On discovering a data breach, which regulators or other government agencies should be notified?
According to Law No. 13.709 of 2018 (Brazilian Data Protection Law), a personal data breach must be notified to the Brazilian Data Protection Authority (ANPD) when it involves personal data and is likely to result in relevant risk or damage to the data subjects.
This obligation arises from the principle of accountability and aims to ensure transparency and prompt action to mitigate potential harm.
The specific details regarding the notification process, including the content, deadlines, and procedures, are established by Resolution No. 15/2024, published by ANPD on April 24, 2024.
In addition, depending on the company's industry and the nature of the data involved, other authorities may require notification, such as the Consumer Protection Officer (PROCON), in situations affecting consumers, and the Central Bank of Brazil (BACEN), in incidents involving financial data and operations.
With regards to cybercrimes, the police should be notified whenever a cybercrime related to data protection occurs.