On the 14th of this month, the General Data Protection Law completed 4 years since its enactment. It was in 2018 that President Michel Temer signed the law, which was immediately published. Since then, much has been said about this regulation, which has placed Brazil among the countries most committed to the protection of personal data.
The law, which was approved in 2018, only came into effect in 2020, and its sanctions only began to apply in 2021. However, much happened during this period. Check out the main developments of the regulation below.
Key advancements in the Brazilian data protection landscape.
- Approval of LGPD: on August 14, 2018.
- The LGPD (Brazilian General Data Protection Law) came into effect on September 18, 2021.
- On December 27, 2018, it was created National Data Protection Authority (ANPD), which was initially linked to the federal government, but since the enactment of Provisional Measure 1.124/22, the Authority has gained the status of special authority, a measure that ensured the ANPD (National Data Protection Authority) had the same degree of autonomy as bodies such as the Central Bank, Anvisa (National Health Surveillance Agency), and Anatel (National Telecommunications Agency);
- In August 2021, the twenty-three members of the National Data Protection Council were appointed (CNPD;
- In February of this year, the LGPD (Brazilian General Data Protection Law) was recognized by the Supreme Federal Court as... fundamental right by Constitutional Amendment 115, which included item LXXIX in article 5 of the Constitution.
Statistics on the data protection landscape during this period.
A study by the company Surfshark The report showed Brazil in 4th place in the ranking of countries that suffered the most security breaches. during the second quarter of 2022, and 1st among all countries in South America.
This same study showed that 3,2 million Brazilian users experienced data breaches – a 771% increase compared to the first quarter – and, in addition, in the global ranking, although Russia leads with 28,8 million breached users, followed by India with 4,4 million and China with 3,4 million, Brazil comes in fourth place – surpassing the USA – with 2,3 million.
According to Agneska Sablovskaja, data researcher at Surfshark: "Across South America, the average person has been affected by data breaches at least once. However, in Brazil, these statistics are even higher.", "The difference may be due to the user's online habits or data collection practices by various services or applications. The high number of affected accounts shows that more needs to be done regarding online data protection."
A study conducted by the Massachusetts Institute of Technology (“MIT”) and published in the ACM Journal of Data and Information Quality showed that There was a 493% increase in data breach statistics in Brazil.
These statistics demonstrate that there is still much to be done. There have been many developments in the process, and currently, expectations are focused on when the ANPD (National Data Protection Authority) will actually be able to apply the appropriate sanctions to data violations that have plagued our country.
The expectation is that by the end of the year, the bureaucratic issues that are currently preventing our regulations from being implemented will be resolved.



















