Digital Trust
May 12, 2026
5 minutos

ECA Digital and Age Verification: Why Compliance Requires More Than Adopting an AI Tool

This article was developed from an analysis presented by Yasodara Córdova, researcher and consultant in privacy and digital identity, during the Conexão Certta event held on March 23, 2026, in São Paulo. The discussion drew coverage from the specialized press and raised questions that go beyond regulatory compliance.

ECA Digital, Brazil’s Digital Child and Adolescent Statute, took effect on March 17 and put a concrete problem on the agenda of digital operations in Brazil: how do you verify a user’s age effectively without expanding the exposure of sensitive data belonging to children and teenagers? The question is straightforward. The answer isn’t.

The market reacted fast. Many companies adopted AI-based solutions for age verification. The problem is that simply adopting these technologies doesn’t, on its own, resolve the compliance question, especially when verification levels need to be calibrated to the risk of each interaction.

This discussion isn’t new, but it has grown in scale. Brazil had 68.6 million people between the ages of 0 and 19 in 2022, according to IBGE. That’s a significant volume of data that started circulating in digital environments without protection models evolving at the same pace. This is the gap the regulation now tries to address.

The Logic of Systems Designed to Grant Access, Not to Protect

Historically, identification systems have been built to enable access. From fingerprint records to digital documents with QR codes, the core logic has always been to enable entry, not to protect the data generated in the process.

“Solutions have always been designed to grant access, not to protect data. That’s a very modern concern when we talk about government.” — Yasodara Córdova, researcher and consultant in privacy and digital identity

ECA Digital creates an opportunity to rebalance that logic. The law prohibits behavioral tracking and requires companies to seek solutions that avoid surveilling children and teenagers. But the path between the regulatory requirement and practical implementation is still being built.

Verifiable Credentials: The Ideal Scenario and What Exists Today

At the Conexão Certta event, Yasodara presented what would be the technically ideal scenario for solving age verification without exposing data.

“The best path is to use a technology we call verifiable credentials, where the only information transmitted is whether or not the person falls within that age range.” — Yasodara Córdova


The logic is simple: instead of transmitting full identity data, the system confirms only the attribute needed for that specific interaction. No additional information circulates. The problem is that this model is still hard to implement at scale in today’s environment.

In practice, a flow compatible with ECA Digital’s criteria works like this: the user accesses the platform, the system identifies the risk context of that interaction, triggers age-attribute verification via a verifiable credential or facial biometrics, confirms the age range without storing full data, and grants or restricts access. Data collected from minors is discarded once confirmation is complete.

Meanwhile, most operations still work with solutions that collect more data than necessary. And when that data involves minors, the level of risk and responsibility changes.

The ANPD Timeline and What Companies Need to Do Now

Brazil’s National Data Protection Authority (ANPD) published a decision setting the implementation process to run through January 2027, when enforcement and sanctions begin. The regulatory parameters on age verification methods, specific to each risk level, are expected to be published starting in August, in the second phase of the timeline.

The deadline exists, but inertia isn’t an option. Iuri Duarte, Certta’s specialist in privacy and personal data protection, is direct about what this moment requires.

“The intent of the regulation isn’t to end a business model, but to require the implementation of effective controls. That’s why companies need to look inward and make sure they’re acting in line with what the law requires.” — Iuri Duarte, Certta


The market already has solutions capable of meeting different levels of requirement. The challenge is structuring those capabilities within operational flows. According to Duarte, when it comes to age verification, criteria like robustness and reliability need to be evaluated case by case, and data collected from minors should be discarded after verification to protect privacy.

Which Sectors Are Most Exposed to ECA Digital, According to Law 15,211/2025 and Decree 12,622/2025

ECA Digital affects operations with very different dynamics from one another. The law applies to any digital product or service with a real possibility of access by minors, which broadens its scope well beyond what many companies assume:

Very high risk: social networks, betting and gambling platforms, and adult content platforms. These sectors are explicitly named in the law and carry the most rigorous age-verification obligations.

High risk: video games (especially those involving in-app purchases and loot boxes, which ECA Digital prohibits for minors), streaming services, and app stores. The main obligation here is to verify age by interaction, not just at sign-up.

Medium to high risk: e-commerce in general, search engines, and any app likely to be accessed by minors. For these sectors, the compliance requirement depends on the type of content and the profile of the audience reached.

In every case, the critical point isn’t verification itself but calibrating the level of verification to the risk of each interaction, without creating unnecessary friction for adult users.

What Changes When Enforcement Is Real: LGPD vs. ECA Digital

“Unfortunately, we managed to settle quite comfortably into LGPD’s requirements, which didn’t bring an enforcement structure capable of effectively holding companies accountable for handling people’s data properly. With ECA Digital, I hope we’ll actually see that accountability now.” — Yasodara Córdova

The signal here matters: the law exists and the timeline is set. What’s changing now is these market experts’ expectation that enforcement will actually happen this time.

Between Protection and Trust: How Parents See ECA Digital

If ECA Digital represents a new stage of regulatory responsibility for companies, for families the conversation also involves setting boundaries in the digital environment without undermining the trust relationship with children and teenagers.

In partnership with Estadão, parents and guardians shared how they already use content control mechanisms day to day and how they view the new age-verification tools set out in the regulation.

Nutritionist Vivian De Cicco, mother of a 13-year-old boy, for example, has always been strict about the content her son accesses. Beyond checking the recommended age rating, she’s developed a habit of checking specialized platforms to look into the context of each film before deciding whether to let her son watch it. She also already uses the tools available to block certain content and services across the digital environment, whether on websites, social media, or games.

For her, verification tools will make everyday life easier, helping ensure her son can build a healthy, useful relationship with new technologies.

Vivian, of course, acknowledges how hard it is to strike a balance between protection and privacy intrusion, without damaging the family environment. “Age verification will certainly make managing access easier. But it’s important to understand that building trust between parents and children is grounded, above all, in respectful, ongoing dialogue,” she concludes.

Digital Trust Infrastructure: The New Challenge of Intelligent Verification

ECA Digital expands a discussion the market will still need to mature over the coming years: how to balance age verification, privacy, data anonymization, and user experience across different business contexts.

In practice, this means companies will need to discuss not just verification mechanisms, but also which information truly needs to be collected, how that data will be handled, and what levels of validation make sense for each risk scenario.

This is exactly the evolution Certta defines as digital trust infrastructure: an approach that connects verification, privacy, and user experience without turning compliance into operational friction.