Brazil's data protection authority ordered Discord on August 12, 2026 to switch off Go Live and every functionally equivalent video feature for users in the country within three business days, after concluding that end-to-end encryption deployed in March left the company unable to observe what happens inside closed servers.

The instrument is Nota Tecnica no 1/2026/CGF/SFI/ANPD, filed under process no 00261.004804/2026-54 and registered as SEI no 0321183. It was signed electronically at 10:06 on August 12 by Samira Borelli Satriano, coordinator for the protection of children and adolescents in the digital environment, and at 10:11 by Jorge Andre Ferreira Fontelles de Lima, general coordinator of inspection. The Superintendencia de Fiscalizacao issued the preventive measure the same morning. Publication on the agency website followed at 11:34.

The order does not remove Discord from Brazil. Text messaging, voice channels and the rest of the service continue. What stops is a single functionality and its technical relatives.

What the suspension covers

The measure names Go Live, the screen and video broadcast feature used inside servers, and extends to any transmission or video-sharing resource that is functionally equivalent, meaning covered by end-to-end encryption and supervised by the same class of mechanisms Discord applies to Go Live.

The scope is drafted to close substitution routes. According to the technical note, the suspension reaches sharing, transmission, retransmission, embedding, mirroring, synchronised reproduction and screen sharing, whether performed by native resources or by bots, WebHooks, APIs, applications, integrations, commands, automations and comparable mechanisms. A separate paragraph requires the company to implement technically effective anti-circumvention measures, listing the renaming of resources, use of intermediary domains, invite codes, redirects, integrations and automations as the evasion patterns to be blocked.

Reinstatement is conditional. The functionality stays suspended until the company demonstrates the implementation and effectiveness of technical, security and governance measures proportionate to the identified risks, and full or partial reactivation depends on express prior authorisation from the regulator.

Three days, ten days, and R$50 million

Discord representatives were notified by the Superintendencia de Fiscalizacao and must prove full compliance across national territory within three business days. The window for filing an appeal with the superintendency is ten business days. Where the superintendency declines to reconsider, the matter can be escalated to the agency's Conselho Diretor.

Two distinct financial exposures sit behind the order. The technical note proposes that failure to prove compliance within the fixed deadline sends the file to the Conselho Diretor for additional measures and possible daily fines, citing article 21, IV of annex I of Decree 12.881 of March 18, 2026. Separately, the agency stated that if irregularities are confirmed in the administrative process, it can determine corrective measures and apply the sanctions set out in article 35 of the ECA Digital, which include fines of up to R$50 million per infraction.

The preventive measure is a cautionary instrument rather than a final ruling. The agency noted that the assessment forms part of preliminary findings and can be contested by the company inside the administrative process, and that other outcomes remain available during the inspection, including a compliance plan covering aspects of the service beyond live video.

The March 2 encryption change

The technical detail at the centre of the file concerns a product change dated March 2, 2026. According to information Discord supplied to the regulator, audio and video communications in direct messages, group direct messages, voice channels and Go Live transmissions have been covered by end-to-end encryption since that date. Content is encrypted on the sender device and can be decrypted only by the recipients, so the company states it has no access to that content while a session is running.

Timing carries legal weight in the note. The ECA Digital, Law 15.211, was signed on September 17, 2025, and its implementing regulation, Decree 12.880, was published on March 18, 2026. The note observes that the less protective product design for live transmissions was implemented immediately after the statute was promulgated and on the eve of its entry into force. Under articles 6 and 8, I of the law, prevention runs from design through continuous risk management, and the note argues that a modification reducing centralised detection capability called for a specific prior risk assessment and proportionate compensating safeguards. The material presented did not demonstrate that either step was taken.

The regulator did not treat encryption itself as the violation. Its reasoning is that architecture is a supplier choice, covering who can create servers, how invitations are sent, how transmission works, how flows are automated and how external links are inserted. Where a security decision makes a given control unworkable, the note holds that the provider carries the burden of implementing substitute controls of equivalent or superior effectiveness, particularly for a product likely to be accessed by adolescents.

Two mechanisms, both found wanting

For private video communications, the note records that Discord relies on two mechanisms to identify serious violations: analysis of behavioural signals associated with accounts and servers, and reports submitted by users.

On the first, the company told the agency it acts proactively using, in the note's rendering of the Portuguese original, behavioural signals, relations between accounts, network patterns, available metadata, reports and enforcement history. The note states that no concrete evidence of implementation or effectiveness accompanied that description in the document sent to the Secretaria de Direitos Digitais of the Ministry of Justice and Public Security.

The failure case is specific. In the episode known as Operacao Livia, reported to the agency by the company itself, the automated detection system assigned an erroneously low risk score to what the note characterises as an extremely serious event. The numerical score and the alert threshold are redacted in the published version, but the note describes the gap between them as showing that the system was not even close to flagging as a priority an environment later associated with facts of extreme gravity. Possible causes listed include insufficient signals, inadequate weighting, an excessively restrictive threshold, missing variables, or an inability to recognise the patterns of groups operating in closed environments.

The company's explanation that lowering the threshold would generate more false positives did not persuade the regulator. Calibration cannot be set solely by operational efficiency, the note argues, because the choice of threshold has to account for the nature of the harm being prevented. Where the risk involves imminent serious injury, self-harm or the death of a child or adolescent, the cost of a false negative is treated as incomparably higher than the cost of routing a server to additional human review.

The closed-server problem

The second mechanism draws sharper criticism. Effectiveness of user reporting depends on at least one participant recognising the violation, not being involved in it, being emotionally able to react, knowing the reporting mechanism exists and trusting that the platform will act in time. Those conditions rarely hold when the victim is a child or adolescent under manipulation, threat, harassment or collective coercion.

In private servers the note goes further, observing that participants are pre-selected precisely for the commission of the offence, so effectiveness of the protective mechanism would depend on the violators reporting themselves.

That argument connects to the removal and notification duty. Article 27 of the statute, as cited in the note, requires removal and communication to authorities of apparent exploitation, sexual abuse, kidnapping and grooming content detected directly or indirectly in the service. Read together with article 6, the provision presupposes that the platform retains a reasonable capacity to identify such situations. Where architecture leaves the company unable to recognise a serious interaction without a participant report, the note concludes that the removal and notification duties risk becoming materially inoperative. The agency's public statement lists the wider inspection as also covering age verification mechanisms under articles 10 and 17, content removal duties under article 29, and communication to competent authorities under article 28.

Discord's own account of the Operacao Livia environment appears in a footnote. The events took place, according to the company filing, in a voice channel inside a private server, restricted by invitation and not available through the platform's discovery mechanisms, with a limited number of members and only a small number of participants online and actively engaged at the time.

Complaint volumes and the qualification test

Data from SaferNet Brasil, cited in the note and repeated in the agency statement, records a 54% increase in complaints involving Discord between January and July 2026 against the same period a year earlier: 406 notifications in 2026 against 264 in the first seven months of 2025, a record for the period in a series that began in 2017.

Qualification of the service under the statute rests on several findings. Discord is treated as a service of probable access by children and adolescents under article 1, sole paragraph of Law 15.211/2025, because the service favours social interaction, entertainment and real-time exchange through servers and channels, and because the terms of service admit users from the age of 13. Concrete evidence is drawn from the Operacao Livia case, in which a 13-year-old joined the platform and broadcast live to more than 200 users. On its corporate site, the company describes itself as a social gaming platform where more than 90 million friends and communities talk through text, voice and video calls every day.

The note also states that live viewing features appear in several documented cases of serious violations, including induced self-harm, suicide, and torture and mistreatment of animals, filed under SEI no 0321215.

Competence flows from a chain of instruments. Law 15.211/2025 defines an autonomous administrative authority for the protection of children's and adolescents' rights in the digital environment in article 2, X, and assigns national enforcement in article 34. Decree 12.622/2025 designated the ANPD for that role. Decree 12.880/2026 confirms that regulation and supervision of the statute fall to the agency, without prejudice to other public bodies inside the rights guarantee system.

The cautionary power invoked is article 45 of Law 9.784/1999, which permits reasoned precautionary steps in situations of imminent risk without prior manifestation from the interested party. The note builds the classic two-part test: plausibility of the administrative position, drawn from structural aspects of the service rather than an isolated incident, and risk in delay, drawn from the gravity and irreversibility of the harms and the continued availability of the functionality.

Proportionality is addressed directly, with reference to articles 17, IV and 39 of the agency's inspection regulation. The measure targets the single functionality identified as carrying the highest risk, leaves other activities and legitimate uses untouched, and is reversible once compliance is demonstrated. Article 32 of the inspection regulation, approved by Resolution CD/ANPD no 1/2021, lists preventive measures and permits others compatible with articles 30 and 31.

Procedural record

The narrative section of the note dates the opening of the inspection process to August 7 and the meeting with company representatives to August 11, giving the year in both instances as 2018. Process references throughout the file, the electronic signatures and the agency's own statement place both events in 2026, with the process opened on Friday, August 7 and the virtual meeting held on Tuesday, August 11 at 10:00.

The sequence recorded in the file runs as follows. The Superintendente de Fiscalizacao opened the process through Despacho no 0319773/2026/SFI/ANPD, and the Coordenacao-Geral de Fiscalizacao sent electronic notice the same day through Oficio no 16/2026/CGF/SFI/ANPD, requesting information. Reports of a meeting between platform representatives and the Advocacia Geral da Uniao, at which the public body had requested an adequacy plan, prompted the superintendent to ask for the same documents. Oficio no 76/2026/SFI/ANPD summoned company representatives to the August 11 virtual meeting. In response, Discord filed the document it had sent to the Ministry of Justice and Public Security in answer to Oficio no 973/2026/GAB-SEDIGI/MJ. At the August 11 meeting the company acknowledged service and committed to provide the requested clarifications by Friday, August 14, 2026. The preventive measure issued the following day, before that commitment fell due.

Why the marketing community is watching

Feature-level suspension is the operative precedent here. Brazilian enforcement has moved from platform-wide questions to a surgical instrument that removes one video product from one market while the rest of the service keeps running, with reinstatement gated on evidence rather than on the passage of time. For any platform selling attention around live video in Brazil, that changes the unit of regulatory risk from the account to the format.

The encryption finding cuts across product roadmaps well beyond one company. Private, encrypted video is a design direction several social and messaging services have taken, and the note establishes that the regulator will read a reduction in centralised detection capability as a risk event requiring documented prior assessment and compensating controls. The tension is not new: the European Union lost its legal basis for voluntary scanning of child abuse material on April 3, 2026, leaving GoogleMeta, Microsoft and Snap pledging continuation without statutory cover, while Signal threatened to withdraw from Germany over the Chat Control proposal to scan messages before encryption. Brazil has now taken a third path, leaving encryption intact and removing the feature instead.

Enforcement pressure on Discord specifically has been accumulating across jurisdictions. Texas filed suit against the company in Collin County District Court on May 22, 2026 under the state's deceptive trade practices act, alleging that parents were misled about safety while minors encountered predators and extremist content, with Nevada and Indiana filing separate actions the same month. Louisiana's earlier case against Roblox described how contacts made on gaming platforms are moved to messaging services including Discord.

Brazilian rules also touch advertising directly. Article 22 of the ECA Digital prohibits profiling techniques for directing commercial advertising to children and adolescents, a provision the agency folded into its 2026 and 2027 enforcement priorities alongside 30 planned inspection actions on child protection. The draft age verification guide, opened for public comment in May 2026, sets out what counts as a reliable mechanism. Platforms likely to be accessed by children and adolescents also face a September 17 deadline to publish transparency reports.

France approved a social media ban for under-15s on July 21, 2026, with September 1 set as the enforcement date, and the European Commission has preliminary findings open against Meta's services on minor protection and addictive design. Regulatory approaches diverge on method. On the question of whether a private, encrypted live video product can be operated at all without demonstrable detection capability, Brazil has now supplied an answer with a deadline attached.

Timeline

Summary

Who: The Superintendencia de Fiscalizacao of Brazil's Agencia Nacional de Protecao de Dados, through coordinators Samira Borelli Satriano and Jorge Andre Ferreira Fontelles de Lima, acting against Discord Inc.

What: A preventive measure requiring suspension of the Go Live functionality and all functionally equivalent encrypted video transmission and sharing features, including bot, API, WebHook and automation routes, with anti-circumvention obligations, pending proof of adequate technical, security and governance safeguards. Non-compliance sends the file to the Conselho Diretor for possible daily fines; confirmed irregularities carry sanctions of up to R$50 million per infraction under article 35 of the ECA Digital.

When: Signed and issued on Wednesday, August 12, 2026, five days after the inspection process opened on August 7. Compliance is due within three business days; the appeal window runs ten business days.

Where: Brazilian national territory, covering users located in the country. Other functions of the service continue operating.

Why: The agency found that end-to-end encryption applied to live video since March 2, 2026 removed centralised content detection, that the remaining behavioural scoring system failed to flag a case of extreme gravity, and that user reporting is structurally weak in invitation-only servers, leaving the duties set out in article 6, II and III of Law 15.211/2025 without effective support.