Brazil’s Data Regulator Says Deepfake Risk Starts Long Before the Fake Video

Table of Contents

Spotting a fake clip is not the whole job. Brazil’s National Data Protection Agency made that case in the sixth issue of its Technology Radar, published 29 July. The paper walks through how synthetic audio, photos, and video get made and spread. It is not a new statute. It is a map of where harm actually begins.

That map matters outside Brazil. Any company that builds, buys, or runs tools that can invent a face or a voice is in the same stack: privacy, fraud, product design, vendor risk, and whether anyone still trusts a recording.

The agency’s role in the country’s digital rules is also getting larger. Decrees 12,975 and 12,976, issued in May 2026, gave the ANPD power to look at how platforms behave as systems and to oversee duties tied to digital fraud and AI used to generate or alter intimate content. The radar does not turn those decrees into a deepfake code. It shows the direction of travel.

Five stages, not one clip

The ANPD treats a deepfake as audio, a photo, or a video that AI has created or changed so it looks real and can pass for a person’s identity or actions. Ordinary edits still count as deception when they fool people. Cuts, speed changes, and dubbed audio can do that without a generative model. The radar still focuses on the AI path because that is where scale and realism have jumped.

It follows the life of the content under Brazil’s LGPD through collection, training, generation, editing, and distribution. Those five steps collapse into three practical phases: how the model was built, how a specific file was made, and how it moved once it left the tool.

Training is where a lot of teams stop asking questions. Faces, voices, gestures, and habits get scraped from social networks, news sites, and stock libraries, or uploaded by users. Sometimes they come from leaks. Public posting is not a free pass to mint a synthetic version of someone. Purpose, legal basis, and what a reasonable person would expect still apply. When the point of the processing is to identify someone from body or voice, the data can sit in the LGPD’s sensitive (biometric) bucket. That raises the bar.

At generation time the questions change. Who asked for the file? Did the person shown agree to the use of their image or voice? What does the product block when the request is fraud, abuse, or explicit content involving someone who never opted in?

Calling the end user the only “controller” because they typed the prompt is too neat. If the provider designed the system, chose the features, and can see repeat abuse, the LGPD analysis has to look at who actually decided what got processed. Civil liability is a separate test: unlawful processing, harm, and a causal link. Contract labels do not rewrite those facts.

Once it is out, deletion is late

Platforms, recommenders, hosts, and ad networks can move a file faster than any takedown queue. The original upload coming down after a complaint is required. It rarely ends the copies. The person’s face and voice keep traveling in places neither they nor the first company control.

The radar lists the harms Brazil is already living with: nonconsensual synthetic pornography, election lies, political violence aimed at women, payment scams, and ads that steal a public figure’s likeness. General elections are set for October 2026. Fabricated candidate statements, fake “ordinary voters,” and doctored images used to intimidate women in public life are not hypotheticals in that calendar.

Those cases are not only privacy cases. They hit public debate, how we authenticate people, and whether a video or voicemail still means anything.

The office voice that is not the CFO

In companies the same tools turn urgency and rank into a better con. A video call, a voice note, or a chat that looks like it came from an executive can be used to move money, change bank details, reset a login, or pull internal files. Approving a payment because the face and voice felt familiar is no longer a control. Neither is “it came through the usual channel.”

A firm that never generated the fake can still sit in the chain if it ships the product, plugs it into workflows, ranks the content, or makes money from the traffic. Who is a controller or processor turns on real decisions and real control, not the paragraph that says otherwise in the MSA. The contract can split the bill. It cannot erase duties owed to people and to the regulator.

Detection is a tool, not a program

The ANPD is blunt about detectors. Compression, low resolution, new generators, and skinny training sets produce misses and false alarms, and the error rate is not even across groups. One vendor’s “deepfake score” is not a strategy.

Start with inventory. What data goes in. Where it lives. Who touches it. Whether prompts, uploads, and outputs get reused to train the next model. Without that, you cannot assign roles or pick controls.

Risk is not uniform. An approved avatar for internal training is not the same as voice clone used as a login factor, a patient’s image, or anything involving children. Purpose, scale, who is depicted, fraud and discrimination risk, and how hard the harm is to unwind should set how hard you look.

Buyers should ask how the system was trained, what happens to files and prompts, whether those materials feed later models, and what the vendor will do to stop abuse, keep evidence, and take content down. The contract should match those answers. It still does not replace the legal analysis of who is doing what to personal data.

On the product side, useful controls depend on the use: stronger authentication, fewer dangerous features, blocked request types, logs, and a human in the loop when the output can move money or reputation. Watermarks, labels, signatures, and provenance standards can show where a file came from and how it was edited. They do not prove the scene is true. They only help if people can challenge the file and if fraud response actually uses that trail.

The radar does not pretend to close the subject. Its use is that it moves the conversation off the finished fake and onto the choices that made the fake cheap to create and hard to bury. For companies in Brazil that work has to happen while you can still pick the data, the vendor, the features, and the playbook, not after the clip has already done its tour.

Written by: 

Online Privacy Compliance Made Easy

Captain Compliance makes it easy to develop, oversee, and expand your privacy program. Book a demo or start a trial now.