In June of this year, Brazil’s National Data Protection Authority (ANPD) opened an administrative enforcement proceeding against Claro, one of the country’s largest telecom carriers, over the sharing of customer data with Serasa, the largest credit bureau in Latin America.
Claro Brazil is one of the three largest telecommunications operators in Brazil, alongside Vivo and TIM. It is controlled by América Móvil, the Mexico-based telecom group owned by Carlos Slim. Claro provides mobile, fixed-line, broadband, and pay-TV services to more than 75 million subscribers in Brazil.
Serasa (Serasa Experian) is the largest credit bureau in Brazil and Latin America, majority-owned by Experian, the London-listed global credit reporting group. It maintains credit files on more than 200 million Brazilian consumers and supplies credit scoring, fraud prevention, and collections analytics to nearly every major bank, retailer, and lender in the country.
According to Fabrício Guimarães, the ANPD’s Superintendent of Enforcement, Claro had transferred more than one hundred pieces of information per customer under a partnership that, in the Authority’s view, violated the principles of necessity, transparency, and purpose limitation set out in Brazil’s General Data Protection Law (LGPD). The fine could reach $50 million Brazilian Real per infraction (roughly $9 million) or 2 percent of the company’s revenue, whichever is greater. Serasa was also notified and faces a parallel supervisory proceeding.
The case is emblematic of a turning point. For almost five years, the ANPD operated in what was essentially educational mode, issuing guidance, warnings, and very few fines. That period is over. In February 2026, with the conversion of Provisional Measure 1.317/2025 into Law 15.352, the ANPD became a full regulatory agency, with functional, technical, decisional, administrative, and financial autonomy. It now has six superintendencies, including a dedicated Enforcement Superintendency, and a permanent staff of 200 regulatory specialists hired through public examination. The Authority’s operational capacity has moved up a level.
For the American compliance officer dealing with Brazilian clients, suppliers, or users, understanding how this apparatus works is no longer optional.
How the ANPD reaches a company
Brazilian enforcement combines three vectors. The first is complaints and petitions from data subjects, which the ANPD receives through a public channel and processes in monitoring cycles. The second is the Priority Topics Maps, documents the Authority publishes every two years to identify the sectors and practices that will be targeted for proactive enforcement. The current Map, covering 2026 and 2027, focuses on four fronts: biometric data, health data, financial data, and the processing of children’s and adolescents’ data. The third is sector-wide sweeps, in which the ANPD opens simultaneous investigations against dozens of companies in the same segment. In December 2024, for example, it notified 20 large companies at once for failing to properly disclose their Data Protection Officer (DPO).
Once signs of an infraction are identified, the Authority opens a supervisory proceeding. The rules are set out in ANPD Board Resolution 1/2021, which defines the sequence: preparatory measures, requests for information, a possible preliminary order, and, where warranted, the initiation of an administrative enforcement proceeding. The company has ten business days to file a defense after being served. Failure to respond may be treated as obstruction and result in an additional penalty. When a case reaches the decision phase, the calculation of penalties follows ANPD Board Resolution 4/2023, which weighs factors such as the severity of the infraction, the economic benefit obtained, the cooperation of the offender, and the existence of a privacy governance program, according to a blog post by the firm Securiti AI.
What recent cases make clear
The ANPD’s trajectory so far sends consistent messages. The first monetary fine, imposed in 2023 against the small company Telekall Infoservice, was only R$14,400 (about U.S. $2,700), but it set two precedents that have been repeated in every decision since, according to a blog post by the law firm Hogan Lovells Cadwalader. Size is not immunity, and the absence of a Data Protection Officer is a standalone infraction, punishable on its own regardless of any other violations. Telekall was selling WhatsApp contact lists for political campaigns without any legal basis and without a DPO. It was sanctioned on both counts.
In 2025, in the case of Tools for Humanity, the entity behind the Worldcoin project, the ANPD imposed a preliminary order prohibiting the collection of iris scans in exchange for cryptocurrency in Brazil, with a daily fine of R$50,000 for non-compliance. The decision showed that the Authority is willing to halt active operations even before a ruling on the merits, when it sees a risk of mass impact on data subjects.
That same year, the State of Santa Catarina Health Secretariat was sanctioned over a leak of sensitive patient data from the public health system. The penalty included four warnings and a requirement to notify the affected data subjects directly. The case reinforces that the public sector is also on the radar and that health data sits among the most heavily protected categories under the LGPD, according to a blog post by the law firm Mayer Brown.
And now, the Claro and Serasa case adds a new layer. For the first time, the ANPD is openly challenging the logic of data-sharing arrangements between large private players, questioning the volume, the purpose, and the clarity of disclosures. The Enforcement Dashboard, launched in November 2025, makes these proceedings public in real time. Reputational damage begins before the final decision.
What multinationals operating in Brazil need to know
The LGPD has extraterritorial reach. It applies to any company, with or without a Brazilian subsidiary, that offers goods or services to individuals located in Brazil or processes data collected in the country. For a U.S. company, that means processing a Brazilian customer’s data from servers in Virginia is still under the ANPD’s jurisdiction. Complying with GDPR is not enough, even though much overlaps. The LGPD has its own regimes for legal bases, incident notification, the Data Protection Officer, and penalty calculation.
The good news for mature programs is that the Authority formally recognizes a compliance program as a mitigating factor in penalty calculation, provided it is documented and operational. The bad news is that the assessment is substantive. A privacy policy posted on the website, without a data mapping, without records of processing activities, and without a DPO who is actually doing the job, will not pass the test.
For American companies with any exposure to the Brazilian market, attention should be redoubled in light of this shift in the practical landscape. The ANPD is no longer an authority in formation. It has become a regulatory agency with the mandate, the structure, and the willingness to enforce.
Gustavo Aguiar is a municipal attorney in Brazil and the developer of Lici Govtech, an AI-driven platform for public procurement oversight. He specializes in bridging the gap between operational infrastructure realities and compliance frameworks like the U.S. FCPA and Brazil’s Anti-Corruption Law.
