Skip to content
BR LGPD · BR-ECA-DIGITAL-AGE-EXPERIENCE-SIGNALS

BR LGPD Arts. 10, 13-15

Provide age-appropriate experiences and receive minimized age signals

CRITICALRequirementAge assuranceBinding regulationIn forceApplies from 17 March 2026

Where this comes from

Provision: Arts. 10, 13-15; Decree Arts. 24-27 - age experiences and signals

Instrument: ECA Digital (Lei nº 15.211/2025), Decreto nº 12.880/2026

Citation: Lei nº 15.211/2025, Arts. 10, 13-15; Decreto nº 12.880/2026, Arts. 22, 24, 25 §4, 26-27 and 54; Lei nº 15.352/2026, Art. 1

Text version: Lei nº 15.211/2025, texto compilado; Lei nº 15.352/2026 Art. 1; Decreto nº 12.880/2026, DOU extra 18 March 2026

Checked against the source: 6 September 2026

Read the official text ↗

Who it applies to

It applies when all of these are true:

  • Brazil ECA Digital assessed fact Q_BR_ECA_CHILD_ACCESS: YES

What engineering work it implies

Sample acceptance criteria Landfall generates for this obligation:

  • Assess the actual Brazil-available product/service directed to or likely accessed by children or adolescents. Statutory Article 10 requires age-appropriate experiences respecting progressive autonomy and Brazilian socioeconomic diversity; missing accounts, restricted offers or a current age-check feature does not decide that general duty.
  • Under statutory Article 14, adopt technical and organizational measures to receive Article 12 age information, and retain the provider's own mechanisms against access to content inappropriate for the relevant age group. App-store/operating-system measures and Chapter IV compliance do not remove the other agents' responsibilities under Article 15.
  • Reconcile Decree Article 26's receiving-signal scope for child-facing/likely-accessed suppliers of improper, inadequate or prohibited offers, its requirement to adapt the experience after receipt, and its browser-access age-assurance provision. Browser-access suppliers may use signals from operating systems, stores or other digital suppliers. Receipt does not relieve the supplier of effective age appropriateness and safeguards. Preserve the broader statute and qualified review of the statute/decree relationship.
  • Apply Decree Article 25 §4 where a supplier's age-assurance information conflicts with a store/operating-system signal: use the more protective alternative for the child/adolescent. An unresolved or missing signal is not proof of adulthood, parental authorization or lawful access. Age signals contain only what is strictly necessary to confirm the required minimum age; do not transmit exact dates of birth, civil identity or profiling data.
  • Article 22's age-assurance dispensation for the eligible editorial-control, previously licensed copyright-content (from a responsible economic agent distinct from an end user), and musical/literary provider classes requires both age-appropriate child accounts/profiles and parental supervision with blocking/restricted access, respecting progressive autonomy and applicable classification. The separate journalistic/sports route requires editorial control and content not subject to classification. Verify every relevant condition and residual duty; do not equate this dispensation with Article 39's different list of statutory provisions or infer it from a generic service label. Preserve age-appropriate experiences and residual duties; receipt of a signal or an existing gate does not establish every condition.

Evidence an auditor expects

  • Assessment documentDocument review

    Provide age-appropriate experiences and receive minimized age signals — scoped assessment evidence

    Assess the actual Brazil-available product/service directed to or likely accessed by children or adolescents. Statutory Article 10 requires age-appropriate experiences respecting progressive autonomy and Brazilian socioeconomic diversity; missing accounts, restricted offers or a current age-check feature does not decide that general duty. Under statutory Article 14, adopt technical and organizational measures to receive Article 12 age information, and retain the provider's own mechanisms against access to content inappropriate for the relevant age group. App-store/operating-system measures and Chapter IV compliance do not remove the other agents' responsibilities under Article 15. Reconcile Decree Article 26's receiving-signal scope for child-facing/likely-accessed suppliers of improper, inadequate or prohibited offers, its requirement to adapt the experience after receipt, and its browser-access age-assurance provision. Browser-access suppliers may use signals from operating systems, stores or other digital suppliers. Receipt does not relieve the supplier of effective age appropriateness and safeguards. Preserve the broader statute and qualified review of the statute/decree relationship. Apply Decree Article 25 §4 where a supplier's age-assurance information conflicts with a store/operating-system signal: use the more protective alternative for the child/adolescent. An unresolved or missing signal is not proof of adulthood, parental authorization or lawful access. Age signals contain only what is strictly necessary to confirm the required minimum age; do not transmit exact dates of birth, civil identity or profiling data. Article 22's age-assurance dispensation for the eligible editorial-control, previously licensed copyright-content (from a responsible economic agent distinct from an end user), and musical/literary provider classes requires both age-appropriate child accounts/profiles and parental supervision with blocking/restricted access, respecting progressive autonomy and applicable classification. The separate journalistic/sports route requires editorial control and content not subject to classification. Verify every relevant condition and residual duty; do not equate this dispensation with Article 39's different list of statutory provisions or infer it from a generic service label. Preserve age-appropriate experiences and residual duties; receipt of a signal or an existing gate does not establish every condition. Where age assurance is performed, apply Decree Article 24's risk proportionality, accuracy/robustness/reliability, data minimization, privacy/security, inclusion/non-discrimination, interoperability, transparency and auditability. Prohibit continuous, automated and unrestricted personal-data sharing and identity, access, request and verification-history traceability. For document-based checks, extract only necessary age or age-range information and immediately and irreversibly delete document images/copies and excess source information. Decree Article 24 also prohibits using age-assurance data for another purpose, including behavioral profiling. Under statutory Article 13, data collected to verify children's/adolescents' ages is limited to that purpose, including no behavioral profiling. Use synthetic users and sanitized signals to test the assessed scope, authorization failures, conflicting/absent signals, bypass and dispute paths. Keep necessary protocol/configuration/test/review records and unresolved gaps; exclude real child identities, exact birth dates, raw credentials/documents/biometrics, access histories and raw dispute evidence from ordinary task attachments, exports and general logs. These are engineering evidence-minimization safeguards, not a prescribed fixed log schema or retention period. Verify current ANPD criteria and qualified Portuguese review. Statutory Articles 10/13-15 commenced on 17 March 2026; the cited decree provisions commenced on 18 March 2026. This record does not approve a historical outcome, implement a universal age-verification method, or claim complete ECA Digital coverage.

Questions people ask

Does BR LGPD Arts. 10, 13-15 apply to my service?
It applies when Brazil ECA Digital assessed fact Q_BR_ECA_CHILD_ACCESS: YES.
From when does this apply?
BR LGPD Arts. 10, 13-15 applies from 17 March 2026. Its current status is: in force.
What evidence does an auditor expect?
Provide age-appropriate experiences and receive minimized age signals — scoped assessment evidence.

Find out whether this one lands on you

Landfall's pre-scan answers the applicability question above for your product in minutes, then turns every obligation that applies into traceable engineering tickets with a citation chain your auditors can follow.

Not legal advice. Landfall maps regulatory obligations to engineering work for planning purposes. Its verdicts are not legal advice and create no attorney-client relationship — verify with qualified counsel before relying on them.

What Landfall Is NOT

Critical Boundaries

Understanding these boundaries is essential before using this product. Misuse of this tool for purposes outside its scope may create legal, regulatory, or commercial risk for your organization.

NOT Legal Advice

This product does not provide legal advice and does not create an attorney-client relationship.

Interpretations are informational analysis, not legal counsel. Always consult qualified legal professionals for compliance decisions.

NOT a Risk Score

We do not quantify, calculate, or certify your compliance risk level.

No numerical risk rating, compliance percentage, or safety score. Risk assessment requires human judgment about your specific context.

NOT Runtime Enforcement

This is a planning and mapping tool, not a runtime enforcement system.

Does not integrate with your production systems. Does not block, filter, or enforce compliance in real-time. Implementation is your responsibility.

NOT Regulatory Approval

Using this tool does not mean you are compliant with any regulation.

No certification, seal of approval, or compliance guarantee. Regulators will evaluate your actual implementation, not your use of this tool.

NOT Authoritative Interpretation

Our interpretations are not binding and may differ from regulatory guidance.

Only regulators and courts provide authoritative interpretation. Our analysis reflects our reading of requirements, which may be incomplete or incorrect.

NOT a Safe Harbor

This tool does not shield you from enforcement actions or liability.

Documentation of your process is valuable, but does not constitute a legal defense. Compliance is ultimately your organization's responsibility.

NOT an AI Compliance Agent

AI features assist analysis but do not make compliance decisions for you.

AI-generated interpretations require human review and approval. Automated suggestions are starting points, not final answers.

NOT Complete Coverage

We do not cover all regulations, all obligations, or all jurisdictions.

Regulatory landscape is vast and evolving. Gaps in our coverage do not mean those requirements don't apply to you.

What This Tool IS:

  • A structured workflow for mapping regulatory requirements to implementation tasks
  • A documentation system for compliance decisions (audit trail)
  • A collaboration platform for compliance, legal, and engineering teams
  • An informational resource for understanding regulatory obligations