Compliance & Governance

Technology.Security.Compliance.

Protecting an environment also means protecting people, data and the way the operation is run.

Regulatory alignment program

CIA has a regulatory alignment program under way, addressing the new private security requirements and the LGPD by reviewing processes, contracts, personnel and technology.

New Private Security Statute

Law No. 14,967/2024

The private security market has changed.

Law No. 14,967 of September 9, 2024 established the Statute of Private Security and Financial Institution Security — Brazil’s Private Security Statute. Among private security services, the law now expressly includes the monitoring of electronic security systems.

  1. 01

    Monitoring is private security

    Monitoring of electronic security systems is on the list of private security services.

    Lei 14.967/2024, art. 5º, VI

  2. 02

    Requires authorization

    The provision of private security services requires prior authorization from the Federal Police, which also controls and oversees the activity.

    art. 4º; art. 40, I e III

  3. 03

    Periodic renewal

    The authorization of monitoring companies must be renewed every five years.

    art. 40, II, "b"

  4. 04

    Regulation published

    The law was regulated by Decree No. 13,012 of June 9, 2026 (Official Gazette, June 10, 2026). The Federal Police then issued Normative Instruction DG/PF No. 340 of July 31, 2026, which sets out the procedures for authorization, control and oversight.

    Decreto nº 13.012/2026; IN DG/PF nº 340/2026

What the new framework covers

  1. 01

    Electronic monitoring

    A private security service.

    art. 5º, VI

  2. 02

    Design

    Preparation of designs that integrate electronic equipment.

    art. 7º, I

  3. 03

    Installation

    Leasing, sale and installation of the equipment.

    art. 7º, II

  4. 04

    Maintenance

    Maintenance of the system’s equipment.

    art. 7º, II

  5. 05

    Technical assistance

    Usage support and technical inspection of the equipment.

    art. 7º, III

  6. 06

    Operation

    The electronic security system operator is a private security professional.

    art. 26, VI

  7. 07

    Personnel

    Under the law, operators must be at least 18, have completed secondary school, be found fit in a mental and psychological health assessment and be employed by a private security provider; under the regulation, a specific training course is also required.

    art. 28, §3º; Decreto 13.012/2026, art. 32

  8. 08

    Governance

    Requirements such as minimum share capital and prior operating authorization from the Federal Police, set out in the law, the regulation and Federal Police rules.

    art. 14, III; Decreto 13.012/2026, art. 18

  9. 09

    Transition period

    The law allows up to three years from its publication for providers to adapt; according to Federal Police guidance, the deadline is September 9, 2027.

    art. 60; Polícia Federal, orientação

Under the regulation, the sale, leasing, installation and maintenance of equipment without the corresponding provision of remote monitoring are treated as standalone commercialization. Lei 14.967/2024, art. 24; Decreto 13.012/2026, art. 34, §4º

What changes for the buyer?

Procuring security technology is not just about comparing equipment.

Comparing is not enough

  • Cameras
  • Price
  • Equipment count

Also evaluate

  • 01Provider’s regulatory standing
  • 02Operational accountability
  • 03Data protection
  • 04Processes
  • 05Personnel
  • 06Technology
  • 07Traceability
  • 08Maintenance
  • 09Governance

Understand the new private security landscape

LGPD (Brazil’s General Data Protection Law, Law No. 13,709/2018)

Privacy by Design

Technology that protects environments without neglecting the protection of people.

FIG. 07 LGPD · data lifecycle SCHEMATIC 01Capture02Processing03Control04Evidence05AuditData lifecycleLGPD · 13.709/18Role-based access · immutable log
  1. 01

    Capture

    Collect only what is necessary for the defined purpose.

  2. 02

    Processing

    Handle with restricted, logged access.

  3. 03

    Control

    Role-based permissions and a retention policy.

  4. 04

    Evidence

    Intact, verifiable records.

  5. 05

    Audit

    Who accessed, when and why.

Personal data
Images, registrations and records, when they identify or make it possible to identify a natural person.LGPD, art. 5º, I
Biometric data
Under the LGPD, biometric data linked to a natural person is sensitive personal data.LGPD, art. 5º, II
Facial recognition
Used for defined purposes, such as access control.
ANPD and biometrics
Brazil’s data protection authority (ANPD) has run a call for input on biometric data; according to the official source, specific rules are still being drafted.ANPD · Participa + Brasil (opens in a new tab)
Access control
Each person accesses only what their role requires.
Images
Recording, retrieval and export under control.
Event records
A history of what happened and who acted.
Logs
Technical trail of access to systems.
Permissions
Profiles reviewed periodically.
Auditing
The ability to reconstruct and verify actions.
Retention
Defined periods and disposal once the purpose ends.
Traceability
Evidence with integrity verification.

The purpose, legal basis, retention periods and responsibilities of each processing activity depend on each operation and each contract. No processing is automatically permitted — it is defined case by case.

Biometrics demands responsibility.

Facial recognition is a mature technology. Using it well requires the same maturity.

Real photo · CIA HQ Facial-recognition terminal at CIA headquarters
FIG. 08 Biometrics · governance SCHEMATIC FACE · 0417MeshEncrypted templatePermissions04PurposeAccessLegal basisDocumentedSharingNoViewingBy roleRetentionDefined periodAuto-disposalNo photo stored · vector only
  1. 01

    Access control

    Biometrics serves a clear purpose: admitting those who are authorized.

  2. 02

    Permission management

    Enrollments, profiles and removals administered by defined owners.

  3. 03

    Purpose

    Data is used for what was disclosed — and nothing else.

  4. 04

    Traceability

    Every access generates a searchable record.

  5. 05

    Data protection

    Restricted access to enrollments and protected communications.

  6. 06

    Records

    History kept for the defined period, then disposed of.

  7. 07

    Governance

    Reviewed, documented policies.

Compliance & Governance

How we structure governance

FIG. 09 Layered architecture SCHEMATIC DevicesL1Segmented networkL2PlatformL3OperationsL4AudittrailLeast privilege · segregated network
  • 01

    Security by Design

    Security built in from the design stage: segregated network, least privilege, updates.

  • 02

    Governance

    Documented protocols, defined owners and continuous review.

  • 03

    Traceability

    Every operational action leaves a verifiable trail.

  • 04

    Auditing

    Searchable records of operators and systems.

  • 05

    Evidence management

    Evidence with cryptographic hashing and a documented chain of custody.

  • 06

    Information security

    Protection of systems, credentials and communications.

CIA does not claim certifications, approvals or full compliance that it cannot substantiate with documentation.

Request an assessment

Compliance centraliaseguranca.com.br/compliance

Transform your operation.

Talk to our specialists and see how artificial intelligence, automation and intelligent security can be applied to your environment.

WhatsApp