BR LGPD Decree Arts. 2, 24, 27, 54
Minimize age-assurance data and provide a way to contest the assessed age
Where this comes from
Provision: Decree Arts. 2, 24, 27, 54; statutory Art. 13 - age-assurance privacy and contests
Instrument: ECA Digital (Lei nº 15.211/2025), Decreto nº 12.880/2026
Citation: Decreto nº 12.880/2026, Arts. 2(IV)-(V), 24, 27 and 54; Lei nº 15.211/2025, Art. 13; Lei nº 15.352/2026, Art. 1
Text version: Lei nº 15.211/2025, texto compilado; Lei nº 15.352/2026 Art. 1; Decreto nº 12.880/2026, DOU extra 18 March 2026
Checked against the source: 6 September 2026
Who it applies to
It applies when all of these are true:
- Brazil ECA Digital assessed fact Q_BR_ECA_BRAZIL_PROVIDER: YES
- Brazil ECA Digital assessed fact Q_BR_ECA_PERFORMS_AGE_ASSURANCE: YES
What engineering work it implies
Sample acceptance criteria Landfall generates for this obligation:
- Assess the Brazil-available supplier's actual age-assurance activity, including direct or delegated verification, estimation or inference under Decree Article 2(IV)-(V). A No for this activity only excludes this conditional safeguard record; it does not excuse an independently applicable duty to adopt age-appropriate experiences or reliable age checks.
- Where age assurance is performed, apply Decree Article 24's risk proportionality, accuracy/robustness/reliability, data minimization, privacy/security, inclusion/non-discrimination, interoperability, transparency and auditability. Prohibit continuous, automated and unrestricted personal-data sharing and identity, access, request and verification-history traceability. For document-based checks, extract only necessary age or age-range information and immediately and irreversibly delete document images/copies and excess source information. Decree Article 24 also prohibits using age-assurance data for another purpose, including behavioral profiling. Under statutory Article 13, data collected to verify children's/adolescents' ages is limited to that purpose, including no behavioral profiling.
- Under Decree Article 27, give users an adequate way to contest an assessed or verified age or age range. Keep the outcome usable and proportionate to the actual product and user needs. Do not invent a fixed numeric response period or require retaining document images as general audit evidence; app-store/operating-system reasoned-correction requirements in Article 25 §2 are separately assessed.
- Keep the age-assurance purpose distinct from commercial profiling and unrelated analytics. Specify minimum necessary attributes and access, challenge/correction handling, deletion and justified preservation before implementation. Auditability must not recreate a cross-service identity or access-history trail prohibited by Article 24.
- Use synthetic users and sanitized signals to test the assessed scope, authorization failures, conflicting/absent signals, bypass and dispute paths. Keep necessary protocol/configuration/test/review records and unresolved gaps; exclude real child identities, exact birth dates, raw credentials/documents/biometrics, access histories and raw dispute evidence from ordinary task attachments, exports and general logs. These are engineering evidence-minimization safeguards, not a prescribed fixed log schema or retention period.
Evidence an auditor expects
- Assessment documentDocument review
Minimize age-assurance data and provide a way to contest the assessed age — scoped assessment evidence
Assess the Brazil-available supplier's actual age-assurance activity, including direct or delegated verification, estimation or inference under Decree Article 2(IV)-(V). A No for this activity only excludes this conditional safeguard record; it does not excuse an independently applicable duty to adopt age-appropriate experiences or reliable age checks. Where age assurance is performed, apply Decree Article 24's risk proportionality, accuracy/robustness/reliability, data minimization, privacy/security, inclusion/non-discrimination, interoperability, transparency and auditability. Prohibit continuous, automated and unrestricted personal-data sharing and identity, access, request and verification-history traceability. For document-based checks, extract only necessary age or age-range information and immediately and irreversibly delete document images/copies and excess source information. Decree Article 24 also prohibits using age-assurance data for another purpose, including behavioral profiling. Under statutory Article 13, data collected to verify children's/adolescents' ages is limited to that purpose, including no behavioral profiling. Under Decree Article 27, give users an adequate way to contest an assessed or verified age or age range. Keep the outcome usable and proportionate to the actual product and user needs. Do not invent a fixed numeric response period or require retaining document images as general audit evidence; app-store/operating-system reasoned-correction requirements in Article 25 §2 are separately assessed. Keep the age-assurance purpose distinct from commercial profiling and unrelated analytics. Specify minimum necessary attributes and access, challenge/correction handling, deletion and justified preservation before implementation. Auditability must not recreate a cross-service identity or access-history trail prohibited by Article 24. Use synthetic users and sanitized signals to test the assessed scope, authorization failures, conflicting/absent signals, bypass and dispute paths. Keep necessary protocol/configuration/test/review records and unresolved gaps; exclude real child identities, exact birth dates, raw credentials/documents/biometrics, access histories and raw dispute evidence from ordinary task attachments, exports and general logs. These are engineering evidence-minimization safeguards, not a prescribed fixed log schema or retention period. Verify current ANPD criteria and qualified Portuguese review. This decree-specific record commenced on 18 March 2026 under Article 54; statutory Article 13's under-18 purpose restriction already commenced on 17 March 2026. No generic consent, store API or self-declaration establishes all requirements. Separate Article 9/sector restrictions, app-store duties and historical dates remain assessable.
Questions people ask
- Does BR LGPD Decree Arts. 2, 24, 27, 54 apply to my service?
- It applies when Brazil ECA Digital assessed fact Q_BR_ECA_BRAZIL_PROVIDER: YES; Brazil ECA Digital assessed fact Q_BR_ECA_PERFORMS_AGE_ASSURANCE: YES.
- From when does this apply?
- BR LGPD Decree Arts. 2, 24, 27, 54 applies from 18 March 2026. Its current status is: in force.
- What evidence does an auditor expect?
- Minimize age-assurance data and provide a way to contest the assessed age — scoped assessment evidence.
Find out whether this one lands on you
Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.
Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.