Quick Answer: What did the Brazil–EU adequacy decisions change?
They removed the need for an additional transfer mechanism for covered Brazil–EU flows. ANPD Resolution No. 32/2026 allows LGPD international transfers based on Article 33(I) to all EU Member States, Iceland, Liechtenstein and Norway, and EU institutions, bodies and agencies. In the opposite direction, Commission Implementing Decision (EU) 2026/179 allows GDPR personal data to be transferred from the EU to controllers and processors in Brazil subject to the LGPD without a further GDPR Chapter V authorization or SCC mechanism. But adequacy does not eliminate the underlying LGPD/GDPR legal basis, purpose limitation, controller-processor contracts, security, transparency, data-subject rights, retention or vendor governance. It also does not automatically cover a recipient's later transfer to a non-adequate country.
Key Takeaways
- Brazil and the EU adopted two independent adequacy decisions. They were coordinated, but each side's decision has its own legal scope.
- Brazil's Resolution 32 covers more than the EU 27. It expressly includes Iceland, Liechtenstein and Norway plus EU institutions, bodies and agencies.
- Brazil-to-EU/covered EEA transfers do not need Brazilian SCCs when adequacy is the Article 33 mechanism.
- EU-to-Brazil transfers covered by Decision 2026/179 do not need GDPR SCCs as an additional Chapter V mechanism.
- Adequacy does not remove the processing legal basis. Article 7/11 LGPD and relevant GDPR lawful-processing rules still matter.
- A DPA can still be required. Transfer adequacy and controller-processor contractual duties are different questions.
- Onward transfers are not automatically covered. An EU recipient sending Brazilian data onward to the U.S. needs a separate transfer analysis.
- The decisions are monitored and reviewable. Both frameworks contemplate ongoing monitoring and a four-year review cycle.
What Happened in January 2026?
On January 26, 2026, ANPD adopted Resolution No. 32, recognizing the European Union as providing an adequate level of personal-data protection for LGPD international-transfer purposes. The European Commission adopted Commission Implementing Decision (EU) 2026/179 on the same date, concluding that Brazil provides an adequate level of protection for personal data transferred from the EU to Brazilian controllers and processors subject to the LGPD.
ANPD described the arrangement as a mutual adequacy framework that allows personal data to circulate between the two jurisdictions more directly and with less transfer-specific bureaucracy. The important legal nuance is that the decisions are unilateral, independent and legally autonomous, even though they were adopted in a coordinated way.
Before adequacy
Brazil → EU: Article 7/11 basis + Article 33 mechanism (often Brazilian SCCs or another route) · EU → Brazil: GDPR lawful processing + Chapter V transfer mechanism (often EU SCCs or another route)
After adequacy for covered transfers
Brazil → covered EU/EEA destination: Article 7/11 basis + adequacy under Article 33(I) · EU → covered Brazilian recipient: GDPR lawful processing + Commission adequacy under Article 45
What Exactly Does Brazil's Resolution 32/2026 Cover?
ANPD recognizes the European Union as providing an adequate level of protection and authorizes international transfers using the mechanism in Article 33(I) of the LGPD. The sole paragraph expressly extends the recognition to all EU Member States, Iceland, Liechtenstein and Norway, and the institutions, bodies and agencies of the European Union.
| Destination | Covered by Resolution 32? | Practical result for Brazil-origin transfers |
|---|---|---|
| EU Member States | Yes | Adequacy can serve as the Article 33 transfer mechanism. |
| Iceland | Yes | Expressly included as an EFTA state in the EEA. |
| Liechtenstein | Yes | Expressly included as an EFTA state in the EEA. |
| Norway | Yes | Expressly included as an EFTA state in the EEA. |
| EU institutions, bodies and agencies | Yes | Expressly included under the Resolution. |
| United Kingdom | No | Requires its own Article 33 analysis. |
| Switzerland | No | Requires its own Article 33 analysis. |
| United States | No | Requires another valid Article 33 mechanism. |
What is excluded from Brazil's decision?
Article 2 says Resolution 32 does not apply to transfers carried out exclusively for:
- public safety;
- national defense;
- State security; or
- investigation and prosecution of criminal offenses.
Those exclusions matter mainly for government and law-enforcement contexts. A normal commercial SaaS, ecommerce, HR, marketing or cloud transfer should still be analyzed against the ordinary scope and facts rather than these excluded purposes.
What Does the EU Decision Cover?
Commission Implementing Decision (EU) 2026/179 is the other half of the practical framework. Its Article 1 says Brazil ensures an adequate level of protection for personal data transferred from the EU to controllers and processors in Brazil subject to the LGPD.
The Commission explains that covered transfers from EU controllers and processors to Brazilian controllers and processors may take place without a further authorization.
Does adequacy make a Brazilian company subject to the GDPR?
No. Adequacy is a transfer mechanism. It does not itself extend the GDPR's territorial scope.
A Brazilian company can separately be directly subject to the GDPR if Article 3 GDPR applies to its own activities, for example because of an EU establishment or certain offering/monitoring activities. The European Commission's adequacy decision expressly says it does not affect the direct application of the GDPR where its territorial-scope rules are met.
Do Companies Still Need Standard Contractual Clauses?
Brazil → covered EU/EEA destination
If the transfer falls within Resolution 32 and the company uses adequacy as its Article 33 mechanism, Brazilian SCCs are not required as an additional transfer mechanism.
Resolution 32 does not prohibit using another Article 33 mechanism. Article 5 expressly says the adequacy decision does not prevent international transfers to covered destinations from relying on other Article 33 mechanisms.
That means an organization can maintain contractual protections for commercial or governance reasons. But it should distinguish:
contractual protections we choose to keep from a transfer mechanism legally required because adequacy is unavailable.
EU → Brazil
For transfers within the scope of the EU adequacy decision, GDPR SCCs are no longer needed as the additional Chapter V transfer mechanism.
This can significantly simplify:
- EU customer → Brazilian SaaS provider;
- EU headquarters → Brazilian affiliate;
- EU controller → Brazilian processor;
- EU processor → Brazilian subprocessor where the decision applies; and
- other covered EU-to-Brazil business data flows.
EU SCCs have not become Brazilian SCCs
ANPD's transfer repository continues to say that no foreign standard contractual clauses have been formally recognized as equivalent Brazilian clauses.
Therefore:
EU adequacy ≠ recognition of EU SCC equivalence.
If a company sends data from Brazil to a non-adequate country and wants to rely on standard contractual clauses under the Brazilian regime, it should use the applicable Brazilian mechanism—not assume an EU SCC signed elsewhere automatically solves the Brazilian Article 33 requirement.
See Brazil's LGPD Standard Contractual Clauses Explained.
What Adequacy Does Not Eliminate
The easiest way to misuse adequacy is to treat it as a general compliance exemption. It is not.
| Compliance layer | Still required? | Why |
|---|---|---|
| Purpose specification | Yes | Adequacy authorizes the transfer mechanism, not an undefined processing purpose. |
| LGPD Article 7/11 legal basis | Yes | Resolution 19 separates the processing legal basis from the transfer mechanism. |
| GDPR lawful-processing basis | Yes where GDPR applies | Article 45 adequacy does not replace Articles 5/6/9 GDPR obligations. |
| Controller-processor contract | Potentially yes | Role-specific processing contracts remain separate from Chapter V / Article 33 transfer mechanisms. |
| Privacy notice / transparency | Yes | Data subjects still need accurate information about processing and relevant sharing/transfers. |
| Security | Yes | Article 46 LGPD and GDPR security duties remain. |
| Data-subject rights | Yes | Adequacy does not suspend access, correction, deletion or other rights. |
| Retention limits | Yes | Purpose and necessity continue to govern data lifecycle. |
| Vendor due diligence | Yes | Adequate jurisdiction does not mean every vendor is secure or compliant. |
| Incident response | Yes | Notification and incident governance remain fully relevant. |
Adequacy does not mean the laws are identical
The European Commission's adequacy analysis is based on an “essentially equivalent” level of protection, not exact duplication of the GDPR. Brazilian and EU rules still differ in legal bases, roles, data-subject procedures, DPO rules, sanctions and other details.
Global companies therefore should not collapse their compliance records into: “Brazil = GDPR now.”
Cloud Vendors, SaaS and Onward Transfers
Adequacy is easiest when the data path ends in the adequate destination. Modern cloud chains often do not.
Example cloud chain
Brazilian Controller → Irish SaaS Provider → U.S. Subprocessor → Global Support Team
Resolution 32 can simplify the first transfer from Brazil to the covered EU recipient. It should not be treated as automatically granting adequate status to the later U.S. destination.
The organization should separately map:
- which entity receives the data in the EU;
- which subprocessors receive or remotely access it later;
- which countries are involved;
- which GDPR transfer mechanism governs an EU-origin onward transfer where GDPR applies;
- which LGPD Article 33 mechanism is relevant to downstream Brazilian-data flows; and
- what the controller's vendor contract says about onward transfers and subprocessors.
Remote access can also matter
An EU-hosted database may still be accessed by support personnel in another country. The company should map the actual flow rather than assuming “server in Germany” ends the transfer analysis.
See LGPD International Data Transfers and LGPD Vendor Compliance.
Example 1: Brazilian Company Using an Irish SaaS Vendor
| Question | Practical answer |
|---|---|
| Is Ireland covered by Resolution 32? | Yes. It is an EU Member State. |
| Need an Article 7/11 legal basis? | Yes. Adequacy does not replace the processing basis. |
| Need Brazilian SCCs solely for Brazil → Ireland? | No, if the transfer falls within Resolution 32 and adequacy is used. |
| Need vendor contract / DPA analysis? | Yes. Controller/operator instructions, security, incidents, retention and rights remain relevant. |
| Vendor uses U.S. subprocessor? | Map separately. The U.S. is not covered by Resolution 32. |
Example 2: German Company Using a Brazilian Processor
A German company sends customer data to a Brazilian service provider that processes the data in Brazil and is subject to the LGPD.
The EU adequacy decision can remove the need for a separate GDPR Chapter V SCC mechanism for that covered transfer. But the German controller still needs to comply with its other GDPR obligations, including the appropriate controller-processor contractual framework, lawful processing, transparency, security and governance.
The Brazilian processor simultaneously remains subject to relevant LGPD obligations for processing within the scope of Brazilian law.
Example 3: French Parent Company and Brazilian Affiliate
A French parent transfers HR and management data to a Brazilian affiliate. Adequacy can simplify the international-transfer mechanism.
But the multinational still needs to distinguish:
- which entity is controller for each HR purpose;
- whether joint or separate purposes exist;
- which lawful basis supports the processing;
- who can access the data;
- how long it is retained;
- whether sensitive data is involved; and
- whether onward transfers leave Brazil or the EU.
Are the UK and Switzerland Included?
No. This is one of the most useful details in Resolution 32.
The Brazilian decision expressly covers:
EU Member States + Iceland + Liechtenstein + Norway + EU institutions/bodies/agencies.
It does not include the United Kingdom or Switzerland.
The same caution applies to vendors that contract through an EU entity but host or support data from another country. Use the real importer, processing locations and onward-transfer chain.
Does the Decision Cover EU Institutions?
Yes. Resolution 32 expressly includes the institutions, bodies and agencies of the European Union, referring to Regulation (EU) 2018/1725 in addition to the GDPR/EEA framework.
This is a more precise statement than simply saying “the EU 27 are adequate.”
What Should Change in Your Transfer Register?
Companies that maintained a 2025 transfer register should update covered EU/EEA rows.
| Field | Before 2026 | After Resolution 32 where covered |
|---|---|---|
| Destination | Ireland | Ireland |
| Processing legal basis | Article 7/11 basis | Same Article 7/11 basis |
| Article 33 mechanism | Brazilian SCCs / other applicable mechanism | Adequacy — Article 33(I), Resolution 32/2026 |
| Vendor contract | DPA + transfer clauses | DPA / processor controls still maintained; SCC transfer layer may be unnecessary for covered flow |
| Onward U.S. subprocessor | Separate review | Still a separate review |
| Review evidence | Transfer mechanism record | Resolution 32 scope + current adequacy repository + vendor chain evidence |
Should Privacy Notices Be Updated?
Potentially, yes. If a privacy notice currently says the company relies on Brazilian SCCs for every EU transfer, that may no longer describe the actual mechanism.
The notice should accurately describe international processing and the current transfer framework at the level appropriate to the audience. It does not need to become a legal memorandum, but it should not state an obsolete transfer mechanism.
Also remember that Resolution 19 has specific transfer transparency obligations. Adequacy changes the mechanism, not the importance of telling people where data goes and how their rights are protected.
What About Existing SCCs Already Signed With EU Vendors?
Resolution 32 expressly says adequacy does not prevent transfers from relying on other Article 33 mechanisms. Therefore, the existence of adequacy does not automatically invalidate an existing Brazilian SCC arrangement.
A company can decide whether to:
- leave the existing clauses in place as contractual protections;
- simplify the transfer section at renewal;
- change the transfer-register basis to adequacy while retaining operational DPA terms; or
- restructure its global transfer addendum for consistency.
The key is to avoid confusing a contractual clause that remains in the agreement with the legal reason currently used for the transfer.
Can Adequacy Be Revoked or Changed?
Yes. Adequacy is not permanent by definition.
Brazilian side
Resolution 32 requires ANPD to continuously monitor the level of protection maintained by the EU. ANPD can request additional information, carry out periodic assessments and must reassess the decision within four years from the Resolution's entry into force.
European side
Commission Decision 2026/179 also requires continuous monitoring. After four years, the Commission must evaluate whether Brazil continues to ensure adequate protection, and subsequent evaluations are to occur at least every four years.
The Commission can amend, suspend or repeal its decision if the required level is no longer assured.
Common Brazil–EU Adequacy Mistakes
“Brazil and the EU now have the same privacy law.”
Incorrect. Adequacy means the level of protection has been assessed as sufficient for transfers; it does not make LGPD and GDPR identical.
“We no longer need a legal basis.”
Incorrect. Adequacy solves the international-transfer mechanism layer, not the underlying lawfulness of processing.
“We can delete our processor DPA.”
Incorrect. Controller-processor contractual obligations and transfer mechanisms are different legal layers.
“All European countries are covered.”
Incorrect. Resolution 32 expressly covers the EU Member States, Iceland, Liechtenstein, Norway and EU institutions/bodies/agencies—not every European country.
“EU SCCs are now automatically Brazilian SCCs.”
Incorrect. ANPD's current repository still says no foreign standard clauses have been recognized as equivalent.
“An EU vendor can send the data anywhere after receiving it.”
Incorrect. Downstream transfers to non-covered destinations require a separate analysis under the applicable transfer rules.
“Adequacy means the vendor is secure.”
No. Adequacy evaluates a jurisdiction's legal framework. It is not a security certification for an individual provider.
18-Point Brazil–EU Adequacy Checklist
Update Your Transfer Register for the 2026 Adequacy Framework
The Brazil LGPD Compliance Playbook — 2026 Edition includes a dedicated International Transfer Review, plus the Data Mapping Worksheet, Processing Inventory / ROPA, Legal-Basis Decision Record, Vendor Privacy and Security Review, Data Processing Agreement Checklist, Retention Schedule, Security Incident Assessment, 100-point compliance audit and 30-day implementation roadmap.
Frequently Asked Questions
Is the European Union adequate under Brazil's LGPD?
Yes. Resolution 32/2026 recognizes the EU as providing an adequate level of personal-data protection for LGPD international-transfer purposes.
Which countries are covered by Brazil's Resolution 32?
All EU Member States plus Iceland, Liechtenstein and Norway are expressly included. EU institutions, bodies and agencies are also covered.
Are the United Kingdom and Switzerland covered?
No. They are not among the destinations expressly covered by Resolution 32 and require their own Article 33 transfer analysis.
Does Brazil-to-EU data still require Brazilian SCCs?
Not when the transfer falls within Resolution 32 and adequacy is used as the Article 33 mechanism. SCCs can remain contractually, but they are not required as an additional transfer mechanism for the covered flow.
Can EU personal data now be transferred to Brazil without GDPR SCCs?
For transfers within Commission Decision 2026/179, yes: the adequacy decision removes the need for an additional GDPR Chapter V SCC mechanism. Other GDPR obligations still apply.
Does adequacy remove the need for a DPA?
No. Transfer mechanisms and controller-processor contractual requirements are separate. A processor relationship can still require an appropriate DPA or processing contract.
Does adequacy replace the Article 7 or Article 11 legal basis?
No. The underlying LGPD processing must still have an applicable legal basis. Adequacy supplies the Article 33 international-transfer mechanism.
Are EU SCCs now recognized as equivalent Brazilian SCCs?
No. ANPD's current transfer repository states that no foreign standard contractual clauses have yet been recognized as equivalent.
Does adequacy cover an EU provider's onward transfer to the United States?
Not automatically. A downstream transfer to a non-covered destination needs its own transfer analysis under the applicable LGPD and GDPR frameworks.
Can adequacy be revoked?
Yes. Both ANPD and the European Commission provide for ongoing monitoring and periodic review. The EU decision can be amended, suspended or repealed if adequate protection is no longer ensured, and ANPD can reassess its own decision.
How often will the adequacy decisions be reviewed?
Brazil's Resolution 32 requires reassessment within four years of entry into force. The European Commission must evaluate its Brazil decision after four years and subsequently at least every four years.
Official Sources Used for This Guide
- ANPD Resolution No. 32/2026 — European Union Adequacy Decision (English) Primary source for covered EU/EEA destinations, excluded purposes, monitoring, four-year reassessment, alternative Article 33 mechanisms and effectiveness.
- ANPD — International Data Transfers Current official adequacy repository and status of equivalent SCCs, specific clauses and binding corporate rules.
- ANPD — Brazil and European Union Recognize Mutual Adequacy Official explanation that the two decisions are coordinated but unilateral, independent and legally autonomous.
- Commission Implementing Decision (EU) 2026/179 Primary EU source for adequacy of Brazil, scope covering controllers/processors in Brazil subject to the LGPD, effect on transfers and the monitoring/review framework.
- European Commission — Adequacy Decisions Current European Commission adequacy repository listing the January 26, 2026 Brazil adequacy decision.
- ANPD Resolution No. 19/2024 — International Transfer Regulation Transfer framework distinguishing the processing legal basis from the Article 33 international-transfer mechanism.
- Law No. 13,709/2018 — LGPD, current compiled text Primary statutory source for Article 3 territorial scope, Articles 7/11 legal bases and Articles 33–36 international transfers.