Skip to content
BR LGPD · BR-ECA-DIGITAL-AGE-ASSURANCE-PRIVACY

BR LGPD Decree Arts. 2, 24, 27, 54

Minimize age-assurance data and provide a way to contest the assessed age

CRITICALRequirementAge assuranceBinding regulationIn forceApplies from 18 March 2026

Where this comes from

Provision: Decree Arts. 2, 24, 27, 54; statutory Art. 13 - age-assurance privacy and contests

Instrument: ECA Digital (Lei nº 15.211/2025), Decreto nº 12.880/2026

Citation: Decreto nº 12.880/2026, Arts. 2(IV)-(V), 24, 27 and 54; Lei nº 15.211/2025, Art. 13; Lei nº 15.352/2026, Art. 1

Text version: Lei nº 15.211/2025, texto compilado; Lei nº 15.352/2026 Art. 1; Decreto nº 12.880/2026, DOU extra 18 March 2026

Checked against the source: 6 September 2026

Read the official text ↗

Who it applies to

It applies when all of these are true:

  • Brazil ECA Digital assessed fact Q_BR_ECA_BRAZIL_PROVIDER: YES
  • Brazil ECA Digital assessed fact Q_BR_ECA_PERFORMS_AGE_ASSURANCE: YES

What engineering work it implies

Sample acceptance criteria Landfall generates for this obligation:

  • Assess the Brazil-available supplier's actual age-assurance activity, including direct or delegated verification, estimation or inference under Decree Article 2(IV)-(V). A No for this activity only excludes this conditional safeguard record; it does not excuse an independently applicable duty to adopt age-appropriate experiences or reliable age checks.
  • Where age assurance is performed, apply Decree Article 24's risk proportionality, accuracy/robustness/reliability, data minimization, privacy/security, inclusion/non-discrimination, interoperability, transparency and auditability. Prohibit continuous, automated and unrestricted personal-data sharing and identity, access, request and verification-history traceability. For document-based checks, extract only necessary age or age-range information and immediately and irreversibly delete document images/copies and excess source information. Decree Article 24 also prohibits using age-assurance data for another purpose, including behavioral profiling. Under statutory Article 13, data collected to verify children's/adolescents' ages is limited to that purpose, including no behavioral profiling.
  • Under Decree Article 27, give users an adequate way to contest an assessed or verified age or age range. Keep the outcome usable and proportionate to the actual product and user needs. Do not invent a fixed numeric response period or require retaining document images as general audit evidence; app-store/operating-system reasoned-correction requirements in Article 25 §2 are separately assessed.
  • Keep the age-assurance purpose distinct from commercial profiling and unrelated analytics. Specify minimum necessary attributes and access, challenge/correction handling, deletion and justified preservation before implementation. Auditability must not recreate a cross-service identity or access-history trail prohibited by Article 24.
  • Use synthetic users and sanitized signals to test the assessed scope, authorization failures, conflicting/absent signals, bypass and dispute paths. Keep necessary protocol/configuration/test/review records and unresolved gaps; exclude real child identities, exact birth dates, raw credentials/documents/biometrics, access histories and raw dispute evidence from ordinary task attachments, exports and general logs. These are engineering evidence-minimization safeguards, not a prescribed fixed log schema or retention period.

Evidence an auditor expects

  • Assessment documentDocument review

    Minimize age-assurance data and provide a way to contest the assessed age — scoped assessment evidence

    Assess the Brazil-available supplier's actual age-assurance activity, including direct or delegated verification, estimation or inference under Decree Article 2(IV)-(V). A No for this activity only excludes this conditional safeguard record; it does not excuse an independently applicable duty to adopt age-appropriate experiences or reliable age checks. Where age assurance is performed, apply Decree Article 24's risk proportionality, accuracy/robustness/reliability, data minimization, privacy/security, inclusion/non-discrimination, interoperability, transparency and auditability. Prohibit continuous, automated and unrestricted personal-data sharing and identity, access, request and verification-history traceability. For document-based checks, extract only necessary age or age-range information and immediately and irreversibly delete document images/copies and excess source information. Decree Article 24 also prohibits using age-assurance data for another purpose, including behavioral profiling. Under statutory Article 13, data collected to verify children's/adolescents' ages is limited to that purpose, including no behavioral profiling. Under Decree Article 27, give users an adequate way to contest an assessed or verified age or age range. Keep the outcome usable and proportionate to the actual product and user needs. Do not invent a fixed numeric response period or require retaining document images as general audit evidence; app-store/operating-system reasoned-correction requirements in Article 25 §2 are separately assessed. Keep the age-assurance purpose distinct from commercial profiling and unrelated analytics. Specify minimum necessary attributes and access, challenge/correction handling, deletion and justified preservation before implementation. Auditability must not recreate a cross-service identity or access-history trail prohibited by Article 24. Use synthetic users and sanitized signals to test the assessed scope, authorization failures, conflicting/absent signals, bypass and dispute paths. Keep necessary protocol/configuration/test/review records and unresolved gaps; exclude real child identities, exact birth dates, raw credentials/documents/biometrics, access histories and raw dispute evidence from ordinary task attachments, exports and general logs. These are engineering evidence-minimization safeguards, not a prescribed fixed log schema or retention period. Verify current ANPD criteria and qualified Portuguese review. This decree-specific record commenced on 18 March 2026 under Article 54; statutory Article 13's under-18 purpose restriction already commenced on 17 March 2026. No generic consent, store API or self-declaration establishes all requirements. Separate Article 9/sector restrictions, app-store duties and historical dates remain assessable.

Questions people ask

Does BR LGPD Decree Arts. 2, 24, 27, 54 apply to my service?
It applies when Brazil ECA Digital assessed fact Q_BR_ECA_BRAZIL_PROVIDER: YES; Brazil ECA Digital assessed fact Q_BR_ECA_PERFORMS_AGE_ASSURANCE: YES.
From when does this apply?
BR LGPD Decree Arts. 2, 24, 27, 54 applies from 18 March 2026. Its current status is: in force.
What evidence does an auditor expect?
Minimize age-assurance data and provide a way to contest the assessed age — scoped assessment evidence.

Find out whether this one lands on you

Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.

Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations