top of page

Digital Law | MLB Lawyers | Brazil

Maldonado Latini e Braguim Advogados | Direito Digital | São Paulo | SP

News

ANPD refers 21 data processing agents to the sanctioning area – DPO duties and data subject support

Jun 30
4 min read

ANPD Refers 21 Data Processing Agents to the Sanctioning Area – DPO Duties and Data Subject Support


The Brazilian National Data Protection Authority (ANPD) has completed the first phase of monitoring procedures aimed at investigating potential violations of the Brazilian General Data Protection Law (LGPD) related to the appointment of the Data Protection Officer (DPO) and the availability of communication channels for data subjects.


The main point of attention is the referral of 21 data processing agents to the area responsible for sanctioning analysis due to their failure to respond to ANPD requests. This measure does not mean that penalties will automatically be imposed, but it represents a significant escalation in regulatory oversight and reinforces that structural privacy governance obligations are already being effectively enforced by the Authority.


Technical Note No. 6/2025/DIM/CGF/ANPD highlights that the absence of a designated DPO, the lack of clear contact information, or deficiencies in communication channels with data subjects may compromise the exercise of rights provided under the LGPD and hinder ANPD’s own regulatory activities.


What motivated the monitoring


The procedure was initiated to verify irregularities related to the absence of appointment, identity disclosure, or contact information of the Data Protection Officer, as well as the absence or inadequacy of communication channels for data subjects.


Some agents were selected based on information provided through an audit by the Federal Court of Accounts (TCU), which identified public organizations without an appointed data officer. Others were included based on the analysis of requests received by ANPD, involving complaints, data subject petitions, lack of adequate contact channels, and situations in which requests sent by the Authority received no response.


The selection considered larger controllers, the volume of processed data, and the scope of operations, aiming to increase regulatory impact and improve the effectiveness of enforcement actions.


Who is the Data Protection Officer (DPO)


The Data Protection Officer, also known as DPO, is the person appointed by the data controller to act as a communication channel between the organization, data subjects, and ANPD.


According to Article 41 of the LGPD, the controller must appoint a Data Protection Officer. Their responsibilities include assisting data subjects, communicating with ANPD, providing internal guidance on personal data processing practices, and monitoring the measures required to comply with data protection legislation.


Therefore, the DPO represents a strategic function for managing regulatory, operational, and reputational risks related to data protection.


The DPO also plays an important role in incident management and in providing timely and appropriate responses in cases involving data subject complaints or ANPD requests.


Formal appointment is not enough


The inspection demonstrates that simply appointing a DPO is insufficient. The DPO’s identity and contact information must be clearly, objectively, and consistently available, updated, prominently displayed, and easily accessible.


The communication channel must also operate effectively in practice. Data subjects must be able to exercise their rights in a simple and effective manner, including requests for access, correction, deletion, information regarding data sharing, portability, and review of automated decisions, when applicable.


Generic, outdated, inaccessible, or ineffective channels may indicate governance failures. The absence of an appropriate channel prevents or limits the exercise of rights and negatively impacts ANPD’s ability to operate, as the Authority lacks a defined point of contact within the organization.


From monitoring to sanctioning analysis


The case demonstrates how ANPD’s enforcement process develops. Actions may begin with monitoring activities, requests for information, and compliance recommendations. However, when an agent fails to respond to official requests or does not correct identified issues, the matter may be referred to the General Coordination of Sanctions for assessment of applicable measures.


This referral is significant because it indicates a possible transition toward an administrative sanctioning proceeding, intended to investigate LGPD violations. Although initiating a sanctioning procedure does not automatically result in penalties, it increases regulatory exposure and requires a technical, documented, and timely response from the data processing agent.


Failure to respond to ANPD may increase risk, as it demonstrates not only a failure regarding the specific obligation under review but also a weakness in regulatory communication capabilities.


Following this ANPD movement, data processing agents should review their minimum data protection compliance structure. This assessment should include the formal appointment of the DPO, updated publication of their identity and contact information, effectiveness of data subject support channels, existence of internal workflows for reviewing and responding to requests, documentation of received demands, and the designation of responsible individuals for responding to communications from the Authority.


It is also recommended to verify whether the organization maintains evidence of the DPO’s activities, records of data subject requests, response history, internal deadlines, security incident procedures, and documentation demonstrating data protection governance measures.


This assessment is particularly relevant for organizations processing large volumes of personal data, handling sensitive data, maintaining extensive databases of customers, users, or employees, or operating digital customer service channels.


DPO as a governance structure


The DPO’s role should be understood as part of privacy governance. The DPO contributes to implementing LGPD principles, especially transparency, accountability, and responsibility.


The structure may be internal or external, depending on the organization’s size, complexity, and level of processing risk. For organizations without a dedicated specialized team, the DPO as a Service model may provide ongoing technical support to maintain channels, workflows, records, training, and regulatory responses.


The key factor is effectiveness. A simple nominal appointment of a DPO, without a functional communication channel, without responses to data subjects, and without the ability to interact with ANPD, is no longer sufficient. Recent enforcement actions confirm that ANPD has moved from a predominantly formal assessment toward an effectiveness-based analysis, where the existence of a channel matters less than its actual ability to function.


Conclusion


The case confirms a change in ANPD’s enforcement approach: oversight is no longer focused solely on the formal existence of privacy structures and has shifted toward verifying whether these structures actually operate in practice. For the market, this means that documentation and appointments alone are no longer sufficient evidence of compliance; the effective ability to respond to data subjects and to the Authority itself will be the main factor evaluated going forward.


MLB Advogados is available to assist organizations in structuring or reviewing DPO operations, implementing data subject support channels, and assessing compliance with LGPD and ANPD requirements.

bottom of page