Skip to main content
Close
Security

LGPD checklist: incident response in 3 business days

Gabriel Ferraresi· CEO | Tech86October 2, 20263 min
lgpdanpdincidentincident-responseprivacycompliance

The LGPD always had an arithmetic problem: the law asked for incident notification within a "reasonable timeframe", and a reasonable timeframe, in practice, was whatever each company decided it was. ANPD Resolution 15 of 2024 settled the ambiguity with a number: 3 business days, counted from knowledge of an incident that may cause relevant risk or harm to subjects.

And enforcement stopped being hypothetical: the ANPD applied the largest fine in LGPD history to ByteDance, and public cases show the cost of not notifying. The checklist below is what the first hour of an incident demands.

Hour 0: contain without destroying evidence

The emergency instinct is to reset everything: rotate passwords, reformat, restore. Containment is necessary, but resetting without preserving evidence erases the timeline the ANPD will ask for.

A sequence that works: isolate (do not shut down), revoke compromised credentials, capture logs and snapshots before any modification, and open the incident record with date and time. Every decision from here on enters that record with a named owner.

Hour 1: classify the risk with criteria

Mandatory notification exists for incidents that may cause relevant risk or harm. The practical criteria:

  • Nature of the data: sensitive, financial, credentials, and children’s or teenagers’ data weigh more.
  • Volume: how many subjects, and of what profile.
  • Possible harm: fraud, discrimination, reputational damage, identity theft.
  • Reversibility: can the effect be undone (block credential, revoke token), or is the damage permanent?

Document the decision, including if you conclude there is no relevant risk. The assessment is the company’s own responsibility, and the record is what separates "I assessed and documented why not" from "I never assessed". The case of 279 million CPFs circulating on criminal forums showed what happens when the assessment is improvised.

Hour 24: notify the ANPD

Within 3 business days of awareness. The minimum content: the nature of the incident, affected data, number of subjects, security risks, security measures adopted, and the possibility of reversing the damage.

The classic mistake is waiting for the complete technical report to notify. The clock counts from awareness: notify with what is known, flag what is still under investigation, and update as it advances. A partial notification on time beats a perfect one late.

Hour 48: notify the subjects

Same truth, different audience. Subjects do not want jargon: they want to know what happened, which of their data was affected, the concrete risk (and whether they need to act: change password, watch statements, distrust calls), and where to reach the company.

Vague communication does not save money: it generates complaints, and complaints feed enforcement. The ANPD’s self-report in the ISAC case, with 500 thousand patients, shows that well-run transparency is treated as good faith.

Hour 72: remediate and build the dossier

With the deadline met, the work shifts from clock to quality: fix the root vulnerability (not just the symptom), update the response plan with what the incident taught, and close the dossier with logs, decisions, and notifications.

That dossier is the most underrated asset of incident response. In an inspection, it changes the conversation: a company that documents its timeline, criteria, and actions demonstrates governance; one that improvised demonstrates luck.

Conclusion

3 business days is too little to solve an incident and plenty of time to notify one. Confusing the two tasks is what makes companies blow the deadline.

The checklist fits on a page and is assembled before the incident: who responds, where they notify, what they say, with which evidence. Preparing costs days; improvising under a regulatory deadline costs sanctions, and the ruler now has a public number: 153.7 million reais.

Need expert guidance?

Schedule a consultation with our specialists.

Compliance and incident response advisory

Frequently Asked Questions

At the moment the company becomes aware of the incident, not when the investigation concludes. ANPD Resolution 15 of 2024 sets 3 business days from knowledge of an event that may cause relevant risk or harm to subjects. Waiting to understand everything before notifying is the most common way to blow the deadline.

The LGPD requires notification for incidents that may cause relevant risk or harm to subjects. Practical criteria: nature of the data (sensitive, financial, credentials, children’s and teenagers’ data weigh more), volume of affected subjects, severity of possible harm (fraud, discrimination, reputational damage), and reversibility. The ByteDance case shows the weight of that last layer: teenager data came with a deletion sanction.

Two fronts: administrative sanction (the LGPD provides for fines of up to 2% of revenue in Brazil, capped at R$ 50 million per violation, plus other sanctions) and reputational damage when the breach surfaces externally. Recent public cases show the cost of silence: the iFood incident, discovered in December 2025 and not notified, with 1.2 million users affected, became the example of assessing relevant risk by oneself.

Yes. The duty to notify applies to every processing agent; size and complexity calibrate the how, not the whether. An SME’s checklist fits on one page and prepares at low cost: who responds, where to notify, what to say, and with which evidence.

For the authority: the nature of the incident, categories and volume of affected data, number of subjects, security risks, security measures adopted, and the possibility of reversing the damage. For subjects: plain language, what happened, which of their data was affected, concrete risks, and practical guidance. One event, two audiences, two depths.

Blog — Get in Touch

Have a question about our articles or services? Our team is ready to help.

Schedule a Meeting

Book a time slot.

Schedule Now

Email

Send us a message.

[email protected]

WhatsApp

Quick conversation.

Address

Avenida Paulista, 1636 - São Paulo - SP - 01310-200

Tech86 Specialist

Online now

Hello! How can we help scale your business today?

Tech86 Engineering

We Value Your Privacy

We use cookies and similar technologies to optimize your experience, analyze site traffic, and personalize content. By clicking "Accept All", you agree to the use of all cookies. Read our Privacy Policy.