Brazil’s National Data Protection Authority, the Agência Nacional de Proteção de Dados (ANPD), has ordered Discord to temporarily suspend its Go Live functionality and equivalent video streaming and sharing features throughout Brazil.
The preventive measure was issued on August 12, 2026, as part of an enforcement proceeding investigating potential failures to protect children and adolescents in digital environments.
Discord was given three business days to implement the suspension.
According to the ANPD, the functionality may only be partially or fully restored after the company demonstrates that effective technical, security and governance measures have been implemented and receives prior authorization from the regulator.
The case has been identified as the first preventive measure in which the ANPD exercised its enforcement authority under Brazil’s Digital Child and Adolescent Statute, known in Portuguese as the Estatuto Digital da Criança e do Adolescente or ECA Digital.
Why did the ANPD suspend Discord’s Go Live feature?
The ANPD stated that Discord’s live-streaming functionality had repeatedly been associated with serious violations involving minors, including violence, harassment and conduct encouraging self-harm and suicide.
The regulator concluded that the safeguards implemented by the platform did not adequately prevent or mitigate those risks.
Importantly, the regulator did not order Discord itself to be blocked in Brazil.
The preventive measure specifically targets Go Live and equivalent video transmission features considered to present a particularly significant risk.
Why is the platform’s technical architecture important?
One of the most significant aspects of the case concerns Discord’s technology architecture.
According to the ANPD, Discord cannot access the audiovisual content of Go Live transmissions while they are taking place.
As a result, centralized server-side audiovisual analysis and real-time detection of certain violations are not technically available under the architecture currently used by the platform.
The regulator also found the alternative safeguards presented by the company insufficient in light of the risks identified.
The case therefore raises a broader issue for technology companies: product architecture itself may become part of the regulatory assessment.
A technical design decision may provide benefits in one dimension, such as privacy or communications security, while simultaneously creating different compliance and safety risks.
What is Brazil’s Digital Child and Adolescent Statute?
Law No. 15,211/2025 established a new legal framework for protecting children and adolescents in digital environments.
Its scope is not limited to services expressly designed for children.
The statute also applies to technology products and services that are likely to be accessed by minors in Brazil. Relevant factors include attractiveness to younger users, ease of access and risks to privacy, safety and psychosocial development.
The framework adopts a preventive approach to online child safety.
What obligations should companies consider?
Among other requirements, the statute addresses:
- risk management for products, features and systems;
- preventive measures beginning at the design stage;
- age-appropriate digital experiences;
- mechanisms relating to age assurance;
- parental supervision tools;
- protective default settings;
- reporting channels for violations;
- procedures for responding to certain harmful content;
- transparency and accountability.
This means compliance cannot be addressed solely through terms of service or post-incident moderation.
Does the law require continuous monitoring of private communications?
The Discord decision should not be interpreted as imposing a universal obligation to conduct real-time surveillance of all communications.
Brazil’s statutory framework requires measures to be proportionate to the nature and risk profile of the service.
The law also expressly protects fundamental rights and prohibits mass, generic or indiscriminate surveillance mechanisms.
Companies therefore face a more nuanced challenge: they must identify material risks and demonstrate that effective safeguards exist without adopting disproportionate monitoring practices.
What does the case mean for digital businesses?
The implications extend well beyond Discord.
Depending on their services and user base, the regulatory framework may be relevant to:
- social media companies;
- gaming platforms;
- messaging and community applications;
- streaming services;
- artificial intelligence tools;
- content-sharing platforms;
- app stores;
- digital marketplaces and other online services likely to be used by minors.
The ANPD has already begun broader monitoring activities involving major digital platforms, AI systems, application stores and other technology services.
A governance agenda for executives and product teams
For boards, C-level executives, General Counsels, DPOs, CISOs and product leaders, the Discord case highlights the need to connect regulatory compliance with product governance.
Organizations may need to assess:
- which features are likely to be accessed by minors;
- the risk profile associated with each feature;
- age-assurance mechanisms;
- default privacy and safety settings;
- parental-control functionality;
- reporting and escalation procedures;
- preventive and detection mechanisms compatible with the platform’s architecture;
- documentation of product-design decisions;
- evidence of ongoing testing and effectiveness;
- governance between Legal, Privacy, Cybersecurity, Product, Compliance and Trust & Safety functions.
Technology architecture is becoming a regulatory issue
The broader significance of the case lies in the regulator’s focus on how the product itself works.
The ANPD did not restrict its assessment to policies or user-facing disclosures.
It examined whether Discord’s technical architecture and the safeguards surrounding that architecture were capable of addressing foreseeable risks to minors.
For technology companies operating in Brazil, this represents an important development.
Decisions involving encryption, recommendation systems, artificial intelligence, live streaming, age assurance and user-to-user communication increasingly sit at the intersection of engineering, legal risk and regulatory governance.