Back to BlogGDPR & Compliance

ANPD Brazil: LGPD Enforcement 2024

Brazil's ANPD issued its first major fines in 2024. LGPD covers 215M Brazilians — larger than Germany, France, and UK combined.

March 6, 202610 minute read
Brazil LGPDANPD enforcementCPF CNPJ detectionBrazilian privacy lawSouth America compliance

ANPD Brazil: LGPD Enforcement 2024

Brazil's privacy regulator, the ANPD, started issuing fines in 2024. These were the first major fines under LGPD — Law No. 13,709/2018. Brazil has 215 million people covered by this law. It also has 180 million internet users — the largest digital economy in Latin America. LGPD compliance is now real and active.

LGPD: Brazil's Privacy Law

LGPD is based on GDPR but has key differences.

Maximum fines: Up to 2% of Brazilian annual revenue. The cap is R$50 million (≈€9M) per violation. GDPR uses global revenue at 4%. LGPD's Brazil-only basis means lower caps for multinationals. But it means higher relative risk for Brazil-only companies.

Sensitive categories: LGPD's list is close to GDPR Article 9. It covers race, political views, religion, health records, genetic data, biometrics, and sexual orientation. The ANPD's 2024 guidance extended these rules under Article 11.

Data subject rights: People can access, correct, delete, and port their records. They can also ask about data sharing. LGPD adds one right not in GDPR: the right to know if AI was used in a decision about them.

Enforcement start: ANPD issued first sanctions in 2024. Main targets were telecoms, financial firms, and healthcare providers. Multinationals in Brazil are the 2025 focus.

For a broader view, see our guide on global PII compliance.

Brazilian PII Identifiers

Brazil's ID system is complex. It is a federal republic. Some documents vary by state.

CPF: An 11-digit taxpayer number (format: XXX.XXX.XXX-XX). It has two check digits using modular math. The CPF is Brazil's main ID for banking, tax, health, and government. All 215 million Brazilians have one.

CNPJ: A 14-digit company number (format: XX.XXX.XXX/XXXX-XX). It has two check digits. It appears in business records tied to company officers.

RG: A state-issued civil ID card. Format varies by state. São Paulo's RG differs from Rio de Janeiro's, and so on across 26 states plus the Federal District. A tool that only knows one state's format will miss most Brazilian RG numbers.

CNH: An 11-digit driver's license number with one check digit.

Título de Eleitor: A 12-digit voter ID. It encodes the voter's registration zone.

PIS/PASEP: An 11-digit social program number. It appears in payroll and employment records.

SUS number: A 15-digit health system ID. Every Brazilian has one. It appears in all health documents.

Our global PII identifier guide covers CPF next to SSN, Aadhaar, and other national IDs.

LGPD vs. GDPR: Key Differences

Both frameworks protect personal records, but they differ in important ways.

Legal bases: LGPD has 10 legal bases. GDPR has 6. LGPD includes "protection of credit" — a basis tied to Brazil's fintech culture. No GDPR match exists for this.

No EU adequacy for Brazil: The EU has not given Brazil an adequacy decision. EU–Brazil transfers need Standard Contractual Clauses or Binding Corporate Rules — the same as for the US.

Consent rules: LGPD consent must be specific, informed, free, and clear — much like GDPR. For sensitive records, LGPD allows broader consent than GDPR's per-purpose standard, as long as the purpose is stated.

ANPD's 2025 Enforcement Focus

ANPD has published its 2025 priorities based on 2024 case outcomes.

Healthcare Records

Article 11 requires explicit consent — or a clear legal basis — to process health records. ANPD found many healthcare apps and providers lacked this basis for SUS numbers and medical files.

Financial Services

CPF numbers in loan files, credit reports, and insurance policies are top targets. ANPD is checking whether retention periods match stated purposes.

Tech Platform Compliance

Social media, e-commerce, and streaming platforms in Brazil are a 2025 focus. ANPD is looking at profiling and cross-border transfers.

What to Do Now

The baseline for Brazilian compliance is CPF and CNPJ detection with check-digit validation. Add RG detection with per-state format logic. Include CNH, Título de Eleitor, and SUS number support for full coverage. See our LGPD anonymization guide for step-by-step detail.

When This Approach Has Limits

Building from CPF and CNPJ check-digit validation out to RG, CNH, Título de Eleitor, and SUS coverage is the correct baseline for LGPD, but limits remain worth stating plainly.

The RG is the format that defeats one-size-fits-all detection. CPF carries two modular check digits and CNPJ two more, so both can be validated reliably. The RG cannot: it is state-issued and its layout varies across 26 states plus the Federal District, so a tool that knows only Sao Paulo's format will miss most Brazilian RG numbers. The 15-digit SUS number, 12-digit Titulo de Eleitor, and 11-digit PIS/PASEP each need their own logic too. Detection accuracy bounds the result, so configure and run held-out testing per identifier class against real documents; the residual false-negative rate, especially on RG, is the number that governs your actual risk.

The ANPD audits the organization, not a tool. Brazil's first major LGPD fines in 2024 hit telecoms, financial firms, and healthcare providers over legal basis, retention periods, and consent, not over the absence of a detection feature. Detection software supports compliance but does not constitute it. Article 11 requires explicit consent or a clear legal basis for health records, and the regulator weighs your whole posture, including the LGPD right to know whether AI was used in a decision. Human and legal review remain part of that posture; no tool discharges it on its own.

Direct-identifier removal can still leave pseudonymized data. Strip the CPF and SUS number and quasi-identifiers such as birth date, municipality, and diagnosis can re-identify a person in combination, particularly in the financial and healthcare files the ANPD prioritized for 2025. Pseudonymized data remains within LGPD scope, with the legal consequences that distinction carries. Test whether the output resists re-identification rather than assuming that deleting the obvious numbers finished the work.

Sources

Ready to protect your data?

Start anonymizing PII with 267+ entity types across 48 languages.

About this page

We update this page when our platform or the law changes.

Read our founder note for how we work.

Each change shows up in the timestamp at the top.

We follow these rules

  • GDPR (EU 2016/679).
  • ISO/IEC 27001:2022.
  • NIS2 (EU 2022/2555).
  • HIPAA safe harbor under 45 CFR § 164.514(b)(2).

Our promise

We do not sell your data.

We do not train models on your text.

We store your files in Germany.

You can delete your account at any time.

You own your work.

Where we run

Our company HQ is in Saarbrücken, Germany. Our servers run in Hetzner's Falkenstein datacenter.

Hetzner holds ISO 27001 certification.

All data stays in the EU.

Backups run every day.

Need help?

Email support@anonym.legal.

We reply within one business day.

How we test

We run a full check suite on every release.

Each surface gets its own sweep script and report.

Human reviewers spot-check the output each week.

We track recall and precision on a labelled set.

Bad runs block the deploy.

What we never do

  • We never sell your information to third parties.
  • We never train models on what you upload.
  • We never keep your work after you delete it.
  • We never share keys with any outside firm.
  • We never run ads inside the product.

Plans in plain words

We sell credits, not seats.

One credit covers one short job.

Long jobs use a few credits each.

You can top up at any time.

Unused credits roll over each month.

Read the plans page for current rates.

Who built this

A small team of engineers and lawyers built this.

We ship from Europe and work in the open.

Our founder note spells out why we started.

Where to start

How the parts fit

A browser add-on cleans text inside Chrome.

A Word plug-in handles drafts in Office.

A small desktop tool works on whole folders.

An agent protocol link feeds large models safely.

All four share one core engine and one rule set.

Words from our team

We started this work after a lunch about cookies.

One friend kept getting odd ads on her phone.

We asked why a court file leaked through a draft.

We sketched the first build on a napkin that week.

By month three we had a tiny demo for a friend.

She used it on her first case the next day.

Common questions we hear

Can the tool read scanned PDFs? Yes, with OCR.

Does it work on long files? Yes, in small chunks.

Can I roll my own rule set? Yes, save it as a preset.

Does it run offline? The desktop build runs offline.

Do you keep my files? No, the cloud build wipes after each run.

Will it learn from my work? No, we never train on inputs.

A short tour of the workflow

Upload a file or paste a snippet of prose.

Pick the entities you want gone from the draft.

Choose a method: replace, mask, hash, encrypt, or redact.

Press run and watch the side panel show each hit.

Skim the result and tweak any rule that misfired.

Save the cleaned file or send it to a teammate.