{"id":109,"date":"2026-08-14T14:46:20","date_gmt":"2026-08-14T14:46:20","guid":{"rendered":"https:\/\/pcreps.com.br\/blog\/?p=109"},"modified":"2026-08-14T14:46:20","modified_gmt":"2026-08-14T14:46:20","slug":"eca-digital-transparency-reports-in-brazil-what-foreign-platforms-need-to-prepare-for-the-17-september-2026-deadline","status":"publish","type":"post","link":"https:\/\/pcreps.com.br\/blog\/eca-digital-transparency-reports-in-brazil-what-foreign-platforms-need-to-prepare-for-the-17-september-2026-deadline\/","title":{"rendered":"ECA Digital Transparency Reports in Brazil: What Foreign Platforms Need to Prepare for the 17 September 2026 Deadline"},"content":{"rendered":"\n<p>For international companies operating digital products in Brazil, regulatory exposure rarely begins with a single form or isolated deadline. It often begins with a more difficult question: can the local operation demonstrate, in Portuguese and with reliable evidence, how its global policies actually protect people in Brazil? That question is becoming particularly relevant for platforms used by children and adolescents.<\/p>\n\n\n\n<p>On 11 August 2026, the Brazilian National Data Protection Authority, or ANPD, published a decision clarifying the first transparency report required under the Digital Statute of the Child and Adolescent, known as the ECA Digital. The first report must be published by 17 September 2026 by certain providers of internet applications directed at, or likely to be accessed by, children and adolescents. The announcement is important for foreign platforms with Brazilian users because it turns a broad statutory obligation into an immediate governance and documentation exercise.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What the ANPD clarified about the first report<\/h2>\n\n\n\n<p>The obligation comes from article 31 of Law No. 15,211\/2025, the ECA Digital. It covers providers of internet applications directed at children and adolescents or likely to be accessed by them that have more than one million registered users in this age group with an internet connection in Brazil. The law requires the report to be prepared in Portuguese and published on the provider\u2019s website.<\/p>\n\n\n\n<p>The ANPD\u2019s Decision CD\/ANPD No. 122\/2026 clarified that the first report must be published by 17 September 2026. As a general rule, it covers the period from 1 January through 30 June 2026. If a provider does not have systematised information for January and February, the initial report may exceptionally cover the period from 17 March through 30 June 2026, because the relevant obligations entered into force on 17 March 2026.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"362\" src=\"https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_1_eca_digital_report_timeline_en-1024x362.png\" alt=\"\" class=\"wp-image-113\" srcset=\"https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_1_eca_digital_report_timeline_en-1024x362.png 1024w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_1_eca_digital_report_timeline_en-300x106.png 300w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_1_eca_digital_report_timeline_en-768x271.png 768w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_1_eca_digital_report_timeline_en-1536x543.png 1536w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_1_eca_digital_report_timeline_en.png 1800w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Who should assess whether the obligation applies?<\/h2>\n\n\n\n<p>The scope analysis is more nuanced than simply asking whether a company has users under 18. The provider must consider the nature of its application, whether it is directed at or likely to be accessed by children and adolescents, the number of registered users in that age group connected from Brazil, and the way the service operates. Article 39 of the ECA Digital also provides that several obligations are applied according to the product\u2019s characteristics and functionality, the provider\u2019s degree of control over content, the number of users and the provider\u2019s size.<\/p>\n\n\n\n<p>The law contains conditional treatment for services with editorial control and certain previously licensed content providers, provided that statutory conditions are met. These provisions should not be treated as a blanket exemption. A foreign group should document the reasoning supporting its classification and obtain case-specific legal or regulatory advice where the answer is uncertain. The ANPD\u2019s own ECA Digital information page makes clear that the agency is responsible for regulating and supervising the law, alongside the broader implementation framework created by the relevant decrees.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What the report must demonstrate<\/h2>\n\n\n\n<p>The report is not merely a statement that policies exist. The law and the ANPD decision require a document that explains the channels available for complaints and the systems and processes used to investigate them; the volume of complaints received; the amount of content or account moderation by type; measures used to identify child accounts on social networks and unlawful acts; technical improvements for children\u2019s data privacy and protection; technical improvements used to assess parental consent; and the methods and results of impact assessments, risk identification and risk management relating to children\u2019s safety and health.<\/p>\n\n\n\n<p>The implementing Decree No. 12,880\/2026 adds that the report must present the number of notifications received by category and proportional data on what happened to those notifications. The decree also states that providers must perform an impact assessment for children\u2019s safety and health, including risk analysis, probability and severity assessment, treatment and mitigation measures, and continuous monitoring of the effectiveness of those measures. A summarised version should be made public in clear and accessible language.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"408\" src=\"https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_2_eca_digital_evidence_areas_en-1024x408.png\" alt=\"\" class=\"wp-image-112\" srcset=\"https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_2_eca_digital_evidence_areas_en-1024x408.png 1024w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_2_eca_digital_evidence_areas_en-300x120.png 300w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_2_eca_digital_evidence_areas_en-768x306.png 768w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_2_eca_digital_evidence_areas_en-1536x612.png 1536w, https:\/\/pcreps.com.br\/blog\/wp-content\/uploads\/2026\/08\/table_2_eca_digital_evidence_areas_en.png 1800w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Why this is a governance issue, not only a privacy issue<\/h2>\n\n\n\n<p>The report sits at the intersection of privacy, child safety, product design, security, data analytics, legal affairs and public accountability. A DPO may be closely involved in privacy and data protection, but the DPO cannot independently manufacture moderation statistics, decide how a product should operate, or replace the controller\u2019s responsibility for decisions about personal-data processing. The ANPD\u2019s guidance explains that the DPO advises and supports the controller, receives communications from the authority and helps coordinate internal responses, while decisions about processing remain with the controller.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">A practical readiness plan for companies with Brazilian exposure<\/h2>\n\n\n\n<p>First, complete a documented scope assessment. Confirm the provider, product, Brazilian user base, age-related metrics, business model and any conditional exemption. Record assumptions and the date on which the assessment was made, since the service and the regulatory context may evolve.<\/p>\n\n\n\n<p>Second, appoint an accountable project owner with authority to coordinate product, trust and safety, moderation, security, analytics, privacy, legal and communications teams. The purpose is not to transfer all obligations to one individual. It is to create a controlled process for gathering and approving the information that will appear in the report.<\/p>\n\n\n\n<p>Third, create an evidence inventory. For each required topic, identify the source system, reporting period, responsible team, data definition, quality control and approval path. Pay particular attention to the difference between complaints, notifications, reports, removals, account actions and escalations. The report should explain methods clearly enough that the figures are meaningful to readers and defensible in a regulatory conversation.<\/p>\n\n\n\n<p>Fourth, test consistency and confidentiality. Numbers published on a website must be checked against internal records, but the company must also avoid disclosing personal data, sensitive investigation details or information that could undermine child-safety controls. A public transparency report is not the same as a raw operational database.<\/p>\n\n\n\n<p>Finally, establish a repeatable calendar. The September 2026 deadline is the immediate priority, but the decision creates an ongoing semiannual rhythm. A company that treats the first report as a one-off publication may face the same evidence and coordination problem again six months later.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How a DPO can support the process<\/h2>\n\n\n\n<p>A DPO or privacy function can help translate regulatory expectations into an internal governance workflow. Depending on the company\u2019s mandate, this may include advising on data minimisation, privacy-by-design evidence, parental-consent mechanisms, impact assessments, records of processing, communication channels and the treatment of requests from the ANPD. The DPO can also help identify the right internal owners, challenge unsupported statements, and coordinate with specialist legal, security or technical teams.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How PCREPS can help international companies operating in Brazil<\/h2>\n\n\n\n<p>For foreign investors and international groups, the challenge is often not the absence of global policies but the need to make those policies operational in Brazil. PCREPS positions itself as a trusted local partner in Brazil, offering \u201cBusiness, Simplified\u201d through legal representation, operational support and strategic coordination. Its services include DPO support, representation for foreign investors and non-resident directors, administration of subsidiaries and branches, registered office address services, and coordination with law firms, accountants, financial advisers and other professional partners.<\/p>\n\n\n\n<p>PCREPS is not a substitute for legal, tax, accounting, cybersecurity or regulatory advice when specialised analysis is required. Each company should assess its scope and obligations with qualified advisers. Nevertheless, a dependable local partner can make the process more predictable by ensuring that responsibilities, evidence and communication are not left between jurisdictions.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Conclusion: use the deadline to strengthen local governance<\/h2>\n\n\n\n<p>The 17 September 2026 deadline is a concrete signal that child-safety, privacy and transparency expectations are moving from broad principles to recurring operational deliverables in Brazil. Foreign platforms that may be covered should begin with scope, evidence and ownership\u2014not with last-minute translation or publication. A structured DPO and local support model can help connect global controls to Brazilian accountability while preserving the role of the controller and specialist advisers.<\/p>\n\n\n\n<p>If your organisation is assessing its exposure to the ECA Digital or needs local support for data-protection governance in Brazil, contact PCREPS to discuss a practical coordination approach.<\/p>\n\n\n\n<p>Important note: This article is for general informational purposes and does not constitute legal, tax, accounting, cybersecurity or regulatory advice. The application of the ECA Digital and related requirements should be assessed case by case with qualified specialists.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>For international companies operating digital products in Brazil, regulatory exposure rarely begins with a single form or isolated deadline. It&hellip; <a class=\"read-more\" href=\"https:\/\/pcreps.com.br\/blog\/eca-digital-transparency-reports-in-brazil-what-foreign-platforms-need-to-prepare-for-the-17-september-2026-deadline\/\">Continue Reading<\/a><\/p>\n","protected":false},"author":2,"featured_media":111,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[80,86,81,22,83,71,84,85,82,87],"class_list":["post-109","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-blog","tag-anpd","tag-brazil-compliance","tag-child-online-safety","tag-corporate-governance-brazil","tag-data-protection-in-brazil","tag-dpo-services-brazil","tag-eca-digital","tag-eca-digital-transparency-report","tag-foreign-platforms-in-brazil","tag-privacy-governance"],"_links":{"self":[{"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/posts\/109","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/comments?post=109"}],"version-history":[{"count":1,"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/posts\/109\/revisions"}],"predecessor-version":[{"id":114,"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/posts\/109\/revisions\/114"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/media\/111"}],"wp:attachment":[{"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/media?parent=109"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/categories?post=109"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/pcreps.com.br\/blog\/wp-json\/wp\/v2\/tags?post=109"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}