Brazil’s Law 15.211/2025, informally called the Felca Law, took effect on March 17, 2026 and establishes child- and adolescent-safety obligations for digital products and services, including operating systems and app stores. The law does not explicitly ban Linux or require an immediate blanket block on operating systems that lack native age-verification capabilities; minimum technical implementation requirements remain subject to Executive-branch regulation.
Claims that the law mandates a Linux ban were amplified after MidnightBSD voluntarily blocked users in Brazil, rather than by a direct legal order. The law’s proportionality provisions, exemptions for essential internet functions, application-level responsibility for restricting inappropriate access, and limits on indiscriminate surveillance indicate that compliance measures may be tailored. Linux environments can also support parental controls and content ratings through tools such as GNOME Malcontent, OARS, Flathub controls, PAM, AppArmor, and SELinux.

See the reporting duties and controls this puts on the clock.
4 events from the most recent confirmed update back to the earliest known activity.
MidnightBSD blocked users in Brazil and stated that Brazilian residents were not authorized to use the system. The cited account characterizes the restriction as a voluntary project decision rather than a Brazilian legal mandate.
Brazil's National Data Protection Authority included Canonical, the company behind Ubuntu, on an oversight list. The cited account states that this inclusion did not ban Canonical or Ubuntu.
Brazil enacted Law 15.211/2025, the Digital Statute for Children and Adolescents. The law covers certain digital products and services, including operating systems and app stores, and establishes child-safety obligations whose minimum technical requirements are to be defined by Executive-branch regulation.
Law 15.211/2025 became effective in Brazil, imposing child- and adolescent-safety obligations on covered digital products and services. Its operational minimum requirements remained subject to future Executive-branch regulation.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.