Compliance
OpenRouter in Brazil
Structured issue-spotting for deploying OpenRouter in Brazil, read against the rules for that jurisdiction.
- Source
- Rules engine over a generic brief — no anchored quote on this page
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01What this reading assumes
- Jurisdiction
- Brazil
- Principal framework
- Lei nº 13.709/2018 (LGPD) is the general data protection statute. The AI-relevant provisions are article 20 on review of decisions taken solely on automated processing, articles 33 to 36 on international transfer bases and adequacy criteria, article 38 letting the authority demand a data protection impact report at any time, and article 46 requiring security measures applied from the design phase of the product through to its execution. Commencement was staged: the authority’s own provisions from December 2018 and administrative sanctions from August 2021. Resolution 15/2024 sets incident notification at three business days to both the regulator and the affected data subjects, and there is still no regulation specific to impact reports — the authority points controllers at the high-risk definition in its small-processing-agent regulation instead.
- Delivery assessed
- Model API
- Data leaves the network
- unknown — the deciding question for a hosted product
- Vendor home jurisdiction
- United States
- Verified vendor positions
- none — every vendor position below is a question, not an assurance
- Rules evaluated
- 37
- Rules fired
- 15
Assumptions about use
- An internal deployment used by employees, not a public-facing product.
- A person reads the output before acting on it — but that is not recorded, so the engine reports it as a gap rather than assuming it.
- No significant automated decision is taken about a person by the system alone.
02Issues to work through
Brazil
The deadline to move onto the Brazilian standard clauses has already passed
The regulator approved the International Data Transfer Regulation together with the content of Brazil’s standard contractual clauses, which must be adopted integrally and without alteration. The window for existing contracts was twelve months, not twenty-four, and it closed in August 2025. European standard clauses do not substitute unless recognised as equivalent, and no equivalent clauses have been recognised.
- Required checks
- Check which clauses the current vendor agreement actually uses, because a contract signed on European clauses is not covered.
- Adopt the Brazilian clauses unaltered — negotiating their text defeats the basis they provide.
- Extend the check to subprocessors, since the transfer chain does not stop at the party you signed with.
- Vendor questions
- Will you sign the Brazilian standard contractual clauses without amendment?
- If not, which other transfer basis do you rely on, and can you evidence it?
Human review required — take this to your counsel
Three business days, to the regulator and to the people affected
Brazil’s security incident notification regulation sets a three-business-day clock and it runs to affected data subjects as well as to the regulator, with an incident register to be kept. Teams routinely plan for a regulator notification and discover the subject notification at the point they can least afford to draft it, which is why the templates belong in the runbook before launch.
- Required checks
- Draft the data-subject notification template before an incident, not during one.
- Decide who decides an incident is notifiable, and make sure they can be reached inside three business days.
- Set up the incident register now; reconstructing one afterwards is not possible.
- Vendor questions
- How quickly will you notify us of an incident affecting our data, and does that fit inside a three-business-day clock that starts with our own awareness?
- Technical controls
- Alert on the signals that would make an AI incident visible — anomalous retrieval volumes, prompt-injection indicators, unexpected egress.
Human review required — take this to your counsel
The European adequacy decision covers Europe, and only Europe
In January 2026 the regulator recognised the European Union as having an adequate level of data protection for the purposes of international transfer, which lets transfers there ride on the adequacy basis. It is the only such decision, it excludes transfers made solely for public security, defence or criminal investigation, and it does nothing for a model vendor established anywhere else.
- Required checks
- Establish where the vendor and its inference actually sit before assuming adequacy helps.
- For a non-European vendor, fall back to the Brazilian standard clauses or another basis and document which.
- Note that the decision is reviewable, so a design that depends on it should be able to survive its withdrawal.
- Vendor questions
- Is the entity we contract with, and the entity that performs inference, established in the European Union?
- Technical controls
- Pin the inference region where the vendor supports it, so the transfer basis matches what actually happens.
Brazil’s AI bill passed the Senate and is still waiting in the Chamber
The Chamber of Deputies’ own record shows PL 2338/2023 awaiting the rapporteur’s opinion in the special committee constituted to consider it. It passed the Senate in December 2024 and has not been voted by the Chamber. There is no Brazilian AI act, no risk classification to complete and no conformity assessment — and the regulator is nonetheless active.
- Required checks
- Do not build a Brazilian AI risk classification; there is nothing to classify against.
- Read the bill anyway if the deployment has a long life, because its treatment of automated decisions is where the regulator is already heading.
We could not confirm whether this vendor trains on customer content
We could not verify whether this vendor uses customer content to train or improve its models. In Brazil that question decides whether a further processing purpose exists, whether the original basis stretches to cover it, and whether the regulator would see a new controller. It is a gap in our evidence rather than a finding against the vendor, and it is answerable in one sentence of a contract.
- Required checks
- Get a written statement that customer content is not used for training, or identify the basis for the use.
- Vendor questions
- Is customer content used to train or improve your models, by default or on any tier?
- If it can be, is switching it off a contractual commitment or a setting we could lose in a product update?
Security measures apply from the design phase, not from launch
LGPD article 46 requires processing agents to adopt security measures capable of protecting personal data, and the article is explicit that they apply from the design phase of the product or service through to its execution. For an AI deployment that reaches the prototype: a proof of concept that pastes production records into a third-party model is already inside the duty.
- Required checks
- Apply the same controls to the pilot as to production, or use data that is not personal in the pilot.
- Record who the controller and who the processor is for each stage, because the duties differ.
- Expect the regulator to be able to demand an impact report at any time, and keep the material that would go into one.
- Vendor questions
- What security certifications or independent assurance can you produce, and what is in scope of them?
- Technical controls
- Keep pilot environments off production personal data by default, and make the exception require a decision.
The regulator is already working on AI, and publishing what it looks at
The data protection authority published the first results of its AI regulatory sandbox in July 2026, having supervised companies testing AI systems in a controlled environment focused on governance, security, transparency and anonymisation. Nothing in it binds anybody. It is the clearest available signal of what the authority will expect when it does issue AI rules, and it is free to read.
- Required checks
- Read the published sandbox material before designing the governance artefacts, rather than inventing your own categories.
- Note that the authority’s regulatory agenda targets the automated-decision article specifically.
Cross Cutting
Confidentiality duties bind independently of data protection law
Material can be entirely free of personal data and still be the material a contract stops you disclosing. Client retainers, non-disclosure agreements, supplier contracts and common-law duties are the usual sources, and several of them require consent before a third party processes the material at all — which a model API call is.
- Required checks
- Review the confidentiality clauses in the contracts covering the material going into the system.
- Identify any contract requiring notice or consent before a subcontractor processes the material.
- Decide whether the deployment needs a confidentiality carve-out negotiated into new contracts.
- Vendor questions
- Will the vendor accept a confidentiality undertaking beyond its standard terms?
- Which staff at the vendor can access customer content, under what controls?
- Technical controls
- Segregate the most sensitive corpora into an index that the general assistant cannot reach.
Human review required — take this to your counsel
What ends up in a prompt, and where it goes next
Every prompt is a transfer of whatever it contains. Staff paste more than they intend, retrieved context travels with the prompt, and system prompts can often be extracted from the output. Assume anything reaching the model has left your control unless the contract and the architecture say otherwise.
- Required checks
- Write down which categories of information may be entered into a prompt, and tell people.
- Establish what the system prompt contains and whether disclosing it would matter.
- Establish which shadow tools staff are already using; the policy has to name the permitted ones.
- Vendor questions
- Are prompts and completions retained, for how long, and can retention be set to zero?
- Are prompts used for abuse monitoring, and if so who can read them and for how long?
- Technical controls
- Redact or block high-risk patterns before the prompt leaves the application.
- Keep prompt and completion logs out of general-purpose observability tools.
- Set an explicit retention period on prompt logs and enforce it.
The acceptable-use policy may exclude your use case
Acceptable-use policies commonly carve out unsupervised legal, medical and financial advice, decisions about people without human review, and some surveillance and biometric uses. They are incorporated into the contract by reference and change without a signature, so the version that matters is the one live on the day you rely on it.
- Required checks
- Read the acceptable-use policy against your actual use case, not against a summary of it.
- Where a carve-out applies, decide whether human review brings the use back inside the policy.
- Set a reminder to re-read the policy — it changes without notice to you.
- Vendor questions
- Does your acceptable-use policy permit this use case, and will you confirm that in writing?
- How are we notified when the acceptable-use policy changes?
Human review required — take this to your counsel
Being able to reconstruct a decision months later
The question that arrives after a complaint is what the system was shown and what it produced on a particular day. Models change, prompts change, and indexes are rebuilt, so the answer has to be recorded at the time. Without it, the only available response is that the output cannot be reproduced.
- Required checks
- Decide what is recorded per interaction: model and version, prompt template version, retrieved document ids, output, reviewer and outcome.
- Set how long those records are kept, balanced against the retention duties that also apply to them.
- Vendor questions
- Does the vendor pin model versions, and how much notice is given before a model is retired or changed?
- Technical controls
- Version prompt templates in source control and log the version used.
- Log the model identifier and version returned by the provider, not the one you requested.
Vendor documentation has not been verified
We could not verify a data processing agreement, a subprocessor list, a position on training on customer data and a stated processing region for this vendor from a retrieved document. That is a gap in our evidence, not a finding against the vendor: until a document has been fetched and read, nothing here should be treated as settled either way.
- Required checks
- Obtain the current versions of the processing agreement, subprocessor list, security page and any regional-processing commitment.
- Check that what the sales conversation promised also appears in the contract.
- Vendor questions
- Where is your data processing agreement published, and which version applies to us?
- Where is your subprocessor list, and how much notice do we get before it changes?
- Do you train on customer content by default, and where is that stated contractually?
- In which country or region is inference performed, and where are logs retained?
We were not told whether a person reviews the output
Where output influences a decision about a person, the reviewer has to be able to disagree with it. That needs three things a rubber-stamp review lacks: enough information to judge, enough time to judge, and an override that is used often enough to be real. Design it before the volume makes it impossible.
- Required checks
- Name the role that reviews the output and what they see when they do.
- Decide what evidence is retained about each review, so the practice can be shown to exist.
- Set a threshold below which the system must not act without review.
- Vendor questions
- Does the product expose the retrieved context and the confidence behind a suggestion, or only the answer?
- Technical controls
- Show the reviewer the retrieved sources next to the suggestion, not the suggestion alone.
- Record the reviewer’s decision, including overrides, as part of the audit trail.
Human review required — take this to your counsel
An AI deployment creates new copies of the data
Vector indexes, prompt logs, completion caches, evaluation datasets, fine-tuning checkpoints and backups are all copies of the source material in places the existing retention schedule does not mention. Deletion requests are the moment this is discovered, because deleting the source document does not delete its embedding.
- Required checks
- List every store the deployment creates and add each to the retention schedule.
- Establish how a deletion request propagates to the index, the caches and the logs.
- Establish how long backups keep material that has been deleted from the live system.
- Vendor questions
- What does the vendor retain, where, and for how long after we delete our copy?
- Technical controls
- Store the source document id with every embedding so deletion can cascade.
- Set time-to-live on prompt and completion logs rather than relying on manual cleanup.
The vendor’s terms may not permit the deployment you are planning
Provider terms routinely restrict things architectures assume: sharing seats, building a competing service, benchmarking and publishing results, reselling capacity, and processing certain data categories. A consumer or self-serve plan often carries different terms from the enterprise agreement, and the enterprise agreement is the one worth reading.
- Required checks
- Identify which contract actually governs — self-serve terms, an order form, or a negotiated agreement.
- Check restrictions on seat sharing and on service accounts, which a shared internal assistant can breach without anyone noticing.
- Check whether the terms allow the categories of data you intend to send.
- Vendor questions
- Which agreement governs our use, and can we have the current version in writing?
- Are there restrictions on the data categories or the industries we may use the service for?
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
03What this reading does not know
- Whether any of the data falls into a special or sensitive category.
- Whether any material is covered by legal professional privilege.
- Whether prompts or documents leave the company network.
- Whether a person reviews the output before it is acted on.
04Instruments these issues point at
- statuteLGPDBrazil’s general data protection statute. It governs personal data, the right to review of decisions taken solely on automated processing, international transfers, impact reports the regulator can demand at any time, and security measures applied from the design phase onwards.
- proposalPL 2338/2023Brazil’s risk-based general AI bill, covering rights, transparency, human review, governance and penalties. It passed the Senate and is still awaiting the rapporteur’s opinion in the Chamber of Deputies’ special committee. It is not law and has not been voted by the Chamber.
- regulationANPD Res. 15/2024The security incident notification regulation under the LGPD. It sets who must be told, in what form and how fast — three business days to notify both the regulator and the affected data subjects — and requires an incident register to be kept.
- regulationANPD Res. 19/2024Approves the International Data Transfer Regulation and the content of Brazil’s standard contractual clauses, which must be adopted integrally and without alteration. It also governs equivalent clauses, specific clauses, global corporate rules and adequacy decisions.
- regulationANPD Res. 2/2022An eased LGPD regime for small processing agents. Its definition of high-risk processing is the ANPD’s stated interim benchmark for deciding when a data protection impact report is needed, because no regulation specific to impact reports has been issued.
- regulationANPD Res. 32/2026The ANPD’s first adequacy decision, recognising the European Union as having a level of data protection adequate for the purposes of international transfer under the LGPD. It excludes transfers made solely for public security, national defence, State security or criminal investigation.
- guidanceANPD AI SandboxAn ANPD pilot supervising a small number of companies testing AI systems in a controlled regulatory environment, focused on governance, security, transparency and anonymisation. It is the clearest signal of what the regulator will expect when it does issue AI rules.
05Vendor documents being watched
- Data residencyhttps://openrouter.ai/docs/guides/features/sovereign-ainot yet fetched
- Privacy policyhttps://openrouter.ai/docs/guides/privacy/data-collectionnot yet fetched
- Security pagehttps://openrouter.ai/docs/guides/features/zdrnot yet fetched
- Terms of servicehttps://openrouter.ai/termsnot yet fetched
06Ask about your own deployment
This page reads the rules against a generic organisation. Your size, industry, data and existing contracts change which of these issues matter and which fall away.