By Paulo Perrotti, lawyer specialized in Compliance, Data Protection, and Cybersecurity, and Coordinator of the Compliance and ESG Committee of the Chamber of Commerce Brazil-Canada*
The protection of children and adolescents in the digital environment has become, in recent decades, one of the most urgent issues in contemporary law. With the exponential growth of minors’ access to the internet — whether through social media, applications, games, streaming platforms, or educational services — the risks associated with the indiscriminate collection of personal data, exposure to inappropriate content, and behavioral manipulation have become central topics on the legislative agendas of governments around the world.
Brazil and Canada have followed different paths in this regulatory journey, yet they have arrived at notable points of convergence. Brazil, after years of parliamentary debate and strong mobilization from civil society, enacted the so-called Digital ECA in 2025 and regulated it in March 2026. Canada, in turn, operates under a fragmented regulatory framework — centered on the Personal Information Protection and Electronic Documents Act (PIPEDA) and the guidelines of the Office of the Privacy Commissioner (OPC) — and is advancing toward the development of a specific children’s privacy code.
The purpose of this study is to analyze both systems, their similarities, differences, and the lessons each can offer the other. Most importantly, however, it seeks to examine what this comparison means for companies operating — or intending to operate — in both countries.
2. The Brazilian Digital ECA: A New Legal Framework for Digital Childhood
The Digital ECA — officially named the Digital Statute of the Child and Adolescent — was enacted in September 2025 and entered into force on March 17, 2026, the same date on which it was regulated through presidential decrees. The text is the result of more than three years of debate in the National Congress and represents the regulatory consolidation of the digital protection of minors in Brazil, complementing the 1990 Statute of the Child and Adolescent (ECA) and the 2018 General Data Protection Law (LGPD).
The legislation applies to any information technology product or service directed at children and adolescents, or that may be accessed by them, regardless of where the provider company is headquartered. This is a significant point: there is no territorial shield. A Canadian company offering an application accessible to Brazilian minors is, in principle, subject to the Digital ECA.
2.2 Main Obligations and Prohibitions
The Digital ECA structures the digital protection of minors around four fundamental pillars:
a) Data Protection and Privacy
The law reinforces and expands, within the digital context, the provisions of Article 14 of the LGPD, which already established the principle of the best interests of the child as the guiding standard for any processing of minors’ personal data. Among the main obligations are:
- Mandatory linkage of accounts belonging to children and adolescents up to 16 years old to a legal guardian;
- Prohibition of behavioral profiling and tracking techniques for targeted advertising aimed at minors;
- Restriction on excessive data collection and on the monetization of content that promotes the sexualization of children;
- Mandatory provision of accessible and user-friendly parental control tools.
b) Content Moderation and Removal
Platforms are now required to immediately remove content related to child abuse or exploitation, with automatic notification to the authorities. The text establishes mechanisms for the immediate reporting of grooming, harassment, and sexual exploitation cases, and created the National Center for the Protection of Children and Adolescents, linked to the Brazilian Federal Police.
c) Age Verification and Parental Control
The Digital ECA prohibits self-declared age as the sole verification mechanism for websites and services restricted to individuals over 18 years old. Platforms must adopt technically robust age verification systems — a significant point of friction for the industry, given the costs and technical complexity involved.
d) Enforcement
The National Data Protection Authority (ANPD) was structured to oversee compliance with the new law, with sanctioning powers. The creation of a national reporting center and the assignment of responsibility to platforms — rather than solely to users — represents a major shift in Brazil’s enforcement approach.
2.3 The LGPD as a Complementary Foundation
Article 14 of the LGPD remains the cornerstone of the protection of minors’ data within the Brazilian legal framework. It establishes:
- Specific and prominently displayed consent from at least one parent or legal guardian for the processing of children’s data;
- Transparency regarding the types of data collected, the manner in which such data is used, and the procedures available for exercising data subject rights;
- Prohibition against conditioning participation in games and applications on the provision of data beyond what is strictly necessary;
- The controller’s responsibility to undertake all reasonable efforts to verify the validity of parental consent.
The combination of the LGPD and the Digital ECA creates one of the world’s most comprehensive regulatory frameworks for the digital protection of minors — while simultaneously imposing significant operational challenges on companies operating in the sector.
3. The Canadian Framework: PIPEDA, the OPC, and the Emerging Children’s Privacy Code
3.1 Absence of a Specific Law and PIPEDA
Unlike Brazil, Canada does not yet have a specific federal law dedicated to the protection of children’s online privacy. The current legislation — PIPEDA — was designed in the 1990s with a focus on commercial relationships and adopts a consent-based protection model that does not distinguish between adults and minors. The Privacy Commissioner himself has publicly acknowledged that PIPEDA is insufficient to address the specific challenges of children’s privacy in the digital environment.
Bill C-27 (Digital Charter Implementation Act, 2022), which proposed the modernization of Canada’s privacy framework through the creation of the Consumer Privacy Protection Act (CPPA), included more robust provisions regarding children’s protection and was widely debated in Parliament. However, as of the date of this article, the bill had not yet been fully approved, and the Canadian legislative process remains ongoing.
3.2 The OPC and the Children’s Privacy Code
In May 2025, the Office of the Privacy Commissioner of Canada (OPC) launched an exploratory consultation for the development of a Children’s Privacy Code, with the objective of aligning Canadian practices with the international landscape — particularly the United Kingdom’s Age Appropriate Design Code — and establishing clear expectations for the sector.
The OPC’s Strategic Plan for 2024–2027 identified as its third strategic priority ensuring that “children’s privacy is protected and that young people can exercise their privacy rights.” This represents a clear institutional direction, even though it does not yet carry the binding force of a specific law.
3.3 The 2026 GPEN Sweep and Its Concerning Findings
On March 25, 2026, the OPC, together with 26 privacy regulatory authorities that are part of the Global Privacy Enforcement Network (GPEN), conducted a sweep of nearly 900 websites and applications used by children. The results, published on the same date, revealed both progress and persistent gaps.
Progress observed since 2015:
- Age verification increased from 15% to 45% among the websites and applications analyzed;
- The availability of account deletion features rose from 29% to 64%;
- Good practices were identified, such as warnings advising children not to use their real names, location services disabled by default, and filtered chats for younger users.
Persistent concerns:
- Age verification mechanisms are still frequently easy to circumvent, especially when based on self-declaration;
- 85% of privacy policies indicate that personal information may be shared with third parties — compared to 51% in 2015;
- Only 25% of websites and applications involving high-risk data processing and child-oriented content provide parental control dashboards;
- 35% contained content inappropriate for children, while 38% included high-risk data processing functionalities;
- Behavioral profiling features were identified in combination with content related to self-harm and eating disorders.
4. Comparative Analysis: Points of Convergence and Divergence
| Aspect | Brazil (Digital ECA + LGPD) | Canada (PIPEDA + OPC) |
| Specific law for minors online | Yes (Digital ECA, 2025) | No (currently under development) |
| Principle of the best interests of the child | Expressly provided for (LGPD, Article 14) | Mentioned in Bill C-27; currently non-binding |
| Parental consent | Mandatory for children’s data (LGPD) | No specific legal obligation (PIPEDA) |
| Age verification | Mandatory; self-declaration prohibited | Encouraged; no federal legal obligation |
| Behavioral profiling | Prohibited for minors | No specific legal prohibition |
| Parental control | Mandatory for platforms | Encouraged by the OPC; no legal obligation |
| Enforcement | ANPD + National Protection Center | OPC (limited powers under PIPEDA) |
| Sanctions | Administrative fines (ANPD) | Limited under PIPEDA; more robust under Bill C-27 |
The most striking difference between the two systems is structural: Brazil adopted a proactive and centralized legislative approach, while Canada still operates largely through non-binding guidelines and regulatory pressure from the OPC — although the environment is clearly evolving toward stricter regulation.
5. Implications for Companies Operating in Brazil and Canada
For companies with operations in both countries — or that offer digital products and services accessible to children — the current regulatory landscape requires heightened attention in at least five areas:
- Audience Mapping: identifying whether the product or service may be accessed by minors and to what extent, both for purposes of the LGPD/Digital ECA and the Canadian OPC guidelines.
- Adaptation of Consent Mechanisms: ensuring that parental consent is effective, verifiable, and properly documented — especially regarding children’s data in Brazil.
- Review of Privacy Policies: policies must be drafted in accessible language, include specific sections for minors and their guardians, and may not simply redirect data processing responsibilities to third parties without transparency.
- Implementation of Technical Controls: age verification, parental control dashboards, and the default deactivation of location tracking and profiling functionalities for users under 18 years old.
- Governance Structure and Incident Response: reporting channels, content removal procedures, and incident notification mechanisms to authorities must be fully operational before regulators come knocking.
The digital protection of children and adolescents is, above all, a matter of human rights. Brazil’s Digital ECA represents a qualitative leap within the national legal framework — and it arrives at a crucial moment, given that the digital environment has become a space of risks as concrete as the physical risks the 1990 ECA sought to mitigate.
Canada, in turn, is currently undergoing a transitional period: the existing framework (PIPEDA) is widely recognized as insufficient, the legislative modernization process continues at a slow pace, but the OPC has demonstrated growing regulatory leadership — as illustrated by the 2026 GPEN Sweep conducted in partnership with 26 privacy authorities from around the world.
The comparison between the two systems reveals that there is no single correct path for protecting children’s privacy. However, it also demonstrates, with equal clarity, that regulatory omission carries a real and measurable cost — and that today’s children cannot wait for the law to someday catch up with the speed at which technology evolves.
For companies, the message is direct: compliance is not optional, it is an obligation. And for those who have not yet begun, the best time was yesterday. The second-best time is now.
*This article is intended for informational purposes only and does not constitute legal advice. For the analysis of specific cases, consultation with a lawyer specialized in data protection and digital compliance is recommended.
- BRAZIL. Law No. 13,709, of August 14, 2018. General Data Protection Law (LGPD). Official Federal Gazette, Brasília, DF, Aug. 15, 2018. Available at: Planalto Official Website. Accessed on: Apr. 9, 2026.
- BRAZIL. Law No. 15,211, of September 17, 2025. Digital Statute of the Child and Adolescent (Digital ECA). Official Federal Gazette, Brasília, DF, Sept. 18, 2025.
- BRAZIL. Decree No. 12,880, of March 17, 2026. Regulates Law No. 15,211 of September 17, 2025, concerning the protection of children and adolescents in digital environments. Official Federal Gazette, Brasília, DF, Mar. 18, 2026.
- BRAZIL. Ministry of Justice and Public Security. Digital ECA. Brasília, 2026. Available at: Ministry of Justice – Digital ECA. Accessed on: Apr. 9, 2026.
- BRAZIL. Federal Government. Brazilian Government Regulates the Digital ECA: A New Milestone in the Protection of Children and Adolescents in Digital Environments. Brasília, Mar. 17, 2026. Available at: Brazilian Digital Government Portal. Accessed on: Apr. 9, 2026.
- Demarest Advogados. Digital Statute of the Child and Adolescent – Law No. 15,211/2025: Guidebook. São Paulo, 2026. Available at: Digital ECA Guidebook PDF. Accessed on: Apr. 9, 2026.
- BRAZIL. Article 14: Personal Data of Children and Adolescents. In: LGPD Brazil – Commentary on the General Data Protection Law. Available at: LGPD Brazil – Article 14. Accessed on: Apr. 9, 2026.
- Office of the Privacy Commissioner of Canada. OPC Examines Websites and Apps Used by Children as Part of Global Privacy Sweep. Gatineau, Mar. 25, 2026. Available at: OPC News Release. Accessed on: Apr. 9, 2026.
- Global Privacy Enforcement Network. 2026: GPEN Sweep Report – Children’s Privacy. 2026.
- Office of the Privacy Commissioner of Canada. Strategic Plan 2024–2027: A Roadmap for Trust, Innovation and Protecting the Fundamental Right to Privacy in the Digital Age. Ottawa, 2024. Available at: OPC Strategic Plan 2024–2027. Accessed on: Apr. 9, 2026.
- CANADA. Parliament. Bill C-27: An Act to enact the Consumer Privacy Protection Act, the Personal Information and Data Protection Tribunal Act and the Artificial Intelligence and Data Act and to make consequential and related amendments to other Acts. Ottawa, 2022. Available at: Government of Canada Publications. Accessed on: Apr. 9, 2026.
- Gowling WLG. The State of Children’s Privacy in 2026: Key Risks and Takeaways. Montréal, 2026. (Translated article).
- Osler, Hoskin & Harcourt LLP. Insights into Canada’s Development of Children’s Privacy Framework. Aug. 19, 2025. Available at: Osler Insights Article. Accessed on: Apr. 9, 2026.

