[codicts-css-switcher id=”346″]

Global Law Experts Logo
brazils supreme court

Brazil's Supreme Court Considers Whether Police Need Judicial Authorisation for Identifying Internet Users, Narrow Urgency Exception Debated

By Global Law Experts
– posted 2 hours ago

Brazil’s Supreme Court is weighing whether police must, as a general matter, obtain prior judicial authorisation before they can identify an internet user by correlating account registration details with connection or application-access logs. In sessions during 2024–2025, the Supremo Tribunal Federal (STF) took up related matters, including ADC 51 and associated actions, that go to the heart of how criminal investigators may reach provider-held data. The core issue concerns the judicial-authorisation requirement anchored in article 10 of the Marco Civil da Internet (Law 12. 965/2014), together with the possibility of a tightly bounded exception for genuine emergencies.

For platforms, internet service providers, multinationals and the counsel who advise them, the practical line being drawn is significant: basic registration data may in many cases be requisitioned directly, but traffic and connection data generally require a court order.

Executive Summary, What Is at Stake and Why It Matters

The direction of travel is one that in-house teams handling Brazilian data demands should factor into their playbooks now, even where a final judgment is not yet published. The essential points:

  • General rule. Identifying a user by matching registration information with connection or app-access records generally requires prior judicial authorisation, consistent with Marco Civil article 10.
  • Possible narrow urgency exception. Legal argument before the court has canvassed a documented, exceptional route for extreme situations, a kidnapping in progress, an attack on hospital infrastructure, or ongoing child sexual exploitation, subject to later judicial review.
  • Data distinction. Basic registration data and traffic/connection data are treated differently; only the former may generally be obtained through direct administrative requisition.
  • Procedural status. Any theses discussed remain provisional until the full court concludes and the minutes are published.
  • Who should read this. Platform legal teams, ISPs, cloud and messaging providers, multinationals with Brazilian operations, and cross-border counsel responding to Brazilian requisitions and letters rogatory.

Because the boundary of police access turns on data type and judicial oversight, organisations that receive Brazilian requests should recalibrate their response procedures now rather than wait for any final ruling.

Background, The Statutes and Constitutional Guarantees at Issue

The dispute sits at the intersection of two statutes and a constitutional guarantee. The Marco Civil da Internet establishes the ground rules for internet governance in Brazil, and its article 10 addresses the protection of records, personal data and private communications held by connection and application providers. The provision conditions the disclosure of connection and access records on a court order, precisely so that logs tying a person to online activity are not surrendered on request alone. Under the statute, the protection of connection records and access-to-application records must serve “a preservação da intimidade, da vida privada, da honra e da imagem”, that is, the preservation of intimacy, private life, honour and image.

Article 10, paragraph 1, provides that the provider is obliged to make such records available only through a judicial order.

The related constitutional actions seek to settle divergent lower-court practice on whether investigators could compel providers to correlate registration and log data without judicial oversight, and to test aspects of Law 12.830/2013, which governs the office and functions of the police delegate (delegado de polícia) and the delegate’s powers to conduct investigations and issue requisitions. The central question is where the boundary lies between the police authority to gather evidence administratively and the constitutional reserve of jurisdiction that protects certain categories of data. The STF’s task is to reconcile efficient criminal investigation with the privacy and due-process guarantees embedded in the Constitution and the Marco Civil.

What the Judicial-Authorisation Requirement Involves

The rationale for prior judicial authorisation turns on the specific act that Marco Civil article 10 is designed to control: the correlation exercise that transforms otherwise separate pieces of information into an identification. Holding a subscriber’s name is one thing; matching that subscriber to a specific IP address at a specific timestamp, and thereby placing a real person behind a particular online action, is the sensitive step that engages the protection of private life. On that logic, police generally cannot compel providers to perform or disclose that correlation without a judge’s authorisation.

Argument before the court has also addressed whether this operates as an absolute barrier in every conceivable scenario. A narrow, documented exception has been canvassed, grounded in the general justifications recognised by the Penal Code (Decreto-Lei nº 2. 848/1940), notably the defence of another (legítima defesa de terceiro) and the state of necessity (estado de necessidade). Any such exception would be confined to extreme, time-critical circumstances where waiting for a warrant would defeat the purpose of the intervention. The examples typically cited are a kidnapping in progress, an attack on hospital infrastructure, and ongoing child sexual exploitation.

In those situations, an investigator might act without prior authorisation but would have to document the emergency justification and submit the action to a judge for review after the fact.

Temporal effect (modulation) is also relevant. To avoid destabilising investigations already under way, the STF can attach prospective effects to a ruling, preserving the validity of requests made up to a defined point such as publication of the judgment. In other words, a new discipline would apply going forward, while earlier requests would be assessed under the framework existing at the time they were made. This modulation matters greatly for any company that has already responded to, or is currently contesting, a Brazilian requisition.

Because a deliberation may be suspended before the full court concludes, counsel should treat any account of interim votes as provisional. The distinction between a suspended deliberation and a finished judgment is not academic: theses can shift when the court resumes, and the operative language of any binding thesis is fixed only once the judgment is concluded and its minutes are published.

Legal Analysis, Distinguishing Data Types and the Authorisation Required

The single most important operational takeaway is that not all provider-held data carries the same protection. The Marco Civil, read alongside Law 12.830/2013 and the constitutional protection of communications, establishes a gradient. At the least-protected end sits basic registration data, the account details a subscriber supplies when opening an account. In the middle sits connection and traffic data, the logs that map online activity to sessions, IP addresses and timestamps. At the most-protected end sits content, the substance of communications, message bodies and uploaded files, which enjoys reinforced constitutional protection.

Basic registration data, a subscriber’s name, email address, billing address or telephone number, can in many cases be requisitioned directly through administrative channels, subject to the specific statutory basis invoked and the provider’s contractual terms. The reason is that these details, standing alone, identify an account holder without revealing the pattern of their online conduct. That said, the Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) still governs how this personal data is processed and disclosed, so providers must ensure any transfer rests on a lawful basis and is properly recorded.

Connection and traffic data are treated differently precisely because they expose behaviour. IP allocation records, session timestamps and access logs are what allow an investigator to establish who did what and when. Under Marco Civil article 10, paragraph 1, these records generally require prior judicial authorisation before they can be handed over, save for any narrow urgency exception the court may recognise. Law 12.830/2013 controls the procedural conduct of the police delegate but does not override the judicial reserve for this protected category.

Content sits at the top of the protective hierarchy. The interception or disclosure of the substance of communications engages constitutional protection (Constitution, article 5, item XII) and demands a specific court order, with the additional safeguards that criminal-procedure rules and the Interception Law (Law 9.296/1996) impose. No urgency shortcut of the kind sometimes proposed for identification data displaces those requirements.

The international dimension is instructive here. The Council of Europe’s Convention on Cybercrime, the Budapest Convention (CETS No. 185), to which Brazil has acceded, establishes cooperation frameworks and encourages harmonised domestic offences and procedures. It does not, however, oblige states to permit direct police requisitions of protected data outside a judicial framework. International cooperation instruments set out how states assist one another; they leave each state to legislate the domestic powers and safeguards that govern access. The Convention therefore reinforces, rather than dilutes, the domestic judicial reserve that the Marco Civil embodies.

Comparison Table, Basic Registration vs Connection/Traffic vs Content

Data type Definition / common examples Can police requisition directly? Legal basis / notes
Basic registration data Subscriber name, email, billing address, phone number, registration form fields Generally yes (administrative requisition may be permissible), but check the specific statute and contractual terms Marco Civil (art. 10) distinguishes basic registration; LGPD applies to the processing
Traffic / connection data IP addresses, timestamps, logs tying activity to connection sessions, access logs Generally no, requires prior judicial authorisation, subject to any narrow urgency exception Marco Civil art. 10(1); Law 12.830/2013 controls police procedure
Content (communications content) Message bodies, uploaded files, email contents Requires a specific court order and enjoys stronger protection Constitution art. 5(XII); Law 9.296/1996; penal-procedure rules; LGPD considerations

A Narrow Urgency Exception, Scope, Documentation and Post-Fact Review

Any exception of this kind is deliberately confined, and organisations should resist reading it broadly. It would apply only where an immediate threat to life or physical integrity makes the delay of a warrant self-defeating. The paradigm cases are a kidnapping unfolding in real time, an attack on hospital infrastructure that endangers patients, and ongoing child sexual exploitation where every hour of delay perpetuates harm. These are situations in which the Penal Code’s general justifications, defence of another and necessity, could supply the legal grounding for acting without prior authorisation.

Such an exception is procedural as much as substantive. To rely on it, the investigating authority would need to document the emergency justification contemporaneously and submit the action to a judge for review after the fact. Post-fact judicial control is the safeguard that prevents an exception from swallowing the rule: a judge later assesses whether the urgency genuinely existed and whether the intrusion was proportionate. For providers, this means that a request framed as urgent should still be scrutinised. A well-run compliance function will ask whether the request identifies the emergency, whether the requesting authority commits to subsequent judicial submission, and whether the data sought is proportionate to the threat described.

Where a request labelled “urgent” seeks broad traffic data unconnected to an imminent threat, the label alone does not dispense with the ordinary judicial-authorisation requirement.

Interaction with Law 12.830/2013 and Police Delegate Powers

Constitutional challenges have tested the reach of the police delegate’s powers under Law 12.830/2013, which recognises the delegate as the authority who directs the police inquiry (inquérito policial) and issues requisitions in the course of an investigation. A balanced approach preserves most of the statute while insisting that the judicial reserve remain intact for protected information. The practical effect is a division of labour: the delegate retains broad authority to conduct and steer investigations and to gather evidence that is not subject to the reserve, but cannot use requisition powers to compel the disclosure of data that the Constitution and the Marco Civil place behind a judicial gate.

This produces a real tension that counsel must navigate. Investigators understandably favour speed and administrative flexibility, while the constitutional design channels access to sensitive data through the judiciary. The resolution is not to strip the delegate of authority but to map that authority onto the correct category of data. Requisitions for basic subscriber details generally stand; requisitions that would compel a provider to correlate registration and log data, or to hand over traffic records, run into the judicial reserve unless a recognised urgency exception applies.

Practical Guidance for Platforms and Cross-Border Counsel

For foreign platforms and multinationals, the operational challenge is to respond lawfully and consistently while protecting users and the business. The following sequence reflects the discipline the applicable framework implies.

  • Preserve first. On receipt of any Brazilian data demand, preserve the requested data immediately to prevent spoliation, regardless of whether you will ultimately produce it. Preservation is not production and can be undertaken while the legal basis is assessed.
  • Classify the data sought. Determine whether the request seeks basic registration data, traffic/connection data, or content. This classification drives everything that follows and should be documented.
  • Check the legal basis. For basic registration data, confirm the statutory authority cited and that the request is properly issued. For traffic/connection data, require a judicial order, unless a genuine, documented urgency justification is presented and recognised in law.
  • Scrutinise urgency claims. Where a request invokes emergency access, verify that it describes an imminent threat to life or physical integrity and commits to subsequent judicial review. Do not accept the “urgent” label as a substitute for the substance.
  • Escalate to counsel. Route requests for protected data to legal, and engage local Brazilian counsel where the demand is contested, ambiguous, or seeks correlation of registration and log data.
  • Use cross-border channels appropriately. For compelled production across borders, consider mutual legal assistance treaty (MLAT) and diplomatic channels, and assess whether a letter rogatory or a domestic court order is the correct instrument.
  • Log everything. Maintain a complete record of the request, the classification, the legal basis assessed, decisions taken, and the individuals involved. This record supports both LGPD accountability and later judicial review.
  • Consider notification. Assess whether and when user notification is permissible; many orders restrict notice, so notification must be weighed against legal obligations and any confidentiality directive.

Sample response language should be measured. For a traffic-data request lacking a court order, a provider might state that it preserves the identified records and will produce them upon receipt of a valid judicial order, in accordance with Marco Civil article 10, unless a documented urgency justification within a recognised exception is supplied. For a request that is unclear about the data category, a provider should ask the authority to specify the exact records sought and the legal basis invoked before producing anything. These are compliance steps, not obstruction: they ensure disclosures rest on the correct legal footing.

Judicial Authorisation for User Identification in Cross-Border Practice

Because Brazilian law generally requires judicial authorisation for the identification of a user, foreign providers cannot safely treat a Brazilian administrative requisition as equivalent to a court order. The identification of a user, the correlation step at the centre of the litigation, is precisely what typically requires a judge. Cross-border teams should build this distinction into their triage: a Brazilian authority’s direct request may reach subscriber details, but the correlation that unmasks a user behind an IP address is reserved to judicial process. Where the requesting authority is outside Brazil and seeks Brazilian user data, the MLAT route or a Brazilian court order is generally the appropriate mechanism.

Data-Protection and Compliance Implications (LGPD and ANPD)

The LGPD does not switch off when a criminal investigation begins. Although the LGPD does not itself apply to processing carried out for exclusively public-security or criminal-investigation purposes by public authorities, private controllers that hold personal data remain subject to the law’s principles, purpose limitation, necessity, transparency and accountability, even when responding to lawful demands. A controller may process and disclose personal data to comply with a legal or regulatory obligation and to give effect to a valid judicial order, but it must be able to identify and document the lawful basis for each disclosure. That documentation discipline is exactly what a later judicial review of an urgency claim, or an ANPD enquiry, may test.

The Autoridade Nacional de Proteção de Dados (ANPD) oversees compliance with the LGPD and issues guidance relevant to how controllers handle requests, including those from public authorities. Controllers should align their internal procedures with ANPD guidance, distinguish between compelled production under a valid order and voluntary cooperation with law enforcement, and treat the two differently. Voluntary disclosure of protected data outside a judicial framework carries heightened risk and should generally be avoided where a court order is required.

Looking Ahead, Next Steps and Monitoring

Where a deliberation remains suspended, the matter is not concluded. Industry observers expect the court to resume and the remaining justices to vote, at which point a binding thesis will be fixed and the minutes published. The likely practical effect, if the judicial-authorisation position prevails, will be a consolidated rule requiring judicial authorisation for user identification and traffic data, potentially with a documented urgency exception subject to post-fact review, and prospective effects that preserve earlier requests up to a defined point. Organisations should establish a monitoring routine for the STF’s publication of the relevant case pages and minutes, and update internal policies as soon as the final theses are known.

Conclusion and Recommended Immediate Actions

The framework is organised around a clear principle: user identification and traffic data belong behind a judicial gate, basic registration data is more readily accessible, and only genuine, documented emergencies may justify acting first and answering to a judge afterwards. Until the STF concludes any pending deliberation, treat the framework as a developing but well-signalled standard and prepare accordingly. The top ten immediate actions:

  1. Preserve requested data on receipt of any Brazilian demand.
  2. Classify every request by data type before deciding whether to produce.
  3. Require a court order for traffic and connection data.
  4. Produce basic registration data only where the statutory basis is confirmed.
  5. Scrutinise urgency claims against narrow exception criteria.
  6. Document each disclosure and its lawful basis under the LGPD.
  7. Escalate contested or ambiguous requests to legal and local counsel.
  8. Use MLAT and judicial channels for cross-border compelled production.
  9. Review notification practices against confidentiality directives.
  10. Update terms, data-processing agreements and law-enforcement response playbooks to reflect the applicable framework.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact André Fortes at Carvalho & Furtado Advogados, a member of the Global Law Experts network.

Sources

  1. Presidência da República, Lei nº 12.965/2014 (Marco Civil da Internet)
  2. Presidência da República, Lei nº 12.830/2013
  3. Presidência da República, Lei nº 13.709/2018 (LGPD)
  4. Presidência da República, Lei nº 9.296/1996 (Interceptação de Comunicações)
  5. Supremo Tribunal Federal (STF)
  6. Código Penal, Decreto-Lei nº 2.848/1940
  7. Council of Europe, Convention on Cybercrime (Budapest Convention), CETS No. 185
  8. Autoridade Nacional de Proteção de Dados (ANPD)
  9. Ordem dos Advogados do Brasil (OAB)

FAQs

Do Brazilian police need a court order to identify an internet user?
As a rule, yes. Identifying a user by correlating registration data with connection or application-access records generally requires prior judicial authorisation under Marco Civil article 10. Where the STF is still deliberating a related matter, any specific thesis remains provisional pending the full court’s conclusion.
Possibly. Legal argument has canvassed a narrow, documented exception for extreme urgency, such as a kidnapping in progress, an attack on hospital infrastructure, or ongoing child sexual exploitation, grounded in the Penal Code justifications of defence of another and necessity, provided the act is documented and later submitted to judicial review. The precise scope of any such exception depends on the final ruling.
Basic registration data are provider-held account details such as name and email. Traffic and connection data are logs tying activity to IP addresses and session timestamps. The former may in many cases be requisitioned directly; the latter generally requires a court order under the Marco Civil.
Preserve the requested data promptly, verify whether the demand seeks basic registration or traffic/connection data, require a court order for traffic data, engage legal counsel, and document all steps. Consider MLAT or diplomatic channels for cross-border compelled production.
The Budapest Convention establishes cooperation frameworks but leaves each state to legislate its own domestic powers and safeguards. It does not by itself expand direct requisition powers beyond domestic law, so it reinforces rather than displaces Brazil’s judicial reserve.
For private controllers, the LGPD continues to apply. Controllers must comply with lawful orders while ensuring processing aligns with LGPD principles and documenting the lawful basis for each disclosure. ANPD guidance should be followed, and voluntary disclosure of protected data outside a judicial framework should generally be avoided.
The STF can attach prospective effects to a ruling, preserving the validity of requests made up to a defined point such as publication of the judgment. Treat earlier requests on a case-by-case basis and seek counsel; any interim position remains provisional pending the final judgment.
Notify the legal team, the data protection officer, security and forensics, senior management, and local counsel, following your incident-response and data-request playbook.
Amit Mishra Joins as Exclusive Commercial Litigation Member in India | GLE News
By Global Law Experts

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Brazil's Supreme Court Considers Whether Police Need Judicial Authorisation for Identifying Internet Users, Narrow Urgency Exception Debated

Send welcome message

Custom Message