What Brazil’s Betting Ban Means for iGaming Operators: Platform Exit, Player Data and Market Migration
Brazil’s Provisional Measure (Medida Provisória) No. 1.394, published and in force since 25 September 2026, prohibits fixed-odds betting and online casino games nationwide and ends every federal authorisation 30 days after publication. For operators, it is not a market exit you can schedule. It is a fixed sequence of deadlines: no new deposits from day one, sites and apps offline after 10 days, a CPF-level refund file within 2 days of that, and at least five years of data retention and regulatory reporting after the licence is gone. For suppliers, it means Brazil-facing integrations have to be closed down cleanly and records kept available for operators.
This article explains what the measure requires from a platform and data point of view, what you can reuse elsewhere and what has to stay behind, and how to plan while the measure is being challenged in court and reviewed by Congress. It is not legal advice. Requirements vary by licence and contract, and Brazilian legal counsel should confirm how each obligation applies to your company.
Last legally reviewed: 30 September 2026. This is a fast-moving situation. We update this page when the legal status changes.
What MP 1.394/2026 changes
The official text of MP 1.394/2026 does five things that matter for technology and operations:
- Prohibits the activity itself. Article 1 prohibits the operation, offer, intermediation and advertising of fixed-odds betting (apostas de quota fixa) in Brazil, physical or online. This covers bets on real sporting events and online games based on random outcome generation, which is how the previous framework brought online casino games under the same regime. Other lottery modalities provided for by law are not covered.
- Reaches offshore operators explicitly. The prohibition applies to agents based abroad that offer bets to people located in Brazil. A foreign licence, a crypto cashier or a non-Brazilian domain does not take a Brazil-facing product outside the measure.
- Ends existing authorisations. Federal authorisations granted under Law 14.790/2023 are extinguished 30 days after publication, with no refund of the authorisation fee (Article 4). No new authorisations are granted, and pending applications are dismissed (Article 6). State and Federal District lottery authorisations for fixed-odds betting are also to be terminated (Article 2).
- Keeps the regulator in charge of the exit. The Secretariat of Prizes and Bets (Secretaria de Prêmios e Apostas, SPA) of the Ministry of Finance keeps supervisory and enforcement powers over past conduct and over the wind-down obligations (Articles 5 and 12).
- Closes the surrounding channels. Payment institutions may only process transactions linked to closure and refunds (Article 14), advertising and sponsorship are banned (Article 16), app stores and platforms must stop distributing betting apps and content (Articles 19 to 22), and sites can be blocked through Anatel and CGI.br (Article 23).
Article 29 revokes most of Law 14.790/2023 and Chapter V of Law 13.756/2018, but keeps the previous rules applicable to past facts and to the transition obligations the measure creates. In practice, the regime that governed your platform continues to govern your records and your reporting, even after your authorisation ends.
The measure applies to sportsbook and casino operators alike. If you run a fixed-odds sportsbook, open bet liability is the first technical problem you have to solve (see below).
The wind-down timeline, mapped to system actions
The measure sets periods, not dates. The calendar dates below are those published by Agência Senado and Agência Câmara. The right-hand column is our recommendation for the platform team, not a legal requirement.
| Date (2026) | What the measure requires | What the platform team should do |
| 25 Sep | MP in force. New deposits prohibited, except movements needed to return funds (Art. 7). No new authorisations (Art. 6). | Disable deposit methods in the cashier and registration flows. Keep login, balance display and withdrawals working. Snapshot the ledger. |
| Until 5 Oct, 23:59 | Players can withdraw their balances voluntarily. Advertising and sponsorship material removed within 10 days (Art. 16). | Prioritise withdrawal throughput and support capacity. Switch off CRM campaigns, affiliate links and promotional placements. |
| From 6 Oct | Sites and apps unavailable (Art. 7). Open bets whose result is not determined by then are void and refunded in full; bets already won are paid. | Take player-facing channels offline. Void and refund open bets in the ledger. Freeze game launches and resolve open casino rounds with providers. |
| Within 2 days of shutdown (7 to 8 Oct) | Ring-fence refund funds, send financial institutions a list of players by CPF with the amounts due, and send the same data to the SPA with proof that the funds are available (Art. 8). Daily fine of R$200,000 for non-compliance. | Generate the refund file from the reconciled ledger: available balances, voided bets and unpaid prizes per CPF. Reconcile the total with the transactional accounts before sending. |
| Within 7 days of receiving the file (by 14 Oct) | Financial institutions pay the refunds to accounts held by the player, preferably the original account. Amounts that cannot be returned go to Caixa Econômica Federal (Art. 9). | Track acknowledgements and failed refunds per player. Keep the operator-side record of every refund outcome. |
| 25 Oct | Federal authorisations extinguished (Art. 4). | Keep the reporting and archive environment running. The obligations below continue. |
| Ongoing | Tax, regulatory, AML, responsible gambling and sports integrity obligations remain; data kept for at least 5 years; information sent through Sigap (Arts. 10 and 11). | Operate a read-only archive with audit access and a reporting pipeline for SPA requests. |
Congress has up to 120 days (60 plus a 60-day extension, not counting parliamentary recess, under Article 62 of the Federal Constitution) to convert the measure into law, with or without amendments. Separately, several industry associations filed direct actions of unconstitutionality (ADIs) at the Supreme Federal Court (STF) on 28 September 2026, asking for the measure to be suspended or for a longer transition. At the time of our review, no suspension had been reported. Until a court or Congress says otherwise, the deadlines above apply.
Balances, open bets and refunds: the ledger work
The refund file is the most exposed deliverable in the whole wind-down. It is a legal filing built from your ledger, with a daily fine attached to it. Three things make it harder than it looks.
The file must be complete per player, not just in total. Article 8 requires the list to identify each player by CPF with the amount due, covering available balances, voided bets and prizes. An aggregate match between the ledger and the transactional accounts can hide offsetting errors. Reconcile per player, per category, and investigate every difference before the file goes out.
Open states have to be closed deliberately. Sportsbook tickets still open at shutdown are voided and refunded at full stake. Casino rounds need a policy agreed with each game provider or aggregator: stop new launches, let active rounds finish, and resolve anything left on the provider side so the final balances are complete. Pending withdrawals requested before shutdown must either be paid or included in the refund file, never both.
Bonus money needs a clear rule. The measure refers to available balances, voided bets and prizes. Whether a given bonus balance counts as money owed to the player depends on your terms and on how your ledger separates cash from bonus funds. This is a question for legal counsel, but the ledger has to be able to answer it: if cash and bonus funds are mixed in one balance field, split them now.
Payments before 5 October are the cheapest refunds you will make. Every player who withdraws voluntarily is one less line in the file, one less institution transfer and one less potential transfer to Caixa.
What must be kept: data retention and Sigap reporting
Losing the authorisation does not end the data obligations. Article 10 keeps tax, regulatory, AML and counter-terrorist-financing, responsible gambling and sports integrity obligations in force, and requires operators to keep records on players, bets, financial operations and prize payments intact and accessible for at least five years. Article 11 requires operators to send the SPA, through the Sigap system, data on players, bets, prizes, deposits, withdrawals and transactional accounts, remaining balances and refunds, revenue and legal allocations, and the responsible gambling measures applied. The SPA may set the format and deadlines by regulation.
Under the pre-ban technical rules in Portaria SPA/MF 722/2024, authorised systems already had to keep backups of recorded data for at least five years, and data held abroad had to be replicated to a database in Brazil. Whether the ordinance’s technical details still bind the archive after the revocations is a question for counsel, but the five-year retention now comes directly from the measure. Brazil’s data protection law, the LGPD, allows personal data to be kept after processing ends where it is needed to meet a legal or regulatory obligation (Article 16), so the retention duty and the privacy framework point the same way. What they do not allow is using that data for new purposes.
Data-retention and migration matrix
| Data category | Obligation under the MP | Recommended handling | Reuse outside Brazil |
| Player identity and KYC (CPF, identity verification results) | Keep 5 years; send via Sigap on request (Arts. 10, 11) | Archive read-only with access logging; keep the link to the player ID used in the ledger | No. Collected for the Brazilian authorisation; counsel should confirm any other basis |
| Bets, game rounds and results | Keep 5 years (Art. 10) | Archive with provider round IDs so disputes can be traced to the RGS or sportsbook engine | No player-level reuse; anonymised aggregates only after counsel review |
| Deposits, withdrawals and transactional account movements | Keep 5 years; report balances and movements (Arts. 10, 11) | Archive the full ledger with the closing snapshot taken at shutdown | No |
| Prizes and refunds | Refund file to institutions and SPA (Art. 8); outcomes reported (Arts. 9, 11) | Keep the refund file, institution acknowledgements and failed-refund list as one audited record | No |
| Responsible gambling measures (limits, self-exclusions, alerts) | Continuing obligation; report measures applied (Arts. 10, 11) | Archive with timestamps; keep available for regulator requests | No |
| AML and CTF records, suspicious activity reports | Continuing obligation (Art. 10) | Archive under restricted access; align with the compliance team’s retention schedule | No |
| Revenue, tax and legal allocations | Continuing obligation; report via Sigap (Arts. 10, 11) | Keep finance exports reconciled with the ledger archive | No |
| Marketing consent and CRM data | Advertising prohibited (Art. 16) | Stop all campaigns; do not move Brazilian contact lists to another brand | No. Contacting Brazilian players about betting is prohibited advertising |
| Audit logs and system events | Needed to show data integrity over the retention period | Keep with integrity controls (hashing, write-once storage) | No |
| Platform code, configuration, game catalogue mappings | None specific | Keep in version control; document Brazil-specific configuration | Yes, subject to the target market’s rules |
The last row is the only one that can travel. Everything tied to Brazilian players stays in a Brazil archive for the retention period, and moving Brazilian player accounts to another brand that remains reachable from Brazil would run straight into the Article 1 prohibition.
Payments, domains, apps and marketing
The measure shuts the channels around the platform, not just the platform itself.
- Payments. Banks and payment institutions may only process betting transactions needed for closure and refunds (Article 14), and the Central Bank is to set up a system that lets institutions reject and reverse transfers linked to illegal betting (Article 15). Under the pre-ban rules, player money moved between player accounts and the operator’s transactional accounts at institutions authorised by the Central Bank. Those accounts are now where the refund funds sit: confirm with each institution what they need from you and in what format.
- Domains. Licensed operators used “.bet.br” domains under the pre-ban ordinance. After shutdown, replace the front end with a static notice page if counsel agrees it is appropriate, and keep control of the domains. Article 23 allows sites offering fixed-odds bets to be blocked through Anatel and CGI.br.
- Apps. App stores and operating systems must stop distributing betting apps (Articles 19 to 21). Unpublish your apps yourself before the deadline so you control the message to users, and keep the ability to send withdrawal and refund notices.
- Marketing. All advertising, promotion and sponsorship is banned, and existing material must be removed within 10 days (Article 16). This includes affiliate content you pay for. Tell affiliates in writing and switch off tracking links, and stop CRM automation that could send a promotional message by mistake.
What B2B suppliers need to do
Article 1 prohibits intermediation, not only operation, and the prohibition reaches offers made from abroad. Suppliers should get their own legal advice, but the technical steps are similar for most platform, aggregator, RGS, sportsbook and payment providers:
- Close Brazil-facing sessions in step with your operators. Agree the date and time when game launches and bet placement stop for each client, and confirm open rounds, free rounds and open bets are resolved on your side before the operator’s final balance snapshot.
- Keep your records available. Operators must keep bet and round data for five years and answer SPA requests. Round logs and transaction histories held in your RGS or sportsbook engine are part of that evidence. Agree how operators will access them after the commercial relationship ends.
- Review contracts. Minimum fees, exclusivity, termination and data-return clauses were written for a regulated market. They now meet a legal prohibition.
- Do not replace licensed clients with Brazil-facing grey-market ones. Offshore or crypto operators that offer bets to people in Brazil fall under the same prohibition, and the measure adds site blocking and payment rejection to enforce it.
Hibernate, redeploy or decommission: planning under legal uncertainty
The ban is in force, but its future is not settled. That makes the decision about your Brazil stack less binary than “shut down or keep running”. Our recommendation is to separate three layers and decide on each one independently:
- Compliance layer (mandatory). The archive, audit access and Sigap reporting pipeline must run for at least five years whatever happens next.
- Live operating stack (hibernate or decommission). Scale the Brazil-specific environment down to a documented, restorable state instead of deleting it, until the legal direction is clearer. Infrastructure costs fall, but the configuration, integrations and certification evidence are not lost.
- Reusable core (redeploy). The platform code, game integrations and product work can support other markets now.
| Scenario | What it means for the platform | Recommended posture |
| MP converted into law as published | Brazil exit is permanent under current law | Decommission the live stack once refunds and reporting are closed; keep the 5-year archive |
| MP converted with amendments | Rules may change for transition, sanctions or a future framework | Hibernate; reassess once the final text is published |
| STF suspends the MP, fully or partly | Operation might become possible again, but the status of authorisations, deadlines and payments would need clarifying | Keep the hibernated stack restorable; do not reopen without written confirmation from counsel and clear regulator guidance |
| MP lapses or is rejected by Congress | The Constitution leaves the legal effects to a legislative decree, and relations formed while the MP was in force may remain governed by it | Do not assume automatic reinstatement of authorisations; plan any restart as a new launch |
In every scenario, the compliance layer keeps running. Any restart in Brazil would be a new project that needs current legal confirmation, not a restore from backup.
What moves to your next market, and what stays in Brazil
Brazil’s framework pushed operators to build features that exist nowhere else in the same form. When you plan to redeploy the platform to other regulated markets, it helps to separate the reusable core from the Brazil-specific layer.
| Component | Reusable in another market? | What changes |
| PAM core (accounts, sessions, statuses) | Yes | New market’s identity, age and eligibility rules |
| Wallet and ledger | Yes | Currency, tax and player-funds rules of the target licence |
| CPF validation and facial verification flow | Mostly no | The KYC vendor integration pattern can be reused with the target market’s identity checks |
| Pix and bank transfer cashier | No | New payment providers and methods; the cashier abstraction can be reused if the integration is modular |
| Sigap reporting module | No | The event pipeline behind it can feed another regulator’s reporting format |
| “.bet.br” front ends | Design and code yes, domain no | New domains, localisation and required on-site disclosures |
| Game integrations and aggregator | Yes, subject to approval | Provider licensing and game certification for the target market |
| Sportsbook engine, feeds and risk rules | Yes | Market catalogue, bet types and limits allowed by the target regulator |
| Responsible gambling logic | Yes | Integration with the target market’s self-exclusion register and limit rules |
| Certification reports from Brazilian-accredited labs | Not automatically | The target regulator decides what testing it accepts; plan for new or additional certification |
| Brazilian player data | No | Stays in the Brazil archive (see the matrix above) |
Two engineering points decide how expensive the redeployment is. First, whether market-specific rules live in configuration or are hard-coded into the core: the more Brazil logic sits in the PAM and cashier code, the more refactoring the next launch needs. Second, whether you control the code and infrastructure. An operator on a vendor’s white label may find that the redeployment question is really a question about the contract. If you are moving the reusable parts onto a platform you control, our guide to casino platform migration covers the data map, reconciliation and cutover in detail.
Operator exit checklist
Use this as a working list for the product, engineering, finance and compliance teams. Confirm each legal item with counsel.
Before shutdown (by 5 October)
- Deposits disabled across every cashier method, app and channel; registration closed.
- Withdrawal flow working and monitored; support scripts ready for refund questions.
- Ledger snapshot taken; cash and bonus balances separated.
- CRM automation, affiliate tracking and promotional placements switched off; advertising and sponsorship material removed.
- Game providers, aggregators and the sportsbook vendor told the exact stop time.
At shutdown (6 October)
- Sites and apps unavailable; a static notice page agreed with counsel if used.
- Open sportsbook bets voided at full stake; open casino rounds resolved with providers.
- Pending withdrawals either paid or included in the refund file.
Refund file (within 2 days)
- Per-player reconciliation completed: available balance, voided bets and prizes by CPF.
- Refund funds ring-fenced and total reconciled against the transactional accounts.
- File sent to financial institutions and to the SPA with proof of funds.
After refunds
- Institution acknowledgements and failed refunds recorded per player.
- Amounts that institutions could not refund, and their transfer to Caixa Econômica Federal, tracked and documented.
Retention and reporting (at least 5 years)
- Read-only archive of players, bets, payments, prizes, refunds, RG measures and AML records, with access logging and integrity controls.
- Sigap reporting pipeline kept operational and owned by a named team.
- Legal representative and contact details kept up to date with the SPA (Article 5).
- Live Brazil stack hibernated or decommissioned according to the scenario plan.
How OmiSoft helps operators through a forced exit
OmiSoft builds and migrates casino and sportsbook platforms for operators who want control over their technology. In a forced exit, the engineering work is the same as in a well-run migration, only on a legal deadline: reconcile the ledger per player, close open states, produce auditable exports, set up a read-only archive and keep the reporting pipeline alive, then move the reusable core to the next market.
Our custom casino platform development is delivered with the source code and project documentation, and the platform can run on infrastructure you own. That matters now: operators who control their code and data can decide what to hibernate, what to archive and what to redeploy, instead of waiting for a vendor’s roadmap.