Law / Brazil

Brazil

15 of 18 named instruments researched to a stage, across all six areas of law we track: 14 in force and 1 proposed. As of 19 September 2026.

When they take effect14 of 15 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 1 instrument (1 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 5 instruments (5 in force) ’20 2021: 2 instruments (2 in force) 2022: 0 instruments 2023: 0 instruments 2024: 3 instruments (3 in force) 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 2 in force, 1 proposed

Research summary (128 words)

Brazil has no general AI-transparency statute in force. The Superior Electoral Court's Resolução TSE nº 23.610/2019, as amended by Resolução TSE nº 23.732, de 27 de fevereiro de 2024, imposes a disclosure duty on AI-generated synthetic content used in electoral advertising and separately prohibits using a fabricated or manipulated deepfake to harm or benefit a candidacy, but these duties bind campaign advertising specifically and do not reach AI output generally.

Brazil's general framework bill for artificial intelligence, Projeto de Lei nº 2.338/2023 (Marco Legal da Inteligência Artificial), was approved by the Senate Federal in substitute form on 10 December 2024 and remitted to the Chamber of Deputies on 17 March 2025, where it remains pending as of this writing; it binds nobody unless and until it is enacted.

AI prohibited practices

TSE Resolution, Prohibition on Electoral Deepfakes

Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024)Official compiled text of Resolução TSE nº 23.610/2019, as amended by Resolução TSE nº 23.732/2024, Tribunal Superior Eleitoral

In force since 4 March 2024. Binds public and private bodies.

What this law does

Article 9º-C, inserted into Resolução TSE nº 23.610/2019 by Resolução TSE nº 23.732/2024, forbids using fabricated or manipulated content in electoral advertising, in any form, to spread notoriously untrue or gravely decontextualized facts with the potential to harm the balance of the election or the integrity of the electoral process.

Paragraph 1 specifically prohibits using synthetic audio, video, or combined audio-video content generated or digitally manipulated, even with the depicted person's authorization, to create, replace, or alter the image or voice of a living, deceased, or fictitious person, to harm or benefit a candidacy (a deep fake).

Paragraph 2 makes a violation of the caput or paragraph 1 an abuse of political power and improper use of the means of social communication, exposing the responsible candidacy to loss of its electoral registration.

What it requires

AI risk obligations

Marco Legal da Inteligência Artificial (PL 2338/2023)

Projeto de Lei nº 2.338/2023 (aprovado pelo Senado Federal em 10 de dezembro de 2024)Tramitação page for Projeto de Lei nº 2.338/2023, Senado Federal

Proposed: draft date not recorded. Before the second chamber, dated 17 March 2025, as of 12 September 2026.

What this law does

Projeto de Lei nº 2.338/2023, the Marco Legal da Inteligência Artificial, authored by Senator Rodrigo Pacheco, would be Brazil's general framework statute for artificial intelligence. The Federal Senate's plenary approved the bill in substitute form on 10 December 2024, and it was remitted to the Chamber of Deputies on 17 March 2025, where it remained pending as of this writing.

What it requires

AI transparency

TSE Resolution, AI-Generated Content Disclosure Duty

Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024)Official compiled text of Resolução TSE nº 23.610/2019, as amended by Resolução TSE nº 23.732/2024, Tribunal Superior Eleitoral

In force since 4 March 2024. Binds public and private bodies.

What this law does

Article 9º-B, inserted into Resolução TSE nº 23.610/2019 by Resolução TSE nº 23.732/2024, requires that any use in electoral advertising of AI-generated synthetic multimedia content, to create, replace, omit, merge, alter the speed of, or overlay images or sounds, carry an explicit, prominent, and accessible disclosure that the content was fabricated or manipulated and which technology was used.

Paragraph 1 requires that disclosure at the start of audio pieces, by a watermark label and audio description for static images, and in both forms for video or combined audio-video pieces. Paragraph 2 excludes image- or sound-quality adjustments, graphic identity elements, and customary marketing techniques such as composite campaign photos from the duty.

The duty binds whoever is responsible for the advertising, which reaches a candidate, party, federation, or coalition, or a service that generates or places AI content on their behalf.

What it requires

Privacy law6 instruments, 6 in force

Research summary (270 words)

Brazil's personal-data regime is the Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018, engaging every family this corpus tracks: a lawful-basis and governance regime for ordinary personal data, heightened conditions for sensitive categories including health, genetic, biometric and children's data, a set of data-subject rights including review of automated decisions, conditioned international transfer, a security-incident notification duty running to the authority and the data subject, and civil liability plus administrative sanctions enforced by the Agência Nacional de Proteção de Dados (ANPD).

The compiled text's most recent redação, given by Lei nº 15.352, de 2026 for the authority's chapter title and definitions and by Lei nº 15.452, de 2026 for its creation article, shows that authority renamed from the Autoridade Nacional de Proteção de Dados the LGPD first created in 2018 to the Agência Nacional de Proteção de Dados, now linked to the Ministério da Justiça e Segurança Pública rather than standing as an autonomous body under the Presidência da República.

The LGPD's general provisions took effect from 18 September 2020, when Lei nº 14.058/2020 settled a legislative dispute over a proposed postponement, and its administrative sanctions (arts. 52-54) took effect separately from 1 August 2021 under Lei nº 14.010/2020.

Publicly accessible personal data remains within the LGPD's scope; only the consent requirement is dispensed for data the data subject has manifestly made public, and the processing must still respect the purpose, good faith and public interest that justified the data's availability. The statute sets no fixed breach-notification clock of its own, leaving the ANPD to define a reasonable period by regulation.

Breach notification

LGPD, security incident notification

Lei nº 13.709, de 2018 (LGPD), art. 48 (security incident notification)Official compiled text of Lei nº 13.709/2018, Presidência da República

In force since 18 September 2020. Binds public and private bodies.

What this law does

Article 48 requires the controller to notify the ANPD and the data subject of a security incident that may create relevant risk or harm to data subjects.

The notification runs on a reasonable period the ANPD itself defines by regulation rather than a fixed number of hours or days stated in the LGPD, and paragraph 1 requires it to describe, at minimum, the nature of the personal data affected, information about the data subjects involved, the technical and security measures used, the risks related to the incident, the reasons for any delay, and the measures taken or planned to reverse or mitigate the harm.

Paragraph 2 lets the ANPD assess the incident's gravity and order the controller to give the incident wide publicity in the media or to adopt measures reversing or mitigating its effects, and paragraph 3 lets the ANPD weigh, in that assessment, whether the controller had already rendered the affected data unintelligible to unauthorized third parties.

What it requires

Comprehensive regime

Lei Geral de Proteção de Dados Pessoais (LGPD)

Lei nº 13.709 de 14 de agosto de 2018 (LGPD), arts. 1º-10, 15-16, 23-32, 37-41, 46-47, 49-51 (general regime, principles, lawful basis, public-sector processing, agents and governance)Official compiled text of Lei nº 13.709/2018, Presidência da República

In force since 18 September 2020. Binds public and private bodies.

What this law does

The LGPD applies to any operation processing personal data by a natural or legal person, public or private, wherever performed, when the operation happens in Brazil, aims to offer goods or services to a person in Brazil, or processes data collected in Brazil, and article 4 exempts processing for exclusively personal and non-economic purposes, for journalistic, artistic or academic purposes, for public safety, national defense, state security or criminal investigation and enforcement under specific legislation, and data originating outside Brazil that is never shared with a Brazilian controller or transferred onward.

Article 5 defines the personal data, controller, operator and encarregado (data protection officer) roles that anchor the regime, and its most recent redação, given by Lei nº 15.352, de 2026, confirms that the body those roles report to is now the Agência Nacional de Proteção de Dados (ANPD), not the Autoridade Nacional de Proteção de Dados the LGPD originally created.

Article 6 states the purpose limitation, necessity, transparency, security and accountability principles that govern every processing operation, and article 7 lists ten lawful bases for ordinary personal data, from consent to legitimate interest, while article 8 sets consent's formal requirements, including a clause set apart from other contract terms and a burden of proof on the controller.

Article 9 requires clear, adequate and prominent information about the processing, and article 10 conditions a legitimate-interest basis on strictly necessary data and transparency measures. Articles 15 and 16 require personal data to be deleted once processing ends, unless retention is needed for a legal obligation, anonymized research, an authorized transfer, or the controller's own anonymized use.

Articles 23 to 32 require a public body to publish the legal basis, purpose and procedures for any processing it carries out, bar it from transferring personal data to a private entity outside the listed cases, and let the ANPD demand a report or issue guidance where a public body's processing violates the law.

Article 37 requires a record of processing operations, especially those resting on legitimate interest, article 38 lets the ANPD demand a data protection impact report, and article 41 requires the controller to name an encarregado and publish their contact details.

Articles 46, 47 and 49 require technical and administrative security measures against unauthorized access and accidental or unlawful destruction, loss, alteration or improper processing, from a product's design through its operation, and articles 50 and 51 encourage a governance program with internal rules, risk-mitigation mechanisms and complaint channels.

What it requires

Cross border transfer

LGPD, international transfer of data

Lei nº 13.709, de 2018 (LGPD), arts. 33-36 (international transfer of data)Official compiled text of Lei nº 13.709/2018, Presidência da República

In force since 18 September 2020. Binds public and private bodies.

What this law does

Article 33 permits international transfer of personal data only to a country or international organization offering an adequate level of data protection, where the controller proves compliance through specific or standard contractual clauses, global corporate rules, or a certification seal, for international legal cooperation among investigative or prosecutorial bodies, to protect life or physical safety, where the ANPD authorizes the transfer, under an international cooperation commitment, for a public-policy purpose given publicity, or with the data subject's specific, highlighted consent given after being told the operation is international.

Article 34 requires the ANPD to weigh the destination country's or organization's general and sectoral rules, the nature of the data, the LGPD's principles and rights, its security measures, and its judicial and institutional guarantees before finding its protection adequate.

Article 35 gives the ANPD authority to define standard contractual clauses and to verify specific clauses, global corporate rules, or certification seals, including through a certifying body it may designate and review, and article 36 requires any change to safeguards the ANPD accepted as sufficient to be reported to it.

What it requires

Data subject rights

LGPD, rights of the data subject

Lei nº 13.709, de 2018 (LGPD), arts. 17-22 (rights of the data subject)Official compiled text of Lei nº 13.709/2018, Presidência da República

In force since 18 September 2020. Binds public and private bodies.

What this law does

Article 17 assures every natural person title to their own personal data and the fundamental rights of liberty, intimacy and privacy that the LGPD protects.

Article 18 gives the data subject the right to confirm processing exists, access, correct, anonymize, block, delete, or port their data to another provider, learn which public and private entities the controller shared their data with, learn the consequences of withholding consent, and revoke consent at any time through a free and easy procedure, and article 19 requires the controller to answer a confirmation or access request immediately in simplified form or within 15 days with a full, clear statement of the data's origin, the criteria used, and the treatment's purpose.

Article 20 gives the data subject the right to request review, by a natural person, of a decision taken solely on automated processing of their personal data that affects their interests, including a decision defining their personal, professional, consumer, or credit profile, and requires the controller to explain, on request, the criteria and procedures behind the automated decision.

Article 21 bars using data about a data subject's exercise of their own rights to their detriment, and article 22 lets the data subject or a representative defend these rights in an individual or collective judicial action.

What it requires

Enforcement supervision

LGPD, civil liability, administrative sanctions and the ANPD

Lei nº 13.709, de 2018 (LGPD), arts. 42-45, 52-54, 55-A a 58-B (civil liability, administrative sanctions and the ANPD)Official compiled text of Lei nº 13.709/2018, Presidência da República

In force since 1 August 2021. Binds public and private bodies.

What this law does

Article 42 makes a controller or operator that causes patrimonial, moral, individual, or collective damage through personal-data processing in violation of the data-protection legislation liable to repair it, holds an operator jointly liable when it breaches the legislation or departs from the controller's lawful instructions, lets a court shift the burden of proof to the controller where the data subject's claim is plausible, and lets the reparation claim proceed collectively in court.

Article 52 subjects a controller or operator to administrative sanctions the ANPD applies after a due process guaranteeing full defense, from a warning with a correction deadline through a simple fine of up to 2% of the private legal entity's, group's, or conglomerate's revenue in Brazil in its last fiscal year, excluding taxes, capped in total at R$50,000,000.00 per infraction, a daily fine observing the same cap, publicity of the confirmed infraction, blocking or deletion of the data at issue, and suspension of the database or the processing activity for up to six months, renewable once.

Articles 53 and 54 require the ANPD to publish, after public consultation, the methodology it uses to calculate a fine's base value and to ground a daily fine's amount in the violation's gravity and the harm caused.

Article 55-A creates the supervisory authority as a special autarchy; its most recent redação, given by Lei nº 15.452, de 2026, names it the Agência Nacional de Proteção de Dados (ANPD) rather than the Autoridade Nacional de Proteção de Dados the LGPD first created in 2018, and links it to the Ministério da Justiça e Segurança Pública with functional, technical, decision-making, administrative, and financial autonomy.

Article 55-J gives the ANPD the power to issue rules, demand information from any controller or operator at any time, receive and act on data-subject complaints, and inspect and sanction noncompliant processing through a process that guarantees the defendant's defense and right of appeal.

Articles 58-A and 58-B create a National Council on Data Protection and Privacy with representatives of government, the legislature, the judiciary, and civil society to advise the ANPD and propose data-protection and privacy policy.

The civil-liability chapter and the ANPD's own creation took effect with the LGPD's general provisions on 18 September 2020, but the administrative-sanctions chapter, articles 52 to 54, did not take effect until 1 August 2021, under article 65, I-A, added by Lei nº 14.010/2020.

What it requires

Sensitive categories

LGPD, sensitive personal data and children's data

Lei nº 13.709, de 2018 (LGPD), arts. 5º, II, 11-14 (sensitive personal data and children's data)Official compiled text of Lei nº 13.709/2018, Presidência da República

In force since 18 September 2020. Binds public and private bodies.

What this law does

Article 5, II defines sensitive personal data as data about racial or ethnic origin, religious conviction, political opinion, union or religious, philosophical or political association, health or sex life, or genetic or biometric data tied to a natural person, and article 11 confines its processing to specific, highlighted consent or a narrow list of alternative bases: a legal or regulatory obligation, a public-policy purpose, research with anonymization where possible, the exercise of a right, protecting life or physical safety, health treatment, or fraud prevention and authentication safeguards.

Article 11, paragraph 4 bars sharing sensitive health data between controllers for economic advantage, except for data-subject-requested portability or the health-service, pharmaceutical and health-assistance transactions the provision lists, and bars a health-insurance operator outright from using health data to select risks in contracting or excluding beneficiaries.

Article 12 excludes anonymized data from the definition of personal data unless the anonymization can be reversed with the controller's own means or reasonable effort, and treats data used to build an identifiable behavioral profile as personal data again. Article 13 lets a research body access personal data for public-health studies only within a controlled and secure environment, anonymized or pseudonymized where possible, and bars any transfer of that data to a third party.

Article 14 requires a child's or adolescent's data to be processed in their best interest, with specific, highlighted consent from at least one parent or legal guardian, except to contact the parent once without storing the data or to protect the child, bars conditioning participation in a game, application or activity on more personal data than the activity strictly needs, and requires the controller to make reasonable efforts, considering available technology, to verify that the consent came from the responsible adult.

What it requires

Scraping law3 instruments, 3 in force

Research summary (267 words)

Brazil has no scraping-specific statute, so general law governs each dimension separately.

The Penal Code's article 154-A, inserted by Lei nº 12.737/2012 and amended by Lei nº 14.155/2021, criminalizes invading a computing device, connected to a network or not, to obtain, alter, or destroy data without authorization, or to install a vulnerability, but the offense turns on invading a device rather than merely reading a page it serves, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, and no reported case has tested the point.

No Brazilian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Law, Lei nº 9.610/1998, protects a database as a compilation where its selection, organization, or arrangement of content constitutes an intellectual creation, but article 7, § 2º expressly excludes the underlying data or materials themselves from that protection, so Brazil has no sui generis extraction-based database right and no text-and-data-mining exception distinct from the ordinary limitations of article 46.

Personal data collected by scraping, including data the data subject has made public, remains subject to the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018): only the LGPD's consent requirement is dispensed for manifestly public data, and the LGPD's other duties, together with the Marco Civil da Internet's own protection-of-records duties, still apply.

No Brazilian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine distinct from the computer-misuse and copyright provisions above, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Penal Code Art. 154-A, Invasion of a Computing Device

Código Penal (Decreto-Lei nº 2.848/1940), art. 154-A (redação dada pela Lei nº 14.155, de 2021, inserido pela Lei nº 12.737, de 2012)Official compiled text of the Penal Code, Decreto-Lei nº 2.848/1940, Presidência da República

In force since 28 May 2021. Binds public and private bodies.

What this law does

Article 154-A punishes invading another person's computing device, whether or not connected to a network, to obtain, alter, or destroy data or information without the device user's express or tacit authorization, or to install a vulnerability to obtain an unlawful advantage, with reclusão of 1 to 4 years and a fine under the wording Lei nº 14.155/2021 gave the offense, up from the original Lei nº 12.737/2012 penalty of detention of 3 months to 1 year and a fine.

Section 2 raises the penalty by one third to two thirds if the invasion causes economic loss.

Section 3 sets a separate penalty of reclusão of 2 to 5 years and a fine where the invasion obtains the content of private electronic communications, trade or industrial secrets, confidential information as defined by law, or unauthorized remote control of the invaded device, and section 4 raises that penalty by one third to two thirds where the obtained material is disclosed, marketed, or transmitted to a third party.

Because the offense's trigger is invading a device, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

What it requires

Database right

Copyright Law, Database Compilation Right

Lei nº 9.610/1998, arts. 7º, XIII, e 87Official compiled text of Lei nº 9.610/1998, Presidência da República

In force since 20 June 1998. Binds public and private bodies.

What this law does

Article 7, XIII protects a database, along with a collection, compilation, anthology, encyclopedia, or dictionary, as an intellectual creation where its selection, organization, or arrangement of content amounts to one, and article 7, § 2º expressly states that this protection does not cover the underlying data or materials themselves and is without prejudice to any copyright that subsists in that data.

Article 87 gives the holder of the patrimonial right over a database the exclusive right to authorize or prohibit reproducing it in whole or in part, translating, adapting, reorganizing, or otherwise modifying it, distributing the original or copies, or communicating it to the public, and reproducing, distributing, or communicating the results of such a modification.

Because the protection reaches only the database's selection and arrangement, and not the data itself, Brazil has no sui generis, investment-based extraction right of the kind the European Union's Database Directive creates, and the Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

What it requires

Personal data

Marco Civil da Internet, Protection of Records and Personal Data

Lei nº 12.965/2014 (Marco Civil da Internet), arts. 7º, 10, e 12Official compiled text of Lei nº 12.965/2014, Presidência da República

In force since 23 June 2014. Binds private bodies.

What this law does

Article 7 assures an internet user rights including inviolability of intimacy and private life, secrecy of the flow of their internet communications except by judicial order, and secrecy of their stored private communications except by judicial order.

Article 10 requires that the retention and disclosure of connection and internet-application-access records, personal data, and the content of private communications observe the intimacy, private life, honor, and image of the parties involved, and article 10, § 1º limits disclosure of records associated with personal data or other identifying information to a judicial order.

Article 12 authorizes a warning, a fine of up to 10% of the economic group's revenue in Brazil in its last fiscal year, excluded taxes, temporary suspension, or prohibition of activity for violations of articles 10 and 11, which extend Brazilian law and these privacy, personal-data, and communications-secrecy rights to any collection, storage, custody, or processing of records, personal data, or communications where at least one such act occurs in Brazilian territory, including where performed by a foreign company that offers a service to the Brazilian public.

These duties bind an internet application provider regardless of how it collected the records, personal data, or communications, including by scraping, so long as at least one act of collection, storage, custody, or processing occurs in Brazilian territory.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (774 words)

Brazil has no enacted, comprehensive cybersecurity law comparable to the EU's Cyber Resilience Act or NIS2. Its posture instead rests on a policy-setting decree, one enacted product-security regulation reaching a narrow class of consumer networking hardware, several sector-specific cybersecurity regimes that each bind a licensed or government-designated role this corpus's activity vocabulary cannot express, and a still-pending general cybersecurity bill.

Decreto nº 11.856, de 26 de dezembro de 2023 instituted the Política Nacional de Cibersegurança (PNCiber) and the Comitê Nacional de Cibersegurança (CNCiber), a public-private coordinating body chaired by the Gabinete de Segurança Institucional da Presidência da República with 19 government, business, civil-society, and scientific seats; its articles state principles and objectives for national cybersecurity activity and create a committee that recommends further policy, but the decree's own text imposes no requirement, duty, or penalty on a private business.

Decreto nº 12.573, de 4 de agosto de 2025 instituted the Estratégia Nacional de Cibersegurança (E-Ciber) that implements PNCiber's guidelines; its provisions are written throughout in the vocabulary of incentive (incentivo, estímulo) toward the private sector, including encouraging Brazilian companies to procure products and services that adopt minimum cybersecurity standards rather than requiring anyone to meet one, so it likewise creates no enforceable duty.

Brazil's one enacted, in-force product-security requirement is Ato nº 2.436, de 7 de março de 2023 of Anatel's Superintendência de Outorga e Recursos à Prestação, which sets mandatory minimum cybersecurity requirements for the conformity assessment (homologação) of consumer-facing customer-premises equipment: cable modems, xDSL modems, ONU/ONT units, fixed-wireless-access and satellite-broadband routers and modems, and wireless routers and access points. Its Annex became mandatory on 10 March 2024 and is researched as the instrument row below.

Three further sector regimes each bind a role this corpus's declared activities cannot identify, so each is named here and none is filed as an instrument, the treatment this profile gives DORA's financial entities and NY DFS Part 500's covered entities.

Anatel's own Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, requires a "prestadora" (a Brazilian telecommunications service provider) to adopt and maintain a board-approved Cybersecurity Policy, source equipment only from suppliers whose own cybersecurity policy is compatible with the Regulation and independently and periodically audited, run cybersecurity vulnerability-assessment cycles, report on its critical telecommunications infrastructure, and notify Anatel of relevant incidents; that duty binds the carrier, not an app or a SaaS product that merely rides the carrier's network, and it is the same Resolução that gives Anatel's product-conformity procedures their cybersecurity mandate, so the two regimes share one legal source without sharing a bound party.

The Banco Central do Brasil's Resolução Conjunta CMN/BCB nº 4.893, de 26 de fevereiro de 2021 requires every institution the Central Bank authorizes to operate, meaning banks and other regulated financial institutions, to implement and maintain a board-approved cybersecurity policy addressing incident response, vulnerability management, and the security of contracted cloud and data-processing services; the bound party is a licensed financial institution, not a declared LexLint activity.

Aneel's Resolução Normativa nº 964, de 28 de setembro de 2021 imposes an analogous cybersecurity policy duty on the electric-power sector; it does not reach a digital-service provider of the kind this corpus's activities identify and is named here for completeness only.

A general cybersecurity statute is pending, not enacted. Projeto de Lei nº 4.752, de 2025, authored by Senator Esperidião Amin and others, would institute a "Marco Legal da Cibersegurança" and a national digital security and resilience program.

As of its most recent Senate committee action the bill remains with a rapporteur in the Comissão de Ciência, Tecnologia, Inovação e Informática, having received further amendments in September 2026, and it has not been enacted, so nothing about its eventual content is asserted here.

Brazil's General Data Protection Law (LGPD, Lei nº 13.709/2018) carries its own security-of-processing duty (Arts. 46 to 49) and its own personal-data breach-notification duty (Art. 48); both are this jurisdiction's privacy-topic findings and are not restated here, the treatment this profile gives a comprehensive regime's own security article.

The Marco Civil da Internet (Lei nº 12.965/2014) likewise requires an internet connection or application provider to keep connection and application-access records under confidentiality in a controlled, secure environment; that duty attaches to the records themselves and is researched with this jurisdiction's other Marco Civil provisions rather than repeated here.

No published enforcement record specific to Anatel's CPE cybersecurity requirements is confirmed in the primary text; Anatel states only that it monitors homologated products in the market on an ongoing basis and can suspend a product's homologação, which bars its distribution in Brazil, if a security flaw is found.

Product security requirements

Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)

Ato nº 2.436 de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019Official act text, Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações (Anatel)

In force since 10 March 2024. Binds private bodies.

What this law does

A manufacturer or supplier of specified consumer customer-premises equipment, meaning a cable modem, xDSL modem, ONU or ONT, fixed-wireless-access or satellite-broadband router or modem, or wireless router or access point sold in Brazil to connect a subscriber to an internet service provider's network, must meet mandatory minimum cybersecurity requirements before Anatel will certify the device.

The device may carry no default, blank, or weak passwords and no password shared across all units as manufactured. It may also carry no credentials or cryptographic keys hard-coded in the device's software or firmware. The manufacturer must provide at least two years of free security updates after launch or for as long as the product stays on the market, whichever is longer.

It must also maintain a published, securely reachable channel plus a coordinated vulnerability-disclosure policy for reporting a security flaw. Anatel enforces the requirement through the device's conformity assessment (homologação) and can suspend a product's homologação, which bars its distribution in Brazil, if it later finds a security flaw.

What it requires

Age gating law1 instrument, 1 in force

Research summary (119 words)

Brazil's age-appropriate design duties for digital services sit in Lei nº 15.211, de 17 de setembro de 2025 (the Estatuto Digital da Criança e do Adolescente, or ECA Digital), which applies to any information-technology product or service directed at children and adolescents, or likely to be accessed by them, wherever the provider is located, and enters into force on 17 March 2026.

The Estatuto da Criança e do Adolescente (ECA, Lei nº 8.069/1990), including as amended by Lei nº 14.811/2024, sets Brazil's general child-protection framework and criminalizes online exhibition or transmission of child sexual abuse material, but its own text imposes no age-verification or age-gating duty on a digital service provider; that duty arrives only with Lei nº 15.211/2025.

Age-appropriate design code

Estatuto Digital da Criança e do Adolescente (ECA Digital)

Lei nº 15.211, de 17 de setembro de 2025Official compiled text of Lei nº 15.211/2025 (Estatuto Digital da Criança e do Adolescente), Presidência da República

In force 6 months, effective 17 March 2026. Binds private bodies.

What this law does

Lei nº 15.211/2025 applies to any information-technology product or service directed at children or adolescents in Brazil, or likely to be accessed by them, regardless of the provider's location, development, manufacture, offer, marketing, or operation. Article 5 requires such a product or service to observe duties of prevention, protection, information, and security, adopting the child's or adolescent's best interest and integral protection as the guiding standard.

Article 11 lets the public authority act as regulator, certifier, or promoter of age-verification technical solutions.

Article 12 requires app-store and terminal operating-system providers to take proportionate, auditable, and technically secure measures to assess users' age or age range, to let parents or legal guardians configure voluntary parental-supervision mechanisms, and to make an age signal available to internet application providers through a privacy-by-design Application Programming Interface, limited to this law's purposes.

Article 14 requires the product or service provider itself, independently of the measures app stores or operating systems adopt, to implement its own mechanisms to prevent children and adolescents from accessing content unsuited to their age range. Articles 16 to 18 require parental-supervision tools, and article 18, § 2º prohibits designing, modifying, or manipulating an interface to undermine a user's autonomy or decision-making where doing so weakens those supervision tools or safeguards.

Article 35 authorizes an advertência, a simple fine of up to 10% of the economic group's revenue in Brazil in its last fiscal year, or, absent revenue, a per-registered-user fine, capped in total at R$50,000,000.00 per infraction, temporary suspension, or prohibition of activity, enforced by an independent administrative authority the law directs be created for this purpose.

The law's article 41-A entry-into-force date was set at six months after publication by Medida Provisória nº 1.319/2025 and then fixed at 17 March 2026 by Lei nº 15.352/2026, and the law has bound covered providers from that date.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (287 words)

Brazil has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Law, Lei nº 9.610/1998, is the only law reaching an aggregator's reproduction of news content.

Article 46, I, a) permits reproducing, in the daily or periodical press, a news item or informative article published in a newspaper or periodical, naming the author if signed and the publication it was transcribed from, and article 46, III separately permits quoting passages of any work in a book, newspaper, magazine, or other communication medium for study, criticism, or controversy, to the extent justified for that purpose, naming the author and the origin of the work.

Neither provision carries a headline-length or short-extract cap distinct from these tests, and no reported Brazilian decision applies either to a systematic news aggregator as opposed to a single periodical reproducing another's item or an individual quoting a published work.

The Act's neighbouring rights protect performers, phonogram producers, and broadcasting organizations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive article 15 creates.

No statute or reported case addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law has been located.

The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists; a text-and-data-mining exception has been proposed only within Projeto de Lei nº 2.338/2023, Brazil's pending general framework bill for artificial intelligence, approved by the Senate in substitute form on 10 December 2024 and, as of this writing, before the Chamber of Deputies.

Snippet reproduction

Copyright Law, Press Reproduction and Quotation Exceptions

Lei nº 9.610/1998, art. 46, I, a), e IIIOfficial compiled text of Lei nº 9.610/1998, Presidência da República

In force since 20 June 1998. Binds public and private bodies.

What this law does

Article 46, I, a) permits, without offending copyright, reproducing a news item or informative article published in a daily or periodical, in the daily or periodical press, naming the author if the item was signed and the publication it was transcribed from.

Article 46, III separately permits quoting passages of any work, in a book, newspaper, magazine, or any other communication medium, for the purposes of study, criticism, or controversy, to the extent justified for the purpose to be achieved, naming the author and the origin of the work.

Neither provision carries a headline-length or short-extract cap distinct from these tests, and no reported Brazilian decision applies either provision to a systematic news aggregator rather than a periodical reproducing another periodical's item or an individual quoting a published work. Neighbouring rights under the Act, covering performers, phonogram producers, and broadcasting organizations, do not extend to a print or online news publisher's own reporting.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.