The World Cup is not the only event to look out for in Brazil this year. Brazil has been developing two significant pieces of privacy legislation since the late 2000s, and it looks like they may be voted on soon. The Marco Civil da Internet (“Civil Internet Bill”) would establish what some have called an “Internet Bill of Rights” that includes data protection requirements and the preservation of net neutrality. The Data Protection Bill would establish a comprehensive, European-style data protection framework governing the processing of all personal data. The proposed laws would replace Brazil’s current sector-specific privacy framework. Brazil is the fifth largest country in the world, and the number of Brazilian Internet and smartphone users is growing rapidly. The new laws would therefore have a significant impact on organizations offering digital products or services to Brazilian consumers. We here provide background on the proposed laws and insights as to their potential impacts.

In 1988, Brazil was at the forefront of Latin American privacy law when the country implemented habeas data rights in its federal constitution. Habeas data provides individuals with the right to file a judicial complaint requesting access to, correction of, or deletion of the data that organizations are holding about them. Several Latin American countries soon followed Brazil in providing these constitutional rights. Brazil’s desire to attract international business, especially from the European Union, may well have been one of the reasons that the country for years has been debating whether to follow the eight Latin American countries that have passed comprehensive data protection laws or regulations modeled on the European Union’s framework and replace Brazil’s sector-specific framework with the Data Protection Bill and the Civil Internet Bill.  

Legislative inertia and the lack of uniform support for the bills have prevented the initiatives from being passed in recent years. However, recent NSA surveillance revelations have reignited the push for data protection reform. Dilma Rousseff, Brazil’s President, has been a vocal critic of U.S. surveillance practices and was actively pressing for data protection reform in the last few months of 2013.  

Brazil’s Civil Internet Bill would do more than just establish online privacy protections. The draft legislation effectively establishes an Internet Bill of Rights for Brazilians. These rights include privacy protections along with a fundamental right to access the Internet and a mandate for net neutrality. The law also regulates the enforcement of digital copyright issues and the online collection of evidence in criminal and civil investigations. In recent months, President Rousseff and members of the Worker’s Party have added new provisions to the Civil Internet Bill. The most controversial of these is a data localization rule, which would give Brazil’s executive branch the right to force operators of online services to store Brazilian data only in Brazilian data centers. Other amendments to the Civil Internet Bill include requiring service providers to obtain express consent from users prior to processing personal data online and providing that companies violating the Bill would be subject to suspension of Brazilian data collection activities or fines of up to 10% of the organizational revenues.

Critics have argued that the Civil Internet Bill, especially with its localization requirements, would raise operating costs significantly for companies doing business in Brazil. Several industry groups have noted that the localization requirements would undermine the decentralized nature of the Internet, which has facilitated the growth of global digital trade.  

Brazil’s Data Protection Bill is modeled primarily on the European Data Protection Directive and would regulate the online and offline processing of personal data. The bill would give Brazilians the rights to access, correct, and delete personal data and require that organizations generally obtain express, informed consent prior to processing a Brazilian’s personal data. The Data Protection Bill would create a data protection authority, the National Data Protection Council. In the event of a data breach, companies would be required to notify the Council and sometimes the media. Like the EU data protection framework, the Data Protection bill would generally prohibit organizations from transferring personal data to countries not providing adequate protections for personal data. Although the Data Protection Bill does not specify which countries do provide adequate protections, it is likely that the Data Protection Council would not deem the United States to be one of those countries. Organizations violating the Data Protection Bill would face penalties of up to 20% of organizational revenue.

If one or both of these bills are passed into law, companies with Brazilian operations would likely have to implement significant changes to their privacy and security practices. Data localization requirements and cross-border transfer restrictions would have a substantial effect on business operations with questionable privacy and security benefits. For example, cyberattacks can occur no matter where data is stored.

In spite of the arguments being raised against the bills, however, the desire to establish Brazil as a leading player in the Global Multistakeholder Meeting on the Future of Internet Governance to be held in São Paulo on April 23-24 may well prompt the Brazilian legislature to pass one or both laws in the next few months. Some reports indicate that the Civil Internet Bill will be voted on in February. A vote on the Data Protection Bill is likely to happen soon after. We will be watching the developments closely and evaluating how the changes may effect Brazilian companies as well as Latin American and global trade.


If you want to comment on this post, you need to login.


Board of Directors

See the esteemed group of leaders shaping the future of the IAPP.

Contact Us

Need someone to talk to? We’re here for you.

IAPP Staff

Looking for someone specific? Visit the staff directory.

Learn more about the IAPP»

Daily Dashboard

The day’s top stories from around the world

Privacy Perspectives

Where the real conversations in privacy happen

The Privacy Advisor

Original reporting and feature articles on the latest privacy developments

Privacy Tracker

Alerts and legal analysis of legislative trends

Privacy Tech

Exploring the technology of privacy

Canada Dashboard Digest

A roundup of the top Canadian privacy news

Europe Data Protection Digest

A roundup of the top European data protection news

Asia-Pacific Dashboard Digest

A roundup of the top privacy news from the Asia-Pacific region

Latin America Dashboard Digest

A roundup of the top privacy news from Latin America

IAPP Westin Research Center

Original works. Groundbreaking research. Emerging scholars.

Get more News »

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

IAPP Job Board

Looking for a new challenge, or need to hire your next privacy pro? The IAPP Job Board is the answer.

Join the Privacy List

Have ideas? Need advice? Subscribe to the Privacy List. It’s crowdsourcing, with an exceptional crowd.

Find a KnowledgeNet Chapter Near You

Talk privacy and network with local members at IAPP KnowledgeNet Chapter meetings, taking place worldwide.

Find more ways to Connect »

Find a Privacy Training Class

Two-day privacy training classes are held around the world. See the complete schedule now.

The Privacy Core™ Library Has Evolved

Privacy Core™ e-learning essentials just expanded to include seven new units for marketers. Keep your data safe and your staff in the know!

Online Privacy Training

Build your knowledge. The privacy know-how you need is just a click away.

Upcoming Web Conferences

See our list of upcoming web conferences. Just log on, listen in and learn!

Train Your Team

Get your team up to speed on privacy by bringing IAPP training to your organization.

Let’s Get You DPO Ready

There’s no better time to train than right now! We have all the resources you need to meet the challenges of the GDPR.

Learn more »

CIPP Certification

The global standard for the go-to person for privacy laws, regulations and frameworks

CIPM Certification

The first and only privacy certification for professionals who manage day-to-day operations

CIPT Certification

The industry benchmark for IT professionals worldwide to validate their knowledge of privacy requirements

FIP Designation

Recognizing the advanced knowledge and issue-spotting skills a privacy pro must attain in today’s complex world of data privacy.

Certify Your Staff

Find out how you can bring the world’s only globally recognized privacy certification to a group in your organization.


The IAPP’S CIPP/E and CIPM are the ANSI/ISO-accredited, industry-recognized combination for DPO readiness. Learn more today.

Learn more about IAPP certification »

Are You Ready for the GDPR?

Check out the IAPP's EU Data Protection Reform page for all the tools and resources you need.

IAPP-OneTrust PIA Platform

New U.S. Government Agency privacy impact assessments - free to IAPP members!

IAPP Communities

Meet locally with privacy pros, dive deep into specialized topics or connect over common interests. Find your Community in KnowledgeNet Chapters, Sections and Affinity Groups.

Privacy Vendor List

Find a privacy vendor to meet your needs with our filterable list of global service providers.

More Resources »

Europe Data Protection Intensive 2017

The Intensive is sold out! But cancellations do happen—so hurry and get on the wait list in case more seats become available.

Global Privacy Summit 2017

The world’s premier privacy conference returns with the sharpest minds, unparalleled programs and preeminent networking opportunities. Early Bird ends TODAY.

Canada Privacy Symposium 2017

The Symposium returns to Toronto this spring and registration has opened! Take advantage of Early Bird rates and join your fellow privacy pros for another stellar program.

The Privacy Bar Section Forum 2017

The Privacy Bar Section Forum returns to Washington, DC April 21, delivering renowned keynote speakers and a distinguished panel of legal and privacy experts.

Asia Privacy Forum 2017

The Forum returns to Singapore for exclusive networking and intensive education on data protection trends and challenges in the Asia Pacific region. Call for Speakers open!

Privacy. Security. Risk. 2017

This year, we're bringing P.S.R. to San Diego. The Call for Speakers is now open. Submit today and be a part of something big! Submission deadline: February 26.

Europe Data Protection Congress 2017

European policy debate, multi-level strategic thinking and thought-provoking discussion. The Call for Speakers is open until March 19.

Sponsor an Event

Increase visibility for your organization—check out sponsorship opportunities today.

More Conferences »

Become a Member

Start taking advantage of the many IAPP member benefits today

Corporate Members

See our list of high-profile corporate members—and find out why you should become one, too

Renew Your Membership

Don’t miss out for a minute—continue accessing your benefits

Join the IAPP»