Brazil passed an update to the Statute of the Child and Adolescent —known as the ECA— that requires digital platforms to implement age verification and parental control mechanisms. On the surface, this seems like a sensible measure. Protecting minors from harmful content is a shared goal. However, upon examining the list of affected companies, a notable irregularity emerges: Canonical, the company behind Ubuntu, the open-source operating system used by millions in servers, education, and privacy activism.

That inclusion reveals tensions in the institutional design of the regulation. Ubuntu is not a social network or a video site. It does not directly expose children to inappropriate material. Its presence in the same category as TikTok or Instagram signals a scope that goes beyond child protection and points toward something broader: the ability to track what digital tools people use.

Protecting children matters, but the uncomfortable question is a different one: who sets the boundaries of that protection, and what information is generated in the process? Verifying age on an operating system implies collecting identity data. For users in Brazil, installing or updating Ubuntu could require identification, tying technical choices to government records. This directly affects those who choose free software for its anonymity: journalists, developers, users seeking digital sovereignty.

The pattern isn't new. A rule that begins with legitimate aims tends to expand its reach. Russia's SORM system started as phone monitoring for national security. The USA PATRIOT Act emerged after terrorist attacks. In China, the social credit system was presented as a financial stabilizer. In each case, data collection tools grew beyond their original purpose. Brazil follows a recognizable structure, though not an identical one.

What makes this kind of regulation more effective is its public invisibility. Most people associate these rules with social networks, not operating systems. The debate centers on TikTok while the law lays the groundwork for tracking what software someone installs on their computer: not just the content they consume, but the tools they choose to work, communicate, or protect themselves. That's not speculation; it's a direct consequence of mandatory verification applied without distinguishing between categories.

Free software operates under a different logic. Its code is auditable, its distribution decentralized, its control in the hands of the user. Including Canonical in this regulation undermines that independence. If identification becomes a requirement for access, digital sovereignty tools fall under the same regime as commercial platforms. Medieval guilds controlled trades by restricting tools; the mechanism was different, but the dynamic was the same: whoever regulates access to basic instruments regulates participation.

There's a technically viable alternative. Focus the rule on content platforms —not infrastructure— and require transparency about data: what's collected, who accesses it, under what conditions. That would preserve protection without extending surveillance to neutral layers of the network. Some countries have struck that balance. Brazil could too; the inconsistency with Canonical suggests it hasn't tried yet.

Free software communities have shown resilience against regulatory pressures, adapting through decentralization and peer-to-peer distribution. But that resilience has limits when regulation operates at the level of identity, not content.

Stones don't lie, but historians sometimes do.


Sources:

1. Estatuto da Criança e do Adolescente — Law No. 8.069/1990 and recent updates (Brazilian Chamber of Deputies)

2. Canonical Ltd. — Official Ubuntu documentation and distribution model (ubuntu.com)

3. Electronic Frontier Foundation — Analysis of age verification regulations and digital privacy (eff.org)

4. Access Now — Reports on digital surveillance legislation in Latin America

5. Free Software Foundation — Conceptual framework on software freedom and digital sovereignty (fsf.org)