Publications

ANPD reinforces the role of the Data Protection Officer and warns of risks in the processing of employees' personal data.

January 12, 2026

The National Data Protection Authority (ANPD) recently published new versions of Treatment Agents and Supervisor Guide, This document consolidates guidelines on the responsibilities of controllers, operators, and data protection officers (DPOs). It provides practical guidelines for compliance with the General Data Protection Law (LGPD) and reinforces the importance of privacy governance. For companies, the content serves as a warning: the processing of personal data, especially that of employees and candidates, requires heightened attention, under penalty of fines and administrative sanctions.

The new guidelines from the ANPD (Brazilian National Data Protection Authority) make it clear that compliance with the LGPD (Brazilian General Data Protection Law) is not limited to the formal existence of a data protection officer. This professional needs autonomy, training, and a channel of communication with data subjects and the ANPD itself. Furthermore, the guidelines provide guidance on how to correctly identify who is the controller (who decides on data processing) and who is the processor (who executes the controller's orders), avoiding contractual gaps and confusion of responsibility, situations that can result in fines, data blocking, or suspension of activities.

In the context of labor relations, the risk is even more significant. From recruitment to employee termination, companies collect and process a large amount of personal and sensitive data: resumes, pre-employment medical exams, health information, payroll, time records, digital monitoring, and performance history. The improper handling of this data, without a legal basis, valid consent, or security measures, may constitute a violation of the LGPD (Brazilian General Data Protection Law) and result in sanctions from the ANPD (National Data Protection Authority), as well as labor lawsuits seeking compensation for moral damages arising from data exposure.

The Brazilian National Data Protection Authority (ANPD) has already signaled that the excessive or unnecessary use of employee information will be subject to scrutiny. This includes practices such as the improper sharing of data with third parties, the maintenance of files without a defined timeframe, unauthorized access by managers, or the use of biometric data without an adequate legal basis. To prevent these risks, it is recommended that companies map the entire lifecycle of employee data, from recruitment to post-contract, define specific legal bases for each stage (such as compliance with legal obligations, contract execution, or legitimate interest), implement access controls, and establish internal policies for data retention and disposal.

Good practices include: limiting access to sensitive data to strictly necessary individuals; reviewing HR forms and systems to eliminate non-essential fields; ensuring that suppliers (accounting, benefits, occupational medicine) are also compliant with the LGPD (Brazilian General Data Protection Law); and formally documenting the actions of the data protection officer, guaranteeing their autonomy. After the termination of the employment relationship, only the data strictly necessary for compliance with legal and social security obligations should be retained, promoting the secure disposal of the remaining data.

The sanctions foreseen by the ANPD go far beyond fines, which can reach up to 2% of the company's revenue (limited to R$ 50 million per infraction). The Authority can order the blocking, deletion, or suspension of the use of databases, which, in practice, can paralyze entire sectors of the operation, impacting payroll, benefits management, and customer relations. Furthermore, the public disclosure of infractions, through public sanctions, directly affects corporate reputation and credibility, with labor and commercial repercussions.

Compliance with the LGPD (Brazilian General Data Protection Law) should be treated as an ongoing governance policy, not a one-off project. It is essential to involve HR, legal, and IT in building a robust privacy program, including data mapping, team training, contract review, and implementation of incident response protocols. Companies that demonstrate good faith and a proactive structure tend to receive more favorable treatment in ANPD (Brazilian National Data Protection Authority) audits, in addition to reducing the risk of labor lawsuits based on data leaks or improper disclosure of personal information.

The current situation demands that companies adopt a proactive stance regarding data protection. Our firm has a team specializing in LGPD (Brazilian General Data Protection Law), digital law, and corporate governance, prepared to assist companies in fully complying with ANPD (Brazilian National Data Protection Authority) guidelines, from risk mapping to the implementation of internal policies and training. Contact us and ensure your company is compliant, preserving its reputation and avoiding administrative and judicial sanctions.

If you have any questions about the topics covered in this publication, please contact any of the lawyers listed below or your usual Mazzucco&Mello contact.

Rafael Mello

+55 11 3090-9195

Israel Carneiro Cruz

+55 11 3090-9195

This communication, which we believe may be of interest to our customers and friends of the company, is intended for general information only. It is not a complete analysis of the matters presented and should not be considered legal advice. In some jurisdictions, this may be considered lawyer advertising. Please see the company's privacy notice for more details.

Related Areas

Related Professionals