While most of the industry spent the first half of 2026 watching London and Brussels, the most consequential new age-assurance regime of the year came into force in Brasília. On 17 March 2026, the grace period ended for Law No. 15,211/2025 — Brazil’s Estatuto Digital da Criança e do Adolescente, universally shortened to the Digital ECA — and Latin America’s largest economy became the first country in the region with a comprehensive, enforceable digital child-safety statute. It is not a proposal, not a consultation, and not a distant deadline. It is live law, backed by decrees, guidelines, and a data-protection regulator that had already been quietly monitoring the market for six months before the law switched on.
For anyone running an online product, the uncomfortable part is the reach. The Digital ECA does not apply only to Brazilian companies, and it does not apply only to services aimed at children. It applies to any provider whose product is likely to be accessed by a minor in Brazil — a test with a deliberately low bar — regardless of where that company is headquartered. If you serve users in a market of more than 150 million people online and you have not mapped your exposure, the clock that matters is not a foreign one. It runs to November 2026, when administrative sanctions begin.
This is the playbook: what the law actually is, why its scope is broader than the UK’s, what the enforcement calendar demands and when, what “reliable age assurance” has been defined to mean, and how to build for it without quietly assembling the surveillance database the same law is designed to prevent.
What the Digital ECA actually is
The Digital ECA did not appear from nowhere. It is the newest layer on a stack Brazil has been building for thirty-five years. The foundation is the original 1990 Estatuto da Criança e do Adolescente, the landmark federal statute that enshrined the principle of absolute priority for the rights of minors — a constitutional-grade commitment that children’s interests come first. On top of that sits the LGPD (Lei nº 13.709/2018), Brazil’s general data-protection law, which was heavily modelled on the GDPR and already imposes strict conditions on processing minors’ data. Lei 15.211/2025 is the specific regulatory layer that lands on both, translating “absolute priority” into concrete engineering obligations for the digital environment.
That lineage matters, because it tells you how the law will be read. The Digital ECA was sanctioned on 17 September 2025 and entered into force on 17 March 2026. The day after it took effect, the federal government published three decrees in an extra edition of the Official Gazette. The most important, Decree No. 12,880/2026, is the primary regulatory instrument — it details providers’ obligations across prevention, protection, age assessment, prohibited content, parental supervision, and advertising. A second decree reconstituted the ANPD (Autoridade Nacional de Proteção de Dados) as an autonomous regulatory agency, and a third created a national screening centre, linked to the Federal Police, to route reports of criminal content involving minors.
Brazil did not invent this framework in isolation. The ANPD’s own technical work draws explicitly on the UK’s Online Safety Act, the findings of the Australia Age Assurance Technology Trial, Ofcom’s “highly effective” methods, and ISO 27566, the emerging international standard for age-assurance systems. If you have already done the work for the UK’s Ofcom regime or Australia’s under-16 rules, you are not starting from zero. But you are also not finished, because Brazil made several choices the others did not.
The scope trap: “provável de ser acessado”
The first choice is scope, and it is where most compliance analyses go wrong. The trigger for the Digital ECA is not “is your service aimed at children?” It is provável de ser acessado — likely to be accessed by minors. Decree 12,880 frames it as a three-part condition: there is a sufficient probability the product is attractive to minors, minors can access it with relative ease, and the product presents a significant risk to a minor’s privacy, safety, or biopsychosocial development.
Read that as an operator and the reach becomes obvious. It sweeps in the expected categories — social networks, messaging apps, streaming platforms, electronic games — but it does not stop there. Marketplaces, payment institutions, virtual advertising platforms, and health and wellness apps have all been named as in-scope, along with any other website or application a minor could plausibly reach. A useful field test is to ask the questions the ANPD’s framing implies: does your service offer free downloads, is it reachable from a standard app store or browser, does it have social features like chat or comments, does its design plausibly appeal to adolescents, can a user sign up without a credit card? A “yes” to any one of them is enough to put the Digital ECA on your desk.
This is a materially wider net than the UK’s Online Safety Act, which is anchored to services and content primarily concerning adults. Brazil inverted the default: the obligation attaches wherever a child could reasonably turn up, not only where a service invites them. And it is expressly extraterritorial. The law binds domestic and foreign providers alike whenever their products are made available in Brazil, and it goes one step further than most regimes by requiring foreign companies to appoint a legal representative inside Brazil to receive service of process and answer to the authorities. There is no serving the market from a distance while treating the statute as someone else’s problem.
One more definition to get right: the Digital ECA distinguishes children (under 12) from adolescents (12 to 18), and several obligations — guardian linkage in particular — turn on the 16-year line rather than the 18-year one. Building a single global “over 18 / under 18” gate and assuming it satisfies Brazil is a mistake the drafting will punish.
The enforcement clock
The reason this is a July problem and not a January one is the ANPD’s phased calendar. The regulator did not wait for the law to take effect to start looking; since the second half of 2025 it has been monitoring 37 companies identified as having direct, continuous influence over minors in Brazil. Enforcement then rolls out in stages:
- March 2026 — Stage 1. Monitoring begins immediately, focused on app stores and proprietary operating systems. The ANPD treats these as structural gatekeepers, capable of embedding age signals and parental supervision at the device level, and starting there produces the broadest systemic effect fastest.
- August 2026 — final guidelines and Stage 2. After public consultation, the ANPD publishes definitive guidance and expands monitoring to other sectors, prioritised by the risk level of each product or service.
- August–November 2026 — transition period. A formal window to let technical solutions mature before the updated inspection and sanctions rules are fully applied.
- November 2026 — administrative sanctions begin.
- January 2027 — formal compliance-verification enforcement.
That structure is why the window is closing now, not later. The definitive guidelines land in August; the transition runs only to November; and the population expands from “app stores and operating systems” to “everyone, by risk” in the same stretch. A platform that waits for the January 2027 enforcement date to start building will have missed two prior checkpoints and the entire grace window.
The penalties give the calendar teeth. Non-compliance can draw warnings, fines of up to 10% of the economic group’s revenue in Brazil for the preceding fiscal year or up to R$50 million (roughly US$9 million) per infraction, temporary suspension of activities, and outright prohibition from operating in Brazilian territory. The ANPD has signalled a responsive posture for the transition — regulatory dialogue and compliance incentives before heavy sanctions — but that is a reason to demonstrate good-faith progress now, not a reason to wait. As Mayer Brown’s analysis notes, ECA Digital compliance is already becoming a line item in M&A due diligence and valuation; the exposure is reputational and commercial well before the first fine lands.
What “reliable age assurance” has been defined to mean
The centre of gravity of the whole framework is one sentence: mere self-declaration is expressly prohibited. The “I am over 18” checkbox that carried the industry for two decades is not a control under the Digital ECA — the same conclusion the UK reached when the ICO fined Reddit and made clear self-declaration is not enough. Brazil codified it from the start.
On 20 March 2026 the ANPD published Preliminary Guidelines on Reliable Age Assessment Mechanisms, and they read like a specification. Six principles govern any acceptable mechanism: proportionality (a risk-based approach that balances measurement accuracy against users’ rights), accuracy, robustness and reliability (fraud-resistant methods verifiable under real conditions, with self-declaration insufficient as a standalone), privacy and data protection (data minimisation, no secondary use, traceability, restricted sharing), inclusion and non-discrimination (accounting for Brazil’s socioeconomic diversity and preventing biased outcomes), transparency and auditability (clear explanations, dispute channels, audit records), and interoperability (standardised protocols and secure APIs that transmit only the strictly necessary age attribute).
The guidelines also draw a distinction the decree leaves for the ANPD to finish — between age assessment (aferição de idade) and age verification (verificação etária) — and organise acceptable techniques into three families. Age estimation infers a probable age from behavioural or biometric characteristics such as face or voice; its accuracy, and its documented error near the threshold, determine where it can responsibly be used. Age verification confirms age against an authoritative source — a government-issued document, or authentication through a secure platform such as Brazil’s national Gov.br digital identity. Age inference deduces age indirectly from context and is used to complement, not replace, the other two.
There is a trap buried in the gatekeeper design that operators must not walk into. Yes, the law requires app stores and operating systems to expose age signals via API — an over_18 = true attribute a downstream service can read. But the ANPD is explicit that the platform itself remains the party primarily responsible for keeping minors out of restricted features. An OS-level signal is an input, not an absolution. This is the same lesson that surfaced when state and device mandates were mistaken for verification: consuming a device signal you did not generate and cannot audit does not discharge a duty the statute places squarely on you.
The obligations that trip people up
Beyond age assurance itself, the Digital ECA carries a set of adjacent obligations that are easy to under-scope:
- Guardian linkage for under-16s. Accounts belonging to users 16 and under must be linked to a legal guardian’s account — which means building verifiable parental consent that proves not just the parent’s identity but the relationship to the child. This is the hardest requirement in the law to implement well, and the one most likely to be built badly under deadline pressure.
- Loot boxes. Decree 12,880 targets games with loot boxes directly, prohibiting them in titles that primarily target or are likely to be accessed by minors, and otherwise requiring a version without them — a sharper line than most of the gaming and loot-box regimes elsewhere.
- No behavioural advertising to minors. Profiling minors for advertising (publicidade comportamental para menores) is prohibited, which forces a hard answer to an upstream question: do you actually know which of your users are minors, and is your ad stack built to exclude them?
- Privacy by default and no dark patterns. The most protective privacy settings must be the default, and manipulative design that encourages compulsive use is banned — the same addictive-design concern the EU is folding into its forthcoming Digital Fairness Act.
- Impact assessments and transparency reports. Providers must run impact assessments covering minors’ rights, including where they use emotional analysis or augmented, extended, and virtual reality. Providers with more than one million minor users in Brazil owe biannual transparency reports — which in practice means audit trails that record when a user proved their age, by what method, and against what circumvention risk.
- Child influencers. Monetising content built around a child now requires prior judicial authorisation — a provision aimed at the creator economy that few global playbooks anticipate.
The privacy paradox — and how not to build a honeypot
Here is the tension at the heart of every age-assurance mandate, and Brazil states it more sharply than most: the law demands that you verify age, and the same law — sitting on top of the LGPD — demands that you minimise data, refuse secondary use, and transmit only the age attribute itself. The interoperability principle is explicit that a compliant mechanism passes the result (“over 18”) to the relying party without disclosing the underlying date of birth or document. Verify hard; retain almost nothing.
That is not a contradiction to be managed. It is a design brief, and it is precisely the architecture we argue for. The failure mode the Digital ECA is built to prevent is the one that has already produced a wave of age-verification data breaches: a platform, told to check IDs, quietly assembles a database of scanned passports and selfies, and turns a compliance requirement into a liability that a regulator, a plaintiff, and an attacker can all reach. The way through is age verification without surveillance — verify the fact, discard the evidence, and hand downstream systems a signed attestation rather than raw identity. Techniques like zero-knowledge proofs and reusable, verify-once credentials are not privacy luxuries under this regime; they are the most direct route to satisfying the interoperability and data-minimisation principles as written.
The operator playbook
Concretely, before the transition window closes:
- Run the probable-access test per surface, not per company. Score each product and feature against the three-part test and the field questions above. Scope is not binary at the org level; a marketing site and a chat-enabled game carry different obligations.
- Decide when to check, using proportionality. The ANPD endorses matching assurance to risk, so you do not have to gate every action. Verify at signup where the whole service is restricted; verify at the feature boundary — unlocking chat, a loot-box-free requirement, adult content — where only part of it is. Checking everyone for everything is both non-compliant with proportionality and a conversion disaster.
- Adopt a risk-based waterfall rather than a single method. Route returning users to a reusable credential, the broad middle to estimation, and anyone near the threshold or on a hard-restricted surface to document or Gov.br verification. Orchestrating layered methods is how you hit the accuracy-and-robustness bar for the cases that matter while keeping friction and cost off the ones that do not.
- Solve guardian linkage early. Under-16 consent is the requirement most likely to slip. Build the parent–child relationship dataset and the verifiable-consent flow now, not in October.
- Instrument audit trails from day one. Transparency-report readiness is not a reporting-season task. Record method, timestamp, and circumvention assessment for every decision so you can later prove the platform took sufficient measures.
- Treat OS age signals as an input, never a shield. Consume them where useful, but keep your own defensible control — you remain the primary responsible party.
- Localise for inclusion. Non-discrimination is a named principle. Account for Brazil’s document landscape and socioeconomic diversity, and offer an accessible fallback path rather than a dead end for users an estimator or a document check serves poorly.
- Appoint your Brazilian legal representative. If you are a foreign provider, this is a statutory prerequisite, not a formality to defer.
Why Brazil matters beyond Brazil
It is tempting to file the Digital ECA as one more entry in the global compliance patchwork. The more useful reading is that the patchwork is converging. The UK’s Online Safety Act, Australia’s under-16 regime, the EU’s DSA and coming age-verification blueprint, and now Brazil’s Digital ECA all reach the same destination from different starting points: self-declaration is dead, the required assurance is effective and auditable, the data handling must be privacy-preserving, and ISO 27566 is emerging as the common vocabulary that ties them together. Brazil is the first mover in Latin America, and where Brazil sets the template, the region tends to follow.
That convergence is the opportunity hiding inside the obligation. A platform that builds one privacy-first orchestration layer — verifying age against strong methods, retaining only a signed attestation, reusing credentials across surfaces, and matching assurance to risk — is not solving Brazil, then the UK, then Australia as separate projects. It is building the control that each of them, in its own language, now requires. The Digital ECA simply moved the deadline closer, and drew the specification in unusually clear ink.
If you serve users in Brazil and want to know exactly which of your surfaces the Digital ECA touches and how to close the gap before the ANPD’s sanctions window opens, that is the conversation to have now.
This article is for general information and does not constitute legal advice. Compliance obligations under the Digital ECA, Decree 12,880/2026, and the LGPD depend on your specific products, data flows, and user base; consult qualified Brazilian counsel for your situation.