# Breach Notification Template — Brazil (LGPD, ANPD)

Template id: `breach-notice-anpd-br.v1` owner: Lilith-Privacy lead + BR
counsel deadline: **3 working days** from knowledge of the incident (ANPD
Resolution CD/ANPD No. 15/2024) submission: ANPD's electronic breach
communication system, in Portuguese

Affected data subjects (titulares) are notified in the same window, in
pt-BR, when the breach may create relevant risk or damage.

## Required content (LGPD Art. 48 §1 and ANPD regulation)

1. **Controller and encarregado (DPO)**: identification and contact, matching
   the pt-BR privacy policy controller block (legal-docs publication gate
   supplement).
2. **Description of the nature of the affected personal data**.
   - V3 data-class checklist: V1 account records / e-mail addresses / payment
     metadata / voice transcripts / recordings / consent-ledger entries /
     DSAR exports / Pixel Streaming session logs (IP addresses).
3. **Affected data subjects**: approximate number of Brazil-resident users;
   flag children/adolescents separately (heightened LGPD treatment).
4. **Risk assessment**: why the incident may (or may not) cause relevant risk
   or damage to data subjects.
5. **Technical and security measures** used before and after the incident
   (encryption-at-rest state of the affected stores is material here).
6. **Timeline**: occurrence, detection, knowledge (3-working-day clock
   anchor), and reasons for any delay.
7. **Measures taken or to be taken** to reverse or mitigate the effects.
8. **Communication plan to data subjects**: content, channel, and date.

## Internal routing

- Drafted by: Lilith-Privacy lead with BR counsel; the pt-BR user notice is
  produced by the localization owner from the counsel-approved Portuguese
  master, never machine-translated unreviewed.
- Evidence: submitted communication, ANPD protocol number, and timestamps in
  the incident evidence bucket, referenced from the Operator Console case.
