

New Measures Strengthen the Protection of Children and Adolescents in the Digital Environment
On August 6, Statute #15,487/2026 was enacted in Brazil, introducing a series of amendments to Brazilian legislation aimed at strengthening efforts to combat sexual violence against children and adolescents, particularly in the digital environment. Among the key changes, the Statute establishes the so-called “virtual patrol”, allowing law enforcement authorities and public prosecutors to use software tools to identify and collect files related to such crimes in publicly accessible digital environments without prior judicial authorization.
The Statute also allows law enforcement authorities and public prosecutors to request connection records and users’ registration data directly from service providers, without prior judicial authorization, in emergency situations where a child or adolescent identified during a virtual patrol operation is at risk of death or physical harm. In such cases, the measure remains subject to subsequent judicial review.
Our Legislative Update, available on our Portal, provides a more detailed assessment of Statute #15,487/2026.
On August 11, the Brazilian Data Protection Agency (ANPD) issued guidelines regarding the publication of transparency reports required under the Digital Statute for Children and Adolescents (the “ECA Digital”). This obligation applies to providers of internet applications directed at or likely to be accessed by children and adolescents with over one million registered users under the age of 18. The guidelines clarify that the first report must be published by September 17, 2026, and must cover the period from January 1 to June 30, 2026. Platforms that do not have systematized data for January and February 2026 may limit the scope of the initial report to the period from March 17 to June 30, 2026.
Our Client Alert provides a more detailed assessment of the guideline issued by the ANPD.
Additionally, on August 27, the ANPD reported that Meta had expressed its intention to request a meeting with the Agency to discuss measures contemplated in a settlement agreement entered into in the United States. The agreement aims to resolve litigation related to the impacts of social media use by children and adolescents.
Finally, the Federal Police announced that it is establishing the National Center for the Protection of Children and Adolescents (CNCA) to receive reports of suspected crimes committed against children and adolescents in the digital environment, as required by the ECA Digital. The Center will be responsible for technical validation, case screening, prioritization, and sharing of information with the authorities responsible for investigations. The first version of the system is expected to be made available for testing by the end of 2026.
Why it matters?
The implementation of the ECA Digital continues to advance, and new minors’ protection initiatives are already creating real impacts for digital platforms and online service providers. The new transparency reporting guidelines, expanded investigative mechanisms, and the establishment of the CNCA all point to increased regulatory activity and heightened expectations from authorities regarding the protection of children and adolescents in the digital environment.
Brazil Intensifies Oversight of Digital Platforms Following the Suspension of Discord’s Go Live Feature and TikTok’s BRL 153.7 Million Fine
On August 12, the ANPD temporarily suspended Discord’s Go Live feature in Brazil, preventing users from accessing its screen-sharing and video-sharing functionalities. The decision was prompted by the tragic death of a teenage girl connected to a coordinated campaign of violence carried out across multiple digital platforms.
In response, Discord stated that the server related to the case had already been removed before the incident. Subsequently, on August 24, the company appealed the decision and requested a stay of its effects to restore the functionalities, while also seeking the annulment of the precautionary measure on the grounds that the ANPD lacked the authority to impose the restriction, that the proceeding suffered from procedural defects, and that the measure was disproportionate.
Additionally, the Attorney General’s Office (AGU) filed a class action before a federal court in Brasília seeking an order requiring Discord to implement product changes and to pay BRL 500 million in damages.
Following the suspension of Discord’s functionalities, the President of the ANPD and the Agency’s Superintendent of Inspection stated in an interview that the Agency is considering expanding the range of digital platforms subject to regulatory oversight. According to them, the ANPD is already monitoring 37 companies considered to pose higher risk and is preparing a new round of supervisory activities later this year.
In parallel, on August 15, the ANPD imposed a BRL 153.7 million fine on ByteDance, TikTok’s parent company, following an administrative enforcement proceeding that investigated irregularities in the processing of minors’ personal data. This is the highest fine ever imposed by the ANPD. The decision also ordered the deletion of unlawfully collected data and the implementation of a compliance plan aimed at strengthening the protection of children and adolescents.
The sanction resulted from an investigation that identified practices inconsistent with the Brazilian General Data Protection Act (LGPD) in two forms of access to the platform: (i) the “non-registered feed”, available without the need to create an account; and (ii) the “registered feed”, linked to a user account on the social network.
Moreover, the 14th Criminal Court of Maceió ordered the nationwide blocking of the Zangi messaging app in Brazil, its removal from app stores, and its blocking by telecommunications operators after the company allegedly failed to comply with a court order requiring the disclosure of user data in the context of a criminal investigation. According to the decision, the company did not provide the requested information despite having been formally notified and subjected to daily fines.
Finally, on August 21, the ANPD announced the launch of monitoring activities directed at major digital platforms, app stores, and generative artificial intelligence tools to verify compliance with obligations established under the Brazilian Internet Act, its implementing regulations, and the ECA Digital. According to the Agency, the initiative is intended to support future enforcement measures and assess whether monitored entities have adopted adequate mechanisms to prevent and reduce the circulation of illegal content, particularly content affecting minors and women.
The monitoring initiative covers two groups of entities: (i) digital platforms and messaging apps, including Instagram, Facebook, TikTok, X, Discord, YouTube, Kwai, LinkedIn, Snapchat, Pinterest, and Reddit, as well as WhatsApp Public Channels and Telegram Public Channels and Public Groups; and (ii) app stores and generative artificial intelligence tools, including the App Store, Google Play Store, Copilot, Claude, DeepSeek, Gemini, ChatGPT, Meta AI, and Perplexity.
Our Regulatory Update provides a more detailed assessment of the monitoring initiative announced by the ANPD.
Why it matters?
The measures adopted by the ANPD, including the suspension of Discord’s Go Live feature, the fine imposed on TikTok, and the launch of monitoring activities targeting major digital platforms, app stores, and generative AI tools, indicate that the Agency has moved beyond merely providing guidance to the market on the new rules. The focus now appears to be on active oversight and the adoption of measures aimed at ensuring compliance with obligations related to digital safety. In addition, recent court decisions demonstrate that the judiciary is also closely scrutinizing digital platforms and the risks associated with their services. Companies operating in this sector should therefore prepare for increased scrutiny and enforcement activity.
The 2026 Elections Reinforce the Debate Over Artificial Intelligence and Disinformation
In a publication issued on August 3, the Federal Senate noted that the 2026 elections will be the first general elections held under specific rules governing the use of artificial intelligence in electoral advertising. Regulations issued by the Superior Electoral Court (TSE) require that any content generated or manipulated by AI include clear, prominent, and accessible disclosure informing users of its use. The requirement applies to text, images, videos, and audio disseminated during election campaigns.
Additionally, during the 72 hours preceding election day and the 24 hours following the close of voting, the dissemination or republication of new synthetic content using the image, voice, or statements of candidates or public figures is prohibited, even where such content is properly identified.
On August 18, the justices of the Superior Electoral Court (TSE) met to discuss the prohibition on the use of deepfakes in electoral campaigns and potential sanctions for violations of applicable rules. Subsequently, on September 1, the Court addressed the issue in a plenary decision adopted by a 5-2 majority, defining a deepfake as synthetic content produced or manipulated through artificial intelligence or equivalent technology that presents a degree of realism and creates, reproduces, or alters the image, voice, or expression of a living, deceased, or fictitious person.
The Court also clarified that the prohibition on the use of deepfakes in elections is not absolute, holding that the restriction applies only where the content qualifies as electoral advertising.
In addition, on August 20, the TSE ordered the removal, within 24 hours, of an artificial intelligence-generated video linking presidential candidate Flávio Bolsonaro to banker Daniel Vorcaro.
Finally, in his government program, President Lula advocates for the creation of a Ministry of Public Security and the advancement of the regulation of social media and digital platforms. The issue is presented as part of a broader strategy to strengthen democracy, including the establishment of rules for such platforms aimed at curbing the dissemination of disinformation, hate speech, and other practices considered harmful to public debate.
Combating cybercrime is also among the priorities outlined in the public security agenda. In this regard, the plan proposes strengthening prevention, intelligence, investigation, and enforcement activities, with a focus on electronic banking fraud, high-technology crimes, hate crimes, and cyber offenses directed against the Brazilian State or involving a transnational dimension.
Why it matters?
As the 2026 elections approach, the use of artificial intelligence in electoral advertising has attracted increasing attention from Brazilian authorities. In this context, it is important for digital platforms, particularly those offering generative AI services, to closely monitor the TSE’s rules regarding synthetic content, as well as broader regulatory and enforcement efforts aimed at combating disinformation.
ANPD Suspends Facial Recognition for School Attendance Tracking; Supreme Court Begins Reviewing Limits on Access to Confidential Data in Investigations
On August 6, the ANPD published its decision suspending the use of facial recognition systems for attendance tracking in Paraná’s state public school system. The Agency classified the processing of biometric data belonging to approximately one million students and 100,000 staff members as a high-risk data processing activity. The decision ordered the suspension of the collection, consultation, comparison, use, and sharing of such data until further determination by the ANPD.
In a statement released on August 20, the Brazilian Institute for Consumer Protection (Idec) and the organization Coding Rights announced that they had requested investigations regarding potential violations of the rights of women, children, and adolescents related to the use of Ray-Ban Meta smart glasses with artificial intelligence (AI) features in Brazil. The organizations filed complaints with the ANPD, the National Consumer Secretariat (Senacon), and the Federal Public Prosecutor’s Office (MPF).
The requests seek coordinated action by the three authorities to assess potential privacy risks and possible violations of the Brazilian General Data Protection Act and the Brazilian Consumer Protection Code arising from the use of the device.
In addition, on August 27, the Brazilian Supreme Court (STF) began reviewing three cases concerning the limits on the disclosure of user data in the context of law enforcement investigations. Direct Action for the Declaration of Constitutionality (ADC) #91, filed by the Brazilian Association of Internet and Telecommunications Providers (Abrint), seeks confirmation of the constitutionality of Article 10, Paragraph 1, of the Brazilian Internet Act, which requires prior judicial authorization for providers to share connection and access logs.
Direct Actions of Unconstitutionality (ADIs) #5059, filed by the National Association of Mobile Operators (ACEL), and #5073, filed by the Brazilian Confederation of Civil Police Workers (Cobrapol), concern provisions of Statute #12,830/2013 governing criminal investigations conducted by police chiefs and the authority to request expert examinations, information, documents, and data necessary for fact-finding.
In ADC 91, Reporting Justice Cristiano Zanin voted to uphold the constitutionality of the challenged provision, which requires prior judicial authorization for service providers to disclose connection and access logs. However, he recognized that, in exceptional emergency situations, authorities may request such data directly, subject to subsequent judicial review. Justice Dias Toffoli largely concurred with the reporting justice but maintained that disclosure without prior judicial authorization is permissible only in the circumstances expressly provided by law.
In ADIs 5059 and 5073, Reporting Justice Dias Toffoli recognized that police chiefs' authority to request information is inherent to investigative activities but does not authorize unrestricted access to data protected by confidentiality obligations. In his view, access to interceptions, call records, messages, and other sensitive information requires prior judicial authorization. He was joined by Justices Gilmar Mendes and Alexandre de Moraes.
Justice Cristiano Zanin also voted for partial relief, but on different grounds. While agreeing that access to more sensitive information requires judicial authorization or a specific legal basis, he proposed a different constitutional interpretation, under which the general authority to request information established by Statute #12,830/2013 supports only direct access to basic subscriber information. He was joined by Justice Nunes Marques.
No date has yet been set for the resumption of the proceedings before the Court. You may follow further developments in these proceedings through the Policy and Enforcement Tracker available in the Regulatory Radar section of our Portal.
Cybersecurity Takes Center Stage Amid the Advancement of Artificial Intelligence
According to the study ISG Provider Lens Cybersecurity Services and Solutions 2026 for Brazil, published by TGT ISG, Brazil was identified as the primary target of cyberattacks in Latin America. Despite the advances brought by the Brazilian General Data Protection Act and the oversight activities undertaken by the ANPD, the country recorded 314.8 billion malicious activities during the period, representing 84% of all attacks detected across Latin America and Canada.
On August 27, more than 100 organizations, including OpenAI, Adobe, Accenture, Anthropic, Google, Dell, Microsoft, IBM, and KPMG, released an open letter calling for a coordinated effort to address cybersecurity challenges in the age of artificial intelligence. The document seeks to foster discussion on the need for increased investment in infrastructure, specialized personnel, and cybersecurity systems.
Among the proposed measures, the organizations highlighted the need to strengthen international cooperation, expand investment in security tools, and enhance workforce training for the protection of AI-based systems. The document also calls for coordinated action among companies to establish new security standards and recommends that governments strengthen mechanisms for threat intelligence sharing, risk prioritization, and cyber incident response coordination at the local, national, and international levels.
What to Expect in the Coming Months?
Over the coming months, Brazil’s digital regulatory agenda is expected to remain focused on the implementation of the ECA Digital, and the enforcement of new obligations imposed on digital platforms, app stores, and providers of artificial intelligence services and tools. The ANPD is expected to continue expanding its monitoring and enforcement activities, with particular attention to issues such as the protection of children and adolescents, platform governance, transparency, and risk mitigation in the digital environment.
It will also be important to monitor the Brazilian Supreme Court’s review of the cases concerning the limits on the disclosure of user data in the context of law enforcement investigations.
At the same time, the upcoming 2026 elections are likely to intensify the debate surrounding the use of artificial intelligence in electoral advertising, the circulation of synthetic content, and measures aimed at combating disinformation.



