Brazil
Not part of a rule-making bloc: national and industry rules are the whole picture. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Brazil — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Brazil does not force data to stay inside the country. You can send personal data abroad. Since August 2025 you normally need a contract the regulator wrote, copied word for word, signed with whoever receives it. Sending data to the European Union needs nothing extra. The regulator is active. In August 2026 it ordered Discord to turn off live video in Brazil.
Data governance in Brazil
The eight things that decide how you handle data about people in Brazil. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Brazil's privacy law reaches a company with no office in Brazil. It applies if you collect data in Brazil, or offer goods or services to people here. There is no size or revenue limit that lets you out. The privacy law itself does not make you appoint anyone local. Two newer rules do. If you run a digital platform you now need a registered office and a legal representative in Brazil.
- What you have to do here:
- Appoint a representative · Appoint a data protection officer
The privacy law is Lei nº 13.709/2018, known as the LGPD. Article 3 applies it whatever the medium, whatever country your head office is in, and wherever the data sits. The internet law is Marco Civil da Internet (Lei nº 12.965/2014). Its article 11 extends Brazilian law to foreign-based companies that offer services to the Brazilian public. It also covers foreign companies with a group company established in Brazil. Lei nº 15.211/2025, the children's digital statute, article 40, makes providers keep a legal representative in Brazil who can accept court papers. Decreto nº 12.975/2026, article 16-A(I), goes further. Providers of internet applications must set up and keep a head office in Brazil. They must also keep a legal representative there, able to answer to regulators and to courts. That means an office, not just an agent. The LGPD does require every company that decides how data is used to name a data protection officer, called the encarregado. It does not say that person must be in Brazil.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018 (Lei Geral de Proteção de Dados Pessoais), articles 3 and 41
planalto.gov.br
“independentemente do meio, do país de sua sede ou do país onde estejam localizados os dados”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 12.965/2014 (Marco Civil da Internet), article 11 §2
planalto.gov.br
“O disposto no caput aplica-se mesmo que as atividades sejam realizadas por pessoa jurídica sediada no exterior, desde que oferte serviço ao público brasileiro ou pelo menos uma integrante do mesmo grupo econômico possua estabelecimento no Brasil.”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilDecreto nº 12.975/2026, article 16-A — office and legal representative in Brazil
planalto.gov.br
“constituir e manter sede e representante legal no País, com poderes para responder perante as esferas administrativa e judicial”
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork. Nothing has to stay in Brazil. Not for banks, not for hospitals, not even for the federal government's own cloud. What you need instead is permission. Before personal data leaves, you must have one of a short list of approved legal grounds. Industry rules add conditions on top. None of them stops data leaving.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses
Checked industry by industry on 18 August 2026: • BANKING AND PAYMENTS. Conditional, and the tightest industry. Under Resolução CMN nº 4.893/2021, a supervised institution may have data handled and stored abroad. But the arrangement must not restrict the Banco Central's access to that data. The central bank must also be able to work with the supervisor in the host country. You must give the Banco Central notice first. The result is that only some countries work, even though the rules never list them. Marked medium confidence. See the unconfirmed list. • INSURANCE. We found no rule about where data must be stored, checked 18 August 2026. SUSEP's cybersecurity and outsourcing circulars copy the central bank's access-and-audit approach. They do not require Brazilian storage. Confidence medium. We could not open SUSEP's own pages. • SECURITIES. We found no rule about where data must be stored, checked 18 August 2026. Confidence medium. • HEALTH. We found no rule about where data must be stored, checked 18 August 2026. What binds doctors and clinics is professional secrecy, not geography. • TELECOMS. No rule about where data must be stored. Anatel's cybersecurity regulation, called R-Ciber, sets security and incident duties. It says nothing about storage location. But the Marco Civil applies Brazilian law to any collection, storage or use of data where at least one step happens in Brazil. It also sets minimum log-keeping periods. • GOVERNMENT CLOUD. Open. Decreto nº 8.135/2013 pushed federal communications data onto systems run by federal bodies. Decreto nº 9.637/2018 revoked it. The current federal cloud contracting model is Portaria SGD/MGI nº 5.950/2023. It sorts workloads by how sensitive they are and by how well they are isolated, physically and logically. It does not sort them by which country the servers are in. • MAPPING AND AERIAL SURVEY. Restricted, but the limit is on the activity, not on storage. The armed forces control aerial surveying of Brazilian territory. A foreign organisation may take part only in exceptional cases. • EDUCATION, GAMING, DEFENCE. We found no separate rule about where data must be stored, checked 18 August 2026.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 33 — grounds for international transfer; no storage-location rule anywhere in the Act
planalto.gov.br
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilDecreto nº 8.135/2013 — federal government communications data; marked 'Revogado pelo Decreto nº 9.637, de 2018'
planalto.gov.br
Link checked 18 August 2026
- Official sourceSecretaria de Governo Digital, Ministério da Gestão e da Inovação em Serviços PúblicosFederal cloud computing contracting model — Portaria SGD/MGI nº 5.950, de 26 de outubro de 2023
gov.br
Link checked 18 August 2026
- Official sourceAgência Nacional de TelecomunicaçõesRegulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações (R-Ciber)
gov.br
Link checked 18 August 2026
What to do: Get the paperwork for one of the routes below signed before any data leaves Brazil.
Sending data out of the country
Pick one of five routes. The easy one is the European Union. Since January 2026 Brazil treats it as safe, so nothing extra is needed. For everywhere else, the normal route is a standard contract the regulator itself wrote. You copy it into your contract exactly and you may not edit it. The deadline to fix older contracts has already passed. It was 23 August 2025.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Explicit consent · To save someone’s life
Resolução CD/ANPD nº 19, de 23 de agosto de 2024, sets five routes. One: an official decision that a country is safe enough. Two: the Brazilian standard contract clauses, which are fixed text you may not change. Three: a foreign set of clauses formally recognised as equivalent. Four: tailor-made clauses, which need the regulator's approval first and are meant for rare cases. Five: global corporate rules for a group of companies. Existing contracts had twelve months from publication to catch up. That deadline was 23 August 2025. The safe-country list has exactly one entry. Resolução nº 32/2026, of 26 January 2026, recognised the European Union as an international organisation that is safe enough. The regulator's own guidance says transfers to a safe destination can happen with no extra paperwork. No other country has been recognised. No tailor-made clauses and no global corporate rules had been approved when we checked. The law itself has a few narrow escape routes. The person's specific consent to the transfer. Protecting someone's life. International legal cooperation. These still work, but they are not built for routine or bulk transfers.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosTransferência internacional de dados — Resolução CD/ANPD nº 19, de 23 de agosto de 2024, and Resolução nº 32/2026 (European Union adequacy, 26 January 2026)
gov.br
“as transferências internacionais de dados para esses países ou organizações podem ocorrer sem a necessidade de mecanismos adicionais”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 33 — the nine statutory grounds for transferring personal data abroad
planalto.gov.br
“países ou organismos internacionais que proporcionem grau de proteção de dados pessoais adequado”
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The National Data Protection Authority, and it is working. A law passed in February 2026 gave it real independence, 200 new specialist jobs and its own budget. In August 2026 it ordered Discord to switch off live video streaming in Brazil within three working days, to protect children. The banking, telecoms, insurance and securities regulators enforce their own rules alongside it. They have done so for years.
- What it costs if you get it wrong:
- Order to stop
The Autoridade Nacional de Proteção de Dados, or ANPD, is now a special-status independent agency. Lei nº 15.352, de 25 de fevereiro de 2026, confirmed that. It has autonomy over its functions, its technical work, its decisions, its administration and its money. The same law created 200 specialist posts by converting 797 empty administrative posts, at no extra cost. Here is what it has actually done. On 12 August 2026 it issued a preventive order against Discord under the children's digital statute. Discord had three business days to switch off the 'Go Live' feature and similar video sharing. The reason was a failure to stop minors seeing self-harm and suicide content. Decretos nº 12.975 and nº 12.976, both of 20 May 2026, added powers to regulate platforms, supervise them and penalise breaches of user rights. One quirk is worth knowing. The authority's website and social media run in restricted mode until the October 2026 general elections end. That makes some material harder to find. It does not pause enforcement. We rate it active rather than aggressive. Fines are still few. The loudest actions so far are orders to stop doing something, not large fines.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosPreventive measure against Discord, 12 August 2026 — suspension of live streaming in Brazil
gov.br
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 15.352, de 25 de fevereiro de 2026 — ANPD autonomy, governance and 200 new specialist posts
planalto.gov.br
“autarquia de natureza especial vinculada ao Ministério da Justiça e Segurança Pública, dotada de autonomia funcional, técnica, decisória, administrativa e financeira”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosANPD's platform supervision powers under Decretos nº 12.975 and nº 12.976 of 20 May 2026
gov.br
“A Agência Nacional de Proteção de Dados – ANPD atuará na regulação, na fiscalização e na apuração de infrações quanto à garantia dos direitos dos usuários”
Link checked 18 August 2026
How long you must keep it — and when to delete it
Rules pull in both directions. On the keep-it side, internet access providers must keep connection records for one year. Websites and apps must keep access records for six months. Tax records need five years. On the delete-it side: the privacy law says you must delete personal data once you have finished what you collected it for. Where the two clash, the duty to keep wins. The law lists that as an express reason to hold on.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Minimums. Marco Civil da Internet article 13: internet connection providers keep connection records for one year, under secrecy, in a controlled and secure place. Article 15: internet application providers that are set up as companies keep application access records for six months. Tax: the Código Tributário Nacional works on a five-year window. Article 150 fixes five years for confirming a return. The time limits for assessment and collection in articles 173 and 174 run on the same five-year scale. So five years is the working minimum for books and tax records. Maximums. LGPD article 16 says personal data must be deleted once you have finished using it. It gives four exceptions. Meeting a legal or regulatory duty. Research, with data anonymised where possible. Passing data to a third party on the same terms. And your own exclusive use of the data in anonymised form. Where a keep-it rule and a delete-it rule clash, the first exception is the answer. A legal duty to keep data lets you hold it past the point where your original purpose ended. It does not let you use it for anything else.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 12.965/2014 (Marco Civil da Internet), articles 13 and 15 — one-year connection logs, six-month application access logs
planalto.gov.br
“manter os registros de conexão, sob sigilo, em ambiente controlado e de segurança, pelo prazo de 1 (um) ano”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 16 — deletion after processing ends, with four exceptions
planalto.gov.br
“Os dados pessoais serão eliminados após o término de seu tratamento”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 5.172/1966 (Código Tributário Nacional), article 150 §4 — five-year tax window
planalto.gov.br
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Three clocks, not one. Privacy: three working days to tell the regulator and the affected people. That clock starts once you have confirmed a breach that could really hurt them. Platform content: two hours to take down intimate images shared without consent, once you are told. On top of that, banks report incidents to the central bank and telecoms operators report to the telecoms regulator. Those run on their own separate timetables.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock one: personal data breach. Resolução CD/ANPD nº 15, de 24 de abril de 2024, gives you three working days to tell the regulator. Three things must all be true first. The incident is confirmed. It involves personal data covered by the privacy law. And it could cause real risk or harm to the people affected. The same three-working-day deadline applies to telling those people. Use plain language. Tell them individually where you can. Your notice must state several things. The kinds of data affected. The security measures in place. The risks you found. The reason for any delay. What you did to limit the damage. The date you found the incident. And a contact point. The regulator can demand a copy of what you sent people at any time. Clock two: intimate content shared without consent. Decreto nº 12.976/2026 requires removal within two hours of being told. Clock three: industry rules. Banks report incidents to the Banco Central under the cyber security and cloud resolution. Telecoms operators report to Anatel under the R-Ciber regulation. Both run separately with their own deadlines. We did not verify the exact hour counts for those two. Two things to get right. The privacy clock is not the only clock. And it starts when you confirm the breach, not when the report reaches your legal team.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosComunicação de Incidente de Segurança — Resolução CD/ANPD nº 15, de 24 de abril de 2024, articles 6 and 9
gov.br
“a comunicação à ANPD ... deverá ser realizada pelo controlador no prazo de três (3) dias úteis”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosDecreto nº 12.976/2026 — two-hour removal deadline for non-consensual intimate content
gov.br
“em até duas horas após a notificação”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 48 — duty to notify the authority and the data subject
planalto.gov.br
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five. (1) Your European standard contract is not enough on its own. Brazil wrote its own clauses. You must copy them exactly, without edits. The deadline to fix old contracts passed on 23 August 2025. (2) A child in Brazil is under 12 and an adolescent is 12 to 17. But the social media rule starts at 16. Accounts for anyone up to 16 must be tied to a parent's account, and asking users to state their own age is banned. (3) Since 20 July 2026 a digital platform needs a real registered office in Brazil, not just a lawyer on retainer. (4) The biggest fine is not in the privacy law. The internet law allows up to 10 percent of your group's Brazilian revenue. (5) The regulator can order your database blocked or your use of data suspended. That usually hurts more than any fine.
- What you have to do here:
- Get a parent's consent for children · No tracking or ads to children · Appoint a representative · Put a transfer safeguard in place
- What it costs if you get it wrong:
- Percentage of global turnover · Order to stop
(1) Resolução CD/ANPD nº 19/2024 makes the Brazilian standard contract clauses fixed text. A foreign set of clauses works only where formally recognised as equivalent. Tailor-made wording needs approval first. Old contracts had twelve months from 23 August 2024 to catch up. That window closed on 23 August 2025. (2) Lei nº 15.211/2025 article 9 bans letting users declare their own age. Article 24 requires accounts of users up to 16 to be linked to a parent's or guardian's account. Article 22 bans profiling to target ads at children and adolescents. It also bans emotional analysis, augmented reality, extended reality and virtual reality for ad targeting. Article 26 bans building behaviour profiles of child and adolescent users, including from data collected to check their age. Article 7 requires products to run by default at the highest level of protection available. (3) Decreto nº 12.975/2026 article 16-A(I) requires an office and a legal representative, able to answer to regulators and to courts. It took effect sixty days after publication on 21 May 2026. (4) Marco Civil article 12 allows a fine of up to 10 percent of the group's Brazilian revenue in its last financial year, before tax. It also allows the activity to be suspended or banned. The children's digital statute, article 35(II), uses the same 10 percent of Brazilian group revenue. Where there is no revenue, it charges between 10 and 1,000 reais per registered user, capped at 50 million reais per breach. The privacy law's own cap is 2 percent of Brazilian revenue, capped at 50 million reais per breach. That is the smallest of the three. (5) LGPD article 52 gives the regulator several powers. It can block the personal data or delete it. It can suspend the database in part or in full. It can suspend your use of the data, and ban that use in part or in full. The Discord order of August 2026 shows how this is used.
Sources
- Official sourcePresidência da República — Casa CivilLei nº 15.211/2025 (ECA Digital), articles 7, 9, 22, 24, 26, 35 and 40
planalto.gov.br
“é vedada a criação de perfis comportamentais de usuários crianças e adolescentes”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 12.965/2014, article 12 — up to 10 percent of Brazilian group revenue
planalto.gov.br
“Multa de até 10% (dez por cento) do faturamento do grupo econômico no Brasil no seu último exercício, excluídos os tributos”
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilLei nº 13.709/2018, article 52 — sanctions including blocking, deletion and suspension of the database
planalto.gov.br
“2% (dois por cento) do faturamento da pessoa jurídica de direito privado ... limitada, no total, a R$ 50.000.000,00 (cinquenta milhões de reais)”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosStandard contractual clauses are fixed text and may not be modified; twelve-month retrofit deadline
gov.br
Link checked 18 August 2026
What's changing next
One firm date: January 2027. That is when the regulator moves from watching platforms to fully enforcing the children's digital rules. Brazil's artificial intelligence bill is still only a bill. As recently as June 2026 it was sitting in a committee waiting for a report. Do not plan around it. The bigger risk is not new law. The regulator can add or remove approved destinations for data transfers by publishing a single resolution, with no consultation.
Timeline. March 2026: the children's digital statute came into force and the regulator began watching app stores and operating systems. August 2026: the watching widened and the final guidance was published. January 2027: full enforcement begins. October 2026: general elections, during which the regulator's own site and social media run restricted. Powers the authority already holds. These matter more than the bills waiting in Congress: • The safe-country list. It was empty until January 2026 and now holds exactly one entry, the European Union. The authority can add destinations, and it can remove one, by resolution. Removing one would force thousands of contracts back onto standard clauses overnight. • Approving tailor-made contract clauses and global corporate rules is entirely up to the authority. None had been granted when we checked. • The authority has 200 new specialist posts and full control of its own budget from February 2026. The amount of enforcement can rise sharply with no change in the law. • The children's statute lets the authority set the detailed rules itself, including how age must be checked. Waiting, not binding: the artificial intelligence bill, PL 2338/2023, reached the Chamber of Deputies on 17 March 2025. On 17 June 2026 it was recorded as awaiting a committee opinion, with related bills attached to it.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosECA Digital implementation timeline — in force 17 March 2026, full enforcement from January 2027
gov.br
Link checked 18 August 2026
- Official sourceCâmara dos Deputados — Dados AbertosPL 2338/2023 (artificial intelligence bill) — status 'Aguardando Parecer' as at 17 June 2026
dadosabertos.camara.leg.br
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosAdequacy decisions and clause approvals are made by resolution of the ANPD board
gov.br
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Children's data rules
Official name: Estatuto Digital da Criança e do Adolescente (ECA Digital) · Lei nº 15.211, de 17 de setembro de 2025; commencement fixed by Lei nº 15.352/2026 · Act of parliament
Brazil's children's digital statute. It bans letting users declare their own age. Accounts for anyone up to 16 must be tied to a parent's account. Profiling and behaviour-based targeting of under-18s are banned. You need a legal representative inside Brazil. It has been in force since 17 March 2026. The regulator is watching first and enforces fully from January 2027.
It is already law, so plan for it — but nobody can be penalised under it until 1 January 2027. A contract you sign may still hold you to it sooner.
Enforced by National Data Protection Authority
What you have to do
- Get a parent's consent for children — applies at: Accounts of users up to 16 must be linked to a parent or guardian's account, from 17 March 2026
- No tracking or ads to children — from 17 March 2026No profiling to target advertising at children or adolescents. No behaviour profiles of them at all, including from age-check data. No emotional analysis, augmented reality, extended reality or virtual reality for ad targeting.
- Appoint a representative — from 17 March 2026A legal representative in Brazil with power to receive service of process.
- Assess high-risk projectsRisk assessment and risk management, reported in the transparency report.
- Keep records of how you use data — applies at: Providers with more than 1,000,000 registered child or adolescent users in BrazilHalf-yearly transparency report, in Portuguese, published on the provider's website.
- Secure the dataProducts must run by default at the highest level of protection available.
What it costs if you get it wrong
- Percentage of global turnover: Até 10% do faturamento do grupo econômico no Brasil, ou R$ 10 a R$ 1.000 por usuário registrado, limitada a R$ 50.000.000,00 por infração — about $9 millionBreach of the children's digital duties. The cash cap is 50 million reais, about 9 million US dollars, per infringement
- Order to stopTemporary suspension or prohibition of the activity, ordered by a court
Sources
- Official sourcePresidência da República — Casa CivilLei nº 15.211, de 17 de setembro de 2025 — Estatuto Digital da Criança e do Adolescente
planalto.gov.br
“deverão manter representante legal no País com poderes para receber citações”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosECA Digital — ANPD's enforcement role and phased timeline to January 2027
gov.br
Link checked 18 August 2026
General data protection law (Social media and online platforms)
Official name: Decreto nº 12.975, de 20 de maio de 2026 (deveres dos provedores de aplicações de internet) · Decreto nº 12.975/2026, published 21 May 2026; companion Decreto nº 12.976/2026 · Directly binding regulation
Since 20 July 2026 there is a new duty for companies that host other people's content for Brazilian users. You must have a real registered office and a legal representative in Brazil. It must also assess systemic risks and publish transparency reports. Private email, private messaging and closed-group video calls are excluded. The data protection authority writes and enforces these rules.
Enforced by National Data Protection Authority
What you have to do
- Appoint a representative — from 20 July 2026An agent is not enough. You must set up and keep a registered office in Brazil, called a sede. You also need a legal representative able to answer to regulators and to courts.
- Assess high-risk projectsDiligent monitoring, identification, assessment and management of systemic risks.
- Keep records of how you use dataTransparency reports covering out-of-court notices, advertising and boosted content.
- Check your algorithms
Sources
- Official sourcePresidência da República — Casa CivilDecreto nº 12.975/2026 — duties of internet application providers, article 16-A
planalto.gov.br
“constituir e manter sede e representante legal no País, com poderes para responder perante as esferas administrativa e judicial”
Link checked 18 August 2026
- Official sourceAutoridade Nacional de Proteção de DadosANPD — Marco Civil da Internet: new competences under Decretos 12.975 and 12.976 of 20 May 2026
gov.br
Link checked 18 August 2026
Banking rules
Official name: Resolução CMN nº 4.893 — política de segurança cibernética e requisitos para contratação de serviços de processamento e armazenamento de dados e de computação em nuvem · Resolução CMN nº 4.893, de 26 de fevereiro de 2021 · Directly binding regulation
Banks and other supervised financial firms may handle and store data abroad. But the Banco Central must still be able to reach that data. It must also be able to work with the supervisor in the host country. So only some countries work for banking data, even though the rules never list them. It is a condition, not a ban. Nothing has to stay in Brazil.
Enforced by Central Bank of Brazil
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Written vendor contractThe contract must not restrict the Banco Central's access to the data or to the supplier's records. It must also provide for audit, and for continuity if the arrangement ends.
- Register or notifyGive the Banco Central notice before you contract for relevant data handling, storage or cloud services abroad.
- Secure the data
- Report cyber incidentsReport incidents to the Banco Central under the same cyber security policy. We did not verify the exact deadline.
Sources
- Official sourceLink may be brokenBanco Central do BrasilResolução CMN nº 4.893, de 26 de fevereiro de 2021 — official text on the Banco Central's normative database
bcb.gov.br
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Modelo de contratação de software e serviços de computação em nuvem · Portaria SGD/MGI nº 5.950, de 26 de outubro de 2023 · Government rules
Brazil's federal cloud contracting model sorts government workloads by how sensitive they are and how well they are isolated. It does not require servers to be on Brazilian soil. The old decree that pushed federal communications data onto systems run by federal bodies was revoked in 2018.
Enforced by Secretariat of Digital Government
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataYou pick the deployment model by how critical and how sensitive the data is, and by physical and logical isolation. Not by which country the servers sit in.
Sources
- Official sourceSecretaria de Governo Digital, Ministério da Gestão e da Inovação em Serviços PúblicosNuvem — Portaria SGD/MGI nº 5.950, de 26 de outubro de 2023
gov.br
Link checked 18 August 2026
- Official sourcePresidência da República — Casa CivilDecreto nº 8.135/2013 — revoked by Decreto nº 9.637 of 2018
planalto.gov.br
“Revogado pelo Decreto nº 9.637, de 2018”
Link checked 18 August 2026
Cyber security rules
Official name: Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações (R-Ciber) · Resolução Anatel nº 740/2020 · Directly binding regulation
Brazil's telecoms cybersecurity rulebook sets security and incident duties for network operators. It does not require network data to be kept in Brazil. The location constraint on telecoms data comes from the internet law's log-keeping periods, not from this regulation.
Enforced by National Telecommunications Agency
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Secure the dataSecurity requirements for telecom equipment, networks and users.
- Report cyber incidentsReport incidents to the telecoms regulator. We did not verify the exact deadline.
Sources
- Official sourceAgência Nacional de TelecomunicaçõesSegurança Cibernética — Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações (R-Ciber)
gov.br
Link checked 18 August 2026
State and security data rules
Official name: Decreto-Lei nº 1.177 — aerolevantamento no território nacional · Decreto-Lei nº 1.177, de 21 de junho de 1971 · Act of parliament
Brazil controls who may fly and photograph its own territory. Aerial surveying is supervised by the armed forces, and a foreign organisation can only take part in exceptional cases. This restricts the activity of collecting detailed mapping data rather than where the resulting files are stored.
Enforced by Ministry of Defence / Armed Forces Staff
What you have to do
- Register or notifyThe armed forces staff control aerial survey work over Brazilian territory. A foreign organisation may take part only in exceptional cases. That means a decision by the President, or meeting an international commitment.
Sources
- Official sourcePresidência da República — Casa CivilDecreto-Lei nº 1.177, de 21 de junho de 1971 — aerolevantamento, articles 2 and 4
planalto.gov.br
“O Estado-Maior das Forças Armadas é o órgão oficial incumbido de controlar as atividades de aerolevantamentos”
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
General data protection law
Official name: Lei Geral de Proteção de Dados Pessoais (LGPD) · Lei nº 13.709, de 14 de agosto de 2018 · Act of parliament
Brazil's general privacy law. It reaches foreign companies with no local office. It requires you to name a data protection contact. Personal data may leave the country only on one of nine listed grounds. It says nothing about where data must be stored. Penalties have applied since 1 August 2021.
Enforced by National Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Explicit consent, To save someone’s life, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Keep records of how you use data
- Appoint a data protection officerCalled the 'encarregado'. Every company that decides how data is used must name one. The law does not say the person must be in Brazil.
- Report breaches to the regulator — within 72 hoursThree business days under the 2024 incident rules, not 72 clock hours. The number given here is the nearest usable match for sorting.
- Tell affected people — within 72 hours
- Delete data after a periodDelete once you have finished using the data. Four exceptions in the law let you keep it.
- Put a transfer safeguard in place
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: 2% do faturamento no Brasil, limitada a R$ 50.000.000,00 por infração — about $9 millionAny breach of the Act; the cash cap is 50 million reais, about 9 million US dollars, per infringement
- Daily fine until fixed: Multa diária, sujeita ao mesmo tetoContinuing non-compliance
- Order to stopBlocking or deletion of the data, partial or total suspension of the database, suspension or prohibition of the processing activity
- Claims by individualsIndividual or collective compensation claims, including class actions by public prosecutors
Sources
- Official sourcePresidência da República — Casa CivilLei nº 13.709, de 14 de agosto de 2018 — Lei Geral de Proteção de Dados Pessoais
planalto.gov.br
“Os dados pessoais serão eliminados após o término de seu tratamento”
Link checked 18 August 2026
General data protection law (2025)
Official name: Regulamento de Transferência Internacional de Dados Pessoais · Resolução CD/ANPD nº 19, de 23 de agosto de 2024; adequacy by Resolução nº 32/2026 · Directly binding regulation
The rulebook for sending personal data out of Brazil. Five routes exist, but only two are usable. Copy the standard contract clauses the regulator wrote, word for word. Or send to a country officially decided to be safe enough. That list holds exactly one entry. The European Union, recognised on 26 January 2026.
Enforced by National Data Protection Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What you have to do
- Put a transfer safeguard in place — from 23 August 2025Contracts signed before 23 August 2024 had twelve months to adopt the Brazilian standard clauses. That window closed on 23 August 2025.
- Written vendor contractThe Brazilian standard clauses are fixed text and may not be changed. Tailor-made clauses need the authority's approval first.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosTransferência Internacional de Dados — Resolução CD/ANPD nº 19/2024 and Resolução nº 32/2026
gov.br
“as transferências internacionais de dados para esses países ou organizações podem ocorrer sem a necessidade de mecanismos adicionais”
Link checked 18 August 2026
Breach reporting rules
Official name: Regulamento de Comunicação de Incidente de Segurança · Resolução CD/ANPD nº 15, de 24 de abril de 2024 · Directly binding regulation
You have three working days to tell the regulator and the affected people about a personal data breach. The clock starts when you confirm it. It applies when the breach could cause real harm. Your notice must list the kinds of data involved, the risks, what you have done about it and when you found out.
Enforced by National Data Protection Authority
What you have to do
- Report breaches to the regulator — within 72 hoursThree business days from the moment you confirm the breach. Over a weekend or a public holiday that is longer than 72 clock hours. But it starts at confirmation, not when the matter reaches your legal team.
- Tell affected people — within 72 hoursSame three-business-day deadline. Plain language, individual notice where possible.
- Keep records of how you use dataThe regulator may demand a copy of the notice sent to individuals at any time.
Sources
- Official sourceAutoridade Nacional de Proteção de DadosComunicação de Incidente de Segurança (CIS) — Resolução CD/ANPD nº 15, de 24 de abril de 2024
gov.br
“a comunicação à ANPD ... deverá ser realizada pelo controlador no prazo de três (3) dias úteis”
Link checked 18 August 2026
Internet and platform rules
Official name: Marco Civil da Internet · Lei nº 12.965, de 23 de abril de 2014 · Act of parliament
Brazil's internet law. It does not require data to be stored in Brazil. A clause requiring that was in the draft and was dropped before the law passed. What it does is apply Brazilian law to any collection, storage or use of data where even one step happens in Brazil. It also sets minimum log-keeping periods. The fine can reach a tenth of the group's Brazilian revenue.
Enforced by National Data Protection Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 1 yearInternet connection providers: connection records, kept under secrecy in a controlled and secure environment.
- Keep logs — 6 monthsInternet application providers organised as companies: application access records.
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: Até 10% do faturamento do grupo econômico no Brasil no último exercício, excluídos os tributosBreach of the duty to respect Brazilian law when collecting, storing or processing records, personal data or communications
- Order to stopTemporary suspension or prohibition of the activities concerned
Sources
- Official sourcePresidência da República — Casa CivilLei nº 12.965, de 23 de abril de 2014 — Marco Civil da Internet, articles 11, 12, 13 and 15
planalto.gov.br
“Em qualquer operação de coleta, armazenamento, guarda e tratamento de registros, de dados pessoais ou de comunicações por provedores de conexão e de aplicações de internet em que pelo menos um desses atos ocorra em território nacional, deverão ser obrigatoriamente respeitados a legislação brasileira”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact wording of the Banco Central's rules on processing and storing financial data abroad (Resolução CMN nº 4.893/2021)
We could not check the exact wording against the Banco Central's own database. The rule is cited to the Banco Central's own page and marked medium confidence. Treat our description of the conditions as broadly correct. Verify the article numbers before you rely on them.
Whether the insurance regulator (SUSEP) or the securities regulator (CVM) imposes any storage-location requirement
We found no rule requiring data to stay in Brazil, checked 18 August 2026. We could not confirm that against either regulator's own list of rules. If you work in insurance or securities, check before you rely on it.
Whether any health-sector rule requires patient records to be held in Brazil
We found no rule requiring patient records to be held in Brazil, checked 18 August 2026. The medical council's site is not a government domain, so we could not cite it to our standard. What binds health providers is professional secrecy rather than geography. We could not confirm that against a government source either. Check before you rely on it.
The precise legal architecture behind Decreto nº 12.975/2026
The decree inserts articles 16-A to 16-P and 19-A into the internet law. That suggests it puts into effect new rules added to that law by a separate 2026 statute. We could not identify that statute. The office-and-representative requirement is quoted word for word from the decree and is not in doubt. Its parent law is.
Whether the Supreme Court's 2025 ruling on intermediary liability changed the enforceable content of the internet law
This is widely reported, but we could not open any decision on the court's own site. So we have not marked any part of the internet law as no longer applied. Check this at the next update. It is the most likely place for Brazil to have a rule that is still printed but no longer enforced.
Exact incident reporting deadlines to the Banco Central and to the telecoms regulator
Both sets of rules exist and both require reporting. We could not confirm the exact hour counts against the official texts. Check them before you build your incident plan.
The exact number and value of fines the data protection authority has issued to date
The authority publishes its penalties through the federal transparency portal rather than on its own sanctions page. Its site is also in restricted election mode. We rate enforcement 'active' on the strength of one dated, named order rather than on fine statistics.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.