Site icon Araújo e Policastro Advogados

The era of guidance is over: how the new ANPD is expanding its oversight of companies

Over the past two years, the National Data Protection Agency (“ANPD”) has shifted from acting primarily as an advisory body to definitively assuming a much more robust regulatory and enforcement role.

The transformation culminated in February 2026 with its conversion into a regulatory agency, endowed with functional, technical, decision-making, administrative, and financial autonomy.

More than just an institutional change, this new status represents a tangible increase in regulatory exposure for public and private companies that process personal data.

The new structure, as a regulatory agency, was accompanied by the creation of a dedicated career track for Regulatory and Data Protection Specialists, with plans to hire 200 (two hundred) new civil servants, the reorganization into specialized superintendencies, and the expansion of its responsibilities, which now include oversight of the Digital Statute for Children and Adolescents (“ECA”).

The expected outcome is an increased capacity for monitoring, investigation, and enforcement, as a result of the following structural changes:

① Inspections are no longer conducted on an ad hoc basis

Recent developments show that the ANPD has begun to prioritize structured and preventive measures targeting sectors considered to be at higher risk.

Priorities for 2026 and 2027 include:

② The initial focus has been on basic compliance obligations

The initial results of the new strategy are noteworthy precisely because they show that the agency is not focusing its efforts solely on major data breaches.

In June 2026, the ANPD completed its monitoring of 56 (fifty-six) data processors —including public agencies and private companies—to verify compliance with obligations considered fundamental, such as the appointment of a data protection officer (DPO) and the provision of a customer service channel for data subjects.

A significant number of the organizations audited had outstanding issues or failed to respond to the agency’s requests, a situation that has already led to the initiation of proceedings for the possible imposition of sanctions.

The message is clear: formal governance failures are now being effectively monitored.

③ Large companies are also being targeted

Another important point is that enforcement efforts already extend to large organizations.

In the Agency’s monitoring efforts, companies in the technology and mobility sectors were ordered to bring their obligations into compliance within a short timeframe, while others—which handle large amounts of personal data—were able to demonstrate compliance and concluded the proceedings without further consequences.

Similarly, in July 2026, the ANPD initiated administrative proceedings to impose sanctions in connection with a security incident that compromised approximately 500,000 (five hundred thousand) patient records managed by a social organization in the healthcare sector.

④ What will change for businesses?

The new situation calls for a change in approach.

Several organizations still focus their efforts solely on compliance projects carried out a few years ago, when the LGPD took effect, without taking into account the fact that this is an ongoing process that requires continuous updates and monitoring, meaning that documents originally produced do not always reflect current operational realities.

The ANPD’s oversight has shown a growing interest in verifying whether governance measures actually exist and function in practice, rather than merely whether they have been formally implemented.

In this context, certain measures deserve special attention:

More than just formally complying with the LGPD, these measures reduce exposure to administrative proceedings, mitigate reputational risks, and enable faster responses to inspections.

⑤ The right time to review compliance

The transformation of the ANPD into a regulatory agency marks the beginning of a new era for data protection in Brazil and a more mature regulatory environment. With an expanded structure, a defined regulatory agenda, and growing operational capacity, the number of inspections is expected to increase significantly throughout 2026 and 2027.

For companies that process personal data on a large scale—especially in the technology, healthcare, financial services, retail, education, human resources, and digital platforms sectors—this is an opportune time to review privacy programs, identify vulnerabilities, and anticipate potential inquiries from the Agency, before they turn into enforcement proceedings, as demonstrated by the Agency’s evolving approach:

AXISSITUATION THROUGH 2024SITUATION IN 2026
Legal NatureSpecial agency reporting to the Presidency (since 2022)An autonomous regulatory agency (Law No. 15,352/2026), with functional, technical, decision-making, administrative, and financial autonomy
StructureLean structure, staff shortageNew organizational structure (Decree No. 12,881/2026 and ANPD Board Resolution No. 33/2026) and a dedicated career track for Regulatory Specialists, with 200 positions to be filled through competitive examinations
Regulatory AgendaPractice focused on general provisions of the LGPD (international data transfers, DPO, compliance incidents)2025–2026 Agenda and New Map of Priority Topics for 2026–2027: AI, biometric data/health, Digital ECA, government
Enforcement stancePrimarily educational and guidance-oriented approach; few sanctions imposedActive monitoring of treatment providers (56 providers inspected; 21 inspections with no response; and a target of at least 75 inspections over the two-year period)

Our Data Protection team at Araújo e Policastro Advogados is available to answer any questions or provide further clarification.

Exit mobile version