CiberLATAMbywhalemate

Brazil Central Bank tightens Pix rules

Brazil’s central bank banned ads and external links on Pix receipts, expanded MED controls, and set new fraud-blocking requirements.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Brazil’s central bank banned ads, offers, commercial promotions and external links from Pix payment receipts, while adding rules for fraud-block alerts and strengthening MED. The updated user-experience requirements for the system take effect on March 1, 2027.

Update September 7, 2026: Brazil’s central bank added requirements to report blocks tied to a well-founded suspicion of fraud and clarified how banks and institutions must respond when a MED refund request is disputed. It also confirmed that the new Pix user-experience rules and receipt requirements will fully take effect on March 1, 2027.

Brazil’s central bank has banned ads, commercial offers, promotions and external links on Pix payment receipts as part of new security rules aimed at cutting scams and fraud. The measure was added to the latest version of Pix’s minimum user-experience requirements manual and will take effect on March 1, 2027.

What changes on Pix receipts?

The new rule limits receipts to a formal record of the transfer, with no promotional content or references unrelated to the transaction. CNN Brasil reported that the ban covers ads, commercial offers, hyperlinks and any content not tied to the payment. NSC Total added that the goal is to close gaps that have been exploited in scams using fake files.

Another local report said Normative Instruction BCB No. 774 requires users to be notified when a transaction is blocked on a well-founded fraud suspicion, in addition to standardizing receipts and banning ads or external links on them, effective March 1, 2027. Atlas Público said that obligation is part of the same regulatory package that governs Pix use.

Beyond the ban on advertising and links, the package approved by the regulator also includes rules to make refunds easier and to strengthen verification of contacts registered in Pix, according to NSC Total. The outlet said the central bank wants to standardize the receipt as a strictly formal document to make fraudulent schemes harder.

What changed with MED and suspicious refunds?

The central bank expanded the response window for a refund request made through the Special Refund Mechanism, or MED, from 30 days to as much as 80 days when someone suspects the request was filed fraudulently. BBC News Brasil reported the change, and DOL said the longer window is meant to protect merchants and service providers.

According to DOL, the extra time allows them to gather documents such as invoices and delivery receipts to prove the transaction was legitimate. In practice, the regulator is giving the receiving party more time to defend the payment against a challenged refund.

G1 added that bank and financial institution apps must let customers attach documents and receipts when disputing a transfer flagged as fraudulent under MED. The outlet also said institutions will have up to 11 days to respond if the refund request was accepted, while the maximum 80-day period to request a refund remains in place.

TNH1 said MED was explicitly defined as the exclusive mechanism for fraud and scams. In that coverage, users still have up to 80 days to request a refund in fraud cases, and the financial institution has up to 11 days to say whether the request was considered valid.

The specialist outlet Clearing Post added that Normative Instruction BCB No. 766 raised the window from 30 to 80 days for the recipient to contest a refund made through the Special Refund Mechanism, and that institutions have until March 1, 2027, to adapt their systems to the new receipt rules.

What did the central bank tighten in cybersecurity and crypto?

The central bank also said it will keep stepping up regulatory and supervisory actions to raise security, governance and risk-management standards across the financial system. Valor Econômico reported that official position and said the regulator is aiming to preserve operational integrity and the proper functioning of markets.

At the same time, specialized coverage reported that the central bank tightened cybersecurity requirements for financial institutions, including secure system integration, access controls, penetration testing, credential monitoring and specific rules for third-party services. That line also appears in the regulator’s agenda for the virtual-assets sector.

What does the new framework require for virtual assets?

Virtual-asset companies already operating in Brazil had until October 30, 2026, to submit the first phase of their authorization request to the central bank under the sector’s new regulatory framework. Global Legal Insights said virtual-asset service providers in place before February 2, 2026, may keep operating while the regulator reviews the application, under a grandfathering regime.

BCB Resolution No. 552 expanded compliance rules, internal controls, auditing and cybersecurity requirements to authorized virtual-asset service providers, according to Fincatch. The same review said existing operators have that deadline to seek authorization, and that the regime covers governance, auditing and security across the sector.

InfoMoney reported that the rules require prior authorization, minimum capital aligned with the business, a physical headquarters in Brazil, asset segregation between the company and customers, and effective anti-money-laundering controls. BlockBR added that SPSAV firms must be legal entities incorporated in Brazil, with an exclusive corporate purpose, minimum capital scaled to size and operational risk, compliance and risk-management policies, KYC and AML processes, and minimum business-continuity standards.

Transfeera said firms seeking to enter the market without prior history cannot use the transitional regime, which raises the entry barrier and subjects them to the regulator’s requirements from the start. Veja added that after the October 30, 2026 deadline, authorized financial institutions will no longer be able to facilitate business with virtual-asset service providers that do not have a license or a pending authorization process. BitNotícias said exchange audits are now a permanent structural requirement, not a one-off procedure.

Sources

View all