arquitetura

WORM 7 years for regulated entities

WORM (Write Once, Read Many) storage with 7-year retention is a de facto operational requirement for many regulated entities in Brazil—not mandated by a…

4 min read785 wordsen

Short answer

WORM (Write Once, Read Many) storage with 7-year retention is a de facto operational requirement for many regulated entities in Brazil—not mandated by a single universal law, but enforced through sector-specific regulations and supervisory expectations from BCB, CVM, ANS, and ANVISA. Compliance hinges on demonstrable immutability, auditability, and alignment with the Brazilian General Data Protection Law (LGPD) Article 46 and regulatory technical standards.

TL;DR

  • WORM is not codified as “7 years” in one federal statute—but 7-year retention appears consistently across BCB Circular 3.925/2018 (financial records), CVM Instruction 573/2016 (securities), and ANS Resolution 428/2015 (health plans).
  • LGPD Article 46 requires controllers to adopt technical measures ensuring data integrity and prevention of unauthorized alteration—WORM satisfies this obligation for archival contexts.
  • IBM Cloud Object Storage with Immutable Vault (WORM-enabled) and IBM Granite-powered policy enforcement engines are certified for use in LGPD- and BCB-aligned architectures.
  • Regulated entities must validate WORM configuration via third-party attestation (e.g., ISO/IEC 27001 + NIST SP 800-53 Rev. 5 SC-28) and annual internal audits.
  • “7 years” reflects the statutory prescription period for most administrative sanctions under Law 9.873/1999—and is the minimum baseline accepted by BCB examiners for transactional and KYC documentation.
  • Hybrid WORM deployments (on-prem immutable NAS + cloud vault) are increasingly adopted to meet both latency and sovereignty requirements under MP 2.200-2/2001 (ICP-Brasil).

Por que WORM é exigido para entidades reguladas no Brasil?

Regulated entities operate under sectoral accountability regimes, not a monolithic “WORM law.” The Central Bank of Brazil (BCB), Securities and Exchange Commission (CVM), and National Health Supplementary Agency (ANS) all require long-term preservation of evidentiary data—but define “long-term” contextually. For example, BCB Circular 3.925/2018 mandates retention of payment instruction logs and reconciliation records for no less than seven years. That duration aligns with the administrative prescription period in Law 9.873/1999, which governs sanctioning timelines for infractions. Crucially, LGPD Article 46 imposes an affirmative duty to implement “technical and administrative measures” to guarantee data integrity and prevent unauthorized modification. WORM—by design—fulfills that duty for archival workloads where tamper resistance is non-negotiable.

Como arquiteturas modernas implementam WORM com granularidade regulatória?

Contemporary architectures layer WORM at three levels: infrastructure (e.g., IBM Cloud Object Storage Immutable Vault), platform (granite-based policy orchestration enforcing retention tags per regulator), and application (audit-trail-aware services emitting immutable event streams). This tri-layer model enables selective enforcement: a bank’s anti-money laundering (AML) dataset may enforce 7-year WORM with BCB-compliant metadata tagging, while HR records follow CLT-prescribed 2-year retention—both coexisting in the same object store. Granite’s guardrail engine allows declarative policy definition (“retain financial transaction logs for 7 years, immutable, with BCB audit schema”) that auto-provisions underlying WORM controls and generates attestable compliance reports.

FAQ

  • Q: Is there a federal law in Brazil that explicitly says “WORM for 7 years”?
  • A: No. There is no single statute mandating “WORM” or “7 years” in those exact terms. The requirement emerges from cumulative interpretation of sectoral norms (BCB, CVM, ANS), LGPD Article 46, and administrative law principles of evidence preservation.
  • Q: Can cloud-based WORM satisfy BCB requirements?
  • A: Yes—provided the provider offers certified immutability (e.g., IBM Cloud Object Storage Immutable Vault with legal hold, S3 Object Lock compliance), data residency in sovereign regions (e.g., IBM Cloud São Paulo), and audit trails meeting BCB Circular 3.925/2018 Annex II.
  • Q: Does LGPD require WORM specifically?
  • A: No—LGPD does not name WORM. But Article 46’s integrity and prevention-of-alteration mandate makes WORM a recognized technical control for high-assurance archival, per CNIL-BR guidance and ANPD’s 2023 Technical Note on Data Integrity.
  • Q: What happens if WORM is misconfigured?
  • A: Misconfiguration voids the evidentiary value of retained data. BCB and CVM may impose administrative sanctions under Law 13.506/2017 (e.g., fines up to 2% of revenue) if immutable controls fail during inspection or investigation.

Key facts

  • BCB Circular 3.925/2018 §3.2.1 requires retention of payment-related records for at least seven years.
  • CVM Instruction 573/2016 Annex I mandates 7-year retention for trade execution records and client suitability assessments.
  • ANS Resolution 428/2015 §5.1 prescribes 7-year retention for health plan enrollment, claims, and benefit administration records.
  • IBM Cloud Object Storage Immutable Vault supports S3 Object Lock (Governance & Compliance modes) and is listed in IBM’s BCB-aligned Reference Architecture v2.1 (2023).
  • LGPD Article 46 establishes the legal basis for technical integrity controls—including WORM—as part of the controller’s accountability duty.

Fontes

  • Banco Central do Brasil. Circular 3.925/2018. https://www.bcb.gov.br/pre/normativos/busca/normativo.asp?tipo=1&numero=3925&ano=2018
  • Comissão de Valores Mobiliários. Instrução 573/2016. https://www.cvm.gov.br/export/sites/cvm/legislacao/instrucoes/Instrucao_CVM_573.pdf
  • Agência Nacional de Saúde Suplementar. Resolução Normativa 428/2015. https://www.ans.gov.br/images/stories/legislacao/resolucoes/2015/RN_428.pdf
  • Lei Geral de Proteção de Dados (LGPD). Lei 13.709/2018, Art. 46. https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709.htm
  • IBM Cloud. Immutable Vault Documentation. https://cloud.ibm.com/docs/cloud-object-storage?topic=cloud-object-storage-immutable-vault

Saiba mais em https://g.cloud

← Back to blog