The infringement notice opens with a sentence that changes the tone of data enforcement in Brazil. According to the ANPD infringement notice, there are "indications of minimizing the gravity of the incident." The Administrative Sanctioning Proceeding was instituted on July 8, 2026 against ISAC, Instituto Saúde e Cidadania, for a ransomware attack in January 2025 that affected approximately 500 thousand records — including 78,772 children and adolescents and 47,921 elderly. We have followed the case and the signal is clear: the ANPD has stopped being a warning body and started demanding technical evidence, a formal DPO, and real communication to data subjects.
The scale of the incident and the defendant's profile
According to the ANPD infringement notice, ISAC is a private non-profit social organization headquartered in Brasília that operates in 6 states: Goiás, Rio Grande do Sul, Bahia, Alagoas, Piauí, and Tocantins. The incident occurred in January 2025 and affected approximately 500 thousand records, reported by ISAC to the ANPD. The data scope is broad: name, date of birth, medical records, exams, prescriptions, consultations, and diagnoses — all sensitive data under the LGPD.
According to the infringement notice, the attackers accessed the cloud backups. ISAC did not pay the ransom and reported to the ANPD spontaneously in 2025. But what looked like a transparency posture became, according to the ANPD, a case of "serious failures in the protection of personal and sensitive data." The difference between reporting and proving is what separates a valid defense from an aggravating factor.
The LGPD articles cited and the literal quotations from the notice
According to the ANPD infringement notice, the cited articles are: Art. 46 (security), Art. 48 (incident communication), Art. 41 (DPO), and Art. 6º, items IV and VI (prevention and accountability). The literal quotations from the notice are harsh:
- "there are indications of minimizing the gravity of the incident"
- "serious failures in the protection of personal and sensitive data"
- "insufficient communication to data subjects"
- "absence of evidence regarding the adoption of corrective measures, despite repeated requests to prove them"
Each of these sentences points to a concrete operational failure: without formal IR, without a formal DPO, and without a communication plan to data subjects, the organization accumulates violations that the ANPD treats as aggravating — not mitigating — factors.
ISAC's defense thesis and why it failed
According to ISAC's defense, the organization denies data leak and exfiltration. It claims "temporary unavailability." It maintains that the attackers accessed "only administrative information and databases related to already-terminated contracts." The problem is that, according to the infringement notice, no technical proof was provided after repeated questioning.
Here is the central lesson for any DPO: a claim without evidence is not a defense. Without a formal incident response report, with chain-of-custody preservation, forensic logs, and exfiltration analysis, the ANPD treats the narrative as speculative. The prevention principle, cited by Fabrício Guimarães, superintendent of Enforcement at ANPD, is explicit: "In a logic of the prevention principle, I have to estimate the worst and prepare for the worst." In other words, the burden of technical proof falls on the controller.
The legal cap and the Telekall precedent
Under Art. 52 of the LGPD, the fine can reach 2% of the private legal entity's revenue, capped at 50 million reais per infraction. Other sanctions include warning, publication of the infraction, blocking or deletion of data, and partial suspension of operations for up to 6 months, per Resolução CD/ANPD nº 4/2023. ISAC's defense deadline is 10 business days. No fine has been applied so far — the proceeding is ongoing.
The precedent matters. The ANPD's first pecuniary fine was applied to Telekall in July 2023, in the amount of 14,400 reais. The ISAC case is a PAS of unprecedented scale against a private public-health organization. As a private legal entity, ISAC can receive a pecuniary fine, unlike public agencies. According to the ANPD, reported by Estadão, Folha, Valor, O Globo, G1, and CNN Brasil, the case redefined the standard for healthcare data enforcement in Brazil.
What Tech86 implements
We repeat: reporting to the ANPD is not enough. You have to prove. What Tech86 implements for healthcare and critical infrastructure clients:
- 24/7 SOC with MDR — the dwell time of a breach becomes detection in hours, not months. The ISAC incident occurred in January 2025 and the PAS was only instituted in July 2026 — an 18-month gap.
- Immutable and offline backup — cloud backups with the same credential are the second target of ransomware. The ISAC attackers accessed the cloud backups directly.
- Incident response with evidence preservation — without formal IR, there is no report for the ANPD. ISAC's defense failed because it provided no technical proof after repeated questioning.
- Incident communication to the ANPD within 3 business days, per Resolução CD/ANPD nº 15/2024 — a technical report with grounding, without speculative narrative.
- LGPD compliance with a formal DPO and a communication plan to data subjects — Art. 41 and Art. 48 charged in the notice are exactly the points where "insufficient communication to data subjects" was cited as a failure.
Conclusion: the burden of technical proof falls on the controller
The ISAC case is not just a ransomware incident — it is, primarily, an LGPD enforcement case about incident response failures. The ANPD is not judging the attack; it is judging the response. According to the infringement notice, "absence of evidence regarding the adoption of corrective measures" is what turns an incident into a sanction. We help organizations build exactly what was missing: a 24/7 SOC, immutable backup, IR with evidence, communication within 3 business days, and a formal DPO. Before the PAS — not after.