World Watch/Brazil/Cybersecurity

Cybersecurity · Brazil

Cybersecurity - Brazil

Sectoral rulesNo single comprehensive horizontal cybersecurity statute in force. Obligations arise from a patchwork: the National Cybersecurity Policy (PNCiber, Decree No. 11.856/2023) and the E-Ciber strategy set government-wide guidelines; sector-specific binding rules apply to finance (CMN/BCB Resolution No. 4.893/2021) and personal data (LGPD + ANPD Resolution No. 15/2024 breach rules). A comprehensive Cybersecurity Legal Framework (Bill No. 4752/2025) creating a National Cybersecurity Authority (ANCiber) is pending in Congress.

Brazil regulates cybersecurity through a combination of an executive-branch national policy (PNCiber, Decree 11.856/2023) and sector-specific obligations rather than one comprehensive law. Binding incident- and breach-reporting duties exist for personal data (LGPD/ANPD) and for financial and payment institutions (BCB), while a comprehensive NIS2-inspired bill creating a national cybersecurity authority is under consideration as of 2026.

National Cybersecurity Policy (PNCiber)

Decree No. 11.856 of 26 December 2023 established the National Cybersecurity Policy and the National Cybersecurity Committee (CNCiber), setting principles and objectives (critical-infrastructure protection, resilience, R&D) for the federal government; it is a policy framework, not a statute imposing direct obligations on the private sector.

Personal-data breach notification (LGPD/ANPD)

ANPD Resolution CD/ANPD No. 15 of 24 April 2024 implements LGPD Art. 48: controllers must notify the ANPD and affected data subjects of incidents posing relevant risk within three business days of confirming personal data was affected, with supplementary information allowed within 20 business days and a five-year incident register required.

Financial-sector cybersecurity rules (BCB)

CMN Resolution No. 4.893 of 26 February 2021 requires financial and payment institutions to adopt a cybersecurity policy, maintain action and incident-response plans, and report relevant incidents to the Central Bank; in force since 1 July 2021, it consolidated the earlier 2018/2019 rules.

Proposed comprehensive law and national authority

Bill No. 4752/2025, introduced in the Senate in 2025, would create Brazil's first comprehensive Cybersecurity Legal Framework and a National Cybersecurity Authority (ANCiber), inspired by the EU NIS2 directive, with public-procurement compliance requirements and shared supply-chain incident responsibility; it remains pending as of 2026.

National Cybersecurity Strategy (E-Ciber)

The GSI/Presidency-led E-Ciber strategy operationalizes PNCiber; an updated text was advanced through CNCiber and issued in 2025, setting a regulatory agenda and guidance for digital service providers and the technology market.

Cross-cutting / no single horizontal law

Brazil has no general mandatory cybersecurity law applicable to all sectors; obligations are layered across the LGPD (data protection), sectoral regulators (BCB for finance, with telecom/Anatel and others), and the public-sector PNCiber/E-Ciber framework, which is why the regime is best characterized as sectoral pending the proposed comprehensive law.

Machine-assisted translation · verified 5/23/2026 · orientation, not legal advice. English version →