What takes a court clerk in the United States takes a judge here — for now
Section 512(h) of the DMCA hands over a user's identity with no lawsuit and no judge. Brazil chose the opposite path and never built an equivalent. The gap between the two models is being measured right now, at the Supreme Court.

▸In this article
When Take-Two filed three requests in August to identify whoever leaked Grand Theft Auto VI material, it did not sue anyone. It didn't have to. Section 512(h) of the DMCA lets a copyright holder ask the court clerk to issue a subpoena ordering a provider to reveal the identity of an alleged infringer, on three purely formal conditions: a prior takedown notification, a proposed subpoena, and a sworn declaration of purpose.
The clerk checks that the three documents are there. Nobody checks whether what is being asked for is proportionate to what is being sought.
In Brazil, that route does not exist. And it does not exist by legislative choice, not by oversight.
The rule: identification requires a court order
Article 10, § 1, of the Marco Civil da Internet establishes that a provider is only required to hand over connection logs or application access logs — on their own or combined with data that would identify the user — pursuant to a court order.
And Article 22 sets out how the request must be made. On pain of dismissal, the petition must contain three things:
- well-founded indications that the unlawful act occurred;
- a reasoned justification of the usefulness of the requested logs for investigative or evidentiary purposes;
- the period covered by the logs.
Note what shifts here. The three American requirements are documentary: the notification exists, the draft subpoena exists, the declaration exists. The three Brazilian ones are substantive: someone has to examine whether there is any indication of an unlawful act, whether those logs are good for anything, and whether the time frame is justified.
The difference is not one of stringency. It is a difference in who decides, and on what.
Addendum, 12 September 2026. The August 2026 filings show the instrument in use, and practice drifted a little from the design. In the three petitions that were granted, the order directing the clerk to issue the subpoena was signed by a judge, not the clerk, and what the judge signed was the draft written by the petitioner itself. In the fourth, the judge sent the petition back asking where the targets' names had come from, and the petitioner chose to withdraw rather than answer. The only check that appeared was not in the statute. It was a question from someone who read the file. The sequence is in Four cases, one question.
What would happen to a request like that one here
The exhibit attached to the subpoena directed at Discord asks for the identification of three named accounts — and, beyond those, all identifying information for every account that is or has been a member of three communities, going back to June 1, 2026.
Run through Article 22, a petition drafted that way would fare differently on each requirement.
Period: satisfied. There is a stated start date.
Indications of the unlawful act: satisfied as to the named accounts. As to the other members, there is no indication whatsoever — there isn't even an allegation that they did anything. Belonging to a server is not conduct.
Usefulness of the logs: this is where the request would run into the greatest difficulty. The justification would have to explain why the email address, phone number, message history and device identifier of every member of a community are useful to the inquiry — and the honest answer, for the overwhelming majority of them, is that they are not.
The point is not that the American request is unlawful: it was made under a different law, in a different country, and there it met what was required of it. The point is that the same text, filed here, would run into a filter that simply isn't in the way over there.
Not a stricter version — the absence of a mechanism
There is one detail that tends to go unnoticed and that explains the rest.
Article 19, § 2, of the Marco Civil says that applying that article to copyright infringement depends on specific statutory provision. In other words: in 2014 the Brazilian legislature looked at the DMCA model, decided not to import it, and left the matter to a future statute.
That statute never came.
The upshot is that a copyright holder in Brazil has no administrative shortcut at all — neither to take content down by that route, nor to identify who posted it. What they have is the ordinary path: go to court, with a reasoned petition, and persuade someone.
Anyone who reads this as Brazilian sluggishness has it backwards. It is by design.
What the STF changed, and what it didn't
Worth separating out, because the confusion is easy to fall into.
In June 2025 the Supreme Court declared Article 19 partially unconstitutional, and on June 17, 2026 it proclaimed the final holding, after motions for clarification. The liability regime for platforms hosting third-party content changed in meaningful ways: extrajudicial notice now suffices in situations that previously required a court order, liability for systemic failure was created, and a rebuttable presumption of fault was established for paid amplification.
None of that reaches Articles 10, 22 and 23.
Holding a platform liable for content and compelling a platform to identify a user are two distinct regimes, and the Supreme Court touched the first one. The judicial-order requirement for logs still stands — at least until the second one is decided.
The point that makes this urgent: ADC 91
Because the rule underpinning all of this is currently under review.
Abrint, the providers' association, filed ADC 91 asking the Supreme Court to declare Article 10, § 1 constitutional — that is, to confirm that sharing connection and access logs really does require prior judicial authorization. The action exists precisely because the practice had been under challenge: administrative authorities requesting traffic data directly from providers, bypassing any judge.
The rapporteur, Justice Cristiano Zanin, voted to uphold constitutionality, drawing a distinction that is the heart of the matter: subscriber data — identity, parentage, address — may be provided directly to the competent authorities, as Article 10, § 3 already allows; traffic data may not, because it makes it possible to reconstruct a person's habits, routines and network of relationships.
Justice Dias Toffoli's separate opinion followed the rapporteur with reservations and proposed reformulating the holding. That is where the most precise formulation of what is at stake appears: Article 10, § 1 being constitutional, "identification of the user by means of the provider's correlation of subscriber data with connection logs or internet application access logs requires specific judicial authorization, save only in the cases provided for by formal and proportionate law."
Worth rereading slowly, because it closes a loophole. It is not that subscriber data is freely available and traffic data is reserved. It is that cross-referencing one against the other to arrive at a person is the act that requires a court order — and cross-referencing subscriber records against logs is exactly what a § 512(h) subpoena asks the provider to do.
Toffoli's proposal also includes ex nunc modulation of effects, excepting ongoing investigations and criminal proceedings in which the defense had already raised the controversy.
None of this has been proclaimed. The case was being decided in the virtual plenary when Justice Flávio Dino requested that it be flagged for further consideration, which pulled it out of the electronic system and sent it to the physical plenary.
Update, 11 September 2026. On 27 August 2026 the full court took the case up again. The rapporteur restated his vote with the original holding, including the exception that lets police and prosecutors request subscriber data linked to traffic data directly in situations of imminent danger, subject to later judicial review. The certificate of judgment records that Justice Dias Toffoli followed him, and does not mention the reservations from his separate opinion. The judgment was suspended. The case was then placed on the calendar for 9 and 10 September and withdrawn on both dates. Since May, that makes nine calendar listings and one session actually held.
That delay is not noise — it is the information. As long as the holding goes unproclaimed, the judicial-order requirement in Article 10 continues to apply as written, and the gap between the two models stays where it is. If it is loosened, the gap narrows — and it narrows from the Brazilian side.
What to do with this
For anyone running a community, platform or provider in Brazil, three things still hold today:
An administrative request for traffic data is not to be honored. The distinction between subscriber data and connection logs is what separates complying with the law from leaking user data. It is in Article 10, and it hasn't changed.
A generic court order is contestable. If the petition did not present indications, usefulness and a period, Article 22 says it is inadmissible — and that argument belongs to the provider as much as to the user.
Being on a list is not an indication. That is what the American subpoena illustrates better than any hypothetical: the exposure of a given person did not turn on what that person did, it turned on where they were.
Sources
- Law No. 12.965/2014 (Marco Civil da Internet), arts. 10, 19, 22 and 23.
- 17 U.S.C. § 512(h).
- In re DMCA Subpoena to Discord, Inc., case 1:26-mc-00422, Southern District of New York, filed 08/20/2026.
- ADC 91, Supremo Tribunal Federal — certificates of judgment for the virtual session of March 6–13, 2026, the source of the holding proposed in the separate opinion, and for the plenary session of August 27, 2026; case docket consulted on 09/11/2026.
- RE 1.037.396 (Topic 987) and RE 1.057.258 (Topic 533), STF.
About the author

Robert F.
request a secure channelRobert F. is the founder of CyberX, a digital intelligence operation applied to investigation, based in Brazil with cross-border reach.
He works in OSINT, on-chain tracing and antifraud for legal teams, corporate compliance, banking antifraud and public authorities.
In CyberX publications we write about what can be said in public — fraud and scam typologies, digital threats, on-chain tracing, regulation, and what separates an investigation from a database lookup. Never about a case we work on, clients, matters under judicial secrecy, or operational detail that would compromise an investigation in progress — ours or anyone else's. A third party's case enters through the public official act, and through what it teaches, not through what it exposed.
Related reading
CyberX works in digital intelligence applied to investigation — OSINT, on-chain tracing, and fraud prevention. This content is informational and does not constitute legal advice.
how we write →Source: https://cyberx.to/en/analysis/what-takes-a-court-clerk-in-the-united-states-takes-a-judge-here-for-now
Retrieved on