In the AI era, protecting data requires verifying identities
Confirming that there really is a person on the other side of the screen has become one of the main challenges of the digital economy. The rise of generative artificial intelligence, combined with increasingly sophisticated fraud techniques, is forcing companies to rely on effective identity verification to ensure they know who is actually using the data they hold.
This landscape is shaped by two pressures pulling in opposite directions. On one side, Brazil's General Data Protection Law (LGPD) and recent updates such as the ECA Digital (Brazil's Digital Child and Adolescent Statute) limit what can be collected, require data to be deleted once its purpose has been fulfilled, and restrict behavioral tracking. On the other, Brazilian courts have begun invalidating digital contracts precisely when companies cannot present a robust and consistent body of evidence proving who carried out the transaction.

Two numbers that measure the pressure on the market
- 72% of organizations reported an increase in cyber risks, according to the World Economic Forum's Global Cybersecurity Outlook 2025.
- 49.7% of electronic contracts analyzed across 21 state courts were invalidated, even when some authentication method was in place, according to research by the E-commerce Studies Center at FGV Law School in Rio de Janeiro (FGV Direito Rio).
Taken together, these figures show that the market's bottleneck lies in how well companies verify the information they already hold, not in the volume of information available to collect.
According to Iuri Duarte, Privacy and Data Protection Specialist at Certta, greater exposure doesn't force companies to collect more data. It forces them to do a better job of verifying who is using the information already in their databases.
"Data protection and identity and document verification are not opposing goals. A well-designed process keeps data collection to what is truly necessary, while cross-checking multiple sources and evidence to confirm the user's identity more securely," he says. - Iuri Duarte

For the specialist, putting this principle into practice means assessing, case by case, what each interaction requires.
"The intelligence in how data is used lies in deciding which validations make sense for each interaction. When we combine different sources of information, context, and risk signals, we can better protect users, reduce fraud, and avoid unnecessary friction in the digital experience," he explains.
What Brazilian courts now require as proof of authorship
The study conducted by the E-commerce Studies Center at FGV Law School in Rio de Janeiro (FGV Direito Rio) analyzed 2,083 appellate rulings issued between January 2023 and September 2025 across 21 state courts. Over 33 months of real-world decisions, the courts established their own criteria for validating digital authorship, and nearly half of the contracts analyzed were invalidated.
The most widespread line of reasoning for validation, found in 16 of the 21 courts, was named "multifocal convergence" by the researchers. It describes the combination of multiple, diverse authentication and traceability elements that together form a coherent chain of contextual evidence. What the courts assess is the whole picture: facial biometrics or an ID document with a selfie to show who performed the action, geolocation to show where it took place, and IP address to indicate which device was used. This trio became known as the "core convergence bundle."
Collecting more data isn't the same as verifying well
The TJGO case is the strongest argument available today against the logic of accumulation. In the contracts upheld by the court, the study identified 23 instances of authentication methods and 25 pieces of evidence. In the invalidated contracts, those numbers rise to 288 authentication methods and 141 pieces of evidence.
The operations that collected the most were the ones that lost the most. The sheer number of layers did not make up for the lack of coherence among the signals presented. For the courts, what determines whether a contract is valid is the evidentiary convergence among the elements, not the number of technological mechanisms used.
Identity verification isn't the opposite of data protection
There is a notion that verifying identity and protecting data pull in opposite directions, with one process demanding more information and the other demanding less exposure. But the problem isn't just the amount of data collected; it's how that data is organized. When each security layer holds its own set of information, and the signals don't talk to each other, the result is more data in circulation and less real ability to protect the operation.
Roberto Ferlis, Vice President of Compliance and Legal at Certta, summed up the risk of the fragmented model in remarks made during the discussion of the FGV study, held in May 2026 under the Chatham House Rule.

"If fraud is so sophisticated that it gets past three challenges, we catch it at the fourth. That's why fragmentation is so dangerous." Roberto Ferlis
While fraudsters operate in an integrated way, many companies still structure their defenses in isolated layers, each collecting its own set of data without the signals talking to each other. The result is the opposite of what both sides are after: more data stored unnecessarily, and less effectiveness in identifying who is actually attempting fraud.
The LGPD's necessity principle and what it requires of identity verification
Behind every identity verification lies an operational definition: the minimum data needed to confirm who a person is, without collecting anything beyond that. Article 6, item III, of the LGPD establishes the necessity principle, which limits data processing to the minimum required to achieve its purposes, covering only data that is relevant, proportionate, and not excessive. This is the provision the market commonly refers to as data minimization.

According to Duarte, processing data is necessary to protect the data subjects themselves, but collecting data should be avoided whenever possible. The challenge arises when the goal is to confirm identity, a process that requires cross-checking a range of different sources to ensure reliability.
Practices that reconcile data minimization with strong evidence
Calibrate the level of validation to the risk of the interaction. Strengthening verification when there are risk signals, and reducing friction when exposure is lower, avoids putting every user through the most invasive flow available, which also meets consumers' own expectations. According to Salesforce's State of the Connected Customer report, 73% of consumers expect companies to personalize their experience, even in digital environments. Risk-based calibration is also the criterion that regulation now requires for age verification.
Preserve the signal, not the raw data. Keeping an auditable record that the geolocation was consistent with the declared address is different from storing the user's location history indefinitely. The FGV study calls this set of practices "digital evidentiary governance," involving organized record preservation, auditability, and the ability to turn technical data into evidence that courts can understand.
When data has already leaked, detecting inconsistencies in identity authentication becomes the defense
Data such as the CPF (Brazil's individual taxpayer ID), full name, and date of birth frequently circulate in the market and can be used to open an account, take out a loan, or apply for a credit card in someone else's name.
This is where the difference between bureaucratic verification and intelligent verification comes in. Even when basic data has been exposed, a well-structured flow can identify inconsistencies that fraudsters struggle to reproduce coherently, without adding extra friction for legitimate users:
- The photo on the ID document doesn't match the selfie submitted, breaking the biometric layer;
- The same data appears in simultaneous attempts from different locations, breaking the geolocation layer;
- The behavior doesn't match the declared profile, breaking the contextual traceability layer.
Each of these signals corresponds to an element of the bundle of evidence that courts now recognize. When captured from the outset, they simultaneously provide a defense against fraud and the proof that upholds the contract in a future dispute. The evidence doesn't need to be reconstructed after the incident, because it is built into the verification process from the start.

"Leaked data is gold for fraudsters. But with a well-structured verification process, it's possible to stop these attempts even when the data is already out there." Iuri Duarte
Verifiable credentials: the technical horizon of the problem
For Yasodara Córdova, a researcher and consultant in Privacy and Digital Identity, the debate over digital identity has, in practice, become a debate about trust.
"In complex systems, trust doesn't come from a single piece of evidence, but from the ability to interpret context, combine different signals, and make decisions proportionate to the risk," she says.

She points to the structural origin of the problem. From fingerprint records to digital documents with QR codes, identification systems were designed with one central goal: enabling access.
"Solutions have always been designed to grant access, not to protect data. That's a very recent concern when it comes to government," she notes.
The technical path to resolving the dilemma between minimal collection and robust proof already exists, at least conceptually. Instead of transmitting complete identity data, the system confirms only the attribute needed for that specific interaction, and no additional information is shared. This is the model the researcher presented at Conexão Certta while discussing the ECA Digital.
"The best approach is to use a technology we call verifiable credentials, in which the only information transmitted is whether or not the person falls within that age range." – Yasodara Córdova
The limitation lies in large-scale implementation, which remains difficult in the current environment. While the model matures, the available answer is the one the courts already recognize: cross-checking independent sources, storing the minimum, and preserving the coherence of the whole.
"Verifying identity is protecting data, because without knowing who is on the other side, you can't protect anyone: not the data subject, and not the business itself." – Iuri Duarte, Privacy and Data Protection Specialist at Certta
This is the logic behind Certta's verification intelligence hub. Every signal captured throughout the user journey makes it possible to produce and preserve, from the outset, the body of evidence that courts recognize as robust proof of digital authorship, with data collection limited to what the purpose requires.
Want to learn more about where security and privacy meet? Follow the Digital Trust section and see how the topic is evolving in Brazil.
Sources
- Interviews with Roberto Ferlis, Iuri Duarte, and Yasodara Córdova, conducted for this article.
- Autenticação de Usuários, Identidade Digital e Aferição de Idade (User Authentication, Digital Identity, and Age Verification), a study by the E-commerce Studies Center (NEEC) at FGV Law School in Rio de Janeiro (FGV Direito Rio), covering 2,083 appellate rulings from 21 state courts collected between January 2023 and September 2025. Executive summary available on the FGV Direito Rio website (in Portuguese).
- Global Cybersecurity Outlook 2025, World Economic Forum (WEF).
- Law No. 15,211/2025 (ECA Digital) and Decree No. 12,622/2025.
- Decision by Brazil's National Data Protection Authority (ANPD) on the implementation timeline for the ECA Digital.
- Law No. 13,709/2018 (LGPD), Article 6, item III.
- Presentation by Yasodara Córdova at the Conexão Certta event, São Paulo, March 23, 2026.


