Brazil LGPD Articles 46-48 Security + Breach Notification. Article 46 Security of Processing (Seguranca do Tratamento) - controllers and processors must adopt technical and administrative measures to protect personal data against unauthorised access + accidental or unlawful destruction + loss + alteration + communication + diffusion + including: state-of-the-art + ISO 27001/27002 alignment + encryption (at rest and in transit) + pseudonymisation + access control + authentication + logging + monitoring + secure SDLC + vulnerability management + backup + business continuity + incident response. Article 47 Persons Involved in Processing under controller authority obligated to data secrecy and confidentiality + LGPD professional secrecy obligation. Article 48 Personal Data Breach Notification (Comunicacao de Incidente de Seguranca) - controller must notify ANPD and affected data subjects within REASONABLE TIME (ANPD Resolution CD/ANPD No. 15 of 26 April 2024 establishes 3 working days from awareness for ANPD notification) of incident likely to result in relevant risk or damage to data subjects + content (nature + categories + approximate number + likely consequences + measures taken or proposed + DPO contact + impact mitigation). Article 49 Cybersecurity coordination with: ANPD + CGI.br Brazilian Internet Steering Committee + CTIR Gov (Centro de Tratamento e Resposta a Incidentes Cibernáticos de Governo) + sectoral CSIRTs + CERT.br + GSI/PR Cybersecurity Strategy + Banco Central + CVM (Comissao de Valores Mobiliarios) + sectoral notification obligations (Banking Resolution 4.893/2021 + ICP-Brasil + Marco Civil da Internet) + cooperation with Federal Police Cybercrime + Ministerio Publico Federal.
The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.