Jurisdiction
Brazil
- Source
- Editorial review of primary sources — not yet re-anchored
- Verified
- Evidence not verified
- Confidence
- Low
Structured issue-spotting to support your own review — not legal advice. Verify against the cited primary sources and your counsel.
01Framework
Brazil regulates AI deployment through data-protection, consumer and platform law rather than a dedicated AI act. The LGPD governs personal data, automated decisions and international transfers, and the national data protection authority is an active regulator that in 2026 gained platform-enforcement powers, issued its first adequacy decision recognising the European Union, opened enforcement against named AI vendors and is drafting an AI instrument. The general AI bill passed the Senate in December 2024 and is still pending in the Chamber of Deputies; it is not law. The consumer code, the digital statute for minors and financial-sector rules add further duties.
- Region
- South America
- ISO code
- BR
- Privacy framework
- Lei nº 13.709/2018 (LGPD) is the general data protection statute. The AI-relevant provisions are article 20 on review of decisions taken solely on automated processing, articles 33 to 36 on international transfer bases and adequacy criteria, article 38 letting the authority demand a data protection impact report at any time, and article 46 requiring security measures applied from the design phase of the product through to its execution. Commencement was staged: the authority’s own provisions from December 2018 and administrative sanctions from August 2021. Resolution 15/2024 sets incident notification at three business days to both the regulator and the affected data subjects, and there is still no regulation specific to impact reports — the authority points controllers at the high-risk definition in its small-processing-agent regulation instead.
- AI-specific rules
- No general AI statute is in force. PL 2338/2023, the Marco Legal da IA, was approved by the Senate in December 2024 and received by the Chamber of Deputies in March 2025, where it awaits the rapporteur’s opinion in a special committee. Binding AI-relevant duties come instead from the LGPD, from the digital statute for children and adolescents in force since March 2026 — which prohibits profiling-based advertising, emotional analysis and immersive-reality targeting of minors — and from Decreto 12.976/2026, which defines intimate content to include material produced or manipulated using artificial intelligence. The ANPD is drafting AI rules under its regulatory agenda, aimed at interpretive parameters for article 20, runs an AI regulatory sandbox whose first monitoring results were published in July 2026, and publishes technical studies on generative AI and deepfakes.
- Last reviewed
- 20 Aug 2026
- Status
- published
Cross-border transfer
The LGPD sets the permitted transfer bases, and Resolution 19/2024 approved the International Data Transfer Regulation together with Brazil’s standard contractual clauses, which must be adopted integrally and without alteration. The window to re-paper existing contracts onto those clauses was twelve months, not twenty-four, and it closed in August 2025; the August 2025 retificação was a cross-reference correction and not an extension. European standard clauses do not substitute unless recognised as equivalent, and the authority states that no equivalent clauses have yet been recognised. In January 2026 the ANPD issued its first adequacy decision, recognising the European Union, which lets transfers there ride on the adequacy basis instead — but only there. A United States or other third-country model vendor still needs the Brazilian clauses or another basis, and that is the case for most AI deployments.
Regulators
Primary sources
- LegislationLei nº 13.709/2018 (LGPD), texto compilado
- LegislationLei nº 12.965/2014 (Marco Civil da Internet)
- LegislationLei nº 8.078/1990 (Código de Defesa do Consumidor), texto compilado
- LegislationLei nº 15.211/2025 (Estatuto Digital da Criança e do Adolescente)
- LegislationDecreto nº 12.975, de 20 de maio de 2026
- LegislationDecreto nº 12.976, de 20 de maio de 2026
- Official faqPL 2338/2023 — ficha de tramitação, Câmara dos Deputados
- Official faqPL 2338/2023 — matéria, Senado Federal
- LegislationResolução CD/ANPD nº 2, de 27 de janeiro de 2022
- Regulator guidanceANPD Conselho Diretor — votos CD 01/2026 (decisão de adequação, União Europeia)
- Regulator guidanceANPD — primeiros resultados do Sandbox Regulatório em Inteligência Artificial
02Regulations and guidance
| Instrument | Status |
|---|---|
| Decreto 12.975/2026Amends the Marco Civil implementing decree to make the national data protection authority the regulator and enforcer of internet application providers’ duties, including the duty of care over criminal content. It is why a data-protection regulator now has platform-enforcement powers. | In force |
| Decreto 12.976/2026Sets guidelines for protecting women online and confronting digital violence against them. It defines intimate content to include material produced or manipulated using artificial intelligence or any other technological resource, and assigns regulation and enforcement to the data protection authority. | In force |
| Marco CivilBrazil’s framework of internet rights and duties. Article 19 conditioned an application provider’s civil liability for third-party content on failing to comply with a specific court order; the Supreme Court has since held it partially unconstitutional, widening liability pending new legislation. | Partly in force |
| LGPDBrazil’s general data protection statute. It governs personal data, the right to review of decisions taken solely on automated processing, international transfers, impact reports the regulator can demand at any time, and security measures applied from the design phase onwards. | In force |
| ECA DigitalProtects minors in digital environments. Article 22 prohibits profiling for advertising directed at children and adolescents, and prohibits emotional analysis and augmented, extended or virtual reality for that purpose. It also requires regular review of AI tools and an opt-out from personalised recommendation. | In force |
| CDCThe consumer code. Article 43 gives a consumer access to the information held about them in registers and databases, and to know its sources, which is the route through which automated consumer scoring becomes explainable in Brazil. Article 39 bars abusive practices. | In force |
| PL 2338/2023Brazil’s risk-based general AI bill, covering rights, transparency, human review, governance and penalties. It passed the Senate and is still awaiting the rapporteur’s opinion in the Chamber of Deputies’ special committee. It is not law and has not been voted by the Chamber. | Proposed |
| ANPD Res. 15/2024The security incident notification regulation under the LGPD. It sets who must be told, in what form and how fast — three business days to notify both the regulator and the affected data subjects — and requires an incident register to be kept. | In force |
| ANPD Res. 19/2024Approves the International Data Transfer Regulation and the content of Brazil’s standard contractual clauses, which must be adopted integrally and without alteration. It also governs equivalent clauses, specific clauses, global corporate rules and adequacy decisions. | In force |
| ANPD Res. 2/2022An eased LGPD regime for small processing agents. Its definition of high-risk processing is the ANPD’s stated interim benchmark for deciding when a data protection impact report is needed, because no regulation specific to impact reports has been issued. | In force |
| ANPD Res. 32/2026The ANPD’s first adequacy decision, recognising the European Union as having a level of data protection adequate for the purposes of international transfer under the LGPD. It excludes transfers made solely for public security, national defence, State security or criminal investigation. | In force |
| ANPD AI SandboxAn ANPD pilot supervising a small number of companies testing AI systems in a controlled regulatory environment, focused on governance, security, transparency and anonymisation. It is the clearest signal of what the regulator will expect when it does issue AI rules. | In force |
03Common enterprise issues
Automated decision-making
Article 20 does not guarantee a human reviewer
The 2018 text required review by a natural person; the 2019 amendment removed those words and the veto of paragraph 3 killed their reinstatement. What survives is a right to review plus, on request, clear information about the criteria and procedures used, subject to trade secrecy — with the regulator able to audit for discriminatory effects where secrecy is invoked.
Cross-border transfers
The standard-clause deadline has already passed
The twelve-month window to move existing contracts onto the ANPD clauses closed in August 2025. Agreements still relying on European standard clauses or bespoke terms are exposed. The 2026 European adequacy decision removes that burden only for transfers to the EU and EEA — not for a United States model vendor.
Transparency
There is no horizontal AI transparency duty; the duties are assembled
Until the AI bill passes, transparency obligations are sourced from LGPD article 20 for automated decisions, from the consumer code’s right of access to consumer databases, and from the digital statute for minors. That means the answer differs depending on who the system affects.
Security
Incident notification is three business days, to the regulator and the people affected
Resolution 15/2024 sets the clock, and it runs to data subjects as well as to the authority. There is still no regulation specific to the impact report, so the authority directs controllers to the high-risk definition in its small-processing-agent regulation while it can demand a report at any time.
Sensitive data
AI-generated intimate imagery is now expressly regulated
Decreto 12.976/2026 defines intimate content to include material produced or manipulated using artificial intelligence, and assigns enforcement to the data protection authority — which has already opened monitoring of providers of AI-based applications and app stores on that basis.
04Vendor restrictions
Restrictions we have written down and the page each one must be checked against. A restriction becomes a verified claim only once the sync job has fetched that page and found the phrase it declares; until then it is an editorial note with a link, and says so.
No vendor restriction has been recorded for this jurisdiction.
05Stacks with notes for this jurisdiction
No published stack carries a compliance note for this jurisdiction yet.
06Evidence
Every instrument above that we have fetched and anchored carries a footnote. The rest link to their primary source but have not been fetched and hashed yet, and are marked ASSESSMENT rather than FACT.
No sources were recorded for this answer. Nothing on this page should be treated as verified.
Improve this page
Sign in to contribute
From the field
0 deployments · 0 questions
Nobody has reported deploying this here yet, and no question has been opened against this page. Both appear once a reviewer accepts them.