By Cesar Augusto Taborda Lima
Before data subjects and the ANPD, Brazil’s National Data Protection Agency, the company answers: it is the controller, and what an employee does on the job is, in law, the company’s own conduct. The vendor answers when, acting as a processor, it departs from the law or from its instructions, or when it causes the damage itself. The employee faces labour consequences and, if the leak was deliberate, possible criminal liability. The ANPD must usually be notified within three working days, and what happens in that window matters almost as much as the mistake.
A controller or processor that, by reason of carrying out personal data processing activities, causes another person pecuniary, moral, individual or collective damage, in violation of personal data protection legislation, is obliged to make reparation for it.
Law 13,709/2018 (LGPD, Brazil’s General Data Protection Law), art. 42, caput (free translation).
Personal account or corporate contract
An analyst pastes the list of overdue customers into an AI assistant to draft collection letters. How the law reads that gesture depends on where it happens.
On corporate plans, major vendors state that they do not train on customer content by default and offer a data processing addendum. The vendor processes data on the company’s behalf and under its instructions, as an operador, the LGPD’s processor (arts. 5(VII) and 39). If it breaches the law or the controller’s lawful instructions, it is jointly liable and treated as a controller (art. 42, §1, I). When the approved tool is used for a legitimate purpose, there may be no incident at all.
On free or individual accounts the picture is reversed. The terms usually let the vendor use content to improve its models unless the user opts out, and make users responsible for what they enter. Deciding for its own purposes what becomes of that content, the vendor tends to act as an independent controller (art. 5(VI)). Client data has gone to a third party without instructions or contract and, if processed abroad, through an international transfer that hardly fits art. 33. That is a security incident under ANPD Resolution 15/2024: a confirmed adverse event breaching the confidentiality of personal data.
The company answers for what the employee did
The ANPD’s guidance on processing agents says employees are neither controllers nor processors: they act under the organisation’s direction, and the organisation answers for their acts before data subjects and the ANPD. The Civil Code agrees: an employer is liable for employees’ acts in the course of their work, even without fault of its own (arts. 932(III) and 933). Pleading a third party’s exclusive fault (LGPD, art. 43(III)) will be hard; the STJ, Brazil’s Superior Court of Justice, refused that defence to a company that could not prove a leak resulted exclusively from an outside attack (REsp 2.147.374/SP, 2024).
The absence of internal rules, approved tools and training weighs against the company: processing is irregular when it lacks the security a data subject can expect (arts. 6(VII), (VIII) and (X), 44 and 46).
On damages, the STJ draws a line. A leak of ordinary personal data does not give rise to presumed moral damages (AREsp 2.130.619/SP, 2023); a leak of sensitive data in a consumer relationship was held to cause presumed damage under strict liability (REsp 2.121.904/SP, 2025). ANPD sanctions range from a warning to a fine of up to 2% of revenue in Brazil, capped at BRL 50 million per infringement, and to a ban on processing (art. 52).
The employee
The employee is not a processing agent, yet the LGPD requires anyone involved in processing to keep information secure (art. 47). Under the CLT, Brazil’s Consolidation of Labour Laws, breach of company secrecy (art. 482(g)) and indiscipline (art. 482(h)) are grounds for dismissal for cause. As I see it, a good-faith mistake in a company with no AI policy will rarely justify that sanction; a written policy that staff know and were trained on changes the analysis. Deducting the loss from wages is lawful only with prior agreement or intent (CLT, art. 462, §1).
Law 9,279/1996, the Industrial Property Law, makes it a crime of unfair competition to disclose or use, without authorisation, confidential information obtained through employment (art. 195(XI)) or by unlawful means (item XII). The offence requires intent and is prosecuted only on the victim’s private complaint (art. 199); it reaches deliberate leaks, leaving aside the distraction of someone seeking help with work. Confidential documents without personal data fall outside the LGPD and are protected by contract, the CLT and that law.
The first hours and days
- Preserve evidence before deleting: export the conversation and note the date, account, plan and training setting.
- Contain: delete the conversation, switch off history and training, revoke access, change any pasted passwords, ask the vendor to erase the data. According to major vendors, opting out only works going forward.
- Assess what data, whose, and how many people. Notification is required when the incident may significantly affect data subjects’ interests and fundamental rights and involves sensitive data, data of children, adolescents or older people, financial or authentication data, data under legal, judicial or professional secrecy, or large-scale data (Resolution 15/2024, art. 5). Law firms, clinics and accountants often fall here.
- Bring in the data protection officer (the encarregado) and decide on notification. The ANPD and data subjects must be notified within three working days of the controller learning that personal data was affected (arts. 6 and 9); the ANPD filing goes through its SEI!ANPD system and may be supplemented within twenty working days. Small processing agents get twice the time, unless they carry out high-risk processing or their own or their group’s gross revenue exceeds the limits referred to in art. 3 of Resolution 2/2022. If the company holds the data as a client’s processor, the client, as controller, notifies (LGPD, art. 48) and should be told at once.
- Record the incident, even if not notified, and keep the record for at least five years (art. 10).
- Review contracts and assess the employee’s conduct proportionately.
Speed pays: under the sanctions dosimetry regulation (Resolution 4/2023, art. 13(I)(a)), a fine falls by 75% if the infringement ceases before the ANPD opens a preliminary proceeding.
Prevention
A short AI policy stating which tools are approved and which data may never be entered. Tools on corporate plans, with a data processing addendum, a no-training commitment, incident notice and, where data leaves Brazil, the ANPD’s standard contractual clauses (Resolution 19/2024). Training built on real cases: on one popular service, rating an answer may send the whole conversation to training even with training switched off. Single sign-on, blocking of unapproved services, and a record of these operations (art. 37). A good-practice and governance policy also cuts any fine by 20% (Resolution 4/2023, art. 13(II)).
The ANPD has placed artificial intelligence among its enforcement priorities for 2026 and 2027 (Resolution 30/2025). A company that merely prohibits pushes use into personal accounts, where it has no contract, no settings and no record; one that contracts well, trains and supervises turns the same gesture into ordinary processing.