Skip to the content
Global Data RulesData governance rules, country by country

Brazil

Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.

The answer

Yes, with paperworkWork: HighEnforcement: Active

Brazil does not force data to stay inside the country. Personal data can leave, but since August 2025 you normally need a contract written by the regulator, word for word, signed with whoever receives it. Sending data to the European Union needs nothing extra. The regulator is awake and has started switching features off large platforms.

Eight questions about Brazil

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Brazil's rules apply to my company?

Yes. Brazil's privacy law reaches a company with no office in Brazil, as long as it collects data in Brazil or offers goods or services to people here. There is no size or revenue threshold that lets you out. The privacy law itself does not make you appoint anyone local — but two newer rules do, and if you run a digital platform you now need a registered office and a legal representative in Brazil.

High confidenceNational rulesAppoint a local representativeAppoint a data protection officer

Can I store my users' data outside Brazil?

Yes, with paperwork. Brazil has no rule making anyone keep a copy of anything inside the country — not for banks, not for hospitals, not even for the federal government's own cloud. What it has instead is a permission slip: before personal data leaves, you need one of a short list of approved legal grounds. Industry rules add conditions on top, but none of them is a wall.

High confidenceYes, with paperworkAllowlistOfficial 'this country is safe' decisionStandard contract clauses

What do I need in place before data leaves Brazil?

Pick one of five routes. The easy one is the European Union: since January 2026 Brazil treats it as safe, so nothing extra is needed. For everywhere else, the normal route is a set of standard contractual clauses that the regulator itself wrote — you copy them into your contract exactly, and you may not edit them. A deadline to retrofit older contracts already passed, on 23 August 2025.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesExplicit consentSomeone's life is at risk

Who enforces the rules in Brazil, and what can they do?

The National Data Protection Authority, and it is genuinely working. A law passed in February 2026 gave it real independence, 200 new specialist jobs and its own budget. In August 2026 it ordered Discord to switch off live video streaming in Brazil within three working days, to protect children. Banking, telecoms, insurance and securities regulators enforce their own rules in parallel and have done so for years.

High confidenceActiveOrder to stop

How long do I have to keep the data?

Both directions, and they pull against each other. The floor: internet access providers must keep connection records for one year, websites and apps must keep access records for six months, and tax records need five years. The ceiling: the privacy law says personal data must be deleted once you have finished doing what you collected it for. Where the two clash, the legal duty to keep wins — the law lists that as an express reason to hold on.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count three clocks, not one. Privacy: three working days to tell the regulator AND the affected people, once you have confirmed a breach that could really hurt them. Platform content: two hours to take down intimate images shared without consent, once notified. On top of that, banks report incidents to the central bank and telecoms operators report to the telecoms regulator under their own separate timetables.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Brazil?

Five. (1) Your European standard contract is not automatically good enough — Brazil wrote its own clauses and you must copy them exactly, unedited, and the deadline to fix old contracts passed on 23 August 2025. (2) A child in Brazil is under 12 and an adolescent is 12 to 17, but the social media rule bites at 16 — accounts for anyone up to 16 must be tied to a parent's account, and asking users to state their own age is banned. (3) Since 20 July 2026 a digital platform needs an actual registered office in Brazil, not just a lawyer on retainer. (4) The biggest fine is not in the privacy law: the internet law allows up to 10 percent of your group's Brazilian revenue. (5) The regulator can order your database blocked or your processing suspended, which usually hurts more than any cheque.

High confidenceGet a parent's consent for childrenNo tracking or ads to childrenAppoint a local representativePut a transfer safeguard in placePercentage of global turnoverOrder to stop

What is changing soon in Brazil?

One firm date: January 2027, when the regulator moves from monitoring platforms to full enforcement of the children's digital rules. Brazil's artificial intelligence bill is still only a bill — it was sitting in a committee waiting for a report as recently as June 2026, so do not plan around it. The bigger risk is not new law: it is that the regulator can add or withdraw approved destinations for data transfers by publishing a single resolution, with no consultation.

High confidenceProposedPartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  2. Layer 2

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

National rules4 rules

Lei Geral de Proteção de Dados Pessoais (LGPD)

Act of parliament · Lei nº 13.709, de 14 de agosto de 2018

In forceYes, with paperwork

Brazil's general privacy law. It reaches foreign companies with no local office, requires a named data protection contact, and lets personal data leave the country only on one of nine listed grounds. It contains no storage-location requirement of any kind. Sanctions have applied since 1 August 2021.

In force since 18 September 2020But only enforceable from 1 August 2021

Enforced by National Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Someone's life is at risk, Legal claims

High confidence

Regulamento de Transferência Internacional de Dados Pessoais

Directly binding regulation · Resolução CD/ANPD nº 19, de 23 de agosto de 2024; adequacy by Resolução nº 32/2026

In forceYes, with paperwork

The rulebook for sending personal data out of Brazil. Five routes exist, but in practice there are two: the standard contractual clauses written by the regulator, which you must copy word for word, or an adequacy decision. The adequacy list holds exactly one entry — the European Union, recognised on 26 January 2026.

In force since 23 August 2024But only enforceable from 23 August 2025

Enforced by National Data Protection Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

High confidence

Regulamento de Comunicação de Incidente de Segurança

Directly binding regulation · Resolução CD/ANPD nº 15, de 24 de abril de 2024

In forceYes, with paperwork

Three working days to tell both the regulator and the affected people about a confirmed personal data breach that could cause them real harm. The notice must list the categories of data involved, the risks, what you have done about it and when you found out.

Enforced by National Data Protection Authority

High confidence

Industry rules6 rules

Estatuto Digital da Criança e do Adolescente (ECA Digital)

Act of parliament · Lei nº 15.211, de 17 de setembro de 2025; commencement fixed by Lei nº 15.352/2026 · Social media and online platforms

Partly in forceYes, with paperwork

Brazil's children's digital statute. It bans self-declared age, ties the accounts of anyone up to 16 to a parent's account, forbids profiling and behavioural targeting of under-18s, and requires a legal representative inside Brazil. In force since 17 March 2026, with monitoring first and full enforcement from January 2027.

In force since 17 March 2026But only enforceable from 1 January 2027

Enforced by National Data Protection Authority

High confidence

Decreto nº 12.975, de 20 de maio de 2026 (deveres dos provedores de aplicações de internet)

Directly binding regulation · Decreto nº 12.975/2026, published 21 May 2026; companion Decreto nº 12.976/2026 · Social media and online platforms

In forceYes, with paperwork

Since 20 July 2026, a company that hosts other people's content for Brazilian users must have an actual registered office and a legal representative in Brazil, run systemic risk assessments and publish transparency reports. Private email, private messaging and closed-group video calls are carved out. The data protection authority regulates and enforces it.

In force since 20 July 2026

Enforced by National Data Protection Authority

Medium confidence

Resolução CMN nº 4.893 — política de segurança cibernética e requisitos para contratação de serviços de processamento e armazenamento de dados e de computação em nuvem

Directly binding regulation · Resolução CMN nº 4.893, de 26 de fevereiro de 2021 · Banking

In forceYes, with paperwork

Banks and other supervised financial institutions may process and store data abroad, but only where the Banco Central can still reach that data and can work with the supervisor in the host country. In practice this behaves like a country allowlist for banking data, without ever being written as one. It is a condition, not a wall — nothing has to stay in Brazil.

Enforced by Central Bank of Brazil

Transfer model: Allowlist · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • Autoridade Nacional de Proteção de Dados (ANPD)

    General privacy law, children's digital statute, and since May 2026 the duties of internet platforms under the internet law

    Fully constituted and issuing decisions. Confirmed as an autonomous body with its own budget and 200 new specialist posts by Lei nº 15.352 of 25 February 2026. Ordered Discord to suspend live streaming in Brazil on 12 August 2026. Its website and social media run in restricted mode until the October 2026 general elections.

  • Banco Central do Brasil

    Banks, payment institutions, payment systems, open finance

  • Agência Nacional de Telecomunicações

    Telecoms networks, cybersecurity of the telecom sector

  • Superintendência de Seguros Privados (SUSEP)

    Insurance, open capitalisation and reinsurance

    Active regulator. Its own normative pages could not be opened during this run, so its cloud and outsourcing circulars are not separately evidenced here.

  • Comissão de Valores Mobiliários (CVM)

    Securities markets, fund and portfolio managers

    Active. No securities-specific data localisation rule was located during this run.

  • Secretaria de Governo Digital (SGD/MGI)

    Federal government IT and cloud procurement

  • Ministério da Defesa / Estado-Maior das Forças Armadas

    Aerial survey and mapping of national territory

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact wording of the Banco Central's rules on processing and storing financial data abroad (Resolução CMN nº 4.893/2021)

    The Banco Central's normative database only renders with JavaScript and every direct route to the text failed during this run, including the legacy PDF paths and the official gazette, which blocks automated fetching. The rule is cited to the Banco Central's own page and marked medium confidence. Treat the description of the conditions as directionally right and verify the article numbers before relying on them.

  • Whether the insurance regulator (SUSEP) or the securities regulator (CVM) imposes any storage-location requirement

    No such rule was located, checked 18 August 2026, but neither regulator's normative index could be opened during this run. This is a 'not found', not a 'does not exist'.

  • Whether any health-sector rule requires patient records to be held in Brazil

    No such rule was located, checked 18 August 2026. The medical council's own site is not on a government domain, so nothing could be cited to the required standard. The operative constraint in health is professional secrecy rather than geography, but that has not been verified against a government source here.

  • The precise legal architecture behind Decreto nº 12.975/2026

    The decree's numbering inserts articles 16-A to 16-P and 19-A into the internet law's scheme, which suggests it implements provisions added to that law by a separate 2026 statute that could not be independently identified in this run. The office-and-representative requirement itself is quoted verbatim from the decree and is not in doubt; its parent statute is.

  • Whether the Supreme Court's 2025 ruling on intermediary liability changed the enforceable content of the internet law

    Widely reported, but no decision on the court's own site was opened during this run. No 'disapplied' status has therefore been asserted for any provision of the internet law. Check this on the next refresh — it is the most likely place for Brazil to hold a disapplied-but-still-printed provision.

  • Exact incident reporting deadlines to the Banco Central and to the telecoms regulator

    Both regimes are confirmed to exist and to impose reporting, but the hour counts were not verified against the instruments.

  • The exact number and value of fines the data protection authority has issued to date

    The authority publishes sanctions through the federal transparency portal rather than on its own sanctions page, and its site is in restricted election mode. Enforcement is rated 'active' on the strength of a dated, named order rather than on fine statistics.

60-day cadence. Three things can move without warning: the adequacy list, which went from empty to one entry in January 2026 and is changed by a single resolution; the children's statute, which switches from monitoring to full enforcement in January 2027; and the newly-resourced regulator, whose enforcement volume can rise sharply with no change in the law. The October 2026 general elections also put the regulator's own communications into restricted mode, which makes verification harder for the rest of the year.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.