Cybersecurity · Brazil
Cybersecurity law & regulation in Brazil (2026)
Brazil shaded by its cybersecurity status
Cybersecurity in Brazil: sectoral rules.
FrameworkPatchwork of sectoral rules (BCB/CMN for finance, ANATEL for telecoms) plus LGPD Law No. 13.709/2018 with ANPD Resolution CD/ANPD No. 15/2024 on security incidents, coordinated under the National Cybersecurity Policy â PNCiber (Decree No. 11.856/2023) and the National Cybersecurity Strategy â E-Ciber (Decree No. 12.573/2025). A comprehensive Cybersecurity Legal Framework (Senate Bill PL 4.752/2025) is pending.
Brazil does not yet have a single comprehensive, NIS2-style cybersecurity law. Instead it relies on a governance framework set by presidential decree (PNCiber 2023 and the updated E-Ciber Strategy of August 2025), combined with sector-specific cybersecurity rules for banking (BCB Resolution 538/2025 and CMN Resolution 5.274/2025) and telecoms (ANATEL Resolutions 740/2020 and 780/2025), plus the LGPD's personal-data breach-notification duties enforced by the ANPD. A dedicated Cybersecurity Legal Framework bill (PL 4.752/2025) that would create a National Cybersecurity Authority was introduced in the Senate in September 2025 but has not been enacted.
Key points
The National Cybersecurity Policy (PNCiber) was created by Decree No. 11.856 of 26 December 2023, establishing the National Cybersecurity Committee (CNCiber) and setting principles/objectives â but it is an executive-branch instrument, not an omnibus cybersecurity law with binding obligations on private operators.
Decree No. 12.573 of 4 August 2025 launched the updated E-Ciber strategy, structured around citizen protection, resilience of critical infrastructure, public-private cooperation and national sovereignty, with ~40 strategic actions to be detailed in a forthcoming National Cybersecurity Plan (P-Ciber).
Bill PL 4.752/2025, introduced in the Federal Senate on 24 September 2025, would create a Legal Framework for Cybersecurity and a National Cybersecurity Authority empowered to set standards, audit and publish compliance lists; as of 2026 it remains under legislative review and is not in force.
CMN Resolution No. 5.274/2025 and BCB Resolution No. 538/2025 (published 18 December 2025, compliance by 1 March 2026) strengthen cybersecurity and cloud-services rules for institutions regulated by the Central Bank of Brazil, updating the earlier CMN Resolution 4.893/2021 and covering the National Financial System and the Brazilian Payment System (including PIX).
ANATEL Resolution No. 740/2020 sets cybersecurity obligations for all providers of telecommunications services of collective interest, and Resolution No. 780/2025 extends robust cybersecurity requirements to data centres integrated with telecommunications networks.
Under the LGPD (Law 13.709/2018) and ANPD Resolution CD/ANPD No. 15 of 24 April 2024, controllers must notify the ANPD and affected data subjects of security incidents involving personal data that create relevant risk within 3 business days (6 for small agents), submitted through the ANPD's online platform, with incident records kept for at least 5 years.
Timeline - major decisions & events
CMN Resolution No. 5,274/2025 and BCB Resolution No. 538/2025 updated cybersecurity policy and cloud/data-processing contracting requirements for BCB-regulated institutions, modernizing the 2018 framework. It raises baseline security and outsourcing obligations across Brazil's financial sector.
Baker McKenzie / Global Compliance News âBrazil enacted a new National Cybersecurity Strategy (E-Ciber) with roughly 40 strategic actions, replacing the 2020 strategy and implementing the PNCiber. It defines timelines and governance to be detailed in a forthcoming National Cybersecurity Plan (P-Ciber).
Mattos Filho âThe STF ruled Article 19 of the Marco Civil da Internet partially unconstitutional, allowing platforms to be held civilly liable for certain unlawful content (hate speech, terrorism, child sexual abuse material, serious disinformation) without a prior court order. It imposes a stricter duty of care on online platforms.
Global Network Initiative âThe data protection authority operationalized LGPD Article 48, requiring controllers to notify ANPD and affected individuals within three business days when a breach poses relevant risk or harm, and to keep breach records for five years. It clarified long-uncertain incident-reporting duties.
DataGuidance / ANPD âThe decree created Brazil's overarching National Cybersecurity Policy with seven principles and eleven objectives, plus the National Cybersecurity Committee (CNCiber) to steer implementation. It set the foundational governance framework guiding the country's later cyber strategy.
PresidĂȘncia da RepĂșblica (Planalto) âAn exposed database revealed personal data of more than 220 million Brazilians and tens of millions of companies, including CPF numbers, addresses, income and credit scores, the largest leak in the country's history. It intensified pressure for stronger data-security enforcement and incident regulation.
Cybernews âCoordinated by the Institutional Security Cabinet (GSI), Brazil's first National Cybersecurity Strategy set federal cyber-defense priorities and made federal agencies responsible for implementing its actions. It marked the first structured national approach to cybersecurity governance.
PresidĂȘncia da RepĂșblica (Planalto) âBrazil's omnibus data-protection law imposed security, breach-notification and accountability duties on public and private data processors and created the basis for the ANPD. It anchors most data-security obligations applicable in Brazil today.
PresidĂȘncia da RepĂșblica (Planalto) âThe National Monetary Council issued Brazil's first binding sector cybersecurity rules, mandating cyber-security policies, incident response and strict cloud/outsourcing requirements for Central Bank-regulated institutions. It became the template for Brazil's financial-sector cyber regulation.
Banco Central do Brasil âThe 'Internet Bill of Rights' set principles for internet use including privacy, data protection, net neutrality and data-retention/security duties for connection and application providers. It established core obligations for handling and safeguarding user data online.
PresidĂȘncia da RepĂșblica (Planalto) âPrompted by the leak of a celebrity's private photos, this law amended the Penal Code to criminalize unauthorized access to computer devices and related cyber offenses. It was Brazil's first dedicated cybercrime statute, laying the criminal-law foundation for cybersecurity.
PresidĂȘncia da RepĂșblica (Planalto) âBrazil - other topics
Cybersecurity in other countries
Last verified 8/15/2026 · Orientation, not legal advice - verify against the primary sources linked above. Methodology & how to cite · State of Technology Regulation 2026 · Explore the full world map â