Brazil
Outside the Eyes alliances but bound into the Budapest Convention, the Mercosur mutual-assistance protocol and the inter-American treaty network, even as the NSA tapped the President’s phone and ABIN ran 60,000+ illegal searches with Israeli spyware
Overview
Brazil’s 1988 Constitution establishes privacy as a fundamental right, strengthened by Amendment EC 115/2022 explicitly protecting personal data including in digital media. The LGPD (Lei Geral de Proteção de Dados, 2018) provides GDPR-influenced data protection, and in January 2026, Brazil became the first Latin American country to receive EU mutual adequacy recognition.[1]
Behind this framework, the Parallel ABIN scandal (2019–2021) revealed that ABIN Director Alexandre Ramagem conducted 60,000+ illegal surveillance searches targeting journalists, STF justices, and opposition politicians using Cognyte First Mile spyware. Ramagem was convicted and sentenced to 16 years. The 2013 Snowden revelations that the NSA intercepted President Rousseff’s communications and hacked Petrobras directly motivated the EllaLink cable project to bypass US routing. Brazil is not an Eyes alliance member but is a BRICS founder.[2][3]
Brazil’s outward data-sharing runs through its alliances and treaties, each detailed below. Not an Eyes member, it is a BRICS founder, holds an EU mutual adequacy decision, and maintains one of the widest bilateral MLAT networks in this directory (about 30 treaties, including with the United States), alongside the regional Inter-American Convention on Mutual Assistance and the Mercosur MLA Protocol; it acceded to the Budapest Convention on Cybercrime in 2023. These are the channels through which the domestic protections described below are, in practice, bypassed.[1][11][15]
International Data Sharing Agreements
Mutual Legal Assistance: 30+ Bilateral Treaties
Brazil maintains bilateral MLATs with approximately 30 countries including: United States (signed October 14, 1997, in force February 21, 2001), Canada, Chile, China, Colombia, Ecuador, Germany, Grenada, Guyana, Hong Kong, India, Ireland, Italy, Jordan, Kazakhstan, Mexico, Morocco, Netherlands, Nigeria, Panama, Paraguay, Philippines, Romania, Spain, Sweden, Thailand, Ukraine, UAE, Uruguay, and Vietnam. Brazil is also party to the Inter-American Convention on MLA in Criminal Matters (the OAS regional instrument, ratified by Brazil in 2007; its 27 parties are Antigua and Barbuda, Argentina, the Bahamas, Bolivia, Brazil, Canada, Chile, Colombia, Costa Rica, Dominica, Ecuador, El Salvador, Grenada, Guatemala, Guyana, Honduras, Jamaica, Mexico, Nicaragua, Panama, Paraguay, Peru, Suriname, Trinidad and Tobago, the United States, Uruguay, and Venezuela) and the Mercosur MLA Protocol (the San Luis Protocol, binding Argentina, Brazil, Paraguay, and Uruguay).[17] Brazil’s treaties are published in the Itamaraty’s Concórdia treaty database.[11]
Convention on Cybercrime (the Budapest Convention, 2001, ETS 185): Brazil acceded in 2023 to the Council of Europe’s cybercrime convention, which governs the expedited preservation and cross-border disclosure of stored computer and subscriber data. As of July 2026 it has 82 parties: 45 Council of Europe member states (every one of the 46 except Ireland, which has signed but not ratified), namely Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom; together with 37 non-member states, Brazil among them: Argentina, Australia, Benin, Brazil, Cabo Verde, Cameroon, Canada, Chile, Colombia, Costa Rica, Côte d’Ivoire, the Dominican Republic, Ecuador, Fiji, Ghana, Grenada, Israel, Japan, Kiribati, Mauritius, Morocco, New Zealand, Nigeria, Panama, Papua New Guinea, Paraguay, Peru, the Philippines, Rwanda, São Tomé and Príncipe, Senegal, Sierra Leone, Sri Lanka, Tonga, Tunisia, the United States, and Vanuatu.[15]
BRICS and EU Adequacy
BRICS: Founding member; 2025 presidency; Working Group on ICTs for real-time threat intelligence exchange. BRICS now comprises eleven members: Brazil, Russia, India, China, South Africa, Egypt, Ethiopia, Iran, Saudi Arabia, the United Arab Emirates, and Indonesia.[16] EU mutual adequacy (January 26, 2026): Reciprocal recognition, first Latin American country. Mercosur: EU-Mercosur Partnership Agreement signed early 2026.[1]
The Privacy Backdoor Effect
Despite LGPD protections and EU adequacy, alternative access exists:
- NSA Upstream: The 2013 revelations showed NSA specifically targeted Brazilian government communications; LGPD does not constrain NSA collection outside Brazil
- ABIN Article 4(III): LGPD explicitly exempts national security; any exempted agency has no data protection constraints
- 30+ MLATs / Budapest Convention: extensive bilateral treaty network, the Inter-American and Mercosur MLA instruments, and the 82 parties to the Budapest Convention, all enabling foreign law enforcement data requests
- Cable transit: Despite EllaLink, some traffic still transits US nodes subject to FAIRVIEW/STORMBREW
- SWIFT/PNR: Financial and travel data subject to US access
Surveillance and Intelligence
ABIN and SISBIN
ABIN (created 1999) reports to the President and coordinates SISBIN (Brazilian Intelligence System) across federal agencies. ABIN cannot intercept communications but can access SISBIN member databases. The Federal Police conducts wiretapping under judicial authorisation (Law 9,296/1996). Parliamentary oversight via CCAI (widely criticised as lacking staff and technical capacity).[5]
The Parallel ABIN Scandal (2019–2021)
Under Director Ramagem, a “parallel intelligence” structure used Cognyte First Mile spyware (purchased 2018 for R$ 5.7M) to track real-time geolocation of up to 10,000 targets per year. 60,000+ illegal searches targeted 12+ journalists, STF Justices, politicians, IBAMA officials. Nine state security departments separately purchased Cognyte totalling R$ 65.7 million. Federal Police Operation Last Mile (2023) led to Ramagem’s conviction (September 2025, 16-year sentence) for illegal surveillance and the 2022–2023 coup plot. He fled to the US before arrest.[2][6]
The NSA Spying Scandal (2013)
Snowden documents revealed the NSA intercepted President Rousseff’s personal communications, hacked Petrobras, and monitored 29 government phone numbers. Rousseff cancelled a state visit to Washington and addressed the UN General Assembly to condemn US surveillance. The revelations directly motivated EllaLink and accelerated the Marco Civil da Internet.[3]
Commercial Surveillance and Facial Recognition
Cellebrite: Federal Police use UFED for mobile forensics. Chinese technology: Huawei, Hikvision, Dahua, ZTE donated 4,000+ cameras for São Paulo’s City Cameras programme. Facial recognition: deployed in São Paulo (plans for 20,000 cameras), Rio de Janeiro (AI drones at Carnival 2025, 63% false positive rate in Maracanã pilot), and Salvador (209 fugitives arrested). Racial bias: more than 90% of FRT arrests target Black Brazilians (CESeC study). No legal framework governs deployment.[7]
Submarine Cable Infrastructure
Brazil is a major cable hub with 14 landing stations at Fortaleza, Rio, Santos, and Salvador. EllaLink (2021, 100 Tbps, direct Portugal-Fortaleza, explicitly bypassing US routing), SACS (2018, first direct South America-Africa), Monet (2017, Google), BRUSA (Rio-Fortaleza-Puerto Rico-Virginia), Firmina (2025, Google, 14,517 km), SAIL (2018, China Unicom). Previously targeted by NSA FAIRVIEW and STORMBREW upstream collection when traffic routed through US nodes.[8]
Recent Developments
Ramagem Conviction (September 2025): Former ABIN Director convicted by STF (4-1) for Parallel ABIN illegal surveillance and coup plot. 16-year sentence. Fled to US.[2]
EU Mutual Adequacy (January 2026): Brazil’s reciprocal adequacy with the EU, the first for a Latin American country, is covered under International Data Sharing above.[1]
ECA Digital (Law 15,211/2025), Now in Force: Became effective March 17, 2026, with implementing decree published March 18. Mandatory age verification replacing self-declaration, profiling and targeted advertising banned for all under-18s, paid loot boxes prohibited in products accessible to minors, under-16 accounts must link to parent/guardian. Establishes National Notification Screening Center (Federal Police) for digital crimes against minors. ANPD enforces with fines up to BRL 50M or 10% of Brazil revenue. The ANPD’s first stage of monitoring (begun March 2026) targets app stores and proprietary operating systems; final guidelines are due August 2026; administrative sanctions begin November 2026 with formal compliance verification from January 2027. The ANPD’s 2026–2027 Priority Themes Map names children’s data, targeted advertising, public-sector data sharing, and AI as the four enforcement priorities.[9][12][13]
ANPD Independence (September 2025): Transformed to full independent regulatory agency with financial/administrative autonomy.[4]
Facial Recognition Racial Bias: the CESeC finding that 90%+ of facial-recognition arrests target Black Brazilians, and the absence of any governing legal framework, are detailed above.[7]
Privacy Framework
The ANPD was transformed into a fully independent agency (September 2025). Maximum penalty: 2% of revenue (capped at R$ 50M per violation). The LGPD grants the Central Government power to exempt any agency for national security (Article 4(III)). Rule of law under the Marco Civil da Internet (2014): court orders required for data access; Article 19 was partially declared unconstitutional (June 2025 STF ruling) for platform liability for hate speech and CSAM.[4]
Age Verification: Identity Infrastructure as Surveillance
The ECA Digital (Law 15,211/2025), enacted September 17, 2025 and effective March 17, 2026, establishes comprehensive digital child protection. Platforms must implement age verification using “highly effective and auditable” technology; self-declaration explicitly banned. Accounts for under-16s must link to a guardian’s account. Behavioral advertising profiling of children is banned. Paid loot boxes prohibited for minors. Fines up to BRL 50 million or 10% of Brazilian revenue per violation. The ANPD enforces.[9]
The law applies to any digital product “aimed at or likely to be accessed by” minors in Brazil regardless of company location, creating extraterritorial reach. The mandatory age verification infrastructure (linking all under-16 accounts to guardian accounts with identity verification) creates a surveillance-capable architecture mapping parent-child relationships to platform access at national scale.
Data Retention
Marco Civil da Internet: Connection logs (ISPs): 1 year; application access logs: 6 months. Court order required for all access. ANATEL Resolution 738/2020: Subscriber/billing/call records: 5 years; internet connection records: 1 year. LGPD Article 4(III) exempts national security activities, meaning exempted agencies face no statutory retention limitation.[10]
Pending Legislation
- PL 2338/2023 (AI bill): the comprehensive AI framework passed the Senate in December 2024 and is under review by a special committee in the Chamber of Deputies; the substitute text designates the ANPD as coordinator of a national AI system and caps penalties at BRL 50 million or 2% of Brazilian revenue. Not yet enacted; staged entry into force is not expected before late 2026 at the earliest.[14]
- ECA Digital staged enforcement: although in force since March 17, 2026, the ANPD’s final implementing guidelines are due August 2026, administrative sanctions begin November 2026, and formal compliance verification starts January 2027.[13]
- Facial-recognition regulation: no statute governs government facial-recognition deployment despite documented racial bias; civil-society proposals for a moratorium or regulatory framework remain pending.[7]
