Brazil protects data as an asset through a combination of copyright, trade secret provisions in its industrial property law, contract law, and the LGPD, its comprehensive data protection statute. Article 7(XIII) of the Copyright Law recognizes databases as intellectual creations where they show originality in selection or arrangement resulting from a human creative process; raw data and mere compilation effort remain unprotected, as Brazilian law rejects the 'sweat of the brow' doctrine and does not extend copyright to works generated solely by AI.
Trade secrets are protected under Article 195 (items XI and XII) of the Industrial Property Law (LPI), which prohibits unauthorized use, disclosure, or acquisition of confidential information obtained through dishonest means, with civil and criminal penalties available. Protection requires confidentiality, commercial value derived from secrecy, and reasonable protective measures, with the burden of proof on the data owner. Brazil has no sui generis database right, relying instead on unfair competition principles as a partial substitute.
Contract law under the Civil Code plays a central role, with NDAs, licensing, and data-sharing agreements governed by good faith and the social function of contract. The LGPD, enacted in 2018 and modeled on the GDPR, regulates personal data processing, grants data subjects a right to request review of automated decisions (Article 20), and imposes fines of up to 2 percent of gross revenue in Brazil, capped at 50 million reais per infraction — while exempting disclosures that would reveal trade secrets.
Key takeaways
- Brazilian copyright protects only the original, human-created selection or arrangement of a database, never the underlying data.
- Trade secret claims under LPI Article 195 require proof that reasonable confidentiality measures were in place, so robust internal policies and NDAs are critical.
- With no sui generis database right, unfair competition principles serve as a partial fallback against data misappropriation.
- AI training on personal data must stay consistent with the original purpose of collection and rest on a valid legal basis under the LGPD.
- LGPD Article 20 gives individuals a right to request review of solely automated decisions — the requirement that review be by a natural person was vetoed in 2019 — directly affecting profiling and AI-driven outputs.
Primary legal instruments
AI-assisted summary of the report, editorially reviewed before publication · AI transparency
Protection mechanisms
Report-derived analysis per mechanism. The report text is fixed; committee members with contributor access can revise the rating (with an audit trail) and add notes below each block.
Recent Developments
Live updates contributed by committee members and the AI research bot — separate from the fixed report content above.
ANPD initiates monitoring of digital platforms and generative AI for content compliance
Brazil's ANPD has begun monitoring major digital platforms, app stores, and generative AI tools to ensure compliance with the Marco Civil da Internet and ECA Digital. The agency is assessing measures taken to prevent criminal content and protect children and women online, with companies required to respond to notifications within ten business days. This action is part of ANPD's plan to implement new competencies from updated internet regulations.
ANPD and PNUD select consultants for studies on AI, data protection, and governance
The ANPD and the United Nations Development Programme (PNUD) have announced the selection of consultants to conduct technical studies on strategic topics related to Artificial Intelligence and personal data protection. These studies will also cover data governance and the protection of children and adolescents in the digital environment. This initiative aims to provide technical and scientific direction for ANPD's regulatory and supervisory activities.
ANPD publishes testing methodology for its AI and Data Protection Regulatory Sandbox
Brazil's ANPD has released the testing methodology for its Regulatory Sandbox on Artificial Intelligence and Data Protection. Developed in collaboration with CIAAM/USP, the document outlines procedures for supervising, monitoring, and evaluating innovative AI solutions. It focuses on assessing transparency, explainability, and personal data protection within AI systems to inform future regulation.
ANPD Details Regulatory Agenda Progress on Digital Child Protection and Internet Framework
The Brazilian National Data Protection Authority (ANPD) released its third semiannual report on the 2025/2026 regulatory agenda, outlining actions from the first half of 2026. Key initiatives focused on implementing the Digital Statute of Children and Adolescents (ECA Digital) and updated Marco Civil da Internet decrees. The report highlights progress on guides for IT providers targeting minors and age verification mechanisms, alongside revisions to fiscalization and sanction regulations to align with ANPD's expanded competencies.
ANPD publishes first monitoring results of Brazil's AI regulatory sandbox
On July 2, 2026 Brazil's data protection authority (ANPD) released the first partial monitoring report of its Regulatory Sandbox on Artificial Intelligence and Data Protection. Three companies selected under Edital 2/2025 are testing AI systems in a supervised experimental environment running until December 2026, after the leveling phase concluded in February. The pilot is designed to generate evidence for the ANPD's forthcoming rules on AI and automated decision-making under the LGPD, including transparency and algorithmic-review obligations.
Creative sector fights removal of copyright and TDM remuneration chapter from Brazil's AI bill (PL 2338)
In May 2026, more than 50 organizations from Brazil's music, audiovisual, journalism and literary sectors issued a public manifesto urging the Chamber of Deputies' special committee and rapporteur Aguinaldo Ribeiro to preserve the copyright chapter of AI framework bill PL 2338/2023. The Senate-approved text limits free text-and-data mining to non-commercial research institutions and gives rightsholders remuneration and opt-out rights when works are used to train commercial AI systems, but drafts of the Chamber substitute reportedly drop these provisions. The dispute has become the main obstacle to the bill's repeatedly postponed 2026 vote.