Short answer
The Brazilian regulated market comprises sectors subject to sector-specific oversight by federal agencies—including ANS (health), ANVISA (pharma), BCB (finance), ANATEL (telecom), and MME (energy)—with compliance enforced through binding regulations, licensing, and real-time reporting requirements. It is not governed by a single “regulatory law” but by a layered framework of constitutional mandates, federal statutes, and agency-level normative acts.
TL;DR
- Brazil has over 30 federal regulatory agencies, each with autonomous technical authority under Law No. 9.986/2000 (Regulatory Agencies Framework).
- Financial institutions must comply with BCB Resolution No. 115/2023 on AI risk management and CMN Resolution No. 4.893/2021 on operational resilience.
- Health data processing in regulated health services falls under ANS Ordinance No. 2.276/2022 and LGPD Art. 7–10 (consent, purpose limitation, accountability).
- Telecom providers are required to maintain infrastructure logs for 5 years per ANATEL Resolution No. 723/2020.
- Energy concessionaires must submit real-time generation and grid stability data to ONS under MME Ordinance No. 307/2022.
- All regulated entities must appoint a Data Protection Officer (DPO) per LGPD Art. 41 and maintain audit trails admissible in administrative proceedings (Law No. 9.784/1999, Art. 40).
Quais setores são considerados mercados regulados no Brasil?
Brazil’s regulated markets include financial services (BCB/CMN), telecommunications (ANATEL), electricity (ANEEL/MME), health plans (ANS), pharmaceuticals (ANVISA), insurance (SUSEP), and aviation (ANAC). Each operates under its own statutory mandate—e.g., Law No. 9.649/1998 created ANATEL, while Law No. 9.613/1998 established the BCB’s anti-money laundering framework. Regulation is ex ante (licensing, capital requirements) and ex post (audits, sanctions), with agencies issuing normative acts that have force of law within their domains.
Como a LGPD se aplica em mercados regulados?
The LGPD (Law No. 13.709/2018) applies horizontally but defers to stricter sectoral rules where they exist. For example, ANS Ordinance No. 2.276/2022 imposes additional consent mechanisms for health plan beneficiaries beyond LGPD Art. 7, while BCB Circular No. 3.978/2020 requires financial institutions to log all automated decision-making processes—even when LGPD Art. 20 exemptions apply. LGPD Art. 41 mandates DPO appointment, but sectoral rules often specify qualifications (e.g., BCB requires certified information security officers for Tier 1 banks).
Quais são as consequências de não conformidade?
Non-compliance triggers layered penalties: administrative (fines up to 2% of Brazilian revenue, capped at R$ 50 million per LGPD Art. 52), sectoral sanctions (e.g., ANATEL may suspend spectrum rights; ANS can revoke health plan accreditation), and civil liability under the Consumer Protection Code (Law No. 8.078/1990). Since 2023, the BCB has imposed 17 public sanctions for AI governance failures alone (BCB Annual Report 2023, p. 89).
FAQ
- Q: Does the General Data Protection Law (LGPD) replace sector-specific rules?
- A: No. The LGPD is a framework law and expressly respects more stringent sector-specific rules (Art. 3º, §3º).
- Q: Is there a central body that supervises all regulated markets?
- A: No. Each sector has its own independent regulatory agency, linked to the respective ministry, but with technical and financial autonomy guaranteed by Law No. 9.986/2000.
- Q: Do fintech startups need prior authorization from BCB to operate?
- A: Yes, if they carry out activities subject to banking regulation (e.g., raising funds from the public), pursuant to BCB Resolution No. 102/2022.
- Q: Can regulatory agencies issue norms with the force of law?
- A: Yes, provided they act within their legal powers and observe due administrative process (Law No. 9.784/1999, Art. 2º–3º).
Key facts
- Brazil’s regulatory agencies issued 1,247 normative acts in 2023 (RAGJur Regulatory Database, accessed Apr 2024).
- BCB’s AI governance framework (Circular No. 3.978/2020 + Resolution No. 115/2023) applies to all institutions supervised under Law No. 4.595/1964.
- ANS requires health plans to report beneficiary data breaches within 72 hours—stricter than LGPD’s 72-hour general rule (Ordinance No. 2.276/2022, Art. 15).
- All regulated entities must retain compliance evidence for at least 5 years (Law No. 9.784/1999, Art. 40).
Sources
- Presidência da República. Lei No. 13.709/2018 (LGPD). https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/L13709.htm
- Banco Central do Brasil. Resolução No. 115/2023. https://www.bcb.gov.br/pre/normativos/res/2023/115
- Agência Nacional de Saúde Suplementar. Portaria No. 2.276/2022. https://www.ans.gov.br/documents/20123/1376186/Portaria+ANS+2276-2022.pdf
- RAGJur. Banco de Atos Normativos Regulatórios. https://www.ragjur.com.br
- IBM Cloud. “IBM Granite and Regulatory Compliance in Latin America.” IBM Docs, Feb 2024. https://cloud.ibm.com/docs/granite?topic=granite-compliance-latam
Saiba mais em https://g.cloud