ANPD inspection reveals Brazilian companies' LGPD compliance gaps
The Agência Nacional de Proteção de Dados (ANPD) completed the first phase of its monitoring program, reviewing 56 data‑treatment agents—39 public bodies and 17 private companies. The audit focused on two core LGPD requirements: the appointment of a Data Protection Officer (DPO) and the provision of communication channels for data‑subject rights. Results showed that 27 organizations complied fully, 8 had pending issues that could be regularised, and 21 did not respond to ANPD’s requests.
In parallel, experts stress that effective document management is essential for LGPD compliance. Companies should map personal data, classify and store documents securely, limit access based on role, define retention periods, and ensure safe disposal. Implementing these practices reduces operational risk, facilitates audits, and demonstrates conformity with ANPD guidelines.
Entities: Agência Nacional de Proteção de Dados (ANPD) · Brazilian companies · Lei Geral de Proteção de Dados (LGPD)