What the Court actually decided
On 26 June 2025, Brazil's Federal Supreme Court (STF) ruled, 8 votes to 3, that Article 19 of the Marco Civil da Internet — the 2014 law that shielded platforms from liability for third-party content absent a specific court order — was partially unconstitutional. On 17 June 2026, the Court closed out 13 embargos de declaração (motions for clarification) and finalized the thesis: platforms now face joint and several liability, rather than the old subsidiary standard, once they receive extrajudicial notice of unlawful content and fail to act (Baker McKenzie). For content the Court classifies as "grave" and prone to mass circulation — crimes against children, incitement to terrorism, coup-plotting, racism — providers now carry an affirmative "duty of care" to prevent systemic spread, not just react to notices.
The Court gave large providers (those with more than one million Brazilian users) 60 days from 18 June 2026 to stand up the structural machinery this requires: a Brazil-based legal representative, accessible complaint channels, and annual transparency reporting (mobiletime.com.br).
The enforcement teeth are new, and they sit at ANPD
What makes this round different from the 2025 ruling is who polices it. Decrees 12.975/2026 and 12.976/2026, published 21 May 2026, amended the Marco Civil's implementing regulation and handed Brazil's data protection authority, ANPD, the job of regulating, inspecting, and sanctioning platforms for systemic non-compliance. ANPD's own guidance is explicit that it will not adjudicate individual posts or force account suspensions — its mandate is evaluating whether a platform's governance is adequate. But the penalties are real: warnings with correction deadlines, fines of up to 10% of the economic group's Brazilian revenue, and, in serious cases, suspension of the service (gov.br/ANPD). Brazil's multistakeholder internet body, CGI.br, has publicly called the decrees "legitimate and relevant" and credited them with incorporating its own application-provider typology rather than writing platform obligations from scratch (CGI.br).
The steelman: WhatsApp fraud in Brazil is a real, large problem
The regulators pushing this framework have a genuine case. WhatsApp is used by roughly 99% of Brazilian smartphone owners, and criminal groups have industrialized abuse of that reach: account-cloning that hijacks a victim's contact list to impersonate them, fabricated PIX payment-confirmation screenshots used to defraud small merchants and delivery drivers, and malware-laced APKs disguised as government benefit apps (NordBridge Security). Brazilian prosecutors have described organized crime factions rotating out of armed robbery and kidnapping into exactly this kind of digital fraud because it is lower-risk and higher-yield. It echoes — without being identical to — the "digital arrest" playbook that has forced WhatsApp into mass account bans in India, where scammers impersonate police over video calls to extort victims. A regulator that says "platforms have to build real anti-fraud governance, not just a reporting button" is responding to something genuinely happening to people, not a hypothetical.
Where the framework overshoots
The problem is not that Brazil is regulating platform conduct — it is how it drew the line. "Duty of care" for "grave and massive" illicit content is a standard, not a rule, and Tech Policy Press's analysis of the ruling flags exactly the failure mode you'd expect: the Court gave platforms liability exposure for under-moderating but no usable guidance on what "diligent" moderation looks like, particularly for borderline political speech like "glorification of the violent abolition of the democratic system" (Tech Policy Press). Facing a 10%-of-revenue fine for guessing wrong, the rational compliance response is to over-remove, especially content adjacent to politics — the opposite of what a healthy speech environment needs ahead of Brazil's next election cycle.
Sixty days from an 18 June clock is also a compressed runway for the exact things that make moderation defensible rather than arbitrary: appeal mechanisms, documented decision criteria, and Brazil-based legal representation, which mid-sized platforms without existing Latin America operations will struggle to stand up on schedule. The EU's Digital Services Act, whatever its own flaws, at least phases obligations by platform size and pairs them with a defined risk-assessment methodology; Brazil's version leans harder on ANPD's post-hoc discretion to decide what "systemic" governance should have looked like.
ANPD's transformation into a genuine regulatory agency — rather than STF issuing case-by-case content rulings — is directionally the right fix, and Congress deserves credit for making that structural change rather than leaving platform liability entirely to litigation. But a fining regulator needs clear rules published before the conduct it punishes, not after. Brazil should use the 60-day window to publish concrete, narrow-scope guidance — starting with the financial-fraud and CSAM categories where consensus is easiest — rather than let the first ANPD enforcement actions define the standard by precedent.