Brazil’s ECA Digital: Is Child Safety Now a Product Requirement?
Six months after entering into force, Brazil’s Digital Statute for Children and Adolescents (Law No. 15,211/2025) has moved from text to enforcement, and the ANPD’s age-assurance guidance is setting the practical bar. This article maps the core obligations, the six requirements behind “reliable” age assurance and what providers, in Brazil and abroad, should prioritise now.
8 October 2026

A statute built for product design, not only for data
Brazil’s ECA Digital (Law No. 15,211/2025) took effect on 17 March 2026 and was regulated the next day by Decree No. 12,880/2026. It applies to any information technology product or service directed at, or likely to be accessed by, children and adolescents, regardless of where it is developed, offered or operated (art. 1). “Likely access” is a cumulative test: sufficient probability of use and attractiveness, considerable ease of access, and significant risk to privacy, safety or biopsychosocial development. Foreign providers must appoint a legal representative in Brazil (art. 40), and their local affiliate is jointly liable for fines (art. 35, §2). The logic is closer to the EU Digital Services Act and the UK Online Safety Act than to a classic privacy law: risk must be prevented by design, not consented away.
What providers must now deliver
Age assurance. Services unsuitable for under-18s must use reliable age verification at every access, and self-declaration is barred (art. 9, §1). App stores and operating systems must assess age, enable parental supervision and expose a privacy-preserving age signal through a secure API (art. 12). Age data may serve no other purpose (art. 13).
Protective defaults. The most protective privacy settings by default (art. 7), accounts of users up to 16 linked to a guardian (art. 24) and parental tools whose defaults restrict contact by unauthorised users, autoplay and engagement features (art. 17, §4).
Commercial limits. Loot boxes are banned in games aimed at, or likely accessed by, minors (art. 20). Profiling for targeted advertising to minors is prohibited, as are emotion analysis and AR/VR techniques for that purpose (art. 22).
Notice and takedown. Apparent child sexual exploitation must be removed and reported (art. 27). Content violating minors’ rights must be removed on notice from victims, prosecutors or child-rights bodies, without a court order (art. 29), with contestation rights for the uploader (art. 30).
Transparency. Platforms with over one million registered users under 18 must publish semi-annual reports in Portuguese (art. 31). The first were due on 17 September 2026.
What “reliable” age assurance means: the ANPD’s six requirements
The ANPD’s preliminary guidance on reliable age-assurance mechanisms (v1.0, March 2026) organises the eleven items of art. 24 of the Decree into six minimum requirements. It states the agency’s institutional position and is the reference for its monitoring until definitive guidance is issued after public consultation; an updated draft received stakeholder input until July 2026. It is not a safe harbour, but it shows how the ANPD will read “reliable”.
Proportionality. Assess the risks of the service and of the age-assurance method itself, then weigh one against the other. A data protection impact assessment (RIPD) and the child-safety risk assessment under art. 47 of the Decree are the suggested tools.
Accuracy, robustness, reliability. Measure and document accuracy, test resistance to circumvention by children and vet data sources. Self-declaration alone is treated as low-reliability.
Privacy and data protection. Process only the age attribute needed, with no secondary use, no traceability of users’ history and no continuous, automated, unrestricted data sharing. Facial biometrics demand stronger justification where less intrusive options exist, while zero-knowledge proofs and verifiable credentials are cited as privacy-preserving alternatives.
Inclusion and non-discrimination. Avoid methods that exclude people without official documents, test for bias across groups (notably in facial analysis) and offer alternative methods.
Transparency and auditability. Explain the mechanism in plain language, provide a way to contest the assessed age and keep audit logs limited to functional metadata, not biometrics, images or ID data.
Interoperability. Share only the age result, ideally through double-blind architectures with defined limits on data flows. Minimum requirements for app stores and operating systems are still to be regulated (art. 12, §3).
Enforcement is not waiting for the final guidance
The ANPD, now a federal regulatory agency, is both Brazil’s data protection authority and the statute’s enforcer. It monitors 37 companies, reviewed app stores, operating systems and adult-content sites from June, and in August extended scrutiny to major platforms and generative AI tools. It opened proceedings against Discord and, as a preventive measure, suspended its live streaming in Brazil: the implementation phase does not shield non-compliance. A dedicated complaint channel has logged about 200 reports.
Sanctions under art. 35 range from warnings to fines of up to 10% of the economic group’s Brazilian revenue (or, absent revenue, BRL 10 to 1,000 per registered user, capped at BRL 50 million per infringement). Suspension or prohibition of activities requires a court order and is enforced through blocking orders. The ANPD signals tougher supervision from early 2027, once the definitive guide and updated enforcement rules are in place.
Lessons learned
Takeaways for international groups
Scope first. Document a “likely access” assessment for every product; adult-oriented services may still be caught.
One baseline, Brazilian overlays. Align DSA, UK and COPPA controls in one child-safety standard, adding Brazilian specifics: age signals from app stores, guardian linkage up to 16, loot boxes, Portuguese-language reports and a local legal representative.
Treat age assurance as a data protection decision. Involve privacy early, run the RIPD and avoid retaining biometric or ID data.
Keep evidence. Accuracy tests, risk assessments, audit logs and reporting workflows are what the regulator will ask for first.
Cooperation with the European Commission (June 2026) and membership of the Global Online Safety Regulators Network (July 2026) point to a converging global agenda.
Article provided by INPLP member: Lorena Botelho (Urbano Vitalino Advogados, Brazil)
By Lorena Botelho — Urbano Vitalino Advogados, Brazil