Insights

ANPD Monitors DPO Appointments and Data Subject Communication Channels

The Brazilian National Data Protection Authority (ANPD) has completed the first phase of two monitoring proceedings aimed at assessing compliance with obligations related to the appointment of Data Protection Officers (DPOs) and the availability of communication channels for data subjects.

A total of 56 data processing agents were monitored, including 39 public authorities and 17 private companies.

According to the results released by the Authority, 27 organizations fully complied with the requests, eight still had outstanding compliance issues, and 21 failed to respond to the requests submitted during the monitoring process.

The list of organizations that did not respond was forwarded to the ANPD’s General Coordination for Sanctions. This department will review the cases and determine which measures should be adopted, including the possible initiation of administrative sanction proceedings.

The referral, therefore, does not constitute an advance finding of liability or the automatic imposition of penalties.

What is the ANPD monitoring?

The monitoring proceedings focus on two obligations directly related to transparency and the exercise of data subject rights:

  • The appointment of a Data Protection Officer;
  • The availability of an accessible and appropriate communication channel.

The DPO acts as a communication channel between the controller, data subjects, and the ANPD. The role also includes providing guidance to employees and supporting the organization on matters related to data protection practices.

The monitoring seeks to verify whether this structure has been formally established and whether it operates effectively in practice.

Who is required to appoint a DPO?

Under the Brazilian General Data Protection Law (Lei Geral de Proteção de Dados – LGPD), controllers are required to appoint a Data Protection Officer. For processors, the appointment is optional and may be regarded as a good governance practice.

Specific exemptions apply to certain small-scale data processing agents. However, such exemptions do not automatically apply to every company classified as a small organization.

Organizations carrying out high-risk processing activities or exceeding applicable regulatory thresholds may remain subject to the obligation to appoint a DPO. Even when exempt from appointing a DPO, a small-scale processing agent must maintain a communication channel for data subjects.

The assessment should therefore take into account the organization’s size, business model, volume of processing activities, nature of the data processed, and the risks involved.

How should the appointment be formalized?

The appointment of the DPO must be made through a formal act.

According to ANPD guidance, this act consists of a written, dated, and signed document clearly demonstrating the organization’s intention to appoint a natural person or legal entity to perform the role.

In the private sector, the appointment may be formalized through a contract, private instrument, amendment, or another document appropriate to the organization’s corporate and employment structure.

This document does not necessarily need to be published on the organization’s website or submitted to the ANPD in advance. However, it must be retained by the organization and presented to the Authority when requested during an inspection or monitoring procedure.

Public authorities and entities must also comply with the applicable transparency and publication requirements governing administrative acts.

What information must be publicly disclosed?

In addition to the formal appointment, the identity and contact details of the DPO must be publicly disclosed in a clear and objective manner.

When the DPO is a natural person, at a minimum, their full name must be disclosed.

When the role is performed by a legal entity, the following information must be made available:

  • Corporate name or trade name;
  • Full name of the natural person responsible for the role;
  • Contact information enabling effective communication.

The ANPD recommends that this information be published prominently and in an easily accessible location on the controller’s website. If the organization does not maintain a website, other communication channels commonly used in its relationship with data subjects may be adopted.

It is not advisable to limit this information to a poorly visible footer, a lengthy document, or a privacy policy that is difficult to locate.

Is publishing an email address sufficient?

Publishing an email address alone does not fully satisfy the organization’s obligations.

The communication channel must operate effectively and allow for:

  • Receipt of data subject requests;
  • Internal routing of requests;
  • Verification of the requester’s identity;
  • Monitoring of applicable deadlines;
  • Recording of responses provided;
  • Receipt of communications from the ANPD;
  • Replacement of the DPO during periods of absence or unavailability.

ANPD guidance itself clarifies that an email address constitutes contact information, but does not replace the requirement to disclose the identity of the DPO.

A webpage that only states “DPO contact,” without identifying the natural person or legal entity responsible for the function, may not fully comply with regulatory requirements.

What were the monitoring results?

Organizations that fully complied with the ANPD’s requests included OpenAI, Shopee, XP Investimentos, Natura, Hotmart, Grupo Casas Bahia, and Méliuz.

At the time of the disclosure, Google Brasil and iFood were among the organizations with outstanding compliance matters. These organizations were granted ten business days from the date of notification to address the issues identified.

The 21 organizations that failed to respond were referred to the sanctions department for review and determination of the appropriate measures.

The selection of monitored organizations was based on information obtained from an audit conducted by the Brazilian Federal Court of Accounts (Tribunal de Contas da União – TCU), requests submitted by data subjects, complaints, petitions, and previous requests issued by the ANPD that had remained unanswered.

The Authority also stated that it prioritized larger controllers, taking into account the volume of data processed and the scope of their activities.

What are the risks for organizations?

Failure to appoint a DPO when required may constitute non-compliance with the LGPD and ANPD regulations.

Other factors that may create compliance risks include:

  • Absence of a formal appointment document;
  • Outdated information on the organization’s website;
  • Disclosure of only an email address without identifying the DPO;
  • Communication channels that fail to receive or properly route requests;
  • Lack of a replacement during periods of absence;
  • Failure to maintain records of requests;
  • Failure to respond to official ANPD communications;
  • Inconsistencies between publicly disclosed information and internal documentation.

Failure to respond to requests from the Authority may lead to further regulatory scrutiny and the potential initiation of administrative sanction proceedings.

How can organizations review their compliance?

Organizations may begin their assessment using an objective checklist.

  1. Confirm whether appointment is mandatory
    The organization should determine whether it acts as a controller, whether any exemption applies, and whether it carries out processing activities classified as high risk.
  2. Locate the formal appointment document
    The appointment document should be current, dated, signed, and stored in an accessible location in case it is requested by the Authority.
  3. Review publicly disclosed information
    The organization’s website should clearly and prominently identify the DPO and provide appropriate contact information.
  4. Test the communication channel
    Periodic testing should be conducted to confirm that messages are being received, properly routed, and answered.
  5. Define internal responsibilities
    The relevant departments should understand who is responsible for receiving, reviewing, and responding to each type of request.
  6. Maintain records
    Requests, communications, deadlines, decisions, and responses should be documented to demonstrate the effectiveness of the compliance program.
  7. Prepare for replacement
    The absence or unavailability of the DPO must not prevent data subjects from exercising their rights or interfere with communication with the ANPD.

Regulatory monitoring reflects increasing enforcement maturity

The monitoring initiative demonstrates that regulatory oversight is moving beyond general guidance toward the practical verification of the structures implemented by organizations.

In this context, having policies or institutional documents in place is not sufficient. Companies must be able to demonstrate that their governance structures operate effectively, that communication channels remain active, and that requests are handled in a traceable manner.

PDK Advogados’ Privacy, Data Protection, and Cybersecurity practice advises on governance structures, DPO activities, data subject communication channels, and responses to regulatory monitoring and enforcement proceedings.

Conteúdo relacionado

CazéTV Case Highlights the Importance of Preventive Trademark Registration

Senacon Investigates Transparency Practices on Digital Ticket Resale Platform

Healthcare Institutions Must Balance Medical Confidentiality, Patient Privacy, and Family Members’ Rights

MENU