Data & compliance

LGPD and Cross-Border Data: Brazil's Standard Contractual Clauses Are Now Mandatory

If your company moves Brazilian personal data abroad — to a parent, a cloud, or a processor — you now need ANPD-approved Standard Contractual Clauses. The grace period is over. Here is what changed and what to sign.

Data & compliance Reviewed by OAB-licensed attorneys 8 min read Updated July 2026

If your company moves the personal data of people in Brazil abroad — to a parent company, to a cloud provider, or to an outsourced processor — the rules changed, and the grace period is over. Since 23 August 2025, a cross-border transfer of Brazilian personal data is lawful only through an approved mechanism, and for most companies that mechanism is the Brazilian Standard Contractual Clauses the data-protection authority introduced. This briefing explains what the LGPD now requires of international data flows, what the new clauses are, and what a foreign company needs to sign.

It is written for the foreign business with a Brazilian footprint — a subsidiary whose HR and customer data flows up to headquarters, a company running its Brazilian operation on US or EU cloud and SaaS, or a group consolidating data across borders. If any Brazilian personal data leaves Brazil in your operation, the transfer regime below applies to you, wherever your company sits.

The LGPD, and why it reaches foreign companies

Brazil's data-protection law is the LGPD — Lei 13.709/2018 — enforced by the ANPD, the Autoridade Nacional de Proteção de Dados. Its most important feature for a foreign company is its extraterritorial reach: the LGPD applies to any company that processes the personal data of people located in Brazil, or that offers goods or services to them, regardless of where the company itself is based. You do not need a Brazilian office to be caught by it; you need Brazilian data subjects.

That reach is why the international-transfer rules matter so much to foreign groups. A company outside Brazil handling Brazilian customer or employee data is squarely inside the LGPD, and when that data crosses a border — which, for a foreign parent or a global cloud, it almost always does — the transfer regime is engaged.

Porto Alegre and the Guaíba at sunset
Brazil's data-protection regime now mirrors Europe's on international transfers. Image: Wikimedia Commons

What changed: Resolution 19/2024 and the end of the grace period

The specific change is ANPD Resolution CD/ANPD No. 19/2024, published on 23 August 2024, which regulates international data transfers and introduced the Brazilian Standard Contractual Clauses — in Portuguese, the Cláusulas-Padrão Contratuais. The regulation came with a one-year grace period, and that period ended on 23 August 2025. Since then, transferring Brazilian personal data abroad is lawful only via an approved mechanism. The window to keep relying on informal or undocumented flows has closed.

For anyone who built a GDPR programme in Europe, the shape of this will look familiar — and that familiarity is the trap, because the Brazilian clauses are their own instrument with their own mandatory wording, not a copy of the European SCCs you may already use.

The grace period is over — this is live now

The transitional year ran out on 23 August 2025. A company still moving Brazilian personal data abroad without an approved transfer mechanism is out of compliance today, not at some future date. If you have not papered your cross-border flows with an approved instrument, that is a present gap to close, not a project to schedule for later.

The lawful bases for a cross-border transfer

Under the regime, an international transfer of Brazilian personal data is lawful on one of a limited set of bases:

MechanismWhat it isPractical reality in 2026
Adequacy decisionANPD recognizes a destination country as offering adequate protectionAs of 2026, ANPD has recognized no country as adequate — including the US
Standard Contractual ClausesANPD's mandatory clauses — wording cannot be altered by the partiesThe route most transfers now rely on
Binding Corporate Rules (BCRs)Approved intra-group rules for multinational transfersAvailable, but heavier to obtain; suits larger groups
Specific ANPD-approved clausesBespoke contractual clauses approved by the ANPDCase-by-case; not the default path

The single most consequential fact in that table is the adequacy column. As of 2026, Brazil has recognized no country as "adequate"including the United States. There is no adequacy shortcut to rely on. The result is that most transfers now depend on the Standard Contractual Clauses, and those clauses come with a hard constraint: their wording is mandatory and the parties may not alter it. You adopt the clauses as issued; you do not negotiate them.

There is no adequate country and no shortcut — for most companies, moving Brazilian data abroad now means signing the Brazilian clauses, unchanged.

The wider LGPD duties behind the transfer rule

The transfer regime does not sit alone; it rides on top of the LGPD's general obligations, which a foreign company processing Brazilian data must also meet:

  • A lawful basis for processing the data in the first place (consent, legitimate interest, contract performance and the other legal bases);
  • Respect for data-subject rights — access, correction, deletion, portability and more;
  • A data protection officer (encarregado), the LGPD's DPO role;
  • Security measures and breach notification to the ANPD;
  • Exposure to fines of up to 2% of Brazilian revenue, capped at R$50 million per infraction.

That penalty structure — a percentage of Brazilian turnover, capped per infraction — is the enforcement backdrop to the whole regime. The point of noting it here is not alarm but proportion: the transfer clauses are one piece of an LGPD compliance programme that a foreign company with Brazilian data needs in any event, and the international-transfer obligation is the piece that changed most recently.

It is also worth being clear that the transfer mechanism does not replace the underlying lawful basis. Signing the Standard Contractual Clauses makes the movement of the data across the border lawful; you still need a valid legal basis to process that data in the first place, and the data subjects still hold their access, correction and deletion rights on both sides of the transfer. The clauses are a gate on the border, not a licence for the processing behind it. A programme that puts the SCCs in place but neglects the lawful basis or the data-subject-rights machinery has fixed the newest problem while leaving older ones open.

2018LGPD enacted (Lei 13.709/2018)
Aug 2025Transfer grace period ended (23 August)
R$50mFine cap per infraction (up to 2% of BR revenue)

How the Brazilian clauses differ from Europe's

Because so many affected companies already run a European programme, the most useful way to understand the Brazilian Standard Contractual Clauses is by contrast with the GDPR ones. The similarity is real — both are pre-set contractual instruments that make a cross-border transfer lawful where there is no adequacy finding — but they are separate instruments under separate laws, and that separation is the whole point.

Two differences matter most in practice. First, the Brazilian clauses have mandatory wording the parties may not alter: you adopt them as issued rather than negotiating bespoke terms, which simplifies the drafting but removes the flexibility some companies expect from contract. Second, they are enforced by the ANPD under the LGPD, with the LGPD's own definitions, data-subject rights and penalty regime behind them — not by European regulators under the GDPR. A company that lifts its EU SCCs, changes the header, and files them in Brazil has not complied; it has papered a Brazilian transfer with a foreign instrument. The correct move is to adopt the Brazilian clauses in their own right and align them with the European ones, keeping both live.

Two instruments, kept in step

If a data flow is already covered by EU SCCs to the same recipient, you do not discard those — you add the Brazilian clauses alongside them so the flow is lawful under both regimes. Think of it as layering, not replacing. A recipient handling both European and Brazilian personal data may end up party to both sets of clauses, and that is expected rather than duplicative.

The foreign-company angle: do not assume GDPR paperwork suffices

Here is the practical scenario the new rules bite hardest. A foreign parent pulls Brazilian employee or customer data up to headquarters for HR, analytics or consolidation. Or a company runs its Brazilian operation on US or EU cloud and SaaS — the data physically leaves Brazil to sit on servers abroad. Both are international transfers, and both must now be papered with the Brazilian Standard Contractual Clauses.

The temptation for a company with a mature European programme is to assume its GDPR documentation carries over. It does not. Align the two by all means — a company that already runs GDPR SCCs and BCRs has the organizational muscle to do this — but do not assume GDPR paperwork satisfies the LGPD. The Brazilian clauses are a distinct instrument under Brazilian law, adopted in their mandatory form, sitting on top of the LGPD's own processing, DPO and breach-notification duties. Treating Brazil as a footnote to the European programme is exactly how the gap opens.

Map the flows before you paper them

Before signing anything, know where your Brazilian personal data actually goes: which parent, which processors, which cloud regions, for what purpose. You cannot apply the correct transfer mechanism to a flow you have not mapped. A short data-flow inventory — origin, destination, purpose, mechanism — is the practical first step, and it doubles as evidence of diligence if the ANPD ever asks.

What to do now

For a foreign company with any Brazilian data, the near-term path is short and concrete.

  1. Inventory the cross-border flows

    Map every flow of Brazilian personal data out of Brazil — to parents, processors, and cloud/SaaS providers — with purpose and destination.

  2. Pick the mechanism per flow

    For most flows, that will be the Brazilian Standard Contractual Clauses in their mandatory wording; larger groups may weigh BCRs. There is no adequacy route to lean on.

  3. Execute the clauses

    Put the SCCs in place with each recipient, adopting the wording as issued rather than negotiating it, and align them with any existing GDPR instruments.

  4. Fix the LGPD foundations

    Confirm the lawful basis, data-subject-rights handling, the encarregado (DPO), security and breach-notification processes sit underneath the transfers.

This work pairs naturally with the rest of a foreign company's Brazilian setup — the corporate structure covered in our Brazil business law practice and business services, and the broader compliance picture for investors weighing Brazil, including our briefing on Brazil's OECD accession. Data compliance is not a standalone chore; it is part of operating a Brazilian business responsibly.

Coordinate Brazil with your global privacy programme

If you already run a GDPR programme, the efficient move is to extend it to Brazil rather than build a parallel one — same data-flow discipline, same DPO function, adapted to the LGPD and the Brazilian clauses. But extension means genuinely adopting the Brazilian instruments and duties, not relabelling the European ones. Have someone who knows both regimes reconcile them.

We help foreign companies bring their Brazilian data flows into compliance: mapping cross-border transfers, putting the ANPD Standard Contractual Clauses in place in their mandatory form, weighing BCRs for larger groups, and shoring up the underlying LGPD obligations — lawful basis, data-subject rights, the encarregado, security and breach notification — so the transfer mechanism rests on solid ground. We coordinate with your existing GDPR programme where you have one, work in English, and quote in writing. To review your Brazilian data flows, explore our business services or get in touch.

General information, not legal advice
Rules, fees, and thresholds in Brazil change by administrative act and vary by nationality and situation. Confirm the current requirements for your case before acting — the first conversation with us is free. Talk to a lawyer →

Frequently asked questions

Does the LGPD apply to a company based outside Brazil?

Yes. The LGPD applies extraterritorially — to any company that processes the personal data of people located in Brazil, or offers them goods or services, regardless of where the company is based. You do not need a Brazilian office to be caught by it; you need Brazilian data subjects. When that data crosses a border, the transfer regime is engaged.

What changed for international data transfers in Brazil?

ANPD Resolution CD/ANPD No. 19/2024, published 23 August 2024, regulates international data transfers and introduced Brazil's Standard Contractual Clauses. It came with a one-year grace period that ended on 23 August 2025. Since then, transferring Brazilian personal data abroad is lawful only via an approved mechanism.

Can I rely on a US adequacy decision to transfer data to the United States?

No. As of 2026, Brazil (the ANPD) has recognized no country as adequate, including the United States. There is no adequacy shortcut, so most transfers — including to the US — now rely on the Brazilian Standard Contractual Clauses, whose wording is mandatory and cannot be altered by the parties.

Do my existing GDPR clauses satisfy the LGPD?

Do not assume so. The Brazilian Standard Contractual Clauses are a distinct instrument under Brazilian law, adopted in their mandatory form, and they sit on top of the LGPD's own processing, DPO and breach-notification duties. You can and should align them with your GDPR programme, but GDPR paperwork alone does not satisfy the LGPD.

What are the mechanisms for a lawful cross-border transfer?

An ANPD adequacy decision (none exists yet), the ANPD Standard Contractual Clauses (mandatory wording, the route most transfers use), Binding Corporate Rules for multinational groups, or specific ANPD-approved contractual clauses on a case-by-case basis. In practice, most companies now depend on the SCCs.

What are the penalties for getting LGPD compliance wrong?

The ANPD can impose fines of up to 2% of a company's Brazilian revenue, capped at R$50 million per infraction, alongside other sanctions. That sits atop the LGPD's general duties — a lawful basis for processing, data-subject rights, a data protection officer (encarregado), security measures and breach notification.

Brazil Legal Shield
OAB-licensed Brazilian attorneys working in English for foreigners. We handle the work in this guide every week — visas, property, companies, tax, family and inheritance.
Keep reading

Related news.

Ready when you are

Want this handled for you?

Everything in this guide is work we do every week. Describe your situation and get a written flat-fee quote within one business day.