personal data.

6. Incident response plan

What it is: a documented, rehearsed process for responding to a security incident, including the obligation to notify the ANPD within a reasonable time (Art. 48).

How to prove it:

  • A formal response plan (playbook, runbook)
  • A severity classification table
  • An internal + external communication flow (ANPD, data subjects)
  • A fill-in notification template
  • Evidence of a simulation or training exercise (at least once a year)
  • Contracts with specialized forensics providers (if applicable)

7. Supply chain security (processors)

What it is: contracts with processors (cloud providers, payment processors, SaaS tools) that set out responsibilities and audit rights.

Legal reference: Art. 39 (processors act on the controller's instructions) + Art. 42 (joint liability with the processor).

How to prove it:

  • A DPA (Data Processing Agreement) with each relevant processor
  • An inventory of processors and the data shared with them
  • An annual review of each processor's security posture (questionnaire, SOC 2 Type II evidence when available)
  • A contract clause requiring notification of incidents on the processor's side

Quick checklist: do you have all 7?

MeasureDo you have it?Typical time to implement
1. Documented pentest < 12 months old☐4–8 weeks
2. Personal data inventory☐2–4 weeks
3. Up-to-date privacy policy☐1–2 weeks
4. Appointed, active DPO☐1 week
5. Auditable access control☐4–12 weeks
6. Incident response plan☐2–4 weeks
7. DPAs with processors☐2–6 weeks (depends on the processor)

Realistic compliance cost

For a small or mid-sized company in Brazil (Brazilian market figures):

  • Documented pentest: R$ 8,000 to R$ 18,000 (the most expensive part)
  • Inventory + policy + DPAs: R$ 3,000 to R$ 10,000 (legal)
  • Outsourced DPO: R$ 1,500 to R$ 4,000/month
  • Technical implementation of RBAC/MFA/logs: already covered by your in-house team

Total initial compliance: R$ 15,000 to R$ 35,000. Annual upkeep: ~R$ 20,000–40,000.

Compare that with the maximum fine: 2% of revenue in Brazil, up to R$ 50 million. For any company with more than R$ 1 million in revenue, the ROI is a no-brainer.

The blind spot every company forgets

The LGPD doesn't just require that you have the measures. It requires that you prove you have them, with dates, and that they're effective. Documentation is the currency of an inspection.

A company that has RBAC in place but no document describing the policy, has MFA turned on but no record of the decision, has run a pentest but has no report on file — in an inspection, it's treated as if it had nothing.

Document everything. And keep your pentest current, every year.

Share

WhatsAppLinkedInX

Next step

Want to apply this to your system?

No Vuln runs in-depth penetration tests with the same methodology described in this article. Request a proposal: mutual NDA within 24h, scope defined on a technical call.