Brazil deepfake regulation

EFF and Allies Push Brazil to Enforce Its Data Law Against Election Microtargeting, Not Just Ban Deepfakes

Ahead of Brazil's Oct. 4 vote, EFF, Access Now, and Data Privacy Brasil want LGPD sensitive-data rules enforced against political microtargeting, not new AI bans.

Brazil's Election-AI Rules, By the Numbers People of Internet Research · Brazil 72 hours Pre-vote AI content blackout TSE bars new synthetic candidate c… R$5,000-30,000 Deepfake violation fines Current TSE penalty range for unla… 155M+ Registered voters affected Brazilians eligible to vote in the… 4 ANPD 2026-27 priority themes AI is one of four ANPD enforcement… peopleofinternet.com
Brazil's Election-AI Rules, By the Num… People of Internet Research · Brazil 72 hours Pre-vote AI content blackout R$5,000-30,000 Deepfake violation fines 155M+ Registered voters affected 4 ANPD 2026-27 priority themes peopleofinternet.com

Key Takeaways

A Second Layer, Not a Rewrite

On August 27, 2026, the Electronic Frontier Foundation, Access Now, and Data Privacy Brasil published joint recommendations urging Brazil to strengthen privacy and data-protection safeguards ahead of the country's October 4 general election. Notably, the groups aren't asking Brazil's Superior Electoral Court (TSE) to write new deepfake bans — it already has them. They're arguing that the country's existing election-integrity framework treats the symptom (fake videos and audio) while leaving the underlying supply chain — the personal-data pipelines that make targeted manipulation effective — largely unpoliced.

That's a meaningful distinction, and it deserves to be taken on its own terms rather than folded into the generic "regulate AI" conversation.

What Brazil Already Has

TSE Resolution 23.732/2024 first required that any AI-generated or AI-altered campaign content carry an explicit, visible disclosure label and banned synthetic content designed to deceive voters. Resolution 23.755, issued March 2, 2026, expanded that framework: platforms must file compliance plans and maintain public ad repositories, and — critically — no new AI-generated content featuring a candidate or public figure may be published, republished, or boosted in the 72 hours before voting or the 24 hours after polls close. Violations carry fines of roughly R$5,000 to R$30,000 (about $970–$5,800) and, in serious cases, candidacy cancellation.

That's a reasonably well-targeted regime: it doesn't ban AI in campaigns, it demands disclosure, and it closes the narrow window — the final 72 hours — when a fabricated video is hardest to debunk before voters act on it.

The Steelman for Going Further

The civil-society coalition's core argument deserves to be stated plainly, because it's a real gap. Brazil's Lei Geral de Proteção de Dados (LGPD, Lei 13.709/2018) already classifies political opinion as sensitive personal data under Article 11, processable only with explicit, specific consent or narrow statutory exceptions. Yet campaigns routinely acquire and process voter-profile data — inferred ideology, behavioral targeting segments — to power the same microtargeting systems that decide who sees an AI-generated ad and when. A disclosure label on a synthetic video does nothing to stop a campaign from using illegally sourced sensitive data to decide which 50,000 voters see it. And AI-generated "synthetic voters" — avatars and bot personas manufacturing the appearance of grassroots consensus — aren't deepfakes of real candidates at all, so TSE's candidate-likeness rules don't clearly reach them. The coalition's seven recommendations — from ANPD-TSE coordination against bot networks to disabling political microtargeting tools during the election period to establishing algorithmic-impact-analysis labs — are aimed squarely at that enforcement gap, not at expanding speech restrictions.

Where Proportionality Still Wins

Even granting the gap is real, not every proposed fix is equally sound. "Disable microtargeting tools for political content during specified electoral periods" is the recommendation that should draw the most scrutiny — it would sweep up legitimate, low-harm uses (get-out-the-vote reminders, issue-specific outreach to registered supporters) along with the deceptive kind, and a blanket shutoff is a blunt instrument compared to enforcing the consent rule that already exists. Likewise, "algorithmic impact analysis labs" risk becoming standing review bodies over ordinary campaign advertising rather than targeted audits of the specific bot-network and synthetic-voter abuses the coalition itself identifies as the real problem.

The more defensible asks are narrower: enforce LGPD Article 11's consent requirement against campaigns and data brokers who are already violating it, give ANPD's small enforcement staff a specific electoral mandate and coordination channel with TSE, and raise TSE's fines, which at R$5,000–R$30,000 are a rounding error against national campaign budgets and unlikely to deter a well-funded operation. Reporting since Resolution 23.755 took effect has flagged the same soft spots from a different angle: AI developers fall outside the platform-focused rules, and enforcement is largely silent on WhatsApp and Telegram — the two channels Brazilian campaigns actually use most, and where mass messaging already runs ahead of both the LGPD and TSE's ad-repository requirements.

The Institutional Problem Underneath

There's a structural reason this recommendation lands now rather than as legislation: ANPD's own December 2025 priority map for 2026–2027 lists four enforcement themes — data-subject rights, child protection online, public-sector data processing, and AI/emerging technology — with no elections-specific line item at all. An authority that hasn't scoped election data into its own priorities isn't positioned to police it under the existing timeline, however sound the LGPD's text is on paper. That's the gap worth closing before the October vote, and it's a gap in institutional capacity and coordination, not in the law's substance or in TSE's disclosure regime. Brazil doesn't need a new statute or a new ban; it needs ANPD funded and mandated to enforce the one it has, working alongside a TSE framework that, so far, has been proportionate by design.

Sources & Citations

  1. EFF: Privacy Protections Are Crucial to Electoral Integrity
  2. Rio Times: Brazil Election AI Rules Tightened for 2026 Vote
  3. Rio Times: Brazil Election AI Rules Ban Deepfakes, Leave Gaps
  4. ANPD: 2026-2027 Priority Enforcement Themes
  5. LGPD (Lei 13.709/2018) — Official Text