A fleet built on comodato, not procurement
Since 2023, BYD has loaned at least 30 electric vehicles to three branches of the Brazilian state under comodato (free-loan) agreements: 20 Seals to the Superior Court of Justice (STJ), nine vehicles to the federal audit court (TCU), and one Tan each to the Presidency and the Chamber of Deputies, according to Poder360. The agencies pay only insurance and electricity; BYD picks up the rest. The arrangement coincides with BYD's push to build its first factory outside Asia, in Camaçari, Bahia, and with a state visit in which President Lula met company representatives at Alvorada Palace. A Brazilian legal expert quoted in that reporting flagged a conflict-of-interest concern — free cars for officials who also set industrial policy for the sector. That is a real governance question. It is a separate one from whether the cars themselves are a data-security problem, and Brazilian analysts are now arguing they are.
What the car actually collects
Connected EVs are, functionally, mobile sensor platforms. Cybersecurity specialist Thiago Guedes, CEO of the Brazilian firm DeServ, put it directly in reporting from Diálogo Américas: "consumers know the vehicle is connected, but they do not clearly understand what data is generated, why it is transmitted, how long it is stored, or with whom it is shared." That reporting also notes BYD's roughly 50% share of Brazil's EV market, and the specific concern driving this story: continuous GPS traces, cabin cameras, and driving-behavior telemetry from vehicles used by senior officials could reveal the routines, routes, and security details of people who run the Brazilian state. CNN Brasil reporting on connected cars generally makes the same point about ordinary drivers: continuous geolocation reveals home, workplace, children's schools, and medical visits, and vehicle data is frequently stored on servers in China, the US, or Europe — jurisdictions the driver never chose and the manufacturer rarely discloses clearly.
The legitimate case for scrutiny
Before dismissing this as protectionist noise, it's worth stating the strongest version of the concern. China's 2017 National Intelligence Law obliges Chinese organizations to "support, assist, and cooperate" with state intelligence work — a legal architecture that gives Beijing a standing claim on data held by Chinese firms, wherever that data physically sits. Washington took this seriously enough to act on it: in January 2025, the Commerce Department's Bureau of Industry and Security finalized a rule banning the import and sale of connected vehicles using Chinese- or Russian-linked software (effective model year 2027) and hardware (2030), citing the risk that "foreign adversaries" could "extract sensitive data, including personal information about vehicle drivers or owners, and remotely manipulate vehicles," per the BIS press release. If the US treats connected-vehicle telemetry as a national-security surface serious enough to restructure its auto-import rules, Brazil putting the exact same technology under its Presidency, Congress, and top courts is not a fringe worry.
Where Brazilian law actually stands
The problem is that the LGPD, Brazil's 2018 general data protection law, was drafted for e-commerce and social platforms, not telemetry-generating vehicles. It requires that cross-border transfers go to jurisdictions with adequate protection or under contractual safeguards approved by the ANPD (Autoridade Nacional de Proteção de Dados), and it caps fines at 2% of Brazilian revenue up to R$50 million per violation — a ceiling CNN Brasil's reporting notes lawyers already consider inadequate deterrence against monetizing driver data without consent. The ANPD is actively working on biometric data standards — it ran a public consultation on biometric processing rules from June to August 2025 that drew 84 submissions, per gov.br — but that consultation is about facial recognition and biometric identification generally, not connected-vehicle telemetry specifically. No LGPD rule, and no government procurement standard, currently requires an independent security audit, local data residency, or disclosure of foreign server locations before a car — Chinese, American, or otherwise — is issued to a sitting minister.
The proportionate answer isn't a ban
Banning Chinese EVs from Brazilian roads, or slow-walking BYD's Bahia factory, would be a costly overcorrection: it would sacrifice Brazil's fastest-growing source of affordable EVs and thousands of manufacturing jobs to solve a problem that a much narrower rule can fix. The US approach is itself narrower than it looks — it targets connectivity hardware and software, not vehicle sales generally, and phases in over years. Brazil doesn't need a blanket import restriction; it needs three specific things it currently lacks: a government-fleet procurement standard requiring data-residency and independent-audit guarantees for any connected vehicle assigned to a public official, an ANPD rule extending its cross-border-transfer safeguards explicitly to vehicle telemetry, and mandatory disclosure — for every connected car sold in Brazil, regardless of origin — of what is collected, where it goes, and for how long it's kept. That protects officials' movements and ordinary drivers' privacy without treating an entire national industry, or Brazil's cheapest path to EV adoption, as a security threat by default.