CoursesBookObservatoryBriefingsCyber InvestigationGlossaryLegislationPreserve EvidenceResearchAbout
Contact
Normative Evolution & PrecedentsUpdated: August 28, 2026

Cybercrime Legislation & Case Law

Consolidated chronological record of federal statutes, international treaties, and landmark appellate precedents shaping digital evidence and cyber criminal prosecution in Brazil.

Mapped Milestones16
Statutory Scope2012 — 2026
Superior CourtsSTJ & STF Precedents
Global TreatiesBudapest & UN Conventions
Displaying 16 of 16 milestones
Filter by nature:
2012November 30, 2012·Federal Legislation

Law 12.737/2012 (Carolina Dieckmann Act) — Computer Intrusion Offenses

Criminalization of unauthorized computer system intrusion and legal protection of digital data

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

First autonomous codification of computer integrity and telematics inviolability in the Brazilian Criminal Code (Art. 154-A). Established the offense of hacking via breach of security mechanisms to obtain, alter, or destroy data, or install malicious software (analogous in scope to the US CFAA § 1030 and UK Computer Misuse Act).

Investigative & Forensic Impact

Formally criminalized unauthorized network breaches, ransomware payloads, trojans, and cyber espionage under specific statutory provisions rather than obsolete mail-tampering or property theft norms.

Key Statutory Provisions
  • Art. 154-A Criminal Code: Unauthorized computer intrusion / hacking
  • Art. 154-A § 1: Malware manufacturing, dissemination, and commercialization
  • Art. 154-A § 3: Aggravated penalty for trade secrets or private communications theft
  • Art. 266 § 1: Disruption of public telematics or telecommunication services
2014April 23, 2014·Federal Legislation

Law 12.965/2014 — Brazilian Internet Civil Rights Framework (Marco Civil da Internet)

Brazil's digital bill of rights: mandatory log retention rules, judicial warrants, and sovereignty principles

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Established the structural legal architecture for the internet in Brazil, bifurcating connection logs (ISPs, 1-year mandatory retention) and application access logs (platforms, 6-month mandatory retention). Strictly mandates prior judicial warrants for communications disclosure (comparable in scope to EU E-Privacy & US Stored Communications Act).

Investigative & Forensic Impact

Forms the primary statutory foundation for subpoenaing technical digital evidence and subscriber logs from tech platforms operating in Brazil.

Key Statutory Provisions
  • Art. 10: Inviolability of private communications and stored data without court order
  • Art. 11: Extra-territorial jurisdiction over foreign providers offering services to Brazilian users
  • Art. 13: Mandatory 1-year connection log retention for ISPs
  • Art. 15: Mandatory 6-month application log retention for online services
  • Arts. 13 § 2 & 15 § 2: Administrative pre-warrant preservation requests by police/prosecutors
2018August 14, 2018·Federal Legislation

Law 13.709/2018 — General Personal Data Protection Law (LGPD)

Comprehensive data privacy framework and law enforcement processing boundaries (Brazil's GDPR equivalent)

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Standardized data governance, transparency, and processing principles modeled after the EU GDPR. Statutorily exempts criminal investigation and national security from standard commercial consent regimes (Art. 4, III) while mandating strict proportionality and institutional safeguards.

Investigative & Forensic Impact

Imposed strict chain-of-custody and data segregation requirements for incidental third-party data intercepted during lawful wiretaps and telematic warrants.

Key Statutory Provisions
  • Art. 4, III: Statutory carve-out for criminal prosecution and national security
  • Art. 4 § 1: Duty of security compliance by investigative agencies
  • Art. 46: Security standards to prevent forensic database leaks
2019December 24, 2019·Federal Legislation

Law 13.964/2019 — Anti-Crime Act (Statutory Chain of Custody)

Mandatory 10-stage chain of custody codification in the Brazilian Criminal Procedure Code (CPP)

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Inserted Arts. 158-A to 158-F into the CPP, establishing a mandatory, chronological traceability framework for digital and physical evidence across 10 statutory stages: recognition, isolation, fixing, collection, packaging, transport, receipt, processing, storage, and disposal (aligning with ISO/IEC 27037:2012 standards).

Investigative & Forensic Impact

Elevated evidence handling rigor. Missing hash calculations at acquisition or broken seals now constitute primary grounds for evidence suppression and procedural nullity in court.

Key Statutory Provisions
  • Art. 158-A CPP: Statutory definition and scope of chain of custody
  • Art. 158-B CPP: Ten mandatory successive stages of evidence preservation
  • Art. 158-C CPP: Collection by authorized forensic experts
  • Art. 158-D CPP: Mandatory numbered and sealed tamper-evident packaging
2020March 10, 2020·Landmark Precedent

STJ — Mandatory Logging and Disclosure of Source Ports under CGNAT (REsp 1.785.383/SP)

Binding Superior Court of Justice precedent on Carrier-Grade NAT source port attribution

Superior Court of Justice (STJ)
Doctrinal Summary & Legal Framework

Settled that ISPs operating under Carrier-Grade NAT (Large Scale NAT) architectures are legally obligated under the Marco Civil to log and disclose the source port (RFC 6888) alongside the public IPv4 address and UTC timestamp to identify individual subscribers.

Investigative & Forensic Impact

Overcame ISP refusal to supply port logs, ensuring suspects sharing public IPv4 addresses on mobile or broadband networks can be uniquely identified in criminal trials.

Key Statutory Provisions
  • Functional interpretation of Marco Civil Arts. 5, VIII & 10
  • ANATEL Resolutions 614/2013 & 720/2020
  • IETF RFC 6888 standard enforcement
2020November 11, 2020·Landmark Precedent

STJ — Binding Theme 997: Jurisdiction over Global Tech Subsidiaries

Compulsory compliance of foreign tech giants with Brazilian court orders via local subsidiaries

Superior Court of Justice (STJ) — 1st Section
Doctrinal Summary & Legal Framework

Binding ruling by the 1st Section of the STJ holding that multinational internet services operating in Brazil through local subsidiaries are subject to Brazilian sovereignty, regardless of where remote data centers are located.

Investigative & Forensic Impact

Neutralized defense claims that subpoenas must exclusively proceed through lengthy diplomatic letters rogatory or MLAT requests for data gathered in Brazil.

Key Statutory Provisions
  • Art. 11 Law 12.965/2014 (Marco Civil da Internet)
  • Direct enforceability of Brazilian judicial warrants on domestic subsidiaries
2021May 27, 2021·Federal Legislation

Law 14.155/2021 — Electronic Fraud and Aggravated Cybercrime Act

Increased penalties for computer intrusion and creation of statutory qualified electronic fraud

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Quadrupled penalties for Art. 154-A (enabling pre-trial detention and wiretaps) and created aggravated electronic fraud (Art. 171 § 4) and electronic larceny (Art. 155 § 4-B) with 4-to-8 year prison sentences. Shifted territorial venue to the victim's domicile (CPP Art. 70 § 4).

Investigative & Forensic Impact

Unlocked pre-trial detention and wiretap warrants for cyber extortion, phishing schemes, and social engineering networks.

Key Statutory Provisions
  • Art. 154-A CP: Severe 1-to-4 year penalties for system intrusion
  • Art. 155 § 4-B CP: Larceny via electronic deception/phishing
  • Art. 171 § 4 CP: Qualified electronic fraud (doubled if foreign servers used)
  • Art. 70 § 4 CPP: Territorial venue at victim's residence
2022February 23, 2022·Landmark Precedent

STJ — Binding Theme 1034: Keyword-Based Telematic Search Orders

Constitutionality and proportionality standards for reverse search and identifier disclosures

Superior Court of Justice (STJ) — 3rd Section
Doctrinal Summary & Legal Framework

The 3rd Section of the STJ established the validity of judicial orders compelling search engines and application providers to produce connection logs of users executing specific keyword queries within delimited timeframes, provided strict necessity and proportionality tests are satisfied.

Investigative & Forensic Impact

Legitimized targeted search-query warrants in homicide and cyber cartel cases while establishing clear boundaries against indiscriminate bulk surveillance.

Key Statutory Provisions
  • Arts. 10 & 22 Marco Civil da Internet (Lei 12.965/2014)
  • Three-step proportionality test against unconstitutional fishing expeditions
2023April 12, 2023·International Treaty

Decree 11.491/2023 — Council of Europe Budapest Convention on Cybercrime

Formal entry into force of the landmark multilateral cybercrime treaty (CETS 185) in Brazil

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Promulgated the Budapest Convention into Brazilian domestic law, harmonizing substantive cyber offenses, procedural powers (production orders, expedited preservation, live interception), and direct mutual legal assistance channels.

Investigative & Forensic Impact

Empowered Brazilian law enforcement with direct 24/7 Network channels for rapid evidence freezing abroad without months-long diplomatic delays.

Key Statutory Provisions
  • Art. 16: Domestic expedited preservation of stored data
  • Art. 18: Direct production orders to service providers
  • Art. 29: Transnational emergency expedited preservation
  • Art. 35: 24/7 High-Tech Crime Network contact point (Federal Police)
2024Consolidated rulings of the 5th and 6th Panels·Landmark Precedent

STJ / STF — Warrant Requirement for Seized Smartphone Extraction

Strict legal distinction between physical hardware seizure and digital messaging extraction

Superior Court of Justice (STJ) & Supreme Federal Court (STF)
Doctrinal Summary & Legal Framework

Settled superior court jurisprudence mandating that physical device seizure during search warrants or in flagrante arrests does NOT authorize forensic extraction of messaging apps (WhatsApp, Signal, Telegram) without explicit, specific judicial data disclosure authorization.

Investigative & Forensic Impact

Requires law enforcement to immediately isolate smartphones in Faraday bags and secure specific judicial extraction warrants before attempting device triage or decryption.

Key Statutory Provisions
  • Art. 5, X & XII Federal Constitution (Privacy of communications)
  • Art. 157 CPP (Fruit of the poisonous tree exclusionary rule)
  • HC 672.483/SP & STF RHC 89.981/MG precedents
2024January 12, 2024·Federal Legislation

Law 14.811/2024 — Cyberbullying & Heinous Crimes Against Minors

Criminalization of systematic virtual intimidation (Art. 146-A CP) and heinous classification for online child exploitation

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Introduced systematic virtual intimidation (cyberbullying) into Art. 146-A of the Criminal Code (2-to-4 year prison terms) and amended the Heinous Crimes Act (Law 8.072/90) to classify child sexual abuse material possession and transmission as heinous offenses with no bail or amnesty.

Investigative & Forensic Impact

Enabled pre-trial detention, mandatory closed-regime sentencing, and accelerated takedown procedures in child online safety cases.

Key Statutory Provisions
  • Art. 146-A CP: Virtual systematic intimidation (Cyberbullying)
  • Art. 1, IX Law 8.072/1990: Heinous classification of online CSAM offenses
  • Aggravated penalties for live-streamed offenses
2024Landmark Precedent — STF Theme 1148·Landmark Precedent

STF — Binding Theme 1148: Geofence Warrants & Keyword Orders (RE 1.301.250)

Supreme Court constitutional parameters for reverse location searches and big data warrants

Supreme Federal Court (STF)
Doctrinal Summary & Legal Framework

Landmark Supreme Court ruling originating in the Marielle Franco assassination investigation validating judicial geofence orders compelling Google to identify accounts present within specific geographic polygons and timeframes, subject to strict subsidiarity and third-party privacy protections.

Investigative & Forensic Impact

Established constitutional validity and operational boundaries for forensic big-data queries in complex homicide and organized crime investigations.

Key Statutory Provisions
  • Art. 5, X & XII Federal Constitution
  • Marco Civil Arts. 10 & 22
  • Three-step proportionality review for big data warrants
2024Approved August 9, 2024 (Signed by Brazil on October 25, 2025)·International Treaty

UN Cybercrime Convention — Global United Nations Treaty on Electronic Evidence

Universal multilateral convention on transnational cyber investigations, e-evidence, and extradition

United Nations Office on Drugs and Crime (UNODC)
Doctrinal Summary & Legal Framework

The first universal cybercrime treaty approved by the UN General Assembly (with Brazil as negotiation committee vice-chair). Extends international legal cooperation beyond Western states, establishing real-time data preservation, cryptoasset tracing, and e-evidence admissibility standards across 190+ member states.

Investigative & Forensic Impact

Significantly broadens Brazilian federal prosecution reach against transnational ransomware syndicates and financial fraud rings located in Asia, Africa, and Eastern Europe outside the Budapest framework.

Key Statutory Provisions
  • Universal international cooperation for digital evidence collection
  • Global technical assistance and cross-border cyber forensics
  • Sovereignty safeguards and human rights compliance
2025Mandatory Enforcement on February 2, 2026·Federal Legislation

Central Bank of Brazil — MED 2.0: Multi-Hop PIX Tracing and Asset Freeze

Automated multi-layer bank account freezing to defeat mule networks and instant fraud routing

Central Bank of Brazil (BCB)
Doctrinal Summary & Legal Framework

Mandatory upgrade of the Special Return Mechanism (MED) by the Central Bank of Brazil. Enables automated interbank tracing and simultaneous multi-tier asset freezing across mule accounts, extending victim dispute windows to 80 days.

Investigative & Forensic Impact

Dismantles rapid money-laundering hops in electronic fraud (Art. 171 § 2-A CP), providing immediate bank audit trails for judicial asset forfeiture.

Key Statutory Provisions
  • Central Bank BCB Resolutions mandating MED 2.0
  • DICT Integration for automated transaction graph tracing
  • Interbank automated protocols for multi-tier asset freeze
2026May 2026·Federal Legislation

Decrees 12.975 & 12.976/2026 — Platform Duty of Care & 2-Hour DeepNude Takedown Standard

Mandatory algorithmic transparency, proactive platform diligence, and emergency takedowns for synthetic non-consensual imagery

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Regulatory decrees implementing Marco Civil diligence standards. Mandates that platforms remove non-consensual AI-generated synthetic intimate imagery (DeepNudes) within 2 hours of formal notification, under strict administrative fines enforced by the ANPD.

Investigative & Forensic Impact

Establishes an emergency administrative takedown framework for victims, utilizing platform compliance logs as statutory corpus delicti for prosecution under Art. 216-B CP.

Key Statutory Provisions
  • Decree 12.975/2026: Content governance and algorithmic transparency obligations
  • Decree 12.976/2026: Emergency 2-hour takedown rule for synthetic intimate media
  • ANPD regulatory and sanctioning jurisdiction
2026August 2026·Federal Legislation

Law 15.487/2026 — Online Undercover Operations and Cyber Child Protection Act

Modernized undercover virtual infiltration, deep web patrols, and emergency metadata subpoenas

Federal Official Gazette (DOU)
Doctrinal Summary & Legal Framework

Overhauled special investigative techniques in cyberspace. Codified virtual police patrolling across open forums and darknet networks to prevent crimes against vulnerable persons, regulated undercover cyber infiltration using synthetic online identities, and authorized emergency metadata production in imminent life-threat scenarios.

Investigative & Forensic Impact

Equips Federal and Civil Police with agile, legally sound undercover operational powers to neutralize high-threat cybercrime syndicates in encrypted forums.

Key Statutory Provisions
  • Undercover cyber infiltration with judicial oversight and evidence safeguards
  • Proactive darknet and illicit forum patrolling
  • Emergency metadata production with post-factum judicial notification

Technical & Doctrinal Interconnection

Each legislative milestone integrates directly with the technical definitions of our bilingual forensic glossary and the specialized training programs in electronic investigation.