0
The obligation to retain the source TCP port
June 15, 2026
Digital Plataforms
Articles

What changes with Decree #12.975/2026?

On May 21, the Brazilian Government published Decree #12,975/2026, which established new rules for digital platforms operating in Brazil. The debates surrounding the decree focused mainly on issues such as content moderation, the requirement for legal representation in the country, and new transparency requirements in the digital environment.
 

Amid these discussions, one of the changes with the potential to impact the operation of digital platforms ended up receiving less attention than it deserved. The decree expressly stipulates in Article 15-A that the obligation of connection providers and Internet application providers to retain IP logs must also cover the user's source TCP port.

In practice, the measure seeks to expand the ability to identify users in investigations in the digital environment and to consolidate what can be required of platforms when a court order mandates the provision of connection and access logs to the authorities.
 

However, adapting platforms to this obligation is neither simple nor without cost. There are a number of issues that Brazil’s Judicial Branch and regulators must consider, so as to ensure that the decree is enforced responsibly and in a balanced manner.
 

For context, it is necessary to understand why an IP address alone is no longer sufficient to identify individuals on the Internet. For years, IPs served as the primary element for identifying users, but they began to lose their effectiveness with the exhaustion of IPv4 addresses and the adoption of CGNAT (Carrier Grade Network Address Translation), a technology that allows different users to share the same public IP address.

In practice, this means that dozens of devices can be linked to the same IP address. Depending on the network architecture used by the provider, a single IP address can be shared by residents of an entire building or even a region.
 

From an operational standpoint, CGNAT solved a major problem. The limitations resulting from the exhaustion of IPv4 addresses were circumvented by sharing the same IP address among different users. On the other hand, in situations where public authorities need to identify the device from which a particular illegal activity originated, the IP address alone is no longer sufficient, given that many users may appear linked to the same IP, making it difficult to pinpoint and individual based solely on this information.
 

It is in this context that the TCP port becomes relevant. In networks operated under CGNAT, each connection also receives a port number associated with that specific session. The combination of the IP address and the TCP port allows for a more precise determination of the device from which the activity under investigation was performed.
 

The Brazilian Superior Court of Justice had already highlighted the importance of safeguarding TCP port by connection and application providers while Brazil has not yet fully migrated to IPv6. Thus, Decree #12,975/2026 codified an understanding that had already been established by the Court’s precedents.
 

The decree also makes clear the ex-ante nature of this obligation. According to the decree, the TCP port must not be stored only after a court decision; rather, it must be kept beforehand in the provider's logs. The logic is the same as that applied to connection logs, which should already be retained: the information needs to be available when required.
 

However, adapting platforms to this obligation is far from simple, quick to implement, or low-cost. A number of important issues need to be taken into consideration when enforcing the rule.
 

First, the obligation to safeguard the TCP port implies an increase in the volume of stored data, which inevitably broadens discussions about privacy. The combination of IP address and TCP port enables the identification of a large number of users and, consequently, increases the risks associated with retaining this information. The larger the volume of data stored by the platforms, the greater the damage that can be caused in the event of a leak.
 

Regarding this point, Brazil’s General Data Protection Act imposes clear limits by establishing that data processing activities must observe the principle of necessity. In other words, data collection should be limited to the minimum necessary to achieve its purposes, encompassing only relevant, proportionate, and non-excessive information.
 

In this context, the Brazilian Superior Court of Justice has already recognized that a connection provider can identify the user based solely on the IP address and the approximate period of the event, without the application provider having to first indicate the lTCP port in order for the connection provider to make the other user identification data available.
 

This indicates that, in practice, the absence of a TCP port does not always prevent user identification, which reinforces the need to carefully assess the extent and scope of the obligation. It is important to note that Decree #12,975/2026 itself establishes that the duty of retention will cover the source TCP port “whenever necessary for the unequivocal identification of the source terminal or the next network link.”
 

Furthermore, as previously discussed, the adaptations necessary for the retention of the TCP port by these platforms are neither simple nor inexpensive. For this to happen, it is necessary to expand the infrastructure and strengthen information security mechanisms. For large platforms, the costs are felt, but the impact is internalized with less difficulty.
 

On the other hand, for smaller companies, undertaking and bearing the cost of all the necessary infrastructure changes can represent a significant expense and pose a risk to the company's ability to compete with larger players, especially considering the time frame established by the decree for the implementation of these measures.
 

This point deserves attention, given that the Brazilian digital environment is comprised of companies of very different sizes and economic capabilities. Requiring the same level of compliance with the new rules from large platforms and smaller providers within the same timeframe could sharpen competitive asymmetries that are already well-known in the sector.
 

Therefore, it is important that the enforcement of the decree takes these differences into consideration. This includes, for instance, the possibility of calibrating storage requirements according to the size of the company, providing for different compliance deadlines, or adopting gradual implementation mechanisms.
 

Without such care, there is a risk that a measure designed to increase the efficiency of investigations may, in practice, end up causing a series of negative effects on competition in this market, to the detriment of smaller companies.
 

From this perspective, adherence to the principle of proportionality is fundamental. On one hand, the measure seeks to facilitate investigations; on the other hand, it can negatively impact user privacy and company costs. Therefore, it is necessary to assess, in each case, whether the requirement is appropriate to achieve the intended objective, whether it is truly necessary in light of less burdensome alternatives, and whether the benefits ultimately justify the costs and risks it imposes.
 

Furthermore, it is important to highlight that the decree preserves the need for a court order to access the logs, pursuant to Article 10, Paragraph 1, of the Brazilian Internet Act. However, there are relevant issues that have not been addressed and remain unresolved. The regulation does not elaborate, for instance, on the minimum security standards platforms must comply with or how cases involving data leaks should be handled.

Thus, Decree #12,975/2026 seeks to strengthen the ability to identify users in the digital environment, but it presents a number of relevant challenges that need to be discussed. Therefore, the market should pay close attention to this matter. While careful application of the rule is expected, with attention to the differences between the actors and the contexts involved, platforms need to closely monitor this agenda and be prepared.
 

Ultimately, a key point will be how this obligation will be enforced in practice. The goal is to strike a balance that preserves the transparency objectives of the rule without imposing excessive costs or disproportionate risks to users' rights and the functioning of the market.

*Translation by Licks Attorneys. This content is available on the Jota.

Offices