CNAD Circular No. 008-2026: New Data Protection Compliance Requirements

CNAD Circular No. 008-2026: New Data Protection Compliance Requirements

August 2026Blog
  • Corporate
By Aldo VianaAssociate

The National Commission of Digital Assets (CNAD) issued Circular No. 008-2026, addressed to Digital Asset Service Providers and Certifiers, through which it communicates the Guidelines for Personal Data Protection Delegates issued by the State Cybersecurity Agency (ACE).

The Guidelines entered into force on August 19, 2026, and, pursuant to the Circular, the entities subject to these requirements have 20 business days to adapt their organizational and operational structures to the applicable requirements.

Among the key aspects highlighted by the CNAD is the obligation to appoint a Personal Data Protection Delegate, verify that the appointed individual meets the required profile and suitability criteria, and complete their formal registration with the ACE’s Personal Data Protection Directorate.

In addition, each entity must establish an institutional email address to serve as an official communication channel with the ACE and notify the relevant authority of such address.

From a compliance perspective, the Circular reinforces the need to integrate personal data protection into the governance structure of entities operating in the digital asset sector. The appointment of a Delegate should not be viewed merely as a formal requirement, but rather as part of a broader review of internal processes related to the processing, safeguarding, and management of personal information.

For entities supervised by the CNAD, it is advisable to promptly review their current structure, identify the professional who will assume this role, and complete the required actions within the established timeframe.

Torres Legal supports technology and digital asset companies in their regulatory compliance and adaptation processes related to personal data protection. 

Next articles in this category

Torres Legal