Organisations should first classify the violation as minor, average, or severe, because that classification drives the sanction range and the later fine calculation. The ANPD looks at the offense’s effect on data subjects, the scale and duration of processing, whether sensitive or children’s data is involved, and whether the conduct was unlawful, discriminatory, or obstructed inspection.
What “minor, average, or severe” means in LGPD enforcement
The classification step is not a formality. It is the legal and practical bridge between the underlying violation and the administrative fine range, so organisations need to treat it as a structured assessment of harm, scope, and conduct rather than a subjective label. The ANPD’s view of severity is driven by the effect on data subjects and by aggravating or mitigating facts that change enforcement intensity.
In practice, that means the same unlawful processing event can land in different buckets depending on who was affected, how long the processing continued, whether the processing involved sensitive or children’s data, and whether the behaviour suggests disregard for lawful processing duties. The classification therefore determines the starting point for the sanction analysis, not just the final number.
Which facts usually move an LGPD case up or down
The classification commonly turns on a small set of material facts: the scale of the processing, its duration, the type of data involved, and the effect on rights or interests. A short-lived, low-impact incident may be treated differently from conduct that affected many data subjects or persisted after notice. Likewise, processing of sensitive or children’s data tends to increase seriousness because the potential harm is greater.
Conduct matters as much as impact. Unlawful processing, discriminatory use of data, or behaviour that obstructs inspection suggests a worse compliance posture and can push the violation toward a harsher category. For that reason, organisations should document not only what happened, but also whether the controller cooperated, corrected the issue, and reduced exposure promptly after discovery.
- Effect on data subjects: actual or likely harm, distress, discrimination, or loss of control over data.
- Scale and duration: how many people or records were involved, and for how long the processing continued.
- Data sensitivity: whether the case involved sensitive data, children’s data, or other higher-risk categories.
- Conduct and cooperation: whether the processing was unlawful, discriminatory, repeated, or obstructed inspection.
How to prepare the classification before the fine is calculated
Organisations should build the classification file before any fine discussion begins. The file should show the facts that support the category, because once the ANPD starts assessing sanction range, missing evidence can make the violation look more serious than it was or hide the factors that support a lower classification.
The best approach is to separate the legal breach from the severity analysis. First establish the violation. Then assess how the violation behaved in context: who was affected, what data was processed, how long it lasted, whether the conduct was isolated or repeated, and whether remediation started immediately. That sequence creates a defensible record and reduces the chance of inconsistent internal decisions.
Risk and Threat Considerations
LGPD classification affects exposure because the same underlying violation can produce materially different administrative consequences depending on severity. The real risk is not only the fine itself, but also the cumulative impact of poor classification, weak documentation, and delayed remediation, which can make an otherwise containable issue look aggravated.
Failure mechanism: Teams often focus on the technical or procedural breach and under-document the aggravating facts that the ANPD uses to grade severity, such as scale, duration, sensitive data, or obstruction of inspection. That leaves the organisation unable to prove why a case should be treated as minor or average.
Impact: A weak evidentiary record can push the matter into a harsher sanction band, complicate settlement discussions, and create reputational damage because the organisation appears unable to explain its own conduct or containment actions.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST SP 800-53 Rev 5 sets the technical controls, while GDPR and ISO/IEC 27001:2022 define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| GDPR | Art.5 — Principles relating to processing of personal data | LGPD severity assessment tracks unlawful processing and data-subject harm principles. |
| Art.9 — Special categories of personal data | Sensitive-data involvement is a core aggravating fact in LGPD severity grading. | |
| Art.35 — Data Protection Impact Assessment | DPIA-style risk analysis mirrors the factors used to judge impact and exposure severity. | |
| Recommendation — Document lawful-processing and minimisation facts that support a lower severity classification. Flag sensitive-data cases early when grading violation severity. Use impact analysis to evidence why a violation is minor, average, or severe. | ||
| NIST SP 800-53 Rev 5 | AU-6 — Audit Record Review, Analysis, and Reporting | Severity decisions depend on evidence, timelines, and reviewable incident records. |
| Recommendation — Retain auditable records showing scope, duration, and response actions. | ||
| ISO/IEC 27001:2022 | A.5.25 — Assessment and decision on information security events | Event assessment practice supports consistent classification of breach seriousness. |
| Recommendation — Apply a documented assessment step before escalating sanctions or external reporting. | ||
Practitioner Guidance
What to verify: Confirm that the case file captures the exact population affected, the data categories involved, the duration of the breach or unlawful processing, and any facts showing cooperation or obstruction. If those facts are not recorded, the classification is not yet reliable.
Decision rule: If sensitive or children’s data was involved, or if the conduct continued after notice, treat the matter as potentially more severe until the facts prove otherwise. If the event was contained quickly and the impact was limited, preserve evidence that supports the lower classification before the record is lost.
Practitioner takeaway: The classification should be evidence-led, not intuition-led, because the facts that drive severity are the same facts that shape the eventual sanction range.