The LGPD turned 8 years old in August 2026, and since its publication in 2018, it has established a comprehensive framework for personal data protection in Brazil. The legislator, however, chose to leave specific matters for future regulation by the Brazilian Data Protection Agency (ANPD), meaning that several provisions refer to regulations, complementary rules, or terms to be defined by the agency.
After 8 years, it is time to assess what has already been regulated and what still lies ahead. In recent years (especially in 2024) the ANPD has addressed central gaps in the LGPD on topics such as the role of the DPO, international data transfers, and security incident reporting. At the same time, however, issues such as data subject rights, the protection of children and adolescents, and artificial intelligence remain in the queue awaiting regulation.
I. What has already been regulated by the ANPD
Data Processing Officer (DPO)
Among the open points in the legislation, the LGPD provided that the ANPD would establish complementary rules on the role of the “data protection officer”. Following the LGPD’s publication, data processing agents faced uncertainty regarding basic issues, such as whether the DPO could be a legal entity, whether an employment relationship with the organization was required, what minimum qualifications applied, and under what circumstances the appointment could be waived.
The Regulation on the Role of the Data Protection Officer (Resolution CD/ANPD No. 18/2024) filled this gap by defining the duties of processing agents in relation to the DPO, establishing exemption hypotheses for small-scale agents, and allowing for the appointment of either an individual or a legal entity, whether internal or external. As a result, organizations now have objective standards for formally designating their DPOs – which even includes a requirement for a formal appointment act).
International Data Transfer
The LGPD delegated to the ANPD the task of defining the content of mechanisms capable of legitimizing the international transfer of data from Brazil to other jurisdictions. In this context, companies with cross-border operations had been operating without formal instruments recognized by the Brazilian agency, creating uncertainty about the compliance of existing data flows.
With the publication of the International Data Transfer Regulation (Resolution CD/ANPD No. 19/2024), the ANPD clarified these issues and introduced the first draft of the Brazilian Standard Contractual Clauses (SCCs), which legitimize international data flows without additional bureaucracy. This adopted framework facilitates interoperability with the European model, something that is especially relevant for multinationals already using similar instruments within the European Union. More recently, in 2026, the ANPD issued its adequacy decision recognizing European Union countries as eligible destinations for data transfers from Brazil, which was met with a reciprocal recognition from the European Union.
Security Incident Reporting
The LGPD indicated that security incidents should be reported within a reasonable timeframe, as defined by the agency. In practice, however, this vagueness created operational uncertainty, since the ANPD had only informally recommended a 2-business-day deadline through its online form, without a binding regulatory standard.
With the issuance of the Security Incident Reporting Regulation (Resolution CD/ANPD No. 15/2024), the ANPD not only defined what constitutes a "security incident,” but also established objective criteria for assessing whether a given occurrence triggers a duty to notify (based on an analysis of the degree of relevant risk or harm) and set a 3-business-day deadline for reporting to the ANPD when notification is required. As a result, companies have been able to structure internal incident response policies based on clear standards and with less room for subjectivity.
II. What is Yet to Come
If 2024 was the year of major resolutions, the coming years promise advances on equally relevant topics. As a way of anticipating what lies ahead, the ANPD signaled in its 2025-2026 Regulatory Agenda (Resolution CD/ANPD No. 31/2025) and in its Priority Themes Map for 2026-2027 (Resolution CD/ANPD No. 30/2025) several starting points, including:
i. Data subject rights: The LGPD provides for rights such as data portability, access to data, and review of automated decisions, but the ANPD has not yet detailed how these rights should be operationalized. This topic is a priority in the 2025-2026 Regulatory Agenda and is also included in the Priority Themes Map as an enforcement focus in sectors such as biometrics, health, and financial data.
ii. Protection of children and adolescents in the digital environment: The LGPD requires that the processing of children’s and adolescents’ data observe their best interest. Until 2023, there was uncertainty as to whether parental consent was the only permissible legal basis, but the ANPD has since allowed other bases, provided that the best interest principle prevails. The landscape has become more complex with the Digital ECA, which introduced obligations related to age verification, security by default, and a prohibition on profiling minors - issues that have gained greater prominence given the ANPD’s focus on enforcement in this area.
iii. Artificial intelligence and emerging technologies: The LGPD grants data subjects the right to request a review of automated decisions, but it does not regulate how this right should be exercised. With the expansion of generative AI in areas such as credit, HR, and healthcare, this gap has become increasingly sensitive. The Priority Themes Map lists AI as an enforcement focus, and the current moment calls for attention to transparency and explainability (since, even absent specific regulation, the LGPD already serves as a basis for scrutiny).
III. What remains from now on
Over the course of 8 years, the LGPD has evolved from a law with open-ended provisions to a more robust regulatory ecosystem, marked by three central regulations in 2024, an adequacy decision in 2026, and an agency with strengthened institutional capacity. The work, however, is far from complete: data subject rights, the protection of children and adolescents, and artificial intelligence represent the next chapters in this trajectory.
For companies operating in Brazil, data protection maturity is an ongoing journey. Staying abreast of the ANPD"s regulatory agenda remains the starting point for any compliance program that aims to stay current and prepared for the next regulatory cycles.
*Written by: Carla Couto, Luiza Sato, and Miguel Carneiro, partners and lawyer in the practice area, respectively.