Electronic Freedom Foundation
EFF and Allies on Brazil's Elections: Privacy Protections are Crucial to Electoral Integrity
EFF, Access Now, and Data Privacy Brasil are putting forward recommendations to strengthen robust privacy and data protection safeguards in the context of Brazil's elections. The recommendations stress the close relationship between violations of personal data protection and challenges to the integrity of electoral processes. They underscore how privacy and data protection guarantees are a crucial tool for curbing the targeted spread of false or manipulative content and other problematic strategies used by political actors that are amplified by digital technologies such as artificial intelligence systems.
The recommendations are part of a broader regional initiative and build on the legal and institutional safeguards already in place in Brazil. They seek to promote greater coordination among oversight institutions, civil society, and digital platforms, and encourage the solid implementation of privacy and data protection guarantees as drivers of electoral integrity. Read the full document below.
The Link Between the Integrity of the Electoral Process and PrivacyProtecting the integrity of the electoral process in the face of internet and social media use is a challenge that many policymakers are addressing or are willing to address. Online, content that can affect the integrity of the electoral process is increasingly personalized. This phenomenon is so concerning that it has been identified as one of the main global short- and medium-term risks.
In an era of generative AI, the economic cost and technical difficulty of producing and spreading false or synthetic content to deceive, manipulate, or simulate authenticity have been considerably reduced. That intensifies concern over the integrity of the electoral process. Meanwhile, online privacy and personal data protection remain unfinished business in Latin America.
There is an intrinsic connection between the ability to collect and process large amounts of personal data and the way false or manipulative content is created and distributed—on social media and messaging apps in particular, and on the internet in general. For this reason, applying strict laws and policies on personal data protection and privacy makes it possible to reduce the impact of false or manipulative content. This is especially important in electoral contexts, where such content affects and impoverishes public debate, directly affecting political and electoral rights and the integrity of the electoral process.
This phenomenon predates the emergence of the internet. However, the rise of new technologies accelerates the generation and spread of false and manipulative content. This is supported by the very economic model that sustains the platforms, amplifying its effectiveness and reach. On the one hand, social media platforms have content recommendation algorithms that use personal data to generate profiles to which they can then serve targeted advertising content, including explicitly political propaganda. This technique is known as "microtargeting."
Political microtargeting seeks to have a direct or indirect impact on democracy. It is used to persuade voters, to encourage or discourage turnout at the polls, or to raise funds using information that is deliberately taken out of context, inaccurate, or erroneous.
The control exercised by these companies raises serious concerns about people's rights. By having access to massive amounts of personal information, these companies have the ability to shape the content that users see and interact with. This happens through the construction of profiles that can reveal habits, social relationships, political preferences, and opinions, to mention a few examples. Personal data is the fuel that amplifies risks to the integrity of the electoral process. That’s true whether it’s provided by the users themselves or generated by the platforms from their interactions online.
For disinformation actors, access to sophisticated tools—such as those used to create "deepfakes" through generative AI, or "bots" programmed to spread content and seek to manipulate public opinion—boosts the effectiveness of this microtargeting in terms of quality and scalability, making it harder to detect as false or manipulative content. AI-generated avatars and synthetic characters that simulate voters, influencers, hosts, commentators, or community leaders can produce footage that appears spontaneous, fabricate the voices of artificial political actors, and make it harder for users to identify if a given public statement was created or mediated by technology.
In this context, paid promotion with nanotargeting seeks to reach increasingly specific profiles with customized content, and AI-based tools are used to assess and map its impact on social networks. Drawing on the personal data of groups of voters, profiles of "synthetic voters" are created to test messages or strategies in search of the most efficient way to influence real voters.
This rapid expansion of AI systems and hyper-personalization with data can lead to a problem of "epistemic erosion" for democratic societies, as pointed out by the UN's Independent Scientific Panel on AI Governance in 2026.
At Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation, we point to the enforcement of personal data protection laws and public privacy policies as an efficient mechanism for improving the quality of our democracies and reducing the manipulation of public discourse in digital environments and its impact in electoral contexts. Measures to broaden access to information for electoral decision-making, and to ensure transparency about campaigns' and political parties' use of digital technologies built on the massive processing of personal data, also play a relevant role in guaranteeing the integrity of the electoral process.
Recommendations for Safeguarding the Integrity of Electoral Processes in Brazil in the Face of New TechnologiesConcern about the effects of spreading false, manipulative, or deliberately decontextualized content is particularly heightened in electoral contexts. From Argentina to Mexico, many countries in Latin America, including Brazil, are holding or will hold significant electoral processes in the coming period.
Providing the public with quality information from a range of sources is an essential element for the exercise of political rights. In order to safeguard the electoral process, these countries must enforce their privacy and personal data protection laws through their competent authorities, in coordination with their judiciaries and electoral courts.
Access Now, Data Privacy Brasil, and the Electronic Frontier Foundation propose the following recommendations to protect the integrity of the electoral process by guaranteeing privacy and data protection during electoral contexts:
1. Strengthen personal data protection guarantees and policies as a key element for the integrity of the electoral process, in particular the principles of necessity, purpose, and proportionality:
- Prohibit the processing of sensitive personal data (such as philosophical beliefs and the labeling of ideological leanings), including inferred data, that reveals or could reveal people's political preferences for the purpose of targeting political content. In electoral contexts, the processing of sensitive personal data is only legitimate when the person has given their consent in advance, explicitly, and with strictly limited and clearly disclosed purposes of use and transfer.
- Processing must be carried out only on personal data that is strictly necessary for the purpose being pursued.
- Prohibit adding users to instant messaging groups for political outreach purposes, except in exceptional cases involving lists of political party members or where prior and informed consent has been given by the data subject.
- Free, specific, and informed consent means that the person is able to make a real choice, set apart from other choices, and does not run any risk of deception, intimidation, coercion, denial of access to products or services, or other significant negative consequences if they do not give their consent.
2. Political parties, federations, and coalitions must improve the information made available to the general public about their personal data processing activities in electoral contexts, including:
- The personal data processing policy adopted, in compliance with data protection legislation and electoral legislation, including the measures adopted to prevent breaches of the general protection principles, to record personal data processing operations, to obtain consent appropriately, and to ensure technical and administrative security in data processing;
- Communication channels where the data subject can obtain information about the processing of their personal data, exercise the rights provided by law, and request to opt out of receiving electronic and instant messages.
- Information about the profiling they carry out for electoral purposes and about the procurement and use of data-based digital technologies in this context, including for purposes of paid promotion, microtargeting, network analysis, and prediction of voters' reactions or behavior.
3. Strengthen cooperation mechanisms between the National Data Protection Authority (ANPD) and the Superior Electoral Court in order to:
- Improve communication channels and strengthen joint initiatives to oversee compliance with data protection guarantees in the electoral context, with the publication of periodic enforcement reports.
- Identify and dismantle coordinated strategies that compromise the integrity of the electoral process and carry out online activities that pretend to be "organic" and citizen-based when they are in fact funded or coordinated by a party, government, or company, such as bot farms, fake personal accounts managed by a single entity, AI avatars and synthetic characters that simulate real voters in order to manipulate public opinion, among others.
- Within the scope of their powers, require the preparation and publication of a data protection impact assessment in cases involving the use of sensitive personal data or emerging technologies for voter profiling.
4. Authorities, political parties, communicators, and social media platforms must ensure, as far as possible, that the population has access to adequate and relevant information for electoral decision-making.
- Political parties, electoral authorities, and data protection authorities must allocate a percentage of their communications budget to warning about the consequences of microtargeting in electoral contexts; and about the use of AI avatars or synthetic voters to simulate support, rejection, outrage, or spontaneous political mobilization.
- Strengthen alliances with fact-checkers and other relevant communicators, such as civil society organizations, influencers, and others, to identify campaigns that compromise the integrity of the electoral process and to inform the public about such alliances through different channels, including official government channels.
- Systematize the electoral proposals developed by candidates and their electoral platforms according to thematic areas to facilitate comparison between political parties.
- Agree on strategies between authorities and online platform companies, including social media platforms and chatbots, at the start of electoral periods, so that priority is given to content developed by electoral authorities.
- Every body, protocol, or policy created that involves authorities or public entities must be communicated in accordance with proactive transparency standards.
5. Platforms must disable microtargeting tools for political and electoral content during previously established periods.
6. Authorities, technical actors, academics, civil society, and/or social media platforms must collaborate in creating an algorithmic impact analysis lab that makes it possible to oversee compliance with these recommendations.
- Produce reports on the results achieved, in particular those that document the existence of microtargeting, the use of personal data for targeting, and exposure to varied content in electoral contexts.
- Establish strict cybersecurity protocols so that the labs prevent access to real users' private information.
7. The authorities responsible for overseeing personal data protection and electoral matters must have sufficient functional, economic, and technical autonomy and independence to guarantee the proper exercise of their powers.
A List of ICE Subpoenas to Tech Companies
Immigration and Customs Enforcement (ICE) has conducted unlawful investigations into dozens of individuals who have documented ICE activities in their communities, social media users who criticized the government, and international students who attended a protest.
A favored tool in these speech chilling investigations are administrative subpoenas sent to technology companies, requesting basic subscriber data about their users. For example, from 2018 to 2020, ICE sent nearly 500 administrative subpoenas to Meta, Google, and Twitter (now X), according to documents obtained by Just Futures Law. In just the second half of 2025, the Department of Homeland Security (DHS) sent 21 administrative subpoenas to Reddit, according to its Transparency Report.
While some subpoenas are routine, ICE has been forced to withdraw others after users challenged them in court or companies pushed back. These challenged subpoenas exceeded the agency's statutory authority and violated users' First Amendment rights.
Below is a non-comprehensive list of DHS subpoenas that we gathered going back to 2025, looking at public reporting and court cases. This is likely an undercount. The full scope is hard to pin down because these subpoenas typically only come to light when a user is given notice and challenges them in court, or when a company documents them in a transparency report (so far, only Reddit appears to break out specific numbers on DHS subpoenas). In addition, DHS has been slow to respond to our Freedom of Information Act requests and lawsuits seeking records that would show how many administrative subpoenas ICE has sent to social media companies since 2025.
If you know of other subpoenas that are not on this list, please reach out to info@eff.org. While the government has abused the subpoena process in other areas, particularly to hospitals, this list focuses on DHS and ICE subpoenas to technology companies for user data.
DATE ISSUED
(and link to subpoena)
TARGETED COMPANY INDIVIDUAL USER TARGETED OUTCOME 3/17/25 Facebook Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 3/23/25 Google Momodou Taal, international student who attended pro-Palestinian protest Withdrawn 4/1/25 Google Amandla Thomas-Johnson, international student who attended pro-Palestinian protest Google disclosed data to ICE on 5/8/25 9/4/25 Meta 6 accounts in Southern California that documented immigration activity, including LB_Protest, Long Beach Rapid Response Network, and Stopice.net Withdrawn after court challenge on 11/24/25 9/11/25* Meta (Instagram) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 9/11/25* Meta (Facebook) Pennsylvania account called "MontCo Community Watch" that documented immigration activity Withdrawn after court challenge on 1/16/26 10/30/25 Google Retired Philadelphia user who emailed criticism to U.S. prosecutor Withdrawn after court challenge on 2/5/26 2/4/26* Google Social media user who regularly posts criticism of the President Subpoena challenged in Court 2/19/26* Reddit "Tired_Thumb," user who posted about ICE officer Withdraw after court challenge on 3/27/26; replaced with grand jury subpoena 2/27/26* X "podslurp,” who posted publicly available address information about ICE officer Withdrawn May 2026; replaced with grand jury subpoena 3/7/26 PayPal/Venmo "Voices of Racial Justice," a racial justice organization in Minnesota PayPal/Venmo disclosed data 3/20/26 4/3/26* Google (YouTube) @TheDonLemonShow, GeorgiaFort, @DemocracyNow, and seven other accounts that reported on protest at Minnesota church Google Objected 4/7/26 4/12/26* T-Mobile Minnesota journalist Georgia Fort and others T-Mobile disclosed data on 4/12/26 First half of 2025 Reddit Reddit account Subpoena withdrawn after questions from Reddit Second half of 2025 Reddit 11 Reddit accounts that posted content "critical of ICE actions" 3 subpoenas withdrawn after Reddit objected* = denotes summonses issued under 19 U.S.C. 1509, an authority that has been abused in the past, according to DHS's inspector general.
EFF's Policy Position on ALPR Surveillance: Eliminate It and Reduce Its Harms
Automated license plate readers (ALPRs) build a searchable map of everywhere a driver goes, fed into databases that police, ICE, and private vendors can query after the fact. Networked across a city, ALPRs are purpose-built to track everyone regardless of suspicion. ALPRs are not a surveillance tool that can be made safe with the right policy or feature update—they are irredeemably harmful.
EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines.
EFF's position is that ALPR mass surveillance—the indiscriminate, continuous collection and retention of location data on every driver, regardless of suspicion—should not exist. Because it nonetheless does, EFF also urges courts and state legislatures to impose strict, enforceable restrictions, such as warrant requirements and deletion deadlines. EFF applies every tool available to eliminate ALPR surveillance and the harm it enacts.
The Case Against ALPRsA note about scope: This post addresses ALPR mass surveillance. It does not address the wider universe of automated traffic enforcement (ATE) such as conventional red light and speed cameras that solely ticket a specific violation, without retaining or networking data on uninvolved drivers. But lawmakers and purchasers should guard against efforts by vendors to piggyback on ATE contracts to market ALPR mass surveillance systems.
ALPRs are frequently marketed as a narrow tool for specific purposes, such as recovering stolen vehicles. But in practice, these sensors sweep up data on every driver who passes a camera, and store it in searchable databases. That indiscriminate collection and retention is precisely why ALPR-fed surveillance systems can be easily weaponized against immigrants, political dissidents, and other targeted communities as ICE and other federal agencies escalate their assault on civil liberties. There is no configuration of an ALPR network that eliminates this risk, because the risk is the mass surveillance itself, not a misuse of it.
Of course, ALPRs cause other predictable harms. Innocent drivers are recurringly arrested and menaced by police because of ALPR errors. Officers regularly abuse ALPR systems to stalk past and potential romantic partners. Creating any database of personal information—including ALPR surveillance databases—inherently creates risk of data theft and subsequent harm to data subjects. And ALPR surveillance of protests and targeting of activists chill participation in First Amendment-protected dissent. But even if these downstream harms could all be prevented (and they likely can’t), ALPRs would remain an intolerable form of mass surveillance.
Fighting on Every Front to Eliminate ALPR SurveillanceAt the city level, EFF works with community members and decision makers to outright refuse ALPR purchasing. ALPRs are not inevitable. The same decision mechanisms used to facilitate runaway surveillance purchasing in U.S. localities can be turned against these systems to dismantle them.
EFF also pushes state legislatures to establish strict state-level limits on ALPR surveillance, such as data-deletion rules and use restrictions. Building such constraints into statute can mitigate the harms of existing ALPR systems.
In courts across the country, EFF files amicus briefs arguing that warrantless police searches of ALPR databases violate the Fourth Amendment. In California state court, EFF and the ACLU of Northern California are suing on behalf of two community groups, SIREN and CAIR-CA, arguing that the San Jose Police Department's practice of letting officers search stored plate data—to the tune of over 100,000 times a year—without a warrant violates the California Constitution. We’ve also sued to block California law enforcement from sharing ALPR data with federal and out-of-state agencies, in violation of a California statute.
A big part of EFF’s work is exposing the harms of ALPR surveillance. Our investigative team tirelessly collects information about how law enforcement uses ALPRs with public records requests, sues to enforce such requests, and publishes reports about them. We’ve also successfully lobbied for a State Auditor investigation of law enforcement’s use of ALPRs.
Coordinated Action Against Mass SurveillanceEFF practices integrated advocacy because all of these tools work best together. City refusals, statehouse restrictions, impact litigation, and investigative activism are different levers EFF pulls toward the same end: eliminating ALPR surveillance, and building the durable public power needed to keep it off our streets. A council vote against a Flock contract and a warrant argument in Santa Clara County Superior Court are both, at their core, the same fight: rejecting mass surveillance infrastructure outright, and using every venue available to eliminate its harmful presence and consequences.
EFF Statement on Meta Settlement
Under this settlement, young users will now have less access to Meta products, and a lesser ability to exercise their rights to speak, access information and art and culture, associate and form communities, and play. The settlement also embeds age assurance into every product, mandating the collection of even more personal information from users of all ages; this enshrines Meta's harmful surveillance into law, and it will compromise users' privacy and anonymity while increasing their exposure to data breaches and government data requests. And the data minimization and security measures don’t keep states from using data collected under the agreement for other law enforcement purposes – which could include things like criminal investigations of abortions or gender-affirming care.
French Top Court Gets It Right, Strikes Down Social Media Ban For Youths
Earlier this month, France’s top court struck down the country’s legislation that banned social media use for people under 15 years old, which had been scheduled to take effect in January 2027. This is a welcome win for free expression, as we face a wave of countries and U.S. states seeking to pass similar laws banning young people from social media.
In particular, the Constitutional Council’s decision focused on two components:
Infringement on Free ExpressionThe Council ruled that the legislation banning under-15s from social media infringed on freedom of expression and communication in a manner that is not appropriate, necessary, or proportionate, which is required by Article 34 of the French Constitution. In particular, it stressed that the ban did not distinguish between different types of online services, and ignored the circumstances of individual users, such as their exact age, level of maturity, and family situation.
The evidence is clear: these are reckless and harmful laws that negatively impact all people, not just those under 15. These measures chill all users’ exercise of the right to free speech and expression online by imposing obstacles on sites or by wrongfully blocking people’s access outright.
By forcing young people into digital isolation, these bans curtail vital access to news and resources for health and development; especially for LGBTQ+ and marginalized youth as social media can often be the only place to find community, explore their identity, or access life-saving resources. They also completely ignore the calls of young people themselves who favor digital literacy and education over surveillance and government control.
These bans also destroy the right to online anonymity—a cornerstone of our right to free expression that in particular protects whistleblowers, journalists, activists, and immigrants.
Infringement on the Right to Private LifeThe Council’s second objection noted that the law requiring every person, even adults, to prove their age before accessing social media platforms impedes the right to private life, and thus infringes on Article 2 of the Déclaration de 1789.
The French Council gets a lot right in this decision: it highlights that bans like this impact not just young people, but everyone online. They force people of all ages to hand over government IDs, face scans, and other sensitive information into a growing surveillance ecosystem. Further, when parental consent is required, companies must collect even more verification data on the parents.
We know that when people are forced to hand over this information, age verification systems frequently misidentify or lock out people of color, people with disabilities, and trans or gender-nonconforming individuals whose IDs may not match their appearance; adding to the privacy concerns around these bans.
Next StepsAs all bills in France are subject to scrutiny by the Constitutional Council to ensure compliance with the French Constitution, French President Emmanuel Macron has tasked Prime Minister Sébastien Lecornu to re-work the legislation with a goal to adopt a ‘legally robust’ version of the social media ban.
Public policy must be effective, proportionate, and respectful of fundamental rights; and the ruling by the Constitutional Council has ramifications beyond France. It sends a message of caution to Brussels, where the EU Commission is working on an EU-wide bill on access restrictions. These legal restrictions would likely require problematic age verification of users. The prominent EU digital identity wallet and the “mini” age verification app, presented as privacy-robust options, instead raise serious privacy and security concerns.
Young people deserve better than a policy built on panic, and all internet users deserve a safe and free internet that includes measures to empower all people with the knowledge they need to navigate online spaces safely. A social media ban generates headlines, but it will not solve the problem.
EFF and Civil Society Groups Call on Nottinghamshire Police to Halt Live Face Recognition
This week, EFF, along with Big Brother Watch, Defend Digital Me, Liberty, Open Rights Group, Race Equality First, Statewatch, and Stopwatch, wrote to Nottinghamshire Police Force in the UK raising concern about the proposed roll-out of live facial recognition technology (LFR), and called for its immediate halt.
In particular, the letter highlights six concerns:
LFR Is Not "Just Another Tool"Nottinghamshire Police has stated that “facial recognition is just another tool to fight crime.” But LFR used in public spaces is an incredibly intrusive biometric mass surveillance technology that scans the faces of everyone who walks past the camera and takes biometric face prints. This is not just another tool, but a major escalation of surveillance that treats everyone as a suspect by default.
People Having "Nothing to Worry About" Does Not Hold to ScrutinyAccording to Nottinghamshire Police, “if you aren’t entering the city or county to commit crime then you have nothing to worry about.” However, many people have legitimate concerns about the normalisation of invasive technologies. So a public that cannot move around their towns and cities without being subjected to a biometric identity check may be less willing to seek medical care or legal advice, speak with journalists, act in a union, vote, protest, or express their gender, sexual or religious identity.
Disproportionate Targeting With LFRWe are particularly concerned to learn that Nottinghamshire Police could deploy LFR to tackle low level crimes, such as youth behavior deemed anti-social, as part of Operation View. Reporting suggests that the force already possesses “a watchlist of young people believed to be causing the most problems,” including children as young as 11 years old. It would be highly disproportionate to deploy live facial recognition to tackle this behaviour. Many of these children are reportedly known to the police, and it is highly likely that there are more proportionate means for locating them.
LFR Could Increase Social ProblemsWe are also concerned that Nottinghamshire Police has not adequately examined the distinct risks of using LFR to target children, including negative impacts on their behaviour and outcomes, risk of recidivism, and relationship with the police. Use of LFR could exacerbate behavioural problems in children and create an adversarial, rather than trusting, relationship with the police from a young age.
Lack of Public SupportRecent polling commissioned by Liberty indicated that 48% of people oppose scanning the faces of those walking on high streets when there is no suspected imminent threat. Furthermore, Opinium found that the majority of people oppose the use of facial recognition in schools. Likewise, a report by the London Policing Ethics Panel found that Londoners aged 16-24 were most likely to find the Metropolitan Police Service’s use of LFR unacceptable and most likely to stay away from events where LFR was in use.
On these grounds, Nottinghamshire Police must immediately halt their plans to use live facial recognition surveillance any further.
Read our full letter here.
Intermediary Liability in Brazil: The Intricate Path Ahead
Brazil's new internet intermediary liability regime is underway. The implementation of changes established by the Supreme Court includes notice and takedown mechanisms and duty of care obligations. Caution is crucial as these measures can create problematic incentives for enforcement overreach and over censorship of protected speech.
The court in June issued a new decision clarifying elements of its 2025 finding that the previous liability regime was partially unconstitutional. The government also published in late May two presidential decrees that detail how the new rules apply.
Under the new regime, social media platforms and other internet applications that curate or interfere with posts can be held liable for third-party content if they don’t remove it after being notified by the user seeking take down unless there's a reasonable doubt that the content is unlawful. For certain specific cases, like crimes against honor (e.g. defamation), platform liability still depends on failing to comply with a judicial order.
For some serious crimes, like human trafficking and crimes against women, applications have a duty of care to remove related content immediately and can be held liable when systemically failing to do so. The precise limits of what constitutes a systemic failure are still unclear. There are also stricter rules for paid ads, boosted content, and bots.
The previous regime, set by Article 19 of the law known as the Brazilian Civil Rights Framework for the Internet (“Marco Civil da Internet” in Portuguese), sought to protect freedom of expression online by holding internet application providers liable for user content if they failed to comply with a judicial order to remove it. There were specific, limited exceptions to this rule, like the unauthorized disclosure of nude or private sexual images. This was meant to prevent providers from over-removal of user content to avoid legal action. Yet, the court found that this provision failed to sufficiently safeguard democracy and fundamental rights.
We outlined the thorny context leading to this shift in Brazil’s intermediary liability rules, including Big Tech’s alignment with the far right and hurdles to approve platform regulation in Congress, through a proper legislative process.
Brazil’s shift is part of broader discussions and changes in response to growing concerns over online harms and digital platforms’ abuses. However, responses focused on platforms’ liability of user-generated content carry important traps and risks—from entrenching dominant platforms’ power over the information flow to escalating arbitrary online surveillance and censorship. The path ahead must prevent this to the extent possible, and the new presidential decrees provide a mixed contribution towards this task.
New Decrees: Strengths and FlawsThe government published two decrees regulating the new regime set by the Supreme Court. One introduces changes to its previous regulation, the Decree 8.771/2016, detailing elements of the decision, including additional duties that the court only briefly addressed (Decree 12.975). The other regulates measures to tackle violence against women online (Decree 12.976).
The Supreme Court's decision didn't establish guidelines to protect users' due process rights when facing content take down and removal demands. Instead, it relies on providers to self regulate, which could lead to over censorship.
The decrees’ provisions on user notification systems are helpful in this sense. They stipulate that providers must inform users (both the notifier and the content author) about the decision to remove or keep the content up, why, and the means to appeal. The guidance makes explicit that a platform may reconsider and reinstate content after an appeal and must explain its reasons to the party requesting removal and content author. The decrees also address concerns with the weaponization of notification systems, establishing that internet applications must adopt measures to prevent abuses.
Decree 12.795 reinforces that applications can keep content up after notification when there’s reasonable doubt that the post is unlawful, stating that the analysis should consider the context of the publications, freedom of religion and belief, and any informational, educational, or critical, satirical, or parodic purpose with the aim of ensuring freedom of expression. With these guidelines, it aims to mirror the Digital Services Act's "notice-and-action" approach. Moreover, for sexual related, intimate content, platforms will provide a specific and easily accessible notice channel where victims or their representatives can follow the case.
One of the most concerning provisions requires applications to proactively report content related to criminal conduct on their platforms to government authorities. Applications must send the post along with information that can identify the user. The Ministry of Justice will regulate this provision, something the Supreme Court didn't touch on in its decision. While it seems to apply just to those providers already required to comply with new content-related obligations (exempting email and videoconference providers, for example), it takes a disastrous step beyond. It’s not only about preventing the spread of unlawful content online; it gets platforms to police and report users to authorities by handing identification information apparently without a court order.
Decree 12.795 also details the definition of messaging applications that are exempt from notice and duty of care obligations. It excludes features for public dissemination of content and open groups so that the exemption doesn't apply. It's still unclear what exactly open groups mean. Especially regarding end-to-end encrypted applications, it's crucial that duties to monitor and take down don't affect conversations that are under this security architecture. Perhaps more troubling, the Supreme Court stated in its clarification ruling that a judicial order can determine email, voice and video conference, and messaging providers to take down content of private communications. Any measure must respect privacy and free expression safeguards and refrain from undermining end-to-end encryption.
Furthermore, decree 12.976 importantly addresses the protection of women online, but it contains a broad definition of online violence against women that will guide how platforms handle takedown notices they receive. This definition involves "any act, conduct, or omission that causes (...) psychological, political, or economic suffering (…) in any aspect of their lives, committed, instigated, facilitated, or aggravated, in whole or in part, by the use of digital technologies." Its breadth could unfortunately result in censoring legitimate criticism and other protected speech, which platforms and authorities must avoid.
The decrees also establish powers to the Brazilian Data Protection Agency (ANPD) to oversee and regulate the new regime. Among controversies, the decrees give ANPD the power to apply penalties for breaches of content-related obligations. These obligations go beyond agency competencies set in the Data Protection Law and the Law 15.211/2025, focused on the online protection of children and adolescents. They are also not clearly covered by Article 12 of Marco Civil as it stipulates administrative penalties for violations of its data privacy provisions.
We appreciate that ANPD has been open to civil society's demands and concerns. While it’s crucial that the agency conducts its oversight role preserving a proportionality commitment and keeping solid participation channels, sanction powers must be prescribed by law.
Alerts for the Path AheadIt’s true that there are critical platform accountability problems we must address, especially regarding the big players. And yes, platforms should align their policies and practices with human rights standards, including by dealing diligently with the dissemination of unlawful, toxic content. But accountability efforts should look at platforms’ systems and processes and promote measures to put checks on the power of tech giants, instead of having a prevalent focus on policing and reporting user behavior.
Key digital competition measures to regulate gatekeeper platforms are under discussion in bill 4675/2025, but the proposal is pending in Congress with no clear timeline for approval.
One important measure is to ensure accountability of take-down requests, including by the government. The Supreme Court’s decision stipulated that internet applications should publish transparency reports of the removal notices they receive. Government institutions should follow suit by periodically disclosing aggregate data of their own requests to online platforms, covering various types of user data and demands for content and account restrictions. Back in 2016, Marco Civil’s regulation decree established that all federal bodies must annually publish statistical reports on their requests of subscriber data to providers. To the best of our knowledge, federal bodies generally fail to meet this provision. ANPD can play a crucial role in stepping up transparency in the implementation of the new rules.
Ultimately, platform accountability under the new liability regime hinges on how accountable its application will be by platforms and state institutions, and on the regime's commitment to protecting fundamental rights, including freedom of expression and privacy.
Some Tech Companies Have Privately Pushed Back on ICE Subpoenas. They Should All Do More.
In a handful of known cases, large social media companies have privately pushed back against Immigration and Customs Enforcement (ICE) subpoenas when the agency tried to unmask anonymous users who tracked immigration activities or criticized the government.
As ICE engages in a pattern of illegal and chilling investigations, any resistance is welcome. But social media companies can do more. When companies receive these unlawful subpoenas, they should be clear with the public that they will not hand over the data unless a court compels them to do so. In addition, companies themselves can take the government to court to challenge these unlawful subpoenas on behalf of their users.
ICE has sent hundreds of subpoenas to large technology companies like Google, Meta, and Reddit.
Publicly challenging these unlawful subpoenas in court has the dual purpose of protecting individual users who may lack the resources or know-how to challenge a subpoena on their own, while also discouraging ICE from issuing similarly unlawful subpoenas in the future.
Companies have a responsibility to protect the privacy of their users. That responsibility does not end simply because companies wish to avoid the ire of this administration—which has sought to chill other powerful institutions like news outlets, law firms, universities, and non-profits.
ICE Has Issued Many Unlawful SubpoenasICE has sent hundreds of subpoenas to large technology companies like Google, Meta, and Reddit seeking basic subscriber information like name, email address, IP address, and session times.
Some of these subpoenas have targeted people who engaged in protected activity—like tracking immigration actions, criticizing the government, or attending a protest. People have a First Amendment right to document law enforcement activities and criticize the government online, without retaliatory government investigations. This right has become more important as immigration agents have engaged in invasive, unconstitutional, and sometimes violent conduct.
In a handful of cases, users themselves have successfully pushed back. After receiving notice of these subpoenas, users have challenged them in court, relying on pro-bono lawyers from groups like the ACLU or Civil Liberties Defense Center. Companies have been largely absent from these court proceedings.
Private Pushback from Meta and RedditWhile not appearing in court, companies like Meta and Reddit have sometimes pushed back behind the scenes.
For example, on September 11, 2025, ICE sent administrative subpoenas to Meta seeking to unmask users who ran Instagram and Facebook accounts that tracked immigration activity in Pennsylvania. On September 19, 2025, Meta’s Law Enforcement Response Team told ICE that the agency did not have the “statutory authorization” to seek the records. It asked for more detail about the investigation and said “Meta will take no further action with respect to this summons until it receives this information.” Later, Meta informed ICE that it planned to notify the users about the subpoenas, since no gag order had been obtained. The government disclosed this information in one of EFF’s Freedom of Information Act lawsuits against ICE and other agencies.
On October 3, 2025, Meta notified the user about the subpoena. Despite its private pushback, Meta told the users it would comply with the subpoenas unless they mounted a court challenge within 10 days—which they did with the help of the ACLU. Ultimately, ICE withdrew the subpoenas when it became likely that ICE would lose the case in court.
In another example, Reddit documented its pushback in a transparency report released a few months ago. Reddit reported that in the second half of 2025, the company received three Department of Homeland Security (DHS) subpoenas seeking account information from 11 users who posted content critical of ICE. In the report, the company stated that “Reddit objected to these legal demands because the users appeared to be engaged in protected activity under the First Amendment, and law enforcement withdrew their requests.” The company reported that most other DHS subpoenas it received appeared to be routine.
A Tech Company Model for Public ResistanceEFF’s demand that technology companies do more to protect their users is not unprecedented. Twitter (now X) did so successfully in the first Trump administration.
On April 6 2017, Twitter went to court to challenge a DHS subpoena that sought to unmask a Twitter account named “@ALT_USCIS,” which frequently criticized the administration’s immigration policies. Twitter challenged the subpoena on both statutory and First Amendment grounds. A day later, DHS withdrew the subpoena and Twitter dismissed the case. The incident led to an inspector general investigation, which criticized a tactic that DHS is still engaged in.
In other circumstances, companies have also gone to court to protect their users and shield themselves from burdensome legal process. In 2013, Microsoft challenged a search warrant for the content of emails stored on servers outside the United States. In 2015, Apple challenged a court order to break the security of its iPhone during an investigation into the San Bernardino shootings. And in 2007, Yahoo challenged the constitutionality of government requests at the Foreign Intelligence Surveillance Court.
