The LGPD always had an arithmetic problem: the law asked for incident notification within a "reasonable timeframe", and a reasonable timeframe, in practice, was whatever each company decided it was. ANPD Resolution 15 of 2024 settled the ambiguity with a number: 3 business days, counted from knowledge of an incident that may cause relevant risk or harm to subjects.
And enforcement stopped being hypothetical: the ANPD applied the largest fine in LGPD history to ByteDance, and public cases show the cost of not notifying. The checklist below is what the first hour of an incident demands.
Hour 0: contain without destroying evidence
The emergency instinct is to reset everything: rotate passwords, reformat, restore. Containment is necessary, but resetting without preserving evidence erases the timeline the ANPD will ask for.
A sequence that works: isolate (do not shut down), revoke compromised credentials, capture logs and snapshots before any modification, and open the incident record with date and time. Every decision from here on enters that record with a named owner.
Hour 1: classify the risk with criteria
Mandatory notification exists for incidents that may cause relevant risk or harm. The practical criteria:
- Nature of the data: sensitive, financial, credentials, and children’s or teenagers’ data weigh more.
- Volume: how many subjects, and of what profile.
- Possible harm: fraud, discrimination, reputational damage, identity theft.
- Reversibility: can the effect be undone (block credential, revoke token), or is the damage permanent?
Document the decision, including if you conclude there is no relevant risk. The assessment is the company’s own responsibility, and the record is what separates "I assessed and documented why not" from "I never assessed". The case of 279 million CPFs circulating on criminal forums showed what happens when the assessment is improvised.
Hour 24: notify the ANPD
Within 3 business days of awareness. The minimum content: the nature of the incident, affected data, number of subjects, security risks, security measures adopted, and the possibility of reversing the damage.
The classic mistake is waiting for the complete technical report to notify. The clock counts from awareness: notify with what is known, flag what is still under investigation, and update as it advances. A partial notification on time beats a perfect one late.
Hour 48: notify the subjects
Same truth, different audience. Subjects do not want jargon: they want to know what happened, which of their data was affected, the concrete risk (and whether they need to act: change password, watch statements, distrust calls), and where to reach the company.
Vague communication does not save money: it generates complaints, and complaints feed enforcement. The ANPD’s self-report in the ISAC case, with 500 thousand patients, shows that well-run transparency is treated as good faith.
Hour 72: remediate and build the dossier
With the deadline met, the work shifts from clock to quality: fix the root vulnerability (not just the symptom), update the response plan with what the incident taught, and close the dossier with logs, decisions, and notifications.
That dossier is the most underrated asset of incident response. In an inspection, it changes the conversation: a company that documents its timeline, criteria, and actions demonstrates governance; one that improvised demonstrates luck.
Conclusion
3 business days is too little to solve an incident and plenty of time to notify one. Confusing the two tasks is what makes companies blow the deadline.
The checklist fits on a page and is assembled before the incident: who responds, where they notify, what they say, with which evidence. Preparing costs days; improvising under a regulatory deadline costs sanctions, and the ruler now has a public number: 153.7 million reais.