Law / Brazil

Brazil

10 of 13 named instruments researched to a stage, across all six areas of law we track: 9 in force and 1 proposed. As of 14 September 2026.

When they take effect9 of 10 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 2 instruments (2 in force) earlier 2014: 1 instrument (1 in force) 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 0 instruments 2019: 0 instruments 2020: 1 instrument (1 in force) ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 0 instruments 2024: 3 instruments (3 in force) 2025: 0 instruments 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 1
  3. Scraping law 3
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 2 in force, 1 proposed

Research summary (128 words)

Brazil has no general AI-transparency statute in force. The Superior Electoral Court's Resolução TSE nº 23.610/2019, as amended by Resolução TSE nº 23.732, de 27 de fevereiro de 2024, imposes a disclosure duty on AI-generated synthetic content used in electoral advertising and separately prohibits using a fabricated or manipulated deepfake to harm or benefit a candidacy, but these duties bind campaign advertising specifically and do not reach AI output generally.

Brazil's general framework bill for artificial intelligence, Projeto de Lei nº 2.338/2023 (Marco Legal da Inteligência Artificial), was approved by the Senate Federal in substitute form on 10 December 2024 and remitted to the Chamber of Deputies on 17 March 2025, where it remains pending as of this writing; it binds nobody unless and until it is enacted.

AI prohibited practices

TSE Resolution, Prohibition on Electoral Deepfakes

Resolução TSE nº 23.610/2019, art. 9º-C (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024)Official compiled text of Resolução TSE nº 23.610/2019, as amended by Resolução TSE nº 23.732/2024, Tribunal Superior Eleitoral

In force since 4 March 2024. Binds public and private bodies.

What this law does

Article 9º-C, inserted into Resolução TSE nº 23.610/2019 by Resolução TSE nº 23.732/2024, forbids using fabricated or manipulated content in electoral advertising, in any form, to spread notoriously untrue or gravely decontextualized facts with the potential to harm the balance of the election or the integrity of the electoral process.

Paragraph 1 specifically prohibits using synthetic audio, video, or combined audio-video content generated or digitally manipulated, even with the depicted person's authorization, to create, replace, or alter the image or voice of a living, deceased, or fictitious person, to harm or benefit a candidacy (a deep fake).

Paragraph 2 makes a violation of the caput or paragraph 1 an abuse of political power and improper use of the means of social communication, exposing the responsible candidacy to loss of its electoral registration.

What it requires

AI risk obligations

Marco Legal da Inteligência Artificial (PL 2338/2023)

Projeto de Lei nº 2.338/2023 (aprovado pelo Senado Federal em 10 de dezembro de 2024)Tramitação page for Projeto de Lei nº 2.338/2023, Senado Federal

Proposed: draft date not recorded. Before the second chamber, dated 17 March 2025, as of 12 September 2026.

What this law does

Projeto de Lei nº 2.338/2023, the Marco Legal da Inteligência Artificial, authored by Senator Rodrigo Pacheco, would be Brazil's general framework statute for artificial intelligence. The Federal Senate's plenary approved the bill in substitute form on 10 December 2024, and it was remitted to the Chamber of Deputies on 17 March 2025, where it remained pending as of this writing.

What it requires

AI transparency

TSE Resolution, AI-Generated Content Disclosure Duty

Resolução TSE nº 23.610/2019, art. 9º-B (redação dada pela Resolução TSE nº 23.732, de 27 de fevereiro de 2024)Official compiled text of Resolução TSE nº 23.610/2019, as amended by Resolução TSE nº 23.732/2024, Tribunal Superior Eleitoral

In force since 4 March 2024. Binds public and private bodies.

What this law does

Article 9º-B, inserted into Resolução TSE nº 23.610/2019 by Resolução TSE nº 23.732/2024, requires that any use in electoral advertising of AI-generated synthetic multimedia content, to create, replace, omit, merge, alter the speed of, or overlay images or sounds, carry an explicit, prominent, and accessible disclosure that the content was fabricated or manipulated and which technology was used.

Paragraph 1 requires that disclosure at the start of audio pieces, by a watermark label and audio description for static images, and in both forms for video or combined audio-video pieces. Paragraph 2 excludes image- or sound-quality adjustments, graphic identity elements, and customary marketing techniques such as composite campaign photos from the duty.

The duty binds whoever is responsible for the advertising, which reaches a candidate, party, federation, or coalition, or a service that generates or places AI content on their behalf.

What it requires

Privacy law1 instrument, 1 in force

Research summary (150 words)

Brazil's private-sector personal-data regime is the Lei Geral de Proteção de Dados Pessoais (LGPD), Lei nº 13.709, de 14 de agosto de 2018, a comprehensive statute requiring a lawful basis for any processing, heightened rules for sensitive categories including genetic and biometric data, a set of data-subject rights including review of automated decisions, conditioned international transfer, and breach notification, enforced by the Autoridade Nacional de Proteção de Dados (ANPD).

The LGPD's general provisions took effect from 18 September 2020, when Lei nº 14.058/2020 settled a legislative dispute over a proposed postponement, and its administrative sanctions (arts. 52-54) took effect separately from 1 August 2021 under Lei nº 14.010/2020.

Publicly accessible personal data remains within the LGPD's scope; only the consent requirement is dispensed for data the data subject has manifestly made public, and the processing must still respect the purpose, good faith, and public interest that justified the data's availability.

Comprehensive regime

Lei Geral de Proteção de Dados Pessoais (LGPD)

Lei nº 13.709, de 14 de agosto de 2018 (LGPD)Official compiled text of Lei nº 13.709/2018, Presidência da República

In force since 18 September 2020. Binds public and private bodies.

What this law does

The LGPD requires a lawful basis under article 7 for any processing of personal data, and article 11 confines processing of sensitive personal data, defined in article 5, II to include racial or ethnic origin, religious conviction, political opinion, health, sex life, and genetic or biometric data, to specific consent or a narrow list of alternative bases.

Article 18 gives every data subject the right to confirm processing exists, access, correct, anonymize, block, or delete their data, and to port it to another provider. Article 20 gives the data subject the right to request review of a decision taken solely on automated processing of personal data that affects their interests, including decisions defining a personal, professional, consumer, or credit profile.

Article 33 permits international transfer only to a country or organization offering an adequate level of protection, or where the controller demonstrates compliance through contractual clauses, corporate rules, seals, or another article 33 safeguard. Article 48 requires the controller to notify the ANPD and the affected data subjects of a security incident that may create relevant risk or harm.

Articles 52 to 54 authorize the ANPD to impose administrative sanctions, including a simple fine of up to 2% of the private legal entity's, group's, or conglomerate's revenue in Brazil in its last fiscal year, excluding taxes, capped in total at R$50,000,000.00 per infraction, and article 42 makes a controller or operator that causes patrimonial, moral, individual, or collective damage through personal-data processing in violation of the data-protection legislation liable to repair it.

What it requires

Scraping law3 instruments, 3 in force

Research summary (267 words)

Brazil has no scraping-specific statute, so general law governs each dimension separately.

The Penal Code's article 154-A, inserted by Lei nº 12.737/2012 and amended by Lei nº 14.155/2021, criminalizes invading a computing device, connected to a network or not, to obtain, alter, or destroy data without authorization, or to install a vulnerability, but the offense turns on invading a device rather than merely reading a page it serves, so a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision, and no reported case has tested the point.

No Brazilian court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright Law, Lei nº 9.610/1998, protects a database as a compilation where its selection, organization, or arrangement of content constitutes an intellectual creation, but article 7, § 2º expressly excludes the underlying data or materials themselves from that protection, so Brazil has no sui generis extraction-based database right and no text-and-data-mining exception distinct from the ordinary limitations of article 46.

Personal data collected by scraping, including data the data subject has made public, remains subject to the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018): only the LGPD's consent requirement is dispensed for manifestly public data, and the LGPD's other duties, together with the Marco Civil da Internet's own protection-of-records duties, still apply.

No Brazilian statute or reported case establishes a scraping-specific unfair-competition, misappropriation, or trespass doctrine distinct from the computer-misuse and copyright provisions above, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule.

Computer misuse

Penal Code Art. 154-A, Invasion of a Computing Device

Código Penal (Decreto-Lei nº 2.848/1940), art. 154-A (redação dada pela Lei nº 14.155, de 2021, inserido pela Lei nº 12.737, de 2012)Official compiled text of the Penal Code, Decreto-Lei nº 2.848/1940, Presidência da República

In force since 28 May 2021. Binds public and private bodies.

What this law does

Article 154-A punishes invading another person's computing device, whether or not connected to a network, to obtain, alter, or destroy data or information without the device user's express or tacit authorization, or to install a vulnerability to obtain an unlawful advantage, with reclusão of 1 to 4 years and a fine under the wording Lei nº 14.155/2021 gave the offense, up from the original Lei nº 12.737/2012 penalty of detention of 3 months to 1 year and a fine.

Section 2 raises the penalty by one third to two thirds if the invasion causes economic loss.

Section 3 sets a separate penalty of reclusão of 2 to 5 years and a fine where the invasion obtains the content of private electronic communications, trade or industrial secrets, confidential information as defined by law, or unauthorized remote control of the invaded device, and section 4 raises that penalty by one third to two thirds where the obtained material is disclosed, marketed, or transmitted to a third party.

Because the offense's trigger is invading a device, a scraper reading a public, unauthenticated page without defeating any access control falls outside a plain reading of the provision.

What it requires

Database right

Copyright Law, Database Compilation Right

Lei nº 9.610/1998, arts. 7º, XIII, e 87Official compiled text of Lei nº 9.610/1998, Presidência da República

In force since 20 June 1998. Binds public and private bodies.

What this law does

Article 7, XIII protects a database, along with a collection, compilation, anthology, encyclopedia, or dictionary, as an intellectual creation where its selection, organization, or arrangement of content amounts to one, and article 7, § 2º expressly states that this protection does not cover the underlying data or materials themselves and is without prejudice to any copyright that subsists in that data.

Article 87 gives the holder of the patrimonial right over a database the exclusive right to authorize or prohibit reproducing it in whole or in part, translating, adapting, reorganizing, or otherwise modifying it, distributing the original or copies, or communicating it to the public, and reproducing, distributing, or communicating the results of such a modification.

Because the protection reaches only the database's selection and arrangement, and not the data itself, Brazil has no sui generis, investment-based extraction right of the kind the European Union's Database Directive creates, and the Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists.

What it requires

Personal data

Marco Civil da Internet, Protection of Records and Personal Data

Lei nº 12.965/2014 (Marco Civil da Internet), arts. 7º, 10, e 12Official compiled text of Lei nº 12.965/2014, Presidência da República

In force since 23 June 2014. Binds private bodies.

What this law does

Article 7 assures an internet user rights including inviolability of intimacy and private life, secrecy of the flow of their internet communications except by judicial order, and secrecy of their stored private communications except by judicial order.

Article 10 requires that the retention and disclosure of connection and internet-application-access records, personal data, and the content of private communications observe the intimacy, private life, honor, and image of the parties involved, and article 10, § 1º limits disclosure of records associated with personal data or other identifying information to a judicial order.

Article 12 authorizes a warning, a fine of up to 10% of the economic group's revenue in Brazil in its last fiscal year, excluded taxes, temporary suspension, or prohibition of activity for violations of articles 10 and 11, which extend Brazilian law and these privacy, personal-data, and communications-secrecy rights to any collection, storage, custody, or processing of records, personal data, or communications where at least one such act occurs in Brazilian territory, including where performed by a foreign company that offers a service to the Brazilian public.

These duties bind an internet application provider regardless of how it collected the records, personal data, or communications, including by scraping, so long as at least one act of collection, storage, custody, or processing occurs in Brazilian territory.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (774 words)

Brazil has no enacted, comprehensive cybersecurity law comparable to the EU's Cyber Resilience Act or NIS2. Its posture instead rests on a policy-setting decree, one enacted product-security regulation reaching a narrow class of consumer networking hardware, several sector-specific cybersecurity regimes that each bind a licensed or government-designated role this corpus's activity vocabulary cannot express, and a still-pending general cybersecurity bill.

Decreto nº 11.856, de 26 de dezembro de 2023 instituted the Política Nacional de Cibersegurança (PNCiber) and the Comitê Nacional de Cibersegurança (CNCiber), a public-private coordinating body chaired by the Gabinete de Segurança Institucional da Presidência da República with 19 government, business, civil-society, and scientific seats; its articles state principles and objectives for national cybersecurity activity and create a committee that recommends further policy, but the decree's own text imposes no requirement, duty, or penalty on a private business.

Decreto nº 12.573, de 4 de agosto de 2025 instituted the Estratégia Nacional de Cibersegurança (E-Ciber) that implements PNCiber's guidelines; its provisions are written throughout in the vocabulary of incentive (incentivo, estímulo) toward the private sector, including encouraging Brazilian companies to procure products and services that adopt minimum cybersecurity standards rather than requiring anyone to meet one, so it likewise creates no enforceable duty.

Brazil's one enacted, in-force product-security requirement is Ato nº 2.436, de 7 de março de 2023 of Anatel's Superintendência de Outorga e Recursos à Prestação, which sets mandatory minimum cybersecurity requirements for the conformity assessment (homologação) of consumer-facing customer-premises equipment: cable modems, xDSL modems, ONU/ONT units, fixed-wireless-access and satellite-broadband routers and modems, and wireless routers and access points. Its Annex became mandatory on 10 March 2024 and is researched as the instrument row below.

Three further sector regimes each bind a role this corpus's declared activities cannot identify, so each is named here and none is filed as an instrument, the treatment this profile gives DORA's financial entities and NY DFS Part 500's covered entities.

Anatel's own Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, requires a "prestadora" (a Brazilian telecommunications service provider) to adopt and maintain a board-approved Cybersecurity Policy, source equipment only from suppliers whose own cybersecurity policy is compatible with the Regulation and independently and periodically audited, run cybersecurity vulnerability-assessment cycles, report on its critical telecommunications infrastructure, and notify Anatel of relevant incidents; that duty binds the carrier, not an app or a SaaS product that merely rides the carrier's network, and it is the same Resolução that gives Anatel's product-conformity procedures their cybersecurity mandate, so the two regimes share one legal source without sharing a bound party.

The Banco Central do Brasil's Resolução Conjunta CMN/BCB nº 4.893, de 26 de fevereiro de 2021 requires every institution the Central Bank authorizes to operate, meaning banks and other regulated financial institutions, to implement and maintain a board-approved cybersecurity policy addressing incident response, vulnerability management, and the security of contracted cloud and data-processing services; the bound party is a licensed financial institution, not a declared LexLint activity.

Aneel's Resolução Normativa nº 964, de 28 de setembro de 2021 imposes an analogous cybersecurity policy duty on the electric-power sector; it does not reach a digital-service provider of the kind this corpus's activities identify and is named here for completeness only.

A general cybersecurity statute is pending, not enacted. Projeto de Lei nº 4.752, de 2025, authored by Senator Esperidião Amin and others, would institute a "Marco Legal da Cibersegurança" and a national digital security and resilience program.

As of its most recent Senate committee action the bill remains with a rapporteur in the Comissão de Ciência, Tecnologia, Inovação e Informática, having received further amendments in September 2026, and it has not been enacted, so nothing about its eventual content is asserted here.

Brazil's General Data Protection Law (LGPD, Lei nº 13.709/2018) carries its own security-of-processing duty (Arts. 46 to 49) and its own personal-data breach-notification duty (Art. 48); both are this jurisdiction's privacy-topic findings and are not restated here, the treatment this profile gives a comprehensive regime's own security article.

The Marco Civil da Internet (Lei nº 12.965/2014) likewise requires an internet connection or application provider to keep connection and application-access records under confidentiality in a controlled, secure environment; that duty attaches to the records themselves and is researched with this jurisdiction's other Marco Civil provisions rather than repeated here.

No published enforcement record specific to Anatel's CPE cybersecurity requirements is confirmed in the primary text; Anatel states only that it monitors homologated products in the market on an ongoing basis and can suspend a product's homologação, which bars its distribution in Brazil, if a security flaw is found.

Product security requirements

Anatel Cybersecurity Requirements for CPE (Customer Premises Equipment)

Ato nº 2.436 de 7 de março de 2023 (Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações), as amended by Ato nº 7.344, de 15 de junho de 2023; issued under the Regulamento de Segurança Cibernética Aplicada ao Setor de Telecomunicações, approved by Resolução nº 740, de 21 de dezembro de 2020, and the Regulamento de Avaliação da Conformidade e de Homologação de Produtos para Telecomunicações, approved by Resolução nº 715, de 23 de outubro de 2019Official act text, Superintendência de Outorga e Recursos à Prestação, Agência Nacional de Telecomunicações (Anatel)

In force since 10 March 2024. Binds private bodies.

What this law does

A manufacturer or supplier of specified consumer customer-premises equipment, meaning a cable modem, xDSL modem, ONU or ONT, fixed-wireless-access or satellite-broadband router or modem, or wireless router or access point sold in Brazil to connect a subscriber to an internet service provider's network, must meet mandatory minimum cybersecurity requirements before Anatel will certify the device.

The device may carry no default, blank, or weak passwords and no password shared across all units as manufactured. It may also carry no credentials or cryptographic keys hard-coded in the device's software or firmware. The manufacturer must provide at least two years of free security updates after launch or for as long as the product stays on the market, whichever is longer.

It must also maintain a published, securely reachable channel plus a coordinated vulnerability-disclosure policy for reporting a security flaw. Anatel enforces the requirement through the device's conformity assessment (homologação) and can suspend a product's homologação, which bars its distribution in Brazil, if it later finds a security flaw.

What it requires

Age gating law1 instrument, 1 in force

Research summary (119 words)

Brazil's age-appropriate design duties for digital services sit in Lei nº 15.211, de 17 de setembro de 2025 (the Estatuto Digital da Criança e do Adolescente, or ECA Digital), which applies to any information-technology product or service directed at children and adolescents, or likely to be accessed by them, wherever the provider is located, and enters into force on 17 March 2026.

The Estatuto da Criança e do Adolescente (ECA, Lei nº 8.069/1990), including as amended by Lei nº 14.811/2024, sets Brazil's general child-protection framework and criminalizes online exhibition or transmission of child sexual abuse material, but its own text imposes no age-verification or age-gating duty on a digital service provider; that duty arrives only with Lei nº 15.211/2025.

Age-appropriate design code

Estatuto Digital da Criança e do Adolescente (ECA Digital)

Lei nº 15.211, de 17 de setembro de 2025Official compiled text of Lei nº 15.211/2025 (Estatuto Digital da Criança e do Adolescente), Presidência da República

In force 6 months, effective 17 March 2026. Binds private bodies.

What this law does

Lei nº 15.211/2025 applies to any information-technology product or service directed at children or adolescents in Brazil, or likely to be accessed by them, regardless of the provider's location, development, manufacture, offer, marketing, or operation. Article 5 requires such a product or service to observe duties of prevention, protection, information, and security, adopting the child's or adolescent's best interest and integral protection as the guiding standard.

Article 11 lets the public authority act as regulator, certifier, or promoter of age-verification technical solutions.

Article 12 requires app-store and terminal operating-system providers to take proportionate, auditable, and technically secure measures to assess users' age or age range, to let parents or legal guardians configure voluntary parental-supervision mechanisms, and to make an age signal available to internet application providers through a privacy-by-design Application Programming Interface, limited to this law's purposes.

Article 14 requires the product or service provider itself, independently of the measures app stores or operating systems adopt, to implement its own mechanisms to prevent children and adolescents from accessing content unsuited to their age range. Articles 16 to 18 require parental-supervision tools, and article 18, § 2º prohibits designing, modifying, or manipulating an interface to undermine a user's autonomy or decision-making where doing so weakens those supervision tools or safeguards.

Article 35 authorizes an advertência, a simple fine of up to 10% of the economic group's revenue in Brazil in its last fiscal year, or, absent revenue, a per-registered-user fine, capped in total at R$50,000,000.00 per infraction, temporary suspension, or prohibition of activity, enforced by an independent administrative authority the law directs be created for this purpose.

The law's article 41-A entry-into-force date was set at six months after publication by Medida Provisória nº 1.319/2025 and then fixed at 17 March 2026 by Lei nº 15.352/2026, and the law has bound covered providers from that date.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (287 words)

Brazil has no press-publisher neighbouring right and no mandatory platform-to-publisher bargaining code; the general copyright framework of the Copyright Law, Lei nº 9.610/1998, is the only law reaching an aggregator's reproduction of news content.

Article 46, I, a) permits reproducing, in the daily or periodical press, a news item or informative article published in a newspaper or periodical, naming the author if signed and the publication it was transcribed from, and article 46, III separately permits quoting passages of any work in a book, newspaper, magazine, or other communication medium for study, criticism, or controversy, to the extent justified for that purpose, naming the author and the origin of the work.

Neither provision carries a headline-length or short-extract cap distinct from these tests, and no reported Brazilian decision applies either to a systematic news aggregator as opposed to a single periodical reproducing another's item or an individual quoting a published work.

The Act's neighbouring rights protect performers, phonogram producers, and broadcasting organizations, not print or online news publishers, so there is no publisher-side neighbouring right of the kind the European Union's Digital Single Market Directive article 15 creates.

No statute or reported case addresses whether a hyperlink is itself a communication to the public, or whether framing or inline display changes the answer, and no hot-news or misappropriation doctrine distinct from ordinary copyright law has been located.

The Act predates the concept of a machine-readable text-and-data-mining reservation, so no opt-out mechanism of that kind exists; a text-and-data-mining exception has been proposed only within Projeto de Lei nº 2.338/2023, Brazil's pending general framework bill for artificial intelligence, approved by the Senate in substitute form on 10 December 2024 and, as of this writing, before the Chamber of Deputies.

Snippet reproduction

Copyright Law, Press Reproduction and Quotation Exceptions

Lei nº 9.610/1998, art. 46, I, a), e IIIOfficial compiled text of Lei nº 9.610/1998, Presidência da República

In force since 20 June 1998. Binds public and private bodies.

What this law does

Article 46, I, a) permits, without offending copyright, reproducing a news item or informative article published in a daily or periodical, in the daily or periodical press, naming the author if the item was signed and the publication it was transcribed from.

Article 46, III separately permits quoting passages of any work, in a book, newspaper, magazine, or any other communication medium, for the purposes of study, criticism, or controversy, to the extent justified for the purpose to be achieved, naming the author and the origin of the work.

Neither provision carries a headline-length or short-extract cap distinct from these tests, and no reported Brazilian decision applies either provision to a systematic news aggregator rather than a periodical reproducing another periodical's item or an individual quoting a published work. Neighbouring rights under the Act, covering performers, phonogram producers, and broadcasting organizations, do not extend to a print or online news publisher's own reporting.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.