After yellow comes green: the paths of privacy in urban data management in São Paulo

30/07/2026 - Artigos

The advance of metropolises toward the smart city model continually redefines the boundaries between the operational efficiency of public management and the preservation of citizens’ fundamental rights. In the urban environment of São Paulo/SP, the intersection of cutting-edge technology, infrastructure, and data privacy has gained a new chapter that could trigger a true regulatory warning sign: Project Green Light, which involves a partnership between Google, the Traffic Engineering Company (Companhia de Engenharia de Tráfego – CET), and the São Paulo Municipal Information Technology Company (Empresa de Tecnologia da Informação do Município de São Paulo – Prodam)[1].

Before delving into the case at hand, we recall the paradigmatic episode involving the concessionaire ViaQuatro—responsible for managing Metro Line 4-Yellow—which established itself as a watershed moment in the practical application of the General Data Protection Law (Lei Geral de Proteção de Dados Pessoais – LGPD) in Brazil.

On that occasion, a public civil action filed by the Brazilian Institute for Consumer Defense (Instituto Brasileiro de Defesa do Consumidor – IDEC), together with the Public Defender’s Office and the Public Prosecutor’s Office of the State of São Paulo, questioned the legality of installing interactive advertising totems equipped with facial detection cameras on boarding platforms. The system performed emotional reaction mapping and demographic profiling of passengers under the pretext of conducting market research.

The São Paulo Judiciary deemed the practice abusive, given the capture of biometric data—classified as sensitive data under the LGPD:

“The rapporteur of the appeal, Reporting Judge Antonio Celso Faria, classified the company’s conduct as blameworthy and offensive to collective morality, emphasizing that it is virtually impossible to calculate the number of passengers using the defendant’s platform daily, a fact that characterizes collective moral damage. Furthermore, the judge highlighted that the concessionaire’s train passengers had their privacy invaded for profit, without authorization and without adequate control over image capture.”[2]

The conviction of the concessionaire by the 8th Chamber of Public Law of the Court of Justice of São Paulo (TJSP) resulted in a fine of R$ 500,000 for collective moral damages, allocated to the Diffuse Rights Defense Fund (Fundo de Defesa de Direitos Difusos – FDD). Beyond punishing the absence of a legal basis and the lack of transparency, the ruling highlighted the systemic risk arising from the exposure of vulnerable individuals, given that the tracking included children and adolescents without the proper safeguards required by the Statute of the Child and Adolescent (Estatuto da Criança e do Adolescente – ECA).

This case marked a regulatory “yellow light,” warning the market that urban development cannot indiscriminately infringe upon and violate privacy rights.

Having revisited this emblematic case, we enter a new scenario. The capital of São Paulo embarks on a new phase of technological innovation applied to mobility, represented by Project Green Light. This is a technical cooperation agreement established between Google, CET, and Prodam.

The initiative, formally announced at the annual Google for Brasil event, utilizes artificial intelligence to optimize traffic flow at complex intersections in the city, reducing wait times and pollutant emissions without requiring physical structural interventions.

Similar to the model adopted in Boston, the tool operates by analyzing macroscopic travel patterns obtained through aggregated traffic data from the Google Maps application. Google’s artificial intelligence monitors road dynamics and recurring bottlenecks, focusing particularly on areas where drivers face severe congestion. Based on this diagnosis, algorithms generate traffic signal recalibration proposals, recommending multi-second adjustments to the green light timing during specific “peak” hours[3].

Unlike the model applied on the Yellow Line, where a direct monitoring mechanism was imposed on individuals, the governance of Project Green Light preserves the autonomy of the public authority. The automated recommendations generated by Google are not directly applied to the city’s traffic lights; instead, they undergo screening, validation, and discretionary approval by CET technicians, who decide whether the recommendations serve the public interest before implementing them in the physical network.

The project is already yielding measurable results in Brazil and globally, demonstrating that technology can operate in a less intrusive and more collective manner. Indeed, the immediate impact of Project Green Light is believed to translate into practical benefits for citizens’ daily commutes and the environmental quality within urban settings.

From a legal privacy perspective, Project Green Light is grounded in de-identification and statistical aggregation, as telemetry and location data provided by Google Maps users are consolidated anonymously before being processed by artificial intelligence. Consequently, the project’s workflow does not involve individualized license plate tracking, vehicle owner identification, or facial image capture of drivers.

This positions the initiative within the scope of legitimate interest and the execution of public policies by municipal authorities, in strict compliance with the guidelines of Article 23 of the LGPD[4]. However, governance over this data sharing must be continuous. Although the information transmitted to CET and Prodam is statistical, the contractual protection of the partnership must prevent any possibility of subsequent re-identification of road users. This ensures that shared data remains strictly limited to traffic engineering purposes, eliminating the risk of secondary use for traffic enforcement or disproportionate state surveillance.

The “Guidance Guide on Personal Data Processing by the Public Sector” released by the ANPD[5] (National Data Protection Authority), alongside public consultations regarding data-sharing regulations between public and private sectors, demonstrates that state discretion is subject to rigorous boundaries.

Thus, any agreement or technical cooperation instrument involving the transfer of citizen data to private entities—or vice versa—must be clearly justified administratively. It must demonstrate the appropriateness of the purposes and mandate information security clauses compatible with current regulations, ensuring that technology’s “green light” moves forward in full alignment with legality.

Utilizing technology—and AI in particular—to improve quality of life in major urban centers is inescapable. However, this movement must observe existing legal and social dynamics so that, under the guise of solving a problem, potentially more severe issues—such as mass monitoring lacking an adequate legal basis—are not created.

Written by: Dr. Henrique Rocha, Partner, and Attorneys Mariana Ferreira Figueiredo and Marcella Guida from Peck Advogados.

Footnotes / Citations:

  • [1] Attorney-at-law with a dual degree from USP and the University of Camerino (Italy). Specialized in Intellectual Property, Entertainment Law, Media, and Fashion Law by ESA OAB. Researcher at the Legal Fronts Institute. Author of articles on technology, intellectual property, digital law, and personal data protection.

  • [2] Attorney-at-law graduated from Faculdade Presbiteriana Mackenzie. Specialist in Digital Law, holding an MBA in Technology for Business (PUC/RS) and a postgraduate degree in Civil Procedure (FGV). Member of the Privacy and Data Protection Commission at OAB/SP.

  • [3] Giacomelli, Maria. Google partners with CET to optimize intersections in SP. CNN, Jun 11, 2026. Available at: https://www.cnnbrasil.com.br/tecnologia/google-firma-parceria-com-cet-para-otimizar-cruzamentos-em-sp/. Accessed on: Jun 19, 2026.

  • [4] Social Communication TJSP – GC. TJSP maintains ban on data collection by ViaQuatro. Court of Justice, May 10, 2023. Available at: https://www.tjsp.jus.br/Noticias/Noticia?codigoNoticia=91605. Accessed on: Jun 19, 2026.

  • [5] Marini, Ari. How Google uses AI to reduce stop-and-go traffic on your route — and fight fuel emissions. Google Blog, Jul 29, 2024. Available at: https://blog.google/company-news/outreach-and-initiatives/sustainability/google-ai-project-greenlight/. Accessed on: Jun 19, 2026.

  • [6] Art. 23. The processing of personal data by public legal entities referred to in the sole paragraph of Art. 1 of Law No. 12,527 of November 18, 2011 (Access to Information Law) shall be carried out to fulfill its public purpose, in pursuit of the public interest, with the objective of executing legal powers or fulfilling the legal duties of public service, provided that:

    • I – the scenarios in which they process personal data in the exercise of their powers are disclosed, providing clear and updated information regarding the legal basis, purpose, procedures, and practices used to execute these activities in easily accessible channels, preferably on their websites;

  • [7] Guidance Guide on Personal Data Processing by the Public Sector (ANPD). Available at: https://www.gov.br/anpd/pt-br/centrais-de-conteudo/materiais-educativos-e-publicacoes/guia_orientativo_tratamento_de_dados_pessoais_pelo_poder_publico. Accessed on: Jun 19, 2026.

AUTHOR

Share

Latest news

21/01/2026

New CMN Resolution No. 5,274 of 12/18/2025

In late December 2025, the National Monetary Council (CMN) published CMN Resolution No. 5,274/2025, which establishes new cybersecurity requirements for all institutions authorized to operate […]

10/06/2026

ANPD opens Call for Inputs on the Age Verification Mechanisms Guide

A Call for Inputs is open at the Brasil Participativo platform by the National Data Protection Authority (ANPD) regarding the Guidance Manual “Age Verification Mechanisms,” […]

24/07/2025

Preventive measures and responses involving digital fraud, theft, and technological means

In its 17th annual report published, the Brazilian Public Security Forum demonstrated that the number of fraud records in Brazil has grown by 326.3% since […]

View more posts

SUBSCRIBE TO OUR NEWSLETTER

Receive content on Law, Innovation, and Business.

SIGN UP

Our Office

Rua Henrique Schaumann, nº 270, 4º andar
Edifício Pinheiros Corporate,
São Paulo – SP | CEP: 05413-909
(11) 2189-0444