Brazil’s ECA Digital Makes Child Safety a Platform Governance Duty
Brazil enacted Law 15,211 on 17 September 2025. Known as the ECA Digital, it applies the protection principles of the Child and Adolescent Statute to digital products and services and makes safety a product-governance responsibility.
The law is not limited to services designed exclusively for children. It reaches digital products and services directed at, or likely to be accessed by, children and adolescents in Brazil. That wider test prevents a platform from relying only on an adult audience statement when its design and actual use tell a different story.
The ECA Digital takes effect on 17 March 2026. The preparation period is therefore a product and engineering deadline, not only a date for changing terms of service.
Safety must be built into the service
Providers need measures to prevent and mitigate risks to children and adolescents. Relevant risks can arise from content, contact, conduct, commercial design, data use and features that encourage harmful or excessive engagement.
This requires more than removing content after a report. Default settings, recommendation logic, messaging, discovery, location sharing, purchases and reporting tools can all change the likelihood and severity of harm.
Age assurance becomes an architectural decision
The law requires reliable age-assurance measures appropriate to the service and risk. That creates a difficult balance. A weak self-declaration may not protect children, while collecting identity documents from every user can create a new concentration of sensitive information.
Providers should select proportionate methods, minimise collected data and separate age signals from unrelated profiling. They should also test error rates and provide a route to challenge an incorrect age result.
Parents need useful controls, not symbolic settings
Parental supervision features should be accessible and understandable. They need to support meaningful choices without exposing a child’s private communications or creating avoidable safety risks. The right design depends on age, maturity, service function and the nature of the risk.
Interfaces should not pressure children to weaken protections or push parents through confusing steps. The same design review should examine advertising, purchases and commercial profiling involving younger users.
Governance needs evidence
The framework includes transparency and reporting expectations, enforcement powers and obligations relating to reports and removal of unlawful or harmful material. The ANPD is responsible for the data protection and regulatory role assigned under the new system.
Providers should be able to demonstrate how they identified likely child access, assessed risks, chose safeguards and measured whether those safeguards work. A single annual assessment will not capture rapid changes in recommendation systems, content formats or user behaviour.
What providers should do
- Identify services and features directed at or likely to be accessed by children in Brazil.
- Assess content, contact, conduct, commercial and data risks by age group.
- Select proportionate age assurance and minimise the data it creates.
- Review defaults, recommendations, messaging, advertising and purchase flows.
- Test reporting, parental controls, response times and evidence retention before the effective date.
Child safety is now part of platform design
The ECA Digital moves the discussion from general concern to operational responsibility. Services likely to be used by children must show how safety, privacy, age assurance and parental support shape the product itself. Compliance cannot be delegated to moderation after the design decisions have already been made.
Official sources
- Federal Senate: Law 15,211 of 2025
- ANPD: ECA Digital guidance in English
- ANPD: ECA Digital implementation hub
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


