Brazil

Outside the Eyes alliances but bound into the Budapest Convention, the Mercosur mutual-assistance protocol and the inter-American treaty network, even as the NSA tapped the President’s phone and ABIN ran 60,000+ illegal searches with Israeli spyware

← Back to Privacy Law Directory

Overview

Brazil’s 1988 Constitution establishes privacy as a fundamental right, strengthened by Amendment EC 115/2022 explicitly protecting personal data including in digital media. The LGPD (Lei Geral de Proteção de Dados, 2018) provides GDPR-influenced data protection, and in January 2026, Brazil became the first Latin American country to receive EU mutual adequacy recognition.[1]

Behind this framework, the Parallel ABIN scandal (2019–2021) revealed that ABIN Director Alexandre Ramagem conducted 60,000+ illegal surveillance searches targeting journalists, STF justices, and opposition politicians using Cognyte First Mile spyware. Ramagem was convicted and sentenced to 16 years. The 2013 Snowden revelations that the NSA intercepted President Rousseff’s communications and hacked Petrobras directly motivated the EllaLink cable project to bypass US routing. Brazil is not an Eyes alliance member but is a BRICS founder.[2][3]

Brazil’s outward data-sharing runs through its alliances and treaties, each detailed below. Not an Eyes member, it is a BRICS founder, holds an EU mutual adequacy decision, and maintains one of the widest bilateral MLAT networks in this directory (about 30 treaties, including with the United States), alongside the regional Inter-American Convention on Mutual Assistance and the Mercosur MLA Protocol; it acceded to the Budapest Convention on Cybercrime in 2023. These are the channels through which the domestic protections described below are, in practice, bypassed.[1][11][15]

International Data Sharing Agreements

Mutual Legal Assistance: 30+ Bilateral Treaties

Brazil maintains bilateral MLATs with approximately 30 countries including: United States (signed October 14, 1997, in force February 21, 2001), Canada, Chile, China, Colombia, Ecuador, Germany, Grenada, Guyana, Hong Kong, India, Ireland, Italy, Jordan, Kazakhstan, Mexico, Morocco, Netherlands, Nigeria, Panama, Paraguay, Philippines, Romania, Spain, Sweden, Thailand, Ukraine, UAE, Uruguay, and Vietnam. Brazil is also party to the Inter-American Convention on MLA in Criminal Matters (the OAS regional instrument, ratified by Brazil in 2007; its 27 parties are Antigua and Barbuda, Argentina, the Bahamas, Bolivia, Brazil, Canada, Chile, Colombia, Costa Rica, Dominica, Ecuador, El Salvador, Grenada, Guatemala, Guyana, Honduras, Jamaica, Mexico, Nicaragua, Panama, Paraguay, Peru, Suriname, Trinidad and Tobago, the United States, Uruguay, and Venezuela) and the Mercosur MLA Protocol (the San Luis Protocol, binding Argentina, Brazil, Paraguay, and Uruguay).[17] Brazil’s treaties are published in the Itamaraty’s Concórdia treaty database.[11]

Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Brazil acceded in 2023 to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states, Brazil among them: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[15]

BRICS and EU Adequacy

BRICS: Founding member; 2025 presidency; Working Group on ICTs for real-time threat intelligence exchange. BRICS now comprises eleven members: Brazil, Russia, India, China, South Africa, Egypt, Ethiopia, Iran, Saudi Arabia, the United Arab Emirates, and Indonesia.[16] EU mutual adequacy (January 26, 2026): Reciprocal recognition, first Latin American country. Mercosur: EU-Mercosur Partnership Agreement signed early 2026.[1]

The Privacy Backdoor Effect

Despite LGPD protections and EU adequacy, alternative access exists:

Surveillance and Intelligence

ABIN and SISBIN

ABIN (created 1999) reports to the President and coordinates SISBIN (Brazilian Intelligence System) across federal agencies. ABIN cannot intercept communications but can access SISBIN member databases. The Federal Police conducts wiretapping under judicial authorisation (Law 9,296/1996). Parliamentary oversight via CCAI (widely criticised as lacking staff and technical capacity).[5]

The Parallel ABIN Scandal (2019–2021)

Under Director Ramagem, a “parallel intelligence” structure used Cognyte First Mile spyware (purchased 2018 for R$ 5.7M) to track real-time geolocation of up to 10,000 targets per year. 60,000+ illegal searches targeted 12+ journalists, STF Justices, politicians, IBAMA officials. Nine state security departments separately purchased Cognyte totalling R$ 65.7 million. Federal Police Operation Last Mile (2023) led to Ramagem’s conviction (September 2025, 16-year sentence) for illegal surveillance and the 2022–2023 coup plot. He fled to the US before arrest.[2][6]

The NSA Spying Scandal (2013)

Snowden documents revealed the NSA intercepted President Rousseff’s personal communications, hacked Petrobras, and monitored 29 government phone numbers. Rousseff cancelled a state visit to Washington and addressed the UN General Assembly to condemn US surveillance. The revelations directly motivated EllaLink and accelerated the Marco Civil da Internet.[3]

Commercial Surveillance and Facial Recognition

Cellebrite: Federal Police use UFED for mobile forensics. Chinese technology: Huawei, Hikvision, Dahua, ZTE donated 4,000+ cameras for São Paulo’s City Cameras programme. Facial recognition: deployed in São Paulo (plans for 20,000 cameras), Rio de Janeiro (AI drones at Carnival 2025, 63% false positive rate in Maracanã pilot), and Salvador (209 fugitives arrested). Racial bias: more than 90% of FRT arrests target Black Brazilians (CESeC study). No legal framework governs deployment.[7]

Submarine Cable Infrastructure

Brazil is a major cable hub with 14 landing stations at Fortaleza, Rio, Santos, and Salvador. EllaLink (2021, 100 Tbps, direct Portugal-Fortaleza, explicitly bypassing US routing), SACS (2018, first direct South America-Africa), Monet (2017, Google), BRUSA (Rio-Fortaleza-Puerto Rico-Virginia), Firmina (2025, Google, 14,517 km), SAIL (2018, China Unicom). Previously targeted by NSA FAIRVIEW and STORMBREW upstream collection when traffic routed through US nodes.[8]

Recent Developments

Ramagem Conviction (September 2025): Former ABIN Director convicted by STF (4-1) for Parallel ABIN illegal surveillance and coup plot. 16-year sentence. Fled to US.[2]

EU Mutual Adequacy (January 2026): Brazil’s reciprocal adequacy with the EU, the first for a Latin American country, is covered under International Data Sharing above.[1]

ECA Digital (Law 15,211/2025), Now in Force: Became effective March 17, 2026, with implementing decree published March 18. Mandatory age verification replacing self-declaration, profiling and targeted advertising banned for all under-18s, paid loot boxes prohibited in products accessible to minors, under-16 accounts must link to parent/guardian. Establishes National Notification Screening Center (Federal Police) for digital crimes against minors. ANPD enforces with fines up to BRL 50M or 10% of Brazil revenue. The ANPD’s first stage of monitoring (begun March 2026) targets app stores and proprietary operating systems; final guidelines are due August 2026; administrative sanctions begin November 2026 with formal compliance verification from January 2027. The ANPD’s 2026–2027 Priority Themes Map names children’s data, targeted advertising, public-sector data sharing, and AI as the four enforcement priorities.[9][12][13]

ANPD Independence (September 2025): Transformed to full independent regulatory agency with financial/administrative autonomy.[4]

Facial Recognition Racial Bias: the CESeC finding that 90%+ of facial-recognition arrests target Black Brazilians, and the absence of any governing legal framework, are detailed above.[7]

Privacy Framework

The ANPD was transformed into a fully independent agency (September 2025). Maximum penalty: 2% of revenue (capped at R$ 50M per violation). The LGPD grants the Central Government power to exempt any agency for national security (Article 4(III)). Rule of law under the Marco Civil da Internet (2014): court orders required for data access; Article 19 was partially declared unconstitutional (June 2025 STF ruling) for platform liability for hate speech and CSAM.[4]

Age Verification: Identity Infrastructure as Surveillance

The ECA Digital (Law 15,211/2025), enacted September 17, 2025 and effective March 17, 2026, establishes comprehensive digital child protection. Platforms must implement age verification using “highly effective and auditable” technology; self-declaration explicitly banned. Accounts for under-16s must link to a guardian’s account. Behavioral advertising profiling of children is banned. Paid loot boxes prohibited for minors. Fines up to BRL 50 million or 10% of Brazilian revenue per violation. The ANPD enforces.[9]

The law applies to any digital product “aimed at or likely to be accessed by” minors in Brazil regardless of company location, creating extraterritorial reach. The mandatory age verification infrastructure (linking all under-16 accounts to guardian accounts with identity verification) creates a surveillance-capable architecture mapping parent-child relationships to platform access at national scale.

Data Retention

Marco Civil da Internet: Connection logs (ISPs): 1 year; application access logs: 6 months. Court order required for all access. ANATEL Resolution 738/2020: Subscriber/billing/call records: 5 years; internet connection records: 1 year. LGPD Article 4(III) exempts national security activities, meaning exempted agencies face no statutory retention limitation.[10]

Pending Legislation

Sources

[1] ANPD: EU Mutual Adequacy (January 2026) – First Latin American country, reciprocal recognition
[2] Wikipedia: Parallel ABIN Scandal – 60,000+ illegal searches, Cognyte First Mile, Ramagem conviction
[3] The Guardian: NSA Surveillance of Brazil (September 2013) – Rousseff interception, Petrobras hack
[4] ANPD: Official Website – Independence, enforcement, LGPD
[5] Wikipedia: ABIN – SISBIN, Federal Police wiretapping, CCAI oversight
[6] Reuters: Ramagem Conviction (September 2025) – 16-year sentence, fled to US
[7] CESeC: Facial Recognition Racial Bias – 90%+ of arrests target Black Brazilians
[8] Submarine Cable Map – EllaLink, SACS, Monet, BRUSA, Firmina, SAIL, 14 landing stations
[9] Inside Privacy: Brazil ECA Digital (September 2025) – Age verification, BRL 50M fines, behavioural ad ban
[10] ICLG: Data Protection – Brazil – Marco Civil retention, ANATEL Resolution, LGPD Article 4(III)
[11] UK FCDO: MLA Treaty List – Brazil bilateral MLATs with 30+ countries; see also OAS: Brazil Multilateral MLA Agreements
[12] Baker McKenzie: Brazil Regulates the ECA Digital (March 2026) – Effective March 17, 2026; implementing decree March 18; under-18 profiling ban; loot box prohibition; under-16 parental account link; National Notification Screening Center
[13] Mayer Brown: Enforcement of Brazil’s ECA Digital (April 2026) – First-stage ANPD monitoring (March 2026) targets app stores and proprietary operating systems; final guidelines due August 2026; administrative sanctions begin November 2026; formal compliance verification January 2027; 2026–2027 Priority Themes Map names children’s data, targeted advertising, public-sector data sharing, and AI as enforcement priorities
[14] IAPP: Global AI Legislation Tracker, Brazil PL 2338/2023 – Comprehensive AI bill passed the Senate December 2024; under review by a Chamber of Deputies special committee; ANPD designated coordinator of the national AI system; penalties capped at BRL 50 million or 2% of Brazilian revenue; not yet enacted
[15] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026 (45 Council of Europe member states plus 37 non-member states), Brazil among the non-member-state parties (acceded 2023)
[16] Wikipedia: BRICS – Eleven member states as of 2026: Brazil, Russia, India, China, South Africa, and, from 2024–2025, Egypt, Ethiopia, Iran, Saudi Arabia, the United Arab Emirates, and Indonesia
[17] OAS: Inter-American Convention on Mutual Assistance in Criminal Matters – Signatures and Ratifications (A-55) – adopted 1992, in force 1996; 27 parties; Brazil signed January 7, 1994 and ratified October 10, 2007 (deposit November 12, 2007)
← Back to Privacy Law Directory