Where there are online safety laws, there is litigation aiming to curb them. So it goes in Brazil, where the country’s rules requiring biometric verification for age assurance to access selected online content are facing a constitutional challenge from upstart political party Partido Missão (Mission Party). The party argues that “requiring adults to submit their faces, fingerprints, voices, or iris scans as a condition of accessing digital content collects more sensitive personal data than the law’s child protection goal requires.”
Activated in March, law 15,211/2025, known as the Estatuto Digital da Criança e do Adolescente (ECA Digital) lays claim to being “the most comprehensive child online safety framework in the Americas.” It applies age assurance requirements to any digital product or service accessible to Brazilian minors, regardless of where the company is located.
The law’s first enforcement phase, focused on app stores and proprietary operating systems. It recently escalated into its second phase, which introduces broader enforcement covering social media, streaming services, messaging platforms, marketplaces and AI tools. In arguing that it requires disproportionate biometric collection, Partido Missão – which only gained formal recognition in 2025 – gives it its first significant legal challenge, and supposedly complicates compliance planning for affected platforms.
The challenge suggests “less invasive technical alternatives could do the same job without harvesting irreplaceable biological identifiers.” In this, it is not an objection to age assurance across the board, but a call to reexamine what methods are best suited to checking age while preserving privacy. While Partido Missão has not suggested alternatives, their argument alludes to zero-knowledge proof systems.
Currently, Brazil’s law lists three acceptable methods for age assurance: biometric verification (including facial recognition and facial age estimation, or FAE), document-based age verification with a government-issued ID, and checks that leverage the CPF database of Brazil’s national taxpayer identification system. Some of these methods don’t require the collection of biometric data or personal information.
At issue for Partido Missão, however, is the status of zero-knowledge proofs (ZKP). The law does not yet specify whether or not cryptographic ZKPs satisfy the requirement for age checks that are “effective and reliable.” The question is expected to be answered later this month, when national data protection authority Autoridade Nacional de Proteção de Dados (ANPD) publishes its final guidelines.
What happened to facial age estimation?
Meanwhile, the legal challenge – formally Direct Action of Unconstitutionality 7,999, or ADI 7999 – appears to have a small hole in it from a biometrics perspective. In calling for less intrusive methods than biometric age verification, it ignores the already accepted option of facial age estimation. Tech Times points out that, “in the United Kingdom, regulators have noted that selfie-based facial age estimation – which estimates age without capturing or storing identity data – is increasingly popular with users, with more than four in five consumers preferring it when offered as a choice.” Its assertion that “UK regulators have tended to favor government-issued ID as the most reliable method” is not grounded in reference to any specific statement or regulation, and can thus be considered an opinion rather than a fact.
Brazilian data protection law classifies biometric data as “sensitive personal data” requiring heightened justification, and the ANPD has acknowledged that its framework must be “strictly compatible with constitutional rights to privacy and personal data protection.” The legal question, then, is “whether the most commercially available methods of satisfying ‘reliable’ verification impose a burden on adult users that exceeds what the law’s protective purpose requires.” Again, however, the language is vague on the question of what counts as “the most commercially available methods.” The age assurance industry would surely argue that facial age estimation is just as commercially available as document-based age checks.
Indeed, Partido Missão’s central argument – “the verification goal and the biometric collection mechanism are separable, and that the latter is not required to achieve the former” – is at the heart of privacy preserving age assurance. No age assurance provider exists to collect biometric data; they do so as part of the goal of proving a user is old enough to access a product or service. So, while the constitutional specifics of Brazil’s law are complicated, the ultimate answer need not be: make privacy preserving age assurance a legal requirement.
There is also missing context from Tech Times’ statement that if the ruling judge “grants a preliminary injunction on the biometric provisions – even a monocratic (single-justice) interim measure pending full plenary review — it would instantly alter the compliance calculus for every platform currently implementing facial recognition or document submission as its primary verification method.”
For some time, the age assurance market has been shifting away from single-solution products to give customers a more complete menu of age assurance offerings. Few firms now offer document verification exclusively, and many that incorporate selfie biometrics have developed FAE algorithms to complement verification capabilities. ZKPs are also increasingly on offer. Adjusting to a new “compliance calculus” could, in the end, be as easy as flipping a switch.
Article Topics
age verification | biometric age estimation | Brazil | facial age estimation (FAE) | reusable digital ID