Skip to the content
Global Data RulesData governance rules, country by country

Brazil

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Brazil — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Yes, with paperworkWork: HighEnforcement: Active

Brazil does not force data to stay inside the country. You can send personal data abroad. Since August 2025 you normally need a contract the regulator wrote, copied word for word, signed with whoever receives it. Sending data to the European Union needs nothing extra. The regulator is active. In August 2026 it ordered Discord to turn off live video in Brazil.

Data governance in Brazil

The eight things that decide how you handle data about people in Brazil. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Brazil's privacy law reaches a company with no office in Brazil. It applies if you collect data in Brazil, or offer goods or services to people here. There is no size or revenue limit that lets you out. The privacy law itself does not make you appoint anyone local. Two newer rules do. If you run a digital platform you now need a registered office and a legal representative in Brazil.

What you have to do here:
Appoint a representative · Appoint a data protection officer

Where the data is allowed to live

Yes, with paperwork. Nothing has to stay in Brazil. Not for banks, not for hospitals, not even for the federal government's own cloud. What you need instead is permission. Before personal data leaves, you must have one of a short list of approved legal grounds. Industry rules add conditions on top. None of them stops data leaving.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses

What to do: Get the paperwork for one of the routes below signed before any data leaves Brazil.

Sending data out of the country

Pick one of five routes. The easy one is the European Union. Since January 2026 Brazil treats it as safe, so nothing extra is needed. For everywhere else, the normal route is a standard contract the regulator itself wrote. You copy it into your contract exactly and you may not edit it. The deadline to fix older contracts has already passed. It was 23 August 2025.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · To save someone’s life

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The National Data Protection Authority, and it is working. A law passed in February 2026 gave it real independence, 200 new specialist jobs and its own budget. In August 2026 it ordered Discord to switch off live video streaming in Brazil within three working days, to protect children. The banking, telecoms, insurance and securities regulators enforce their own rules alongside it. They have done so for years.

What it costs if you get it wrong:
Order to stop

How long you must keep it — and when to delete it

Rules pull in both directions. On the keep-it side, internet access providers must keep connection records for one year. Websites and apps must keep access records for six months. Tax records need five years. On the delete-it side: the privacy law says you must delete personal data once you have finished what you collected it for. Where the two clash, the duty to keep wins. The law lists that as an express reason to hold on.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Three clocks, not one. Privacy: three working days to tell the regulator and the affected people. That clock starts once you have confirmed a breach that could really hurt them. Platform content: two hours to take down intimate images shared without consent, once you are told. On top of that, banks report incidents to the central bank and telecoms operators report to the telecoms regulator. Those run on their own separate timetables.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five. (1) Your European standard contract is not enough on its own. Brazil wrote its own clauses. You must copy them exactly, without edits. The deadline to fix old contracts passed on 23 August 2025. (2) A child in Brazil is under 12 and an adolescent is 12 to 17. But the social media rule starts at 16. Accounts for anyone up to 16 must be tied to a parent's account, and asking users to state their own age is banned. (3) Since 20 July 2026 a digital platform needs a real registered office in Brazil, not just a lawyer on retainer. (4) The biggest fine is not in the privacy law. The internet law allows up to 10 percent of your group's Brazilian revenue. (5) The regulator can order your database blocked or your use of data suspended. That usually hurts more than any fine.

What you have to do here:
Get a parent's consent for children · No tracking or ads to children · Appoint a representative · Put a transfer safeguard in place
What it costs if you get it wrong:
Percentage of global turnover · Order to stop

What's changing next

One firm date: January 2027. That is when the regulator moves from watching platforms to fully enforcing the children's digital rules. Brazil's artificial intelligence bill is still only a bill. As recently as June 2026 it was sitting in a committee waiting for a report. Do not plan around it. The bigger risk is not new law. The regulator can add or remove approved destinations for data transfers by publishing a single resolution, with no consultation.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Social media and online platforms

Children's data rules

Official name: Estatuto Digital da Criança e do Adolescente (ECA Digital) · Lei nº 15.211, de 17 de setembro de 2025; commencement fixed by Lei nº 15.352/2026 · Act of parliament

Partly in forceYes, with paperwork

Brazil's children's digital statute. It bans letting users declare their own age. Accounts for anyone up to 16 must be tied to a parent's account. Profiling and behaviour-based targeting of under-18s are banned. You need a legal representative inside Brazil. It has been in force since 17 March 2026. The regulator is watching first and enforces fully from January 2027.

In force since 17 March 2026In force now, but not enforced until 1 January 2027

It is already law, so plan for it — but nobody can be penalised under it until 1 January 2027. A contract you sign may still hold you to it sooner.

Enforced by National Data Protection Authority

Social media and online platforms

General data protection law (Social media and online platforms)

Official name: Decreto nº 12.975, de 20 de maio de 2026 (deveres dos provedores de aplicações de internet) · Decreto nº 12.975/2026, published 21 May 2026; companion Decreto nº 12.976/2026 · Directly binding regulation

In forceYes, with paperwork

Since 20 July 2026 there is a new duty for companies that host other people's content for Brazilian users. You must have a real registered office and a legal representative in Brazil. It must also assess systemic risks and publish transparency reports. Private email, private messaging and closed-group video calls are excluded. The data protection authority writes and enforces these rules.

In force since 20 July 2026

Enforced by National Data Protection Authority

Not fully verified — see “What we're not sure about” below.
Banking

Banking rules

Official name: Resolução CMN nº 4.893 — política de segurança cibernética e requisitos para contratação de serviços de processamento e armazenamento de dados e de computação em nuvem · Resolução CMN nº 4.893, de 26 de fevereiro de 2021 · Directly binding regulation

In forceYes, with paperwork

Banks and other supervised financial firms may handle and store data abroad. But the Banco Central must still be able to reach that data. It must also be able to work with the supervisor in the host country. So only some countries work for banking data, even though the rules never list them. It is a condition, not a ban. Nothing has to stay in Brazil.

Enforced by Central Bank of Brazil

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

General data protection law

Official name: Lei Geral de Proteção de Dados Pessoais (LGPD) · Lei nº 13.709, de 14 de agosto de 2018 · Act of parliament

In forceYes, with paperwork

Brazil's general privacy law. It reaches foreign companies with no local office. It requires you to name a data protection contact. Personal data may leave the country only on one of nine listed grounds. It says nothing about where data must be stored. Penalties have applied since 1 August 2021.

In force since 18 September 2020Enforced from 1 August 2021

Enforced by National Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, To save someone’s life, Legal claims

General data protection law (2025)

Official name: Regulamento de Transferência Internacional de Dados Pessoais · Resolução CD/ANPD nº 19, de 23 de agosto de 2024; adequacy by Resolução nº 32/2026 · Directly binding regulation

In forceYes, with paperwork

The rulebook for sending personal data out of Brazil. Five routes exist, but only two are usable. Copy the standard contract clauses the regulator wrote, word for word. Or send to a country officially decided to be safe enough. That list holds exactly one entry. The European Union, recognised on 26 January 2026.

In force since 23 August 2024Enforced from 23 August 2025

Enforced by National Data Protection Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

Breach reporting rules

Official name: Regulamento de Comunicação de Incidente de Segurança · Resolução CD/ANPD nº 15, de 24 de abril de 2024 · Directly binding regulation

In forceYes, with paperwork

You have three working days to tell the regulator and the affected people about a personal data breach. The clock starts when you confirm it. It applies when the breach could cause real harm. Your notice must list the kinds of data involved, the risks, what you have done about it and when you found out.

Enforced by National Data Protection Authority

Who you would hear from

  • Autoridade Nacional de Proteção de Dados (ANPD)

    General privacy law, children's digital statute, and since May 2026 the duties of internet platforms under the internet law

    Fully constituted and issuing decisions. Confirmed as an autonomous body with its own budget and 200 new specialist posts by Lei nº 15.352 of 25 February 2026. Ordered Discord to suspend live streaming in Brazil on 12 August 2026.

  • Banco Central do Brasil

    Banks, payment institutions, payment systems, open finance

  • Agência Nacional de Telecomunicações

    Telecoms networks, cybersecurity of the telecom sector

  • Superintendência de Seguros Privados (SUSEP)

    Insurance, open capitalisation and reinsurance

    Active regulator. We could not open its own rules pages, so its cloud and outsourcing circulars are not separately evidenced here.

  • Comissão de Valores Mobiliários (CVM)

    Securities markets, fund and portfolio managers

    Active. We found no securities rule requiring data to stay in Brazil.

  • Secretaria de Governo Digital (SGD/MGI)

    Federal government IT and cloud procurement

  • Ministério da Defesa / Estado-Maior das Forças Armadas

    Aerial survey and mapping of national territory

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact wording of the Banco Central's rules on processing and storing financial data abroad (Resolução CMN nº 4.893/2021)

    We could not check the exact wording against the Banco Central's own database. The rule is cited to the Banco Central's own page and marked medium confidence. Treat our description of the conditions as broadly correct. Verify the article numbers before you rely on them.

  • Whether the insurance regulator (SUSEP) or the securities regulator (CVM) imposes any storage-location requirement

    We found no rule requiring data to stay in Brazil, checked 18 August 2026. We could not confirm that against either regulator's own list of rules. If you work in insurance or securities, check before you rely on it.

  • Whether any health-sector rule requires patient records to be held in Brazil

    We found no rule requiring patient records to be held in Brazil, checked 18 August 2026. The medical council's site is not a government domain, so we could not cite it to our standard. What binds health providers is professional secrecy rather than geography. We could not confirm that against a government source either. Check before you rely on it.

  • The precise legal architecture behind Decreto nº 12.975/2026

    The decree inserts articles 16-A to 16-P and 19-A into the internet law. That suggests it puts into effect new rules added to that law by a separate 2026 statute. We could not identify that statute. The office-and-representative requirement is quoted word for word from the decree and is not in doubt. Its parent law is.

  • Whether the Supreme Court's 2025 ruling on intermediary liability changed the enforceable content of the internet law

    This is widely reported, but we could not open any decision on the court's own site. So we have not marked any part of the internet law as no longer applied. Check this at the next update. It is the most likely place for Brazil to have a rule that is still printed but no longer enforced.

  • Exact incident reporting deadlines to the Banco Central and to the telecoms regulator

    Both sets of rules exist and both require reporting. We could not confirm the exact hour counts against the official texts. Check them before you build your incident plan.

  • The exact number and value of fines the data protection authority has issued to date

    The authority publishes its penalties through the federal transparency portal rather than on its own sanctions page. Its site is also in restricted election mode. We rate enforcement 'active' on the strength of one dated, named order rather than on fine statistics.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.