Brazil data localisation APAC

Brazil's Data Center Bill Localizes State Data, Not the Internet — For Now

A Chamber committee backed onshore storage only for defense and security data, but its 'data embassy' carve-out and unfinished path through Congress leave room for scope creep.

Brazil's Data Center Bill: What's Confirmed So Far People of Internet Research · Brazil 2 Committee votes still needed Finance and Taxation, then Constit… ~7% Trade output loss per restriction point ITIF's cross-country model links e… 1 Countries with ANPD adequacy status The EU is the only jurisdiction Br… ~14 Months from filing to committee approval PL 1680/2025 was filed April 14, 2… peopleofinternet.com
Brazil's Data Center Bill: What's Conf… People of Internet Research · Brazil 2 Committee votes still needed ~7% Trade output loss per restriction … 1 Countries with ANPD adequacy st… ~14 Months from filing to commit… peopleofinternet.com

Key Takeaways

A Narrower Mandate Than the Headline Suggests

On June 10, 2026, the Chamber of Deputies' Science, Technology and Innovation Committee approved a substitute text for PL 1680/2025, which creates Brazil's National Policy for Digital Processing and Storage. Filed in April 2025 by Deputy Pedro Lucas Fernandes (União-MA) and reported by Deputy David Soares, the bill's most consequential clause requires that Brazilian data tied to national defense, public security and crime prevention be "processed and stored exclusively in data centers located in national territory" — or in reciprocal "data embassies" Brazil establishes abroad, according to the Chamber's own announcement.

That scope matters. This is not a Russian- or Chinese-style blanket citizen-data localization mandate reaching every company that touches a Brazilian's personal information — it is a sovereign-data carve-out limited to the categories of information governments routinely wall off for national-security reasons. The steelman case is real: keeping classified defense records, ongoing criminal investigations and public-safety intelligence on domestic soil, immune to foreign subpoena or seizure, is standard practice among mature democracies. The United States runs FedRAMP High and GovCloud enclaves for sensitive federal workloads; the EU has pushed "sovereign cloud" requirements for government data; India requires its own government-cloud empanelment. Brazil legislating a similar boundary for its own defense and law-enforcement data is not radical — it is catching up.

What the Text Actually Does

Beyond the localization clause, the approved substitute creates a Data Embassy regime: foreign governments may store their own critical data inside Brazil under a reciprocal international agreement, with that data treated legally as an extension of the origin country's territory. Notably, embassy data is exempted from Brazil's general data-protection law (LGPD) and its cybersecurity rules — though not from environmental or fire-safety codes, per reporting from Mobile Time. The bill separately grants data centers priority access to the electrical grid in regions with surplus generation, and lets operators fund transmission infrastructure themselves — provided those costs are not passed onto consumer electricity tariffs. Notably, the rapporteur stripped the original tax-exemption provisions from the text, so this is now a narrower industrial-policy vehicle than when it was filed, not a broader one.

A Long Way From Becoming Law

Committee approval is a floor, not a finish line. Under Brazil's "conclusive appraisal" process, PL 1680/2025 still needs sign-off from the Finance and Taxation Committee — which has not yet even named a rapporteur — and the Constitution and Justice Committee, before it can reach a floor vote in the Chamber and then the Senate. Two more committees and two full chamber votes stand between this text and the president's desk. Coverage framing this as Brazil "mandating" localization risks getting ahead of where the process actually is.

Why Keeping the Scope Narrow Is the Right Call

Brazil already has a working framework for cross-border data flows that does not rely on hard localization. The National Data Protection Authority's (ANPD) Resolution 19/2024, in force since August 2024, lets companies move personal data abroad via adequacy decisions, standard contractual clauses, or binding corporate rules — the EU is so far the only jurisdiction to receive an adequacy determination, but the mechanism itself is flow-permissive, not flow-blocking. That is the right default. Research from the Information Technology and Innovation Foundation, using econometric modeling across dozens of countries, found that each one-point increase in a nation's cross-border data-restrictiveness score cuts its gross trade output roughly 7 percent over five years, alongside measurable productivity and price effects. Those costs compound the broader the localization mandate; a rule limited to defense and security data avoids most of that drag because it touches a sliver of the data economy, not the whole cloud sector serving Brazilian consumers and businesses.

The Loophole Worth Closing

The one design flaw lawmakers should fix before final passage is the data-embassy exemption from LGPD and cybersecurity oversight. Carving foreign-government data out of Brazil's own privacy statute is defensible when that data genuinely belongs to another sovereign under a reciprocal treaty — but an undefined exemption is an invitation for scope creep, letting commercial data get relabeled as diplomatic to dodge domestic rules. As the bill moves through Finance and Constitution and Justice, the committees should tighten the definition of "strategic data" to the defense, public-security and crime-prevention categories already in the text, and require that any data embassy remain subject to Brazilian cybersecurity audit even where LGPD itself doesn't apply. Get that narrow and it's a defensible sovereignty measure. Broaden it — to financial data, health data, or general personal data, as India's and China's laws eventually did — and Brazil imports the costs ITIF has already measured elsewhere.

Sources & Citations

  1. Câmara dos Deputados — committee approves National Data Center Policy
  2. Câmara dos Deputados — PL 1680/2025 tramitação (bill tracker)
  3. ANPD — Transferência Internacional de Dados
  4. ITIF — How Barriers to Cross-Border Data Flows Are Spreading Globally
  5. Mobile Time — Redata é aprovado em Comissão