Brazil data protection

Brazil's ANPD Widens Age-Verification Enforcement Beyond App Stores as ECA Digital Enters Phase Two

ANPD's August 2026 expansion moves ECA Digital oversight from Apple, Google and Microsoft to risk-rated sectors, ahead of January 2027 enforcement.

ECA Digital Enforcement: From Three Firms to a Risk-… People of Internet Research · Brazil 10% Maximum revenue-based fine ANPD can fine repeat offenders up … 3 Firms under initial oversight Apple, Google and Microsoft were t… 7 CGI.br proportionality recommendations Brazil's internet-governance body … Jan 2027 Formal enforcement begins ANPD's compliance verification aga… peopleofinternet.com
ECA Digital Enforcement: From Three Fi… People of Internet Research · Brazil 10% Maximum revenue-based fi… 3 Firms under initial oversight 7 CGI.br proportionality … Jan 2027 Formal enforcement begi… peopleofinternet.com

Key Takeaways

Brazil's National Data Protection Authority (ANPD) is moving into the second stage of enforcing the Digital Statute of the Child and Adolescent — ECA Digital — this August, expanding age-verification oversight beyond the three companies it started with and into other sectors selected by risk level. It is a deliberately incremental rollout of one of the most ambitious child-safety data regimes any jurisdiction has attempted, and how ANPD handles the expansion will say a lot about whether risk-based regulation can actually stay proportionate once it scales.

From three gatekeepers to a risk-tiered sweep

ECA Digital — Law 15.211/2025, enacted in September 2025 and in force since March 17, 2026 — requires that any digital product or service with "probable access" by minors deploy reliable age-verification mechanisms, ban self-declaration of age, and give parents supervision tools. Decree 12.880/2026, published a day after the law took effect, laid out 54 articles of implementation detail and handed ANPD the job of sequencing enforcement rather than flipping every switch at once.

ANPD's first move, starting June 10, 2026, was narrow by design: it began requiring Apple (App Store), Google (Google Play) and Microsoft (Windows) to disclose system architecture, data flows and age-verification mechanisms within 15 business days, on the theory that app stores and operating systems are the chokepoint through which nearly all Brazilian minors reach everything else online. Phase two, opening this August after ANPD finalizes its technical guidance, extends monitoring to "other sectors or groups of providers" — chosen using the risk criteria embedded in the law itself, with tougher verification expected for social networks, gaming platforms and other services carrying higher exposure risk. Administrative sanctions become available in November 2026, and formal compliance verification — actual enforcement actions against noncompliant firms — starts in January 2027.

The case for going slow and starting narrow

The sequencing deserves credit before it draws criticism. Regulators who try to enforce a sweeping new obligation against every covered entity on day one typically produce chaos: inconsistent guidance, overwhelmed compliance teams, and enforcement that lands hardest on whoever is easiest to find rather than whoever poses the greatest risk. By starting with three infrastructural gatekeepers and using what it learns from them to calibrate a risk-tiered expansion, ANPD is doing something regulators rarely manage — building the muscle before using it at scale. Brazil's internet-governance body, CGI.br, made exactly this case in its formal submission to ANPD's public consultation, urging the agency to scale verification rigor to a service's actual risk level rather than mandating one uniform method everywhere, from biometric checks to token-based age signals depending on context.

Where the design still has to prove itself

The steelman only carries the law so far. Age verification of any kind means someone — a platform, an OS maker, or a third-party verifier — collects identity documents, facial biometrics, or behavioral signals from users who are, by definition, not just the minors the law is trying to protect. Brazilian privacy researchers and lawyers have been blunt about this: reporting from Gazeta do Povo quotes experts warning that document- and biometric-based checks "end anonymity on the internet" and build large databases of sensitive data with no settled answer on retention — whether records are purged when a user turns 18 or persist as a "digital history from childhood." ANPD itself has acknowledged security and discrimination risks in its own preliminary guidance. Overbroad content moderation is the other predictable failure mode: platforms facing fines of up to 10% of their Brazil revenue (capped at R$50 million per infraction) have every incentive to over-block ambiguous content rather than risk a violation, which chills legitimate speech for adults as collateral damage.

A compressed runway, twice over

The practical risk in phase two is timing, not just design. The first three companies had a defined 15-business-day disclosure window and months of lead time before their obligations bit. Firms newly swept into scope this August — social platforms, gaming services, and whatever else ANPD's risk criteria capture — get a shorter runway to a January 2027 enforcement date that was set before anyone knew which sectors would be added. TechPolicy.press has reported that ANPD itself is still building out staff capacity even as its mandate widens, which raises the odds that guidance arrives late relative to the sanctions clock now running.

None of this argues against child-safety regulation as such — ECA Digital responds to real harms, and a phased, risk-calibrated rollout beats a blanket mandate. But proportionality has to survive contact with scale. If ANPD's August guidance genuinely ties verification rigor to demonstrated risk, as CGI.br recommended, phase two could become a workable template other jurisdictions study. If it instead defaults to the most invasive method as the safe compliance choice, Brazil will have traded a privacy problem confined to three companies for one spread across its entire digital economy — with adults' data swept up alongside the minors the law set out to protect.

Sources & Citations

  1. ANPD: Preliminary Guidance and Timeline for Age Verification
  2. Decree No. 12,880/2026 (regulates Law 15.211/2025)
  3. CGI.br: Seven Recommendations on Age Verification
  4. Mayer Brown: Enforcement of Brazil's ECA Digital
  5. Tech Policy Press: Brazil Wants to Reshape the Internet for Kids
  6. Gazeta do Povo: Privacy Risks in ECA Digital Age Verification
  7. Leonardi Advogados: ANPD Monitors Apple, Google and Microsoft