Brazil
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked today.
The answer
Brazil does not force data to stay inside the country. Personal data can leave, but since August 2025 you normally need a contract written by the regulator, word for word, signed with whoever receives it. Sending data to the European Union needs nothing extra. The regulator is awake and has started switching features off large platforms.
Eight questions about Brazil
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Brazil's rules apply to my company?
Yes. Brazil's privacy law reaches a company with no office in Brazil, as long as it collects data in Brazil or offers goods or services to people here. There is no size or revenue threshold that lets you out. The privacy law itself does not make you appoint anyone local — but two newer rules do, and if you run a digital platform you now need a registered office and a legal representative in Brazil.
Lei nº 13.709/2018 (LGPD) art. 3 applies 'independentemente do meio, do país de sua sede ou do país onde estejam localizados os dados'. Marco Civil da Internet (Lei nº 12.965/2014) art. 11 §2 extends Brazilian law to foreign-seated companies that offer services to the Brazilian public or that have a group company established in Brazil. Lei nº 15.211/2025 (ECA Digital) art. 40 requires providers to 'manter representante legal no País com poderes para receber citações'. Decreto nº 12.975/2026 art. 16-A(I) goes further and requires providers of internet applications to 'constituir e manter sede e representante legal no País, com poderes para responder perante as esferas administrativa e judicial' — an office, not only an agent. The LGPD does require every controller to name a data protection officer (encarregado), but does not say that person must be in Brazil.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018 (Lei Geral de Proteção de Dados Pessoais), articles 3 and 41
planalto.gov.br
“independentemente do meio, do país de sua sede ou do país onde estejam localizados os dados”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 12.965/2014 (Marco Civil da Internet), article 11 §2
planalto.gov.br
“O disposto no caput aplica-se mesmo que as atividades sejam realizadas por pessoa jurídica sediada no exterior, desde que oferte serviço ao público brasileiro ou pelo menos uma integrante do mesmo grupo econômico possua estabelecimento no Brasil.”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilDecreto nº 12.975/2026, article 16-A — office and legal representative in Brazil
planalto.gov.br
“constituir e manter sede e representante legal no País, com poderes para responder perante as esferas administrativa e judicial”
Link checked 18 August 2026
Can I store my users' data outside Brazil?
Yes, with paperwork. Brazil has no rule making anyone keep a copy of anything inside the country — not for banks, not for hospitals, not even for the federal government's own cloud. What it has instead is a permission slip: before personal data leaves, you need one of a short list of approved legal grounds. Industry rules add conditions on top, but none of them is a wall.
Sector by sector, checked 18 August 2026: • BANKING AND PAYMENTS — conditional, and the tightest sector. Under Resolução CMN nº 4.893/2021, a supervised institution may have data processed and stored abroad, but only where the arrangement does not restrict the Banco Central's access to the data, and the central bank must be able to work with the supervisor in the host country. Prior notice to the Banco Central is required. Effect: a country allowlist in practice, without ever using that word. Marked medium confidence — see 'unconfirmed'. • INSURANCE — no localisation rule located, checked 18 August 2026. SUSEP's cybersecurity and outsourcing circulars mirror the central bank's access-and-audit approach rather than requiring Brazilian storage. Confidence medium; SUSEP's own pages could not be opened during this run. • SECURITIES — no localisation rule located, checked 18 August 2026. Confidence medium. • HEALTH — no localisation rule located, checked 18 August 2026. The binding constraint is professional secrecy for doctors and clinics rather than geography. • TELECOMS — no localisation rule. Anatel's cybersecurity regulation (R-Ciber) sets security and incident duties, not storage location. But the Marco Civil pins Brazilian law onto any collection, storage or processing where at least one step happens in Brazil, and sets minimum log-keeping periods. • GOVERNMENT CLOUD — open, and this is the finding most trackers get wrong. Decreto nº 8.135/2013, which pushed federal communications data onto systems run by federal bodies, was revoked by Decreto nº 9.637/2018. The current federal cloud contracting model, Portaria SGD/MGI nº 5.950/2023, sorts workloads by how sensitive they are and by logical and physical isolation — not by which country the servers are in. • MAPPING AND AERIAL SURVEY — restricted, but as an activity rather than as storage. Aerial surveying of Brazilian territory is controlled by the armed forces, and a foreign organisation may only take part exceptionally. • EDUCATION, GAMING, DEFENCE — no separate localisation rule located, checked 18 August 2026.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 33 — grounds for international transfer; no storage-location rule anywhere in the Act
planalto.gov.br
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilDecreto nº 8.135/2013 — federal government communications data; marked 'Revogado pelo Decreto nº 9.637, de 2018'
planalto.gov.br
Link checked 18 August 2026
- Official sourceSecretaria de Governo Digital, Ministério da Gestão e da Inovação em Serviços PúblicosFederal cloud computing contracting model — Portaria SGD/MGI nº 5.950, de 26 de outubro de 2023
gov.br
Link checked 18 August 2026
- Official sourceAgência Nacional de TelecomunicaçõesRegulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações (R-Ciber)
gov.br
Link checked 18 August 2026
What do I need in place before data leaves Brazil?
Pick one of five routes. The easy one is the European Union: since January 2026 Brazil treats it as safe, so nothing extra is needed. For everywhere else, the normal route is a set of standard contractual clauses that the regulator itself wrote — you copy them into your contract exactly, and you may not edit them. A deadline to retrofit older contracts already passed, on 23 August 2025.
Resolução CD/ANPD nº 19, de 23 de agosto de 2024, sets five mechanisms: adequacy decisions; the Brazilian standard contractual clauses, which are fixed and may not be modified; foreign clause sets formally recognised as equivalent; bespoke specific clauses, which need the regulator's prior approval and are meant for exceptional cases; and global corporate rules for a group of companies. Existing contracts had twelve months from publication to be brought into line — that is 23 August 2025. The adequacy list is populated, but with exactly one entry: Resolução nº 32/2026, of 26 January 2026, recognised the European Union as an adequate international organisation, and the regulator's own guidance is that transfers to an adequate destination 'podem ocorrer sem a necessidade de mecanismos adicionais'. No other adequacy decision, no specific clause set and no global corporate rules had been approved as at this check. The narrow escape hatches in the Act itself — the person's specific consent to the transfer, protection of someone's life, international legal cooperation — remain available but are not built for routine or bulk transfers.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosTransferência internacional de dados — Resolução CD/ANPD nº 19, de 23 de agosto de 2024, and Resolução nº 32/2026 (European Union adequacy, 26 January 2026)
gov.br
“as transferências internacionais de dados para esses países ou organizações podem ocorrer sem a necessidade de mecanismos adicionais”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 33 — the nine statutory grounds for transferring personal data abroad
planalto.gov.br
“países ou organismos internacionais que proporcionem grau de proteção de dados pessoais adequado”
Link checked 18 August 2026
Who enforces the rules in Brazil, and what can they do?
The National Data Protection Authority, and it is genuinely working. A law passed in February 2026 gave it real independence, 200 new specialist jobs and its own budget. In August 2026 it ordered Discord to switch off live video streaming in Brazil within three working days, to protect children. Banking, telecoms, insurance and securities regulators enforce their own rules in parallel and have done so for years.
The Autoridade Nacional de Proteção de Dados (ANPD) was confirmed as an autarquia de natureza especial with functional, technical, decision-making, administrative and financial autonomy by Lei nº 15.352, de 25 de fevereiro de 2026, which also created 200 specialist posts by converting 797 vacant administrative posts, at no extra cost. Observable enforcement, not text: on 12 August 2026 the authority issued a preventive measure against Discord under the ECA Digital, giving three business days to suspend the 'Go Live' feature and equivalent video-sharing, over failures to prevent minors being exposed to self-harm and suicide content. Decretos nº 12.975 and nº 12.976, both of 20 May 2026, added platform regulation, supervision and infringement powers over user rights. One quirk worth knowing: the authority's own website and social media are running in restricted mode until the end of the October 2026 general elections, which makes some material harder to find but does not pause enforcement. Rated active rather than aggressive: fines are still relatively few, and the loudest actions so far are orders to stop doing something rather than large financial penalties.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosPreventive measure against Discord, 12 August 2026 — suspension of live streaming in Brazil
gov.br
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 15.352, de 25 de fevereiro de 2026 — ANPD autonomy, governance and 200 new specialist posts
planalto.gov.br
“autarquia de natureza especial vinculada ao Ministério da Justiça e Segurança Pública, dotada de autonomia funcional, técnica, decisória, administrativa e financeira”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosANPD's platform supervision powers under Decretos nº 12.975 and nº 12.976 of 20 May 2026
gov.br
“A Agência Nacional de Proteção de Dados – ANPD atuará na regulação, na fiscalização e na apuração de infrações quanto à garantia dos direitos dos usuários”
Link checked 18 August 2026
How long do I have to keep the data?
Both directions, and they pull against each other. The floor: internet access providers must keep connection records for one year, websites and apps must keep access records for six months, and tax records need five years. The ceiling: the privacy law says personal data must be deleted once you have finished doing what you collected it for. Where the two clash, the legal duty to keep wins — the law lists that as an express reason to hold on.
Floor. Marco Civil da Internet art. 13: connection records kept under secrecy, in a controlled and secure environment, 'pelo prazo de 1 (um) ano'. Art. 15: internet application providers organised as companies keep application access records 'pelo prazo de 6 (seis) meses'. Tax: the Código Tributário Nacional works on a five-year window — art. 150 §4 fixes five years for homologation, and the assessment and collection limitation periods in arts. 173 and 174 run on the same five-year scale, so five years is the practical floor for books and fiscal records. Ceiling. LGPD art. 16: 'Os dados pessoais serão eliminados após o término de seu tratamento', with four carve-outs — compliance with a legal or regulatory obligation, research with anonymisation where possible, transfer to a third party on the same terms, and the controller's own exclusive use in anonymised form. Conflict resolution: the first carve-out is the express answer. A statutory retention duty is a lawful reason to keep data past the point where the original purpose ended, but it does not licence keeping it for anything else.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 12.965/2014 (Marco Civil da Internet), articles 13 and 15 — one-year connection logs, six-month application access logs
planalto.gov.br
“manter os registros de conexão, sob sigilo, em ambiente controlado e de segurança, pelo prazo de 1 (um) ano”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 16 — deletion after processing ends, with four exceptions
planalto.gov.br
“Os dados pessoais serão eliminados após o término de seu tratamento”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 5.172/1966 (Código Tributário Nacional), article 150 §4 — five-year tax window
planalto.gov.br
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, not one. Privacy: three working days to tell the regulator AND the affected people, once you have confirmed a breach that could really hurt them. Platform content: two hours to take down intimate images shared without consent, once notified. On top of that, banks report incidents to the central bank and telecoms operators report to the telecoms regulator under their own separate timetables.
Clock one — personal data breach. Resolução CD/ANPD nº 15, de 24 de abril de 2024: 'a comunicação à ANPD ... deverá ser realizada pelo controlador no prazo de três (3) dias úteis'. Three cumulative triggers: the incident is confirmed, it involves personal data covered by the privacy law, and it is 'capaz de acarretar risco ou dano relevante aos titulares'. The same three-working-day deadline applies to telling the individuals, in plain language, individually where possible, and the notice must state the categories of data affected, the security measures in place, the risks identified, the reason for any delay, the mitigation taken, the date the incident was discovered and a contact point. The regulator may demand a copy of what you sent people at any time. Clock two — non-consensual intimate content. Decreto nº 12.976/2026 requires removal 'em até duas horas após a notificação'. Clock three — sectoral. Banking incident reporting to the Banco Central under the cyber security and cloud resolution, and telecoms incident reporting to Anatel under the R-Ciber regulation, run separately with their own deadlines; the exact hour counts for these two were not verified in this run. The common failure mode is treating the privacy clock as the only clock, and starting it from the day the report lands on the legal team's desk rather than from confirmation.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosComunicação de Incidente de Segurança — Resolução CD/ANPD nº 15, de 24 de abril de 2024, articles 6 and 9
gov.br
“a comunicação à ANPD ... deverá ser realizada pelo controlador no prazo de três (3) dias úteis”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosDecreto nº 12.976/2026 — two-hour removal deadline for non-consensual intimate content
gov.br
“em até duas horas após a notificação”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 48 — duty to notify the authority and the data subject
planalto.gov.br
Link checked 18 August 2026
What trips people up in Brazil?
Five. (1) Your European standard contract is not automatically good enough — Brazil wrote its own clauses and you must copy them exactly, unedited, and the deadline to fix old contracts passed on 23 August 2025. (2) A child in Brazil is under 12 and an adolescent is 12 to 17, but the social media rule bites at 16 — accounts for anyone up to 16 must be tied to a parent's account, and asking users to state their own age is banned. (3) Since 20 July 2026 a digital platform needs an actual registered office in Brazil, not just a lawyer on retainer. (4) The biggest fine is not in the privacy law: the internet law allows up to 10 percent of your group's Brazilian revenue. (5) The regulator can order your database blocked or your processing suspended, which usually hurts more than any cheque.
(1) Resolução CD/ANPD nº 19/2024 makes the Brazilian standard contractual clauses non-negotiable text. Foreign clause sets only work where formally recognised as equivalent; bespoke wording needs prior approval. Twelve-month retrofit window from 23 August 2024 expired 23 August 2025. (2) Lei nº 15.211/2025 art. 9 §1 bans self-declared age ('vedada a autodeclaração'); art. 24 requires accounts of users up to 16 to be linked to a parent or guardian's account; art. 22 bans profiling to target advertising at children and adolescents, and bans emotional analysis, augmented reality, extended reality and virtual reality for ad targeting; art. 26 bans building behavioural profiles of child and adolescent users, including from the data collected to verify their age. Art. 7 §1 requires products to run by default at the highest available level of protection. (3) Decreto nº 12.975/2026 art. 16-A(I): office and legal representative, with authority to answer administratively and judicially. In force sixty days after publication on 21 May 2026. (4) Marco Civil art. 12: 'Multa de até 10% (dez por cento) do faturamento do grupo econômico no Brasil no seu último exercício, excluídos os tributos', plus temporary suspension or prohibition of the activities. The ECA Digital art. 35(II) uses the same 10 percent of Brazilian group revenue, or where there is no revenue, between 10 and 1,000 reais per registered user, capped at 50 million reais per infringement. The LGPD's own cap is 2 percent of Brazilian revenue capped at 50 million reais per infringement — the smallest of the three. (5) LGPD art. 52 sanctions include blocking the personal data concerned, deleting it, partial or total suspension of the database, suspension of the processing activity and partial or total prohibition of processing. The Discord order of August 2026 is the live example of how this is used.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 15.211/2025 (ECA Digital), articles 7, 9, 22, 24, 26, 35 and 40
planalto.gov.br
“é vedada a criação de perfis comportamentais de usuários crianças e adolescentes”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 12.965/2014, article 12 — up to 10 percent of Brazilian group revenue
planalto.gov.br
“Multa de até 10% (dez por cento) do faturamento do grupo econômico no Brasil no seu último exercício, excluídos os tributos”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 52 — sanctions including blocking, deletion and suspension of the database
planalto.gov.br
“2% (dois por cento) do faturamento da pessoa jurídica de direito privado ... limitada, no total, a R$ 50.000.000,00 (cinquenta milhões de reais)”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosStandard contractual clauses are fixed text and may not be modified; twelve-month retrofit deadline
gov.br
Link checked 18 August 2026
What is changing soon in Brazil?
One firm date: January 2027, when the regulator moves from monitoring platforms to full enforcement of the children's digital rules. Brazil's artificial intelligence bill is still only a bill — it was sitting in a committee waiting for a report as recently as June 2026, so do not plan around it. The bigger risk is not new law: it is that the regulator can add or withdraw approved destinations for data transfers by publishing a single resolution, with no consultation.
Timeline. March 2026: the children's digital statute came into force and the regulator began monitoring app stores and operating systems. August 2026: monitoring widened and the final regulatory guidance was published. January 2027: full enforcement action begins. October 2026: general elections, during which the regulator's own site and social media run restricted. Dormant switches, which matter more than the pending bills: • The adequacy list. It was empty until January 2026 and now holds exactly one entry, the European Union. The authority can add destinations, and it can withdraw one, by resolution. A withdrawal would instantly require thousands of contracts to fall back on standard clauses. • Approval of specific contractual clauses and of global corporate rules is entirely at the authority's discretion, and none had been granted at this check. • The authority now has 200 new specialist posts and full budget autonomy from February 2026. Enforcement volume can rise sharply without any change in the law. • The children's statute lets the authority set the detailed rules by regulation, including how age must be checked. Pending, not binding: the artificial intelligence bill (PL 2338/2023, which reached the Chamber of Deputies on 17 March 2025) was recorded as 'Aguardando Parecer' — awaiting a committee opinion — on 17 June 2026, with related bills attached to it.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosECA Digital implementation timeline — in force 17 March 2026, full enforcement from January 2027
gov.br
Link checked 18 August 2026
- Official sourceCâmara dos Deputados — Dados AbertosPL 2338/2023 (artificial intelligence bill) — status 'Aguardando Parecer' as at 17 June 2026
dadosabertos.camara.leg.br
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosAdequacy decisions and clause approvals are made by resolution of the ANPD board
gov.br
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 2
Industry rules
Made by an industry regulator. These usually beat the general position.
6 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
National rules4 rules
Lei Geral de Proteção de Dados Pessoais (LGPD)
Act of parliament · Lei nº 13.709, de 14 de agosto de 2018
Brazil's general privacy law. It reaches foreign companies with no local office, requires a named data protection contact, and lets personal data leave the country only on one of nine listed grounds. It contains no storage-location requirement of any kind. Sanctions have applied since 1 August 2021.
Enforced by National Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, Someone's life is at risk, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of processing
- Appoint a data protection officerCalled the 'encarregado'. Required of every controller. The law does not say the person must be located in Brazil.
- Report breaches to the regulator — within 72 hoursThree business days under the 2024 incident regulation, not 72 clock hours. The number given here is the nearest usable approximation for sorting.
- Tell affected people — within 72 hours
- Delete data after a periodDelete once processing ends, subject to four statutory carve-outs.
- Put a transfer safeguard in place
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: 2% do faturamento no Brasil, limitada a R$ 50.000.000,00 por infração — about $9 millionAny breach of the Act; the cash cap is 50 million reais, about 9 million US dollars, per infringement
- Daily fine until fixed: Multa diária, sujeita ao mesmo tetoContinuing non-compliance
- Order to stopBlocking or deletion of the data, partial or total suspension of the database, suspension or prohibition of the processing activity
- Claims by individualsIndividual or collective compensation claims, including class actions by public prosecutors
Sources
- Official sourcePresidência da República — Casa CivilLei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais
planalto.gov.br
“Os dados pessoais serão eliminados após o término de seu tratamento”
Link checked 18 August 2026
Regulamento de Transferência Internacional de Dados Pessoais
Directly binding regulation · Resolução CD/ANPD nº 19, de 23 de agosto de 2024; adequacy by Resolução nº 32/2026
The rulebook for sending personal data out of Brazil. Five routes exist, but in practice there are two: the standard contractual clauses written by the regulator, which you must copy word for word, or an adequacy decision. The adequacy list holds exactly one entry — the European Union, recognised on 26 January 2026.
Enforced by National Data Protection Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What it makes you do
- Put a transfer safeguard in place — from 23 August 2025Contracts signed before 23 August 2024 had twelve months to adopt the Brazilian standard clauses. That window closed on 23 August 2025.
- Written vendor contractThe Brazilian standard clauses are fixed text and may not be modified. Bespoke 'specific clauses' need the authority's prior approval.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosTransferência Internacional de Dados — Resolução CD/ANPD nº 19/2024 and Resolução nº 32/2026
gov.br
“as transferências internacionais de dados para esses países ou organizações podem ocorrer sem a necessidade de mecanismos adicionais”
Link checked 18 August 2026
Regulamento de Comunicação de Incidente de Segurança
Directly binding regulation · Resolução CD/ANPD nº 15, de 24 de abril de 2024
Three working days to tell both the regulator and the affected people about a confirmed personal data breach that could cause them real harm. The notice must list the categories of data involved, the risks, what you have done about it and when you found out.
Enforced by National Data Protection Authority
What it makes you do
- Report breaches to the regulator — within 72 hoursThree business days from confirmation. Over a weekend or a public holiday this is materially longer than 72 clock hours — but it starts at confirmation, not at escalation to legal.
- Tell affected people — within 72 hoursSame three-business-day deadline. Plain language, individual notice where possible.
- Keep records of processingThe regulator may demand a copy of the notice sent to individuals at any time.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosComunicação de Incidente de Segurança (CIS) — Resolução CD/ANPD nº 15, de 24 de abril de 2024
gov.br
“a comunicação à ANPD ... deverá ser realizada pelo controlador no prazo de três (3) dias úteis”
Link checked 18 August 2026
Marco Civil da Internet
Act of parliament · Lei nº 12.965, de 23 de abril de 2014 · Telecoms
Brazil's internet law. It does not require data to be stored in Brazil — a localisation clause was in the draft and was dropped before the law passed. What it does is pin Brazilian law onto any collection, storage or processing where even one step happens in Brazil, set minimum log-keeping periods, and back that with a fine of up to a tenth of the group's Brazilian revenue.
Enforced by National Data Protection Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 1 yearInternet connection providers: connection records, kept under secrecy in a controlled and secure environment.
- Keep logs — 6 monthsInternet application providers organised as companies: application access records.
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: Até 10% do faturamento do grupo econômico no Brasil no último exercício, excluídos os tributosBreach of the duty to respect Brazilian law when collecting, storing or processing records, personal data or communications
- Order to stopTemporary suspension or prohibition of the activities concerned
Sources
- Official sourcePresidência da República — Casa CivilLei nº 12.965, de 23 de abril de 2014 — Marco Civil da Internet, articles 11, 12, 13 and 15
planalto.gov.br
“Em qualquer operação de coleta, armazenamento, guarda e tratamento de registros, de dados pessoais ou de comunicações por provedores de conexão e de aplicações de internet em que pelo menos um desses atos ocorra em território nacional, deverão ser obrigatoriamente respeitados a legislação brasileira”
Link checked 18 August 2026
Industry rules6 rules
Estatuto Digital da Criança e do Adolescente (ECA Digital)
Act of parliament · Lei nº 15.211, de 17 de setembro de 2025; commencement fixed by Lei nº 15.352/2026 · Social media and online platforms
Brazil's children's digital statute. It bans self-declared age, ties the accounts of anyone up to 16 to a parent's account, forbids profiling and behavioural targeting of under-18s, and requires a legal representative inside Brazil. In force since 17 March 2026, with monitoring first and full enforcement from January 2027.
Enforced by National Data Protection Authority
What it makes you do
- Get a parent's consent for children — applies at: Accounts of users up to 16 must be linked to a parent or guardian's account, from 17 March 2026
- No tracking or ads to children — from 17 March 2026No profiling to target advertising at children or adolescents; no behavioural profiles of them at all, including from age-check data; no emotional analysis, augmented, extended or virtual reality for ad targeting.
- Appoint a local representative — from 17 March 2026A legal representative in Brazil with power to receive service of process.
- Assess high-risk projectsRisk assessment and risk management, reported in the transparency report.
- Keep records of processing — applies at: Providers with more than 1,000,000 registered child or adolescent users in BrazilHalf-yearly transparency report, in Portuguese, published on the provider's website.
- Secure the dataProducts must run by default at the highest level of protection available.
What it costs if you get it wrong
- Percentage of global turnover: Até 10% do faturamento do grupo econômico no Brasil, ou R$ 10 a R$ 1.000 por usuário registrado, limitada a R$ 50.000.000,00 por infração — about $9 millionBreach of the children's digital duties. The cash cap is 50 million reais, about 9 million US dollars, per infringement
- Order to stopTemporary suspension or prohibition of the activity, ordered by a court
Sources
- Official sourcePresidência da República — Casa CivilLei nº 15.211, de 17 de setembro de 2025 — Estatuto Digital da Criança e do Adolescente
planalto.gov.br
“deverão manter representante legal no País com poderes para receber citações”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosECA Digital — ANPD's enforcement role and phased timeline to January 2027
gov.br
Link checked 18 August 2026
Decreto nº 12.975, de 20 de maio de 2026 (deveres dos provedores de aplicações de internet)
Directly binding regulation · Decreto nº 12.975/2026, published 21 May 2026; companion Decreto nº 12.976/2026 · Social media and online platforms
Since 20 July 2026, a company that hosts other people's content for Brazilian users must have an actual registered office and a legal representative in Brazil, run systemic risk assessments and publish transparency reports. Private email, private messaging and closed-group video calls are carved out. The data protection authority regulates and enforces it.
Enforced by National Data Protection Authority
What it makes you do
- Appoint a local representative — from 20 July 2026Not just an agent: the provider must establish and maintain a registered office (sede) in Brazil as well as a legal representative able to answer administratively and judicially.
- Assess high-risk projectsDiligent monitoring, identification, assessment and management of systemic risks.
- Keep records of processingTransparency reports covering out-of-court notices, advertising and boosted content.
- Check your algorithms
Sources
- Official sourcePresidência da República — Casa CivilDecreto nº 12.975/2026 — duties of internet application providers, article 16-A
planalto.gov.br
“constituir e manter sede e representante legal no País, com poderes para responder perante as esferas administrativa e judicial”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosANPD — Marco Civil da Internet: new competences under Decretos 12.975 and 12.976 of 20 May 2026
gov.br
Link checked 18 August 2026
Resolução CMN nº 4.893 — política de segurança cibernética e requisitos para contratação de serviços de processamento e armazenamento de dados e de computação em nuvem
Directly binding regulation · Resolução CMN nº 4.893, de 26 de fevereiro de 2021 · Banking
Banks and other supervised financial institutions may process and store data abroad, but only where the Banco Central can still reach that data and can work with the supervisor in the host country. In practice this behaves like a country allowlist for banking data, without ever being written as one. It is a condition, not a wall — nothing has to stay in Brazil.
Enforced by Central Bank of Brazil
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Written vendor contractThe contract must not restrict the Banco Central's access to the data and to the supplier's records, and must provide for audit and for continuity if the arrangement ends.
- Register or notifyPrior notice to the Banco Central before contracting relevant processing, storage or cloud services abroad.
- Secure the data
- Report cyber incidentsIncident reporting to the Banco Central under the same cyber security policy. Exact deadline not verified in this run.
Sources
- Official sourceLink may be brokenBanco Central do BrasilResolução CMN nº 4.893, de 26 de fevereiro de 2021 — official text on the Banco Central's normative database
bcb.gov.br
Link checked 18 August 2026
Modelo de contratação de software e serviços de computação em nuvem
Government rules · Portaria SGD/MGI nº 5.950, de 26 de outubro de 2023 · Government
The rule most often reported wrongly. Brazil's federal cloud contracting model sorts government workloads by how sensitive they are and how well they are isolated, and does not require servers to be on Brazilian soil. The old decree that pushed federal communications data onto systems run by federal bodies was revoked in 2018.
Enforced by Secretariat of Digital Government
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataDeployment model chosen by criticality and classification of the data, and by logical and physical isolation — not by which country the servers sit in.
Sources
- Official sourceSecretaria de Governo Digital, Ministério da Gestão e da Inovação em Serviços PúblicosNuvem — Portaria SGD/MGI nº 5.950, de 26 de outubro de 2023
gov.br
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilDecreto nº 8.135/2013 — revoked by Decreto nº 9.637 of 2018
planalto.gov.br
“Revogado pelo Decreto nº 9.637, de 2018”
Link checked 18 August 2026
Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações (R-Ciber)
Directly binding regulation · Resolução Anatel nº 740/2020 · Telecoms
Brazil's telecoms cybersecurity rulebook sets security and incident duties for network operators. It does not require network data to be kept in Brazil. The location constraint on telecoms data comes from the internet law's log-keeping periods, not from this regulation.
Enforced by National Telecommunications Agency
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Secure the dataSecurity requirements for telecom equipment, networks and users.
- Report cyber incidentsIncident reporting to the telecoms regulator. Exact deadline not verified in this run.
Sources
- Official sourceAgência Nacional de TelecomunicaçõesSegurança Cibernética — Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações (R-Ciber)
gov.br
Link checked 18 August 2026
Decreto-Lei nº 1.177 — aerolevantamento no território nacional
Act of parliament · Decreto-Lei nº 1.177, de 21 de junho de 1971 · Mapping and location
Brazil controls who may fly and photograph its own territory. Aerial surveying is supervised by the armed forces, and a foreign organisation can only take part in exceptional cases. This restricts the activity of collecting detailed mapping data rather than where the resulting files are stored.
Enforced by Ministry of Defence / Armed Forces Staff
What it makes you do
- Register or notifyAerial survey activity over Brazilian territory is controlled by the armed forces staff. A foreign organisation may take part only exceptionally — by a decision of the President or to meet an international commitment.
Sources
- Official sourcePresidência da República — Casa CivilDecreto-Lei nº 1.177, de 21 de junho de 1971 — aerolevantamento, articles 2 and 4
planalto.gov.br
“O Estado-Maior das Forças Armadas é o órgão oficial incumbido de controlar as atividades de aerolevantamentos”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact wording of the Banco Central's rules on processing and storing financial data abroad (Resolução CMN nº 4.893/2021)
The Banco Central's normative database only renders with JavaScript and every direct route to the text failed during this run, including the legacy PDF paths and the official gazette, which blocks automated fetching. The rule is cited to the Banco Central's own page and marked medium confidence. Treat the description of the conditions as directionally right and verify the article numbers before relying on them.
Whether the insurance regulator (SUSEP) or the securities regulator (CVM) imposes any storage-location requirement
No such rule was located, checked 18 August 2026, but neither regulator's normative index could be opened during this run. This is a 'not found', not a 'does not exist'.
Whether any health-sector rule requires patient records to be held in Brazil
No such rule was located, checked 18 August 2026. The medical council's own site is not on a government domain, so nothing could be cited to the required standard. The operative constraint in health is professional secrecy rather than geography, but that has not been verified against a government source here.
The precise legal architecture behind Decreto nº 12.975/2026
The decree's numbering inserts articles 16-A to 16-P and 19-A into the internet law's scheme, which suggests it implements provisions added to that law by a separate 2026 statute that could not be independently identified in this run. The office-and-representative requirement itself is quoted verbatim from the decree and is not in doubt; its parent statute is.
Whether the Supreme Court's 2025 ruling on intermediary liability changed the enforceable content of the internet law
Widely reported, but no decision on the court's own site was opened during this run. No 'disapplied' status has therefore been asserted for any provision of the internet law. Check this on the next refresh — it is the most likely place for Brazil to hold a disapplied-but-still-printed provision.
Exact incident reporting deadlines to the Banco Central and to the telecoms regulator
Both regimes are confirmed to exist and to impose reporting, but the hour counts were not verified against the instruments.
The exact number and value of fines the data protection authority has issued to date
The authority publishes sanctions through the federal transparency portal rather than on its own sanctions page, and its site is in restricted election mode. Enforcement is rated 'active' on the strength of a dated, named order rather than on fine statistics.
60-day cadence. Three things can move without warning: the adequacy list, which went from empty to one entry in January 2026 and is changed by a single resolution; the children's statute, which switches from monitoring to full enforcement in January 2027; and the newly-resourced regulator, whose enforcement volume can rise sharply with no change in the law. The October 2026 general elections also put the regulator's own communications into restricted mode, which makes verification harder for the rest of the year.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Brazil versus Argentina
- Brazil versus Armenia
- Brazil versus Australia
- Brazil versus Austria
- Brazil versus Azerbaijan
- Brazil versus Bulgaria
- Brazil versus Cambodia
- Brazil versus Canada
- Brazil versus China
- Brazil versus Croatia
- Brazil versus Cyprus
- Brazil versus Estonia
- Brazil versus France
- Brazil versus Georgia
- Brazil versus Germany
- Brazil versus Greece
- Brazil versus Hong Kong SAR
- Brazil versus Hungary
- Brazil versus Iceland
- Brazil versus India
- Brazil versus Indonesia
- Brazil versus Ireland
- Brazil versus Israel
- Brazil versus Italy
- Brazil versus Japan
- Brazil versus Latvia
- Brazil versus Lithuania
- Brazil versus Luxembourg
- Brazil versus Malta
- Brazil versus Mexico
- Brazil versus Mongolia
- Brazil versus Nepal
- Brazil versus Netherlands
- Brazil versus Poland
- Brazil versus Russia
- Brazil versus Saudi Arabia
- Brazil versus Serbia
- Brazil versus Singapore
- Brazil versus Slovakia
- Brazil versus Slovenia
- Brazil versus South Korea
- Brazil versus Spain
- Brazil versus Sri Lanka
- Brazil versus Sweden
- Brazil versus Switzerland
- Brazil versus Taiwan
- Brazil versus Thailand
- Brazil versus Turkey
- Brazil versus Ukraine
- Brazil versus United Arab Emirates
- Brazil versus United Kingdom
- Brazil versus United States
- Brazil versus Uzbekistan