Posting a Notice Isn't Notifying: What the ANPD Requires in a Breach Communication
A healthcare organization reported a data breach to the ANPD and posted a notice on its own website. The Authority opened a sanctioning proceeding anyway — because the duty to notify has content and a channel defined by regulation, and neither is the controller's to choose.

▸In this article
On 8 July 2026, the ANPD opened an administrative sanctioning proceeding against Instituto Saúde e Cidadania, a social organization that manages public health facilities across six states. The incident was a ransomware attack in 2025 affecting roughly 500,000 records — among them, according to figures reported by the organization itself, approximately 78,772 belonging to children and adolescents and 47,921 to elderly individuals.
The organization did report the incident to the ANPD. And it is facing a proceeding all the same.
That is the point that matters to anyone working in incident response. What the Authority is examining is not the breach itself — it is the conduct that followed.
What is under investigation
According to the ANPD, the proceeding covers four fronts: failure to adopt adequate technical and administrative security measures, inadequate communication to affected individuals, failure to make information about the data protection officer available, and breach of the principles of prevention and accountability.
Three of those four have nothing to do with the attack. They have to do with what was done about it.
On the communication, the Authority notes that the organization did not notify data subjects individually: it published a notice on its institutional website, and that notice did not state the date of the incident, the nature of the data, who was affected, or the measures taken.
A point of precision: the proceeding is still at the investigative stage. Nothing has been decided, and the Instituto has the right to present a defense. The sanctions provided for in art. 52 of the LGPD — warning, fine of up to 2% of revenue, suspension or prohibition of processing activities — are what may come at the end, not what has happened.
What has already been settled, regardless of how this case turns out, is the standard. It has been on the books since 2024.
The duty to notify has substance
The Security Incident Communication Regulation, approved by Resolução CD/ANPD nº 15 of 24 April 2024, separates two communications that are routinely treated as one.
To the ANPD (art. 6): three business days from becoming aware that the incident affected personal data, with twelve mandatory items of information — among them the number of affected data subjects, broken out by children, adolescents and the elderly. That information may be supplemented, with justification, within twenty business days.
To the data subject (art. 9): the same three-business-day deadline, with seven mandatory items:
- nature and category of the personal data affected;
- technical and security measures used to protect the data;
- risks arising from the incident, including possible impacts;
- reasons for the delay, if the communication missed the deadline;
- measures taken or to be taken to reverse or mitigate the effects;
- date on which the incident became known;
- a contact point for further information and, where applicable, the DPO's details.
With items missing, the communication exists as an act but does not serve its purpose. That is why "we notified" does not settle the matter: the rule does not ask whether a notice was issued, it asks what the notice contained.
The channel is an obligation too, not a preference
Here is the part most often gotten wrong in practice.
Art. 9, § 1, II requires that communication to the data subject be direct and individualized whenever the individual can be identified. Paragraph 2 defines what that means, leaving no room for interpretation: the channels the controller already uses to reach that person — telephone, email, electronic message or letter.
A website notice is plan B. Paragraph 3 allows it only where direct communication proves unfeasible or where the affected individuals cannot be identified, in whole or in part. And even then it is not a lighter version of the duty: it must go out within the same deadline, with the same information listed in the main provision, and remain online in a directly and easily visible position for at least three months.
The distinction carries more weight in some sectors than others. A health network has patient records — the registry that would make direct communication possible is generally the very one that was compromised. Claiming an inability to identify data subjects whose data you know precisely is a difficult position to sustain.
And the regulation anticipated the outcome: under art. 19, § 3, where the communication made by the controller proves insufficient to reach a significant share of those affected, the ANPD may order broad disclosure of the incident through media outlets — at the controller's expense. The discreet notice in the website footer is not the end of the story; it is the beginning of a more expensive one.
Three business days is not a drafting problem
The clock runs from awareness that the incident affected personal data — not from the conclusion of forensics, not from the end of negotiations with the attacker, not from legal's opinion.
That means the communication has to be born with the nature of the data, the identified risks and the measures taken already in hand on day three, when little is yet known. Anyone who reaches that point having preserved nothing does not have a drafting problem: they have an incident response problem, and it has already occurred.
It is the same logic that applies to a fraud victim — what decides the case is what gets preserved in the first few hours, by someone who does not yet know they will need it.
The regulation reinforces this from another angle. Art. 10 requires the controller to keep a record of the incident for at least five years, including incidents that were not reported to the ANPD or to data subjects — and the record must state the reasons for the absence of communication. Deciding not to notify is a decision the rule requires you to document and retain.
Why 2026 changes the stakes
The yardstick has existed since 2024. What changed this year is the capacity to apply it.
Lei nº 15.352 of 25 February 2026 converted the ANPD into an autarquia of special nature, with technical, decision-making, administrative and financial autonomy, and created its own career track of data protection regulation specialists, filled by public examination. An authority with a permanent structure enforces differently from one that depended on seconded staff.
Anyone who treated the 2024 Regulation as text without practical consequence is betting against that shift.
In one line
Reporting an incident is not publishing a notice: it is notifying every identifiable data subject, through the channel you already use with them, within three business days, with the seven items the rule lists. The website is a conditional exception — and the exception has its own minimum content and deadline.
Sources
- ANPD, instauração de processo administrativo sancionador, 08/07/2026 — proceeding no. 00261.003381/2026-55.
- Resolução CD/ANPD nº 15, de 24 de abril de 2024 — Security Incident Communication Regulation.
- Lei nº 15.352, de 25 de fevereiro de 2026 — legal status of the ANPD.
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/analysis/posting-a-notice-isnt-notifying-what-the-anpd-requires-in-a-breach-communication
Retrieved on