← all writing
análise09 Jun 2025

LGPD/ANPD: 2025: Review H1, Public Cases, Proposed Agenda

#VCIA | Brito \ 08-06-2025 \ 18:06 (Sun.) The Brazilian General Data Protection Law (LGPD) is in the regulatory evolution phase in 2025, with the National Data Protection Authority (ANPD)…

cover image

#VCIA | Brito \ 08-06-2025 \ 18:06 (Sun.) The Brazilian General Data Protection Law (LGPD) is in the regulatory evolution phase in 2025, with the National Data Protection Authority (ANPD) intensifying its enforcement action and developing new regulations on priority topics such as biometric data and children's data protection, while organizations seek effective strategies to navigate through the official guides, international frameworks such as GDPR and NIST, and emblematic cases such as Worldcoin that highlight the complexity of regulatory compliance in Brazil.

Intensification of Inspection (Compliance / Due Dilligence)

In the first half of 2025, the ANPD consolidated its position as a supervisory body, intensifying its monitoring and enforcement actions. As predicted in previous reports, the authority has significantly expanded its scope of action, with a special focus on strategic sectors such as health, finance and technology.1 This intensification occurs in the context of the celebration of the authority's four years of activity, a period in which the institution presented a positive balance of deliveries and regulatory advances.

[1](https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-comemora-4-anos-com-balanco-positivo-das-entregas-e-promessa-de-avancos-na-regulamentacao

Priority Themes H2/2025 - 2026

The ANPD's third regulatory agenda for the 2024-2025 biennium established clear priorities that have guided inspection actions in the first half of the year. Among the most prominent topics are:

- Artificial Intelligence and Data Protection: The authority has initiated specific analyses on the impact of AI systems on the processing of personal data, with guidelines expected to be published by the end of 2025 [3 Fonte: Deliberações do Conselho Diretor 2025](https://www.gov.br/anpd/pt-br/assuntos/deliberacoes-do-conselho-diretor-1/circuitos-deliberativos-ano-2025/cd-10-2025-votos.pdf)

- Data Protection of Children and Adolescents: This topic received special attention, with regulatory activities scheduled for completion by the first half of 2025, including public consultations and institutional interactions. [4 Fonte: ANPD via Telesintese.com.br](https://www.telesintese.com.br/anpd-analisara-regras-sobre-ia-e-dados-de-criancas-entre-2024-e-2025/)

- Biometric Data: After the Worldcoin case, the ANPD intensified its supervision of companies that collect biometric data, establishing stricter criteria for validating consent and purpose of processing.

Emblematic Cases H1

The first half of 2025 was marked by cases of great repercussion that highlighted the ANPD's more assertive performance:

- Data Leak in Financial Institution: One of the largest financial institutions in the country suffered a penalty after an incident that exposed data from millions of customers. The ANPD imposed a significant fine and determined specific corrective measures, setting an important precedent for the sector.

- Health and Consent Apps: Several health monitoring apps have been notified for poor practices of obtaining consent and sharing sensitive data with third parties, resulting in conduct adjustment terms.

- Compliance with Preventive Measures: In February 2025, the ANPD's General Coordination of Supervision considered the preventive measures imposed on an organization to be timely complied with, demonstrating the effectiveness of the adequacy process when there is collaboration from processing agents. [5 Fonte: ANPD via Jabosconsultoria.com.br](https://www.jacobsconsultoria.com.br/post/prioridades-da-anpd-at%C3%A9-2025-incluem-tratamento-de-dados-pessoais-de-crian%C3%A7as-e-adolescentes-no-ambi)

ANPD Strengthening / Efforts

The necessary strengthening of the ANPD to ensure legal certainty in the Brazilian digital environment has been a recurring theme in sectoral discussions. The authority was tasked with preparing guidelines for the future National Data Protection and Privacy Policy (PNPD), currently under public consultation.

This process demonstrates the consolidation of the ANPD's role not only as a supervisory body, but also as a formulator of public policies for the sector. [6 Press: Netcpa.com.br](https://netcpa.com.br/colunas/noticia-como-a-anpd-vem-fiscalizando-a-lei-geral-de-protecao-de-dados-entenda/24365) 

Report and Outlook H1/2025

The report for the first half of 2024, published in September, already indicated the trend of intensification of inspection activities for 2025. 7 Source: ABES.com.br

The actions carried out in the first half of 2025 confirmed this forecast, with a significant increase in the number of administrative proceedings initiated and the application of administrative sanctions.

The ANPD's public agenda for June and July 2025, available on the authority's official portal and in the Official Diary Press, details the main inspection actions scheduled for the next two months, as well as strategic projections for 2026. This planning shows the continuity and intensification of regulatory activities, reinforcing the authority's commitment to the protection of personal data in the country.

* Official ANPD / LDPG Agenda: https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-publica-agenda-regulatoria-2025-2026

Case Worldcoin (TFH): Money

https://www.youtube.com/watch?v=PiYsybME1m4

The World ID Case: Iris Biometrics by Cryptocurrencies

The case of Tools for Humanity (TFH) and its World ID project has become emblematic in the data protection landscape in Brazil in 2025. The company implemented an iris scanning system that offered financial compensation in cryptocurrencies (WorldCoin) in exchange for the collection of this sensitive biometric data, attracting thousands of Brazilians who faced queues to participate in the process

The project claimed to aim to assist in differentiating between humans and artificial intelligences, using ocular biometrics to create a "global digital identity" [2 Fonte: Universidade Federal Fluminense - uff.br]

However, the practice has raised serious regulatory concerns, especially regarding the validity of the consent obtained. The ANPD began investigations in November 2024 and, in February 2025, suspended the offer of financial compensation for the collection of iris in Brazil. Subsequently, in March 2025, the authority maintained the ban and established a daily fine of R$ 50 thousand in case of non-compliance [3 Curadoria: conjur.com.br](https://www.conjur.com.br/2025-jan-21/coleta-de-dados-biometricos-oculares-no-brasil-implicacoes-juridicas-etica-e-riscos-a-privacidade/).

Legal and Ethical Issues

The case highlighted fundamental problems related to consent:

- Non-free consent: The offer of financial reward (which could reach R$ 700) compromised the freedom of consent, especially in contexts of economic vulnerability [3 Curadoria: conjur.com.br](https://www.conjur.com.br/2025-jan-21/coleta-de-dados-biometricos-oculares-no-brasil-implicacoes-juridicas-etica-e-riscos-a-privacidade/)

- Lack of transparency: Many participants did not fully understand the purposes of their iris treatment, limiting themselves to accepting the scan only to obtain the consideration [4 Curadoria: agenciabrasil.ebc.com.br](https://agenciabrasil.ebc.com.br/geral/noticia/2025-02/empresa-suspende-coleta-de-iris-de-brasileiros)

- Impossibility of revocation: There were reports about the difficulty of users in revoking consent after registration, a right guaranteed by the LGPD [5 Press: estadao.com.br](https://www.estadao.com.br/link/empresas/anpd-mantem-proibicao-de-pagamento-por-coleta-de-iris-da-world-id-e-impoe-multa-diaria-de-r-50-mil-nprei/)

The case is not isolated on the international scene. In countries such as Spain, Portugal, South Korea, and Argentina, similar services have been banned due to the lack of transparency about the processing and purpose of the data collected [5 Fonte: estadao.com.br](https://www.estadao.com.br/link/empresas/anpd-mantem-proibicao-de-pagamento-por-coleta-de-iris-da-world-id-e-impoe-multa-diaria-de-r-50-mil-nprei/). 

The ANPD's decision reinforced that the protection of sensitive biometric data requires exceptional rigor, especially when there are financial incentives that can compromise the autonomy of data subjects. [3 Curadoria: conjur.com.br](https://www.conjur.com.br/2025-jan-21/coleta-de-dados-biometricos-oculares-no-brasil-implicacoes-juridicas-etica-e-riscos-a-privacidade/).

Regulatory Limitations and Challenges

Despite the existence of official guides, studies from 2023 indicate that only 36% of Brazilian organizations are fully compliant with the LGPD, while 43% still implement adequacy measures. [Dados: SEC.gov]

The "umbrella" nature of the law establishes general rules, leaving room for specific interpretations and regulations by the ANPD. Esta característica, inicialmente vista como limitação, pode representar vantagem estratégica para inovações como IA, permitindo adaptação regulatória contínua sem necessidade de revisões legislativas complexas.

The ANPD faces the challenge of balancing strict oversight with clear guidance, having established administrative sanctions through Resolution No. 4 of February 2023, which may include fines of up to 2% of revenue (limited to R$50 million per infraction), warnings, partial suspension of databases, and even a total ban on processing activities [4 Analise: UFMS.br](https://lgpd.ufms.br/guias-e-documentos-tecnicos/).

Convergence with International Frameworks

LGPD Manual - Practices | Efforts

The convergence of the LGPD with international security and data protection frameworks represents a strategic approach for organizations seeking efficient and comprehensive compliance. This integration allows you to take advantage of already established and globally recognized structures, optimizing resources and strengthening the security posture.

LGPD-GDPR Alignment

The LGPD was heavily inspired by the European General Data Protection Regulation (GDPR), sharing similar core principles and frameworks. [1 Dados: SEC.gov](https://www.sec.gov/Archives/edgar/data/1432364/000162828025020401/azul-20241231.htm)

Among the points of convergence are:

  • Explicit consent for data processing

  • Definition of clear purposes for collection and use

  • Guarantee of rights to data subjects (access, rectification, deletion)

  • Obligation of adequate security measures

Despite the similarities, there are significant differences in the definitions of personal and sensitive data, processing mechanisms, and enforcement frameworks that need to be considered in international compliance strategies.

Complementary Security Frameworks

[4 Analise: UFMS.br](https://lgpd.ufms.br/guias-e-documentos-tecnicos/)

Integration with cybersecurity frameworks provides practical frameworks for implementing the technical requirements of the LGPD:

- NIST CSF (Cybersecurity Framework): Provides guidelines for identifying, protecting, detecting, responding, and recovering from security incidents, complementing the requirements of the LGPD regarding technical and administrative measures

- CIS Controls: Presents prioritized and actionable security controls that can be implemented to mitigate risks of data breaches, aligning with ANPD requirements on technical security measures

- ISO 27001/27701: Provides framework for Information Security and Privacy Management System, facilitating the demonstration of compliance with the organizational requirements of the LGPD

Benefits of the Integrated Approach

The convergence of frameworks offers significant advantages for organizations:

  • Operational efficiency: Avoids duplication of effort by unifying controls that meet multiple regulations

  • Holistic view of risks: Allows for a comprehensive approach that considers both legal and technical requirements

  • Compliance demonstration: Facilitates evidence of compliance with the LGPD through internationally recognized frameworks

  • Regulatory adaptability: Provides flexible structure that can be adjusted as new ANPD regulations are published.

Practical Implementation

To implement a converged approach, it is recommended to:

  1. Cross-mapping between LGPD requirements and controls of the adopted frameworks

  2. Prioritize implementation based on risk and impact analysis

  3. Document evidence of compliance in a structured manner

  4. Establish a continuous monitoring program in line with regulatory updates

  5. Designate those responsible for monitoring developments in both the LGPD/ANPD and international frameworks

Based: [7 GOV.br] || [8 SEC.gov]

Next Steps 2025 / 2026

The second half of 2025 and early 2026 will represent a decisive period for data protection in Brazil, with the ANPD consolidating its regulatory authority and broadening its scope to emerging technologies such as artificial intelligence, biometric data processing, and special protection for data of minors6. Organizations that adopt convergent compliance approaches will have a significant competitive advantage, adapting quickly to new requirements through already implemented controls and international frameworks.

The experience of multinationals such as XP Inc. and Nu Holdings demonstrates the strategic value of the designation of DPOs and specialized teams, as well as the implementation of complementary frameworks to efficiently navigate the complex Brazilian regulatory environment that will intensify in this period, especially for companies operating with cutting-edge technologies and massive processing of personal data.

Fontes: [6 gatefy.com - GDPR] || [9 FURG.br - LGPD] || [8 SEC.gov - FORM 20-F]

Compliance Strategies

The intensification of the ANPD's performance in 2025 requires organizations to adopt robust strategies to ensure compliance with the LGPD. Among the most effective approaches are the implementation of privacy governance programs, the designation of data protection officers (DPOs), regular internal audits, and the use of specialized technologies.

Documentation and Internal Controls

Efficient document management has become a key pillar for compliance, requiring the secure storage of consent forms, contracts, and privacy policies 1. In 2025, the ANPD is making it mandatory to have a stricter control of documentation related to data processing, which requires automated systems for tracking and auditing.

Source: SEC.gov || Case: ([1 Azul Linhas Aéreas] https://www.sec.gov/Archives/edgar/data/1432364/000162828025020401/azul-20241231.htm))

Organizations should keep detailed records of processing activities, including:

  • Legal basis used for each transaction

  • Specific purpose of the processing

  • Security measures implemented

  • Procedures to meet the rights of data subjects

Incident Response and Transparency

With increased enforcement, preparedness for incident response has become crucial. In the event of a data leak, companies must quickly notify the ANPD and the affected data subjects, following established protocols.

Transparency in communications and the implementation of immediate corrective measures are essential to mitigate penalties that can reach 2% of revenue, limited to R$50 million per infraction.

Investment in Technology and Automation

Automation in document control emerges as an effective strategy to ensure continuous compliance. Specialized tools enable centralized document management, ensuring organization, accessibility, and protection against unauthorized access 1.

Companies like XP Inc. have invested in teams specialized in privacy and personal data protection to oversee compliance with the LGPD 3.

Training and Organizational Culture

The human factor remains crucial to the success of compliance strategies. Training and awareness programs for employees reduce the risk of errors and strengthen the culture of data protection1.

Multinational companies like Nu Holdings have been implementing comprehensive measures, including the designation of DPOs and specialized teams to oversee compliance2.

Continuous Monitoring and Adaptation

Conducting periodic audits to evaluate data processing processes and identify vulnerabilities has become an essential practice1.

Continuous monitoring allows for quick adjustments as new regulations are published by the ANPD, whose 2025-2026 agenda includes topics such as biometric data, protection of children and adolescents, and technical security measures.

The adoption of these integrated strategies not only avoids administrative sanctions, but also strengthens the trust of data subjects, transforming compliance with the LGPD from a regulatory obligation into a sustainable competitive advantage.

vNext

"I hope to soon bring more information about the next steps, certain that we are still far from an outcome. This article aims to bring to the public a vision of hope about the advances and opportunities that lie ahead, where policies seen as restrictive have the potential to become strategic, not restricted to Brazil alone. Perhaps this is a great opportunity to make the Brazilian way an indispensable asset for the next stages of this journey!"

Regards, Brito