Platform Security · 14 min read

Brazil’s Discord Video Restriction Is a Test of Proportionality — and of What Privacy Tools Are For

Brazil’s ANPD ordered Discord to suspend Go Live and equivalent live-video or video-sharing functions, not the whole service. The impact on creators is immediate, while Law 15.487/2026 raises a separate, narrower question: how should a child-protection law treat lawful privacy tools?

Published by PrivacyWarden Editorial.

What has changed — and what has not

Brazil’s data-protection authority, the ANPD, ordered Discord to suspend Go Live in Brazil and to suspend equivalent live-video or video-sharing functions until the company demonstrates effective measures to protect children and teenagers. The order is a preventive administrative measure, not a nationwide order to block all of Discord. The ANPD says text, voice, and other legitimate uses of the service are not the target of this specific measure. 1

That distinction matters. It would be inaccurate to say that Discord has been fully banned in Brazil. It would also be misleading to pretend that a restriction focused on live video has no serious practical cost. For creators, community moderators, accessibility volunteers, teachers, friends, and families, live visual communication is often the work itself: a camera check-in, a shared screen for technical help, a collaborative review, a small event, or a broadcast that relies on real-time participation.

The verified scope deserves careful wording. The ANPD’s published notice names Go Live and equivalent live-video or video-sharing functions. It does not publish an exhaustive, feature-by-feature list of every client behavior. That means reports of camera or screen-sharing impact should be understood as a real-world creator concern and implementation question, not a reason to claim facts beyond the official notice. The correct question is not whether those workflows matter. They plainly do. The question is whether the response is proportionate, technically defensible, and transparent about what users lose while a platform works through a safety order.

The child-safety concern is serious. So is the remedy’s human cost.

The ANPD says it acted after identifying what it describes as robust evidence of failures to prevent or mitigate severe harms to children and adolescents, including material involving violence, self-harm, and suicide. Its notice says the agency considered Discord’s live-video architecture and its reliance on reports and automated systems inadequate for the risks it identified. 1

Those are grave allegations. A platform should not be permitted to treat child safety as an optional afterthought, and a public discussion about this case should not minimize violence against young people. Discord told Reuters that the decision was premature, while BBC reporting quoted the company as saying that groups promoting violence have no place on the service, that it shut down the invite-only server involved, and that it was cooperating with law enforcement. 2 3

But a serious objective does not remove the need for a serious standard of proof, a clear scope, an appeal path, and a public explanation of what will restore the affected functions. A targeted suspension may be more proportionate than blocking an entire service; the ANPD explicitly says it is not blocking Discord. Still, any feature-level restriction should have measurable criteria, a transparent timetable, independent review where the law provides it, and a way to evaluate whether the intervention reduces harm rather than merely moving it somewhere less visible.

Why creators feel the loss immediately

For someone whose work depends on live communities, a visual feature is not a decorative extra. It can be a safety tool, a collaboration tool, an accessibility tool, and a source of income. The loss of screen sharing can make remote troubleshooting and moderation harder. The loss of camera-dependent or live-video workflows can remove low-friction ways to check in with trusted people, review creative work, host a small class, or share a performance with a community.

· Function under pressure · Legitimate creator and community use · What a proportionate response should explain · · Live video / Go Live · Events, performances, classes, watch-alongs, community updates · Which risk the restriction addresses and what evidence permits restoration · · Screen sharing · Technical help, collaborative work, moderation review, accessibility support · Whether the implementation affects the feature, for whom, and how users can appeal or obtain support · · Camera-based participation · Private check-ins, interviews, small-group collaboration, sign-language or visual communication · How the service can protect minors without treating every visual interaction as suspect ·

This is not an argument that platforms should leave known harms unaddressed. It is an argument that policy should recognize the people who use communication tools responsibly. Treating every affected person as collateral damage is not a safety strategy. It is a failure to design for the actual public.

The separate issue in Law 15.487/2026: privacy tools are not illegal

The current Discord measure and Law 15.487/2026 are related in public debate, but they are not the same action. Law 15.487/2026 added Article 226-A to the Brazilian child-and-adolescent statute. The provision raises the penalty by one-third to two-thirds when an offender commits a qualifying offence using a proxy modulator or a technique to mask, hide, falsify, alter, or anonymize an IP address or other digital identifier with the objective of preventing or making identification difficult. 4

The statutory text also contains a crucial safeguard: it says the provision does not apply to legitimate use of digital privacy and security technologies for lawful purposes, including personal or commercial data protection, privacy, and cybersecurity. 4

That is why the headline shorthand “VPN use is an aggravating factor” needs care. A VPN is not prohibited by this text. Ordinary lawful use is not, by itself, a penalty. The provision concerns a specified criminal context and an identified purpose of obstructing identification. Anyone facing a real legal question should obtain advice from a qualified lawyer, not rely on a blog post or a social-media summary.

The safeguard does not make the policy debate disappear. A broad list of covered technologies can still create uncertainty and chill legitimate security practices if users, employers, journalists, survivors, or small organizations fear that ordinary protective tools will be interpreted through suspicion. The Brazilian Internet Steering Committee, CGI.br, made this point before enactment: it supported child protection while warning that the language covers a broad set of technologies with essential security, privacy, and operational uses. 5

Why the warning about VPNs deserves support — on the precise facts

The report from Reclaim The Net that drew attention to this issue gets an important public-interest question right: a society should not casually normalize the idea that the use of a privacy or security tool makes a person inherently more suspicious. Its report also notes that the law does not make VPNs illegal. 6

PrivacyWarden supports that central warning. VPNs, proxies, encrypted tunnels, and other protective tools are used by people who need safer communications: employees connecting to work systems, hospitals protecting data, journalists protecting sources, people facing harassment, researchers, families on unsafe networks, and ordinary users who do not want an Internet provider to profile every destination they visit. Internet Society Brazil and its partners argued before enactment that the concern about Article 226-A was narrow and technical, not opposition to the law’s child-protection goals. 7

The better public position is therefore not “privacy tools excuse crime,” nor “privacy tools themselves prove criminal intent.” Both are wrong. Criminal conduct should be investigated and prosecuted with evidence, due process, and safeguards. Lawful security practice should remain lawful security practice. A sound child-safety policy can do both.

The AI disclosure: what it actually says

There is another issue in the official legislative record that deserves attention. The Senate page for PL 3066/2025 includes a plain-language “Entenda a proposta” explanatory panel labeled as generated by artificial intelligence with human review. That disclosure applies to the explanatory summary presented on the page. 8

It does not establish that the bill text, amendments, parliamentary deliberation, vote, or enacted Law 15.487/2026 was written by AI. Saying that the law itself was AI-authored would overstate the evidence and make the public discussion less trustworthy.

The disclosure still matters. A legislative explainer can influence how people understand their rights, obligations, and risks. “Human review” is not a complete answer unless the institution also makes clear what material was summarized, who was responsible for review, what limitations the generated explanation has, and where readers can reach the authoritative text. The official law and its legislative history must remain the reference point. AI summaries should be clearly subordinate to those primary materials, especially when criminal penalties, privacy, or platform access are involved.

Editorial position: AI can assist public institutions with navigation and plain-language explanations only when provenance, human accountability, correction routes, and a direct path to the authoritative legal text are visible. It cannot replace legislative judgment, legal drafting accountability, or a citizen’s right to know what the law actually says.

What a better response looks like

A durable response to child-safety failures should be narrower than a demand to remove an entire communications service and more ambitious than a temporary feature switch. It should require platforms to publish meaningful safety evidence, establish accountable escalation pathways, support affected users, and show how technical safeguards work in practice. It should also be evaluated against independent evidence: did the change reduce the documented risk, and at what cost to legitimate users?

For the legal framework, the next step is careful implementation and scrutiny. Prosecutors and courts should apply Article 226-A according to its offence-specific and intent-based wording, including its explicit protection for legitimate privacy and security technology. Policymakers should listen to technical organizations when they say that security infrastructure is not a sign of wrongdoing. And public agencies should resist turning a tragedy into a reason to make ordinary private communication less safe for everyone.

Practical guidance for affected communities

If live visual functions are unavailable, document the exact feature, date, client version, and official notice shown to you. Do not post account identifiers, private server links, personal IP information, or screenshots containing private messages. Check Discord’s official notices and the ANPD process for changes or appeal outcomes. If your work depends on a visual feature, prepare a privacy-respecting backup communication plan with your team before a live event rather than improvising in public.

Do not treat an access restriction as a reason to weaken your account security, disclose identity documents to unverified parties, install unknown “fix” software, or follow unverified instructions that claim to restore a feature. Preserve your privacy, verify the source of any notice, and separate a platform-access problem from a security emergency.

The principle worth keeping

The tragedy that prompted this enforcement action deserves a response that protects young people. The people who use Discord for ordinary creative, educational, social, and support work deserve a response that remains proportionate, reviewable, and transparent. The people who use a VPN or other privacy technology for lawful reasons deserve not to have a fundamental security practice treated as a character flaw.

Those principles can coexist. They have to. A safer Internet is not one where communication becomes more vulnerable, law becomes harder to read, or entire communities lose normal tools without a clear path back. It is one where safety measures are evidence-led, rights-respecting, technically literate, and accountable to the people they affect.

Explore all PrivacyWarden guides