Our Expert in Brazil
No results available
Brazil’s Supreme Court is weighing whether police must, as a general matter, obtain prior judicial authorisation before they can identify an internet user by correlating account registration details with connection or application-access logs. In sessions during 2024–2025, the Supremo Tribunal Federal (STF) took up related matters, including ADC 51 and associated actions, that go to the heart of how criminal investigators may reach provider-held data. The core issue concerns the judicial-authorisation requirement anchored in article 10 of the Marco Civil da Internet (Law 12. 965/2014), together with the possibility of a tightly bounded exception for genuine emergencies.
For platforms, internet service providers, multinationals and the counsel who advise them, the practical line being drawn is significant: basic registration data may in many cases be requisitioned directly, but traffic and connection data generally require a court order.
The direction of travel is one that in-house teams handling Brazilian data demands should factor into their playbooks now, even where a final judgment is not yet published. The essential points:
Because the boundary of police access turns on data type and judicial oversight, organisations that receive Brazilian requests should recalibrate their response procedures now rather than wait for any final ruling.
The dispute sits at the intersection of two statutes and a constitutional guarantee. The Marco Civil da Internet establishes the ground rules for internet governance in Brazil, and its article 10 addresses the protection of records, personal data and private communications held by connection and application providers. The provision conditions the disclosure of connection and access records on a court order, precisely so that logs tying a person to online activity are not surrendered on request alone. Under the statute, the protection of connection records and access-to-application records must serve “a preservação da intimidade, da vida privada, da honra e da imagem”, that is, the preservation of intimacy, private life, honour and image.
Article 10, paragraph 1, provides that the provider is obliged to make such records available only through a judicial order.
The related constitutional actions seek to settle divergent lower-court practice on whether investigators could compel providers to correlate registration and log data without judicial oversight, and to test aspects of Law 12.830/2013, which governs the office and functions of the police delegate (delegado de polícia) and the delegate’s powers to conduct investigations and issue requisitions. The central question is where the boundary lies between the police authority to gather evidence administratively and the constitutional reserve of jurisdiction that protects certain categories of data. The STF’s task is to reconcile efficient criminal investigation with the privacy and due-process guarantees embedded in the Constitution and the Marco Civil.
The rationale for prior judicial authorisation turns on the specific act that Marco Civil article 10 is designed to control: the correlation exercise that transforms otherwise separate pieces of information into an identification. Holding a subscriber’s name is one thing; matching that subscriber to a specific IP address at a specific timestamp, and thereby placing a real person behind a particular online action, is the sensitive step that engages the protection of private life. On that logic, police generally cannot compel providers to perform or disclose that correlation without a judge’s authorisation.
Argument before the court has also addressed whether this operates as an absolute barrier in every conceivable scenario. A narrow, documented exception has been canvassed, grounded in the general justifications recognised by the Penal Code (Decreto-Lei nº 2. 848/1940), notably the defence of another (legítima defesa de terceiro) and the state of necessity (estado de necessidade). Any such exception would be confined to extreme, time-critical circumstances where waiting for a warrant would defeat the purpose of the intervention. The examples typically cited are a kidnapping in progress, an attack on hospital infrastructure, and ongoing child sexual exploitation.
In those situations, an investigator might act without prior authorisation but would have to document the emergency justification and submit the action to a judge for review after the fact.
Temporal effect (modulation) is also relevant. To avoid destabilising investigations already under way, the STF can attach prospective effects to a ruling, preserving the validity of requests made up to a defined point such as publication of the judgment. In other words, a new discipline would apply going forward, while earlier requests would be assessed under the framework existing at the time they were made. This modulation matters greatly for any company that has already responded to, or is currently contesting, a Brazilian requisition.
Because a deliberation may be suspended before the full court concludes, counsel should treat any account of interim votes as provisional. The distinction between a suspended deliberation and a finished judgment is not academic: theses can shift when the court resumes, and the operative language of any binding thesis is fixed only once the judgment is concluded and its minutes are published.
The single most important operational takeaway is that not all provider-held data carries the same protection. The Marco Civil, read alongside Law 12.830/2013 and the constitutional protection of communications, establishes a gradient. At the least-protected end sits basic registration data, the account details a subscriber supplies when opening an account. In the middle sits connection and traffic data, the logs that map online activity to sessions, IP addresses and timestamps. At the most-protected end sits content, the substance of communications, message bodies and uploaded files, which enjoys reinforced constitutional protection.
Basic registration data, a subscriber’s name, email address, billing address or telephone number, can in many cases be requisitioned directly through administrative channels, subject to the specific statutory basis invoked and the provider’s contractual terms. The reason is that these details, standing alone, identify an account holder without revealing the pattern of their online conduct. That said, the Lei Geral de Proteção de Dados (LGPD, Law 13.709/2018) still governs how this personal data is processed and disclosed, so providers must ensure any transfer rests on a lawful basis and is properly recorded.
Connection and traffic data are treated differently precisely because they expose behaviour. IP allocation records, session timestamps and access logs are what allow an investigator to establish who did what and when. Under Marco Civil article 10, paragraph 1, these records generally require prior judicial authorisation before they can be handed over, save for any narrow urgency exception the court may recognise. Law 12.830/2013 controls the procedural conduct of the police delegate but does not override the judicial reserve for this protected category.
Content sits at the top of the protective hierarchy. The interception or disclosure of the substance of communications engages constitutional protection (Constitution, article 5, item XII) and demands a specific court order, with the additional safeguards that criminal-procedure rules and the Interception Law (Law 9.296/1996) impose. No urgency shortcut of the kind sometimes proposed for identification data displaces those requirements.
The international dimension is instructive here. The Council of Europe’s Convention on Cybercrime, the Budapest Convention (CETS No. 185), to which Brazil has acceded, establishes cooperation frameworks and encourages harmonised domestic offences and procedures. It does not, however, oblige states to permit direct police requisitions of protected data outside a judicial framework. International cooperation instruments set out how states assist one another; they leave each state to legislate the domestic powers and safeguards that govern access. The Convention therefore reinforces, rather than dilutes, the domestic judicial reserve that the Marco Civil embodies.
| Data type | Definition / common examples | Can police requisition directly? | Legal basis / notes |
|---|---|---|---|
| Basic registration data | Subscriber name, email, billing address, phone number, registration form fields | Generally yes (administrative requisition may be permissible), but check the specific statute and contractual terms | Marco Civil (art. 10) distinguishes basic registration; LGPD applies to the processing |
| Traffic / connection data | IP addresses, timestamps, logs tying activity to connection sessions, access logs | Generally no, requires prior judicial authorisation, subject to any narrow urgency exception | Marco Civil art. 10(1); Law 12.830/2013 controls police procedure |
| Content (communications content) | Message bodies, uploaded files, email contents | Requires a specific court order and enjoys stronger protection | Constitution art. 5(XII); Law 9.296/1996; penal-procedure rules; LGPD considerations |
Any exception of this kind is deliberately confined, and organisations should resist reading it broadly. It would apply only where an immediate threat to life or physical integrity makes the delay of a warrant self-defeating. The paradigm cases are a kidnapping unfolding in real time, an attack on hospital infrastructure that endangers patients, and ongoing child sexual exploitation where every hour of delay perpetuates harm. These are situations in which the Penal Code’s general justifications, defence of another and necessity, could supply the legal grounding for acting without prior authorisation.
Such an exception is procedural as much as substantive. To rely on it, the investigating authority would need to document the emergency justification contemporaneously and submit the action to a judge for review after the fact. Post-fact judicial control is the safeguard that prevents an exception from swallowing the rule: a judge later assesses whether the urgency genuinely existed and whether the intrusion was proportionate. For providers, this means that a request framed as urgent should still be scrutinised. A well-run compliance function will ask whether the request identifies the emergency, whether the requesting authority commits to subsequent judicial submission, and whether the data sought is proportionate to the threat described.
Where a request labelled “urgent” seeks broad traffic data unconnected to an imminent threat, the label alone does not dispense with the ordinary judicial-authorisation requirement.
Constitutional challenges have tested the reach of the police delegate’s powers under Law 12.830/2013, which recognises the delegate as the authority who directs the police inquiry (inquérito policial) and issues requisitions in the course of an investigation. A balanced approach preserves most of the statute while insisting that the judicial reserve remain intact for protected information. The practical effect is a division of labour: the delegate retains broad authority to conduct and steer investigations and to gather evidence that is not subject to the reserve, but cannot use requisition powers to compel the disclosure of data that the Constitution and the Marco Civil place behind a judicial gate.
This produces a real tension that counsel must navigate. Investigators understandably favour speed and administrative flexibility, while the constitutional design channels access to sensitive data through the judiciary. The resolution is not to strip the delegate of authority but to map that authority onto the correct category of data. Requisitions for basic subscriber details generally stand; requisitions that would compel a provider to correlate registration and log data, or to hand over traffic records, run into the judicial reserve unless a recognised urgency exception applies.
For foreign platforms and multinationals, the operational challenge is to respond lawfully and consistently while protecting users and the business. The following sequence reflects the discipline the applicable framework implies.
Sample response language should be measured. For a traffic-data request lacking a court order, a provider might state that it preserves the identified records and will produce them upon receipt of a valid judicial order, in accordance with Marco Civil article 10, unless a documented urgency justification within a recognised exception is supplied. For a request that is unclear about the data category, a provider should ask the authority to specify the exact records sought and the legal basis invoked before producing anything. These are compliance steps, not obstruction: they ensure disclosures rest on the correct legal footing.
Because Brazilian law generally requires judicial authorisation for the identification of a user, foreign providers cannot safely treat a Brazilian administrative requisition as equivalent to a court order. The identification of a user, the correlation step at the centre of the litigation, is precisely what typically requires a judge. Cross-border teams should build this distinction into their triage: a Brazilian authority’s direct request may reach subscriber details, but the correlation that unmasks a user behind an IP address is reserved to judicial process. Where the requesting authority is outside Brazil and seeks Brazilian user data, the MLAT route or a Brazilian court order is generally the appropriate mechanism.
The LGPD does not switch off when a criminal investigation begins. Although the LGPD does not itself apply to processing carried out for exclusively public-security or criminal-investigation purposes by public authorities, private controllers that hold personal data remain subject to the law’s principles, purpose limitation, necessity, transparency and accountability, even when responding to lawful demands. A controller may process and disclose personal data to comply with a legal or regulatory obligation and to give effect to a valid judicial order, but it must be able to identify and document the lawful basis for each disclosure. That documentation discipline is exactly what a later judicial review of an urgency claim, or an ANPD enquiry, may test.
The Autoridade Nacional de Proteção de Dados (ANPD) oversees compliance with the LGPD and issues guidance relevant to how controllers handle requests, including those from public authorities. Controllers should align their internal procedures with ANPD guidance, distinguish between compelled production under a valid order and voluntary cooperation with law enforcement, and treat the two differently. Voluntary disclosure of protected data outside a judicial framework carries heightened risk and should generally be avoided where a court order is required.
Where a deliberation remains suspended, the matter is not concluded. Industry observers expect the court to resume and the remaining justices to vote, at which point a binding thesis will be fixed and the minutes published. The likely practical effect, if the judicial-authorisation position prevails, will be a consolidated rule requiring judicial authorisation for user identification and traffic data, potentially with a documented urgency exception subject to post-fact review, and prospective effects that preserve earlier requests up to a defined point. Organisations should establish a monitoring routine for the STF’s publication of the relevant case pages and minutes, and update internal policies as soon as the final theses are known.
The framework is organised around a clear principle: user identification and traffic data belong behind a judicial gate, basic registration data is more readily accessible, and only genuine, documented emergencies may justify acting first and answering to a judge afterwards. Until the STF concludes any pending deliberation, treat the framework as a developing but well-signalled standard and prepare accordingly. The top ten immediate actions:
This article was produced by Global Law Experts. For specialist advice on this topic, contact André Fortes at Carvalho & Furtado Advogados, a member of the Global Law Experts network.
posted 10 minutes ago
posted 26 minutes ago
posted 43 minutes ago
posted 48 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
No results available
Find the right Legal Expert for your business
Send welcome message