2026 Edition · Sources checked August 19, 2026 · Independent educational resource · Not legal advice
International Data Transfers

LGPD International Data Transfers: A Practical Guide for Global Businesses

Brazil's transfer rules are no longer a topic that global companies can address with a generic sentence saying “we may process data internationally.” Article 33 of the LGPD and ANPD Resolution No. 19/2024 create a concrete framework for adequacy, Brazilian standard contractual clauses, equivalent clauses, specific clauses, binding corporate rules, and other statutory transfer routes. This guide turns that framework into an operational map.

Published: Last reviewed: Reading time: ~20 minutes By LGPD Brazil Editorial Team

Quick Answer: How can personal data be transferred internationally under the LGPD?

Article 33 of Brazil's LGPD permits international transfers only in specified situations. For global businesses, the most important routes include an ANPD adequacy decision or documented safeguards such as ANPD standard contractual clauses, ANPD-approved equivalent standard clauses, specific contractual clauses approved by ANPD, or binding corporate rules approved by ANPD. Article 33 also contains other statutory routes, including specific highlighted consent for the international transfer and certain necessity-based situations. Resolution CD/ANPD No. 19/2024 regulates the main institutional and contractual mechanisms. As of August 19, 2026, ANPD's official repository lists the European Union as adequate; it does not list the United States.

Key Takeaways

  • International transfer is a separate compliance question. A lawful processing basis under Article 7 does not automatically resolve Article 33.
  • The EU is currently the major adequacy route. ANPD lists the European Union as adequate under Resolution No. 32/2026.
  • U.S. transfers need a separate mechanism analysis. The United States is not listed in ANPD's current adequacy repository.
  • Brazilian SCCs are already operational. Resolution 19/2024 includes ANPD clauses in Annex II and required implementation without modification when used as the mechanism.
  • Do not only map server location. Vendors, subprocessors, affiliates, support access, engineering access, backups, and global security tools can create cross-border flows.

International transfers are one of the most important LGPD topics for a company operating globally because modern systems rarely keep every processing operation inside one jurisdiction.

A Brazilian customer may use a U.S.-hosted SaaS platform, send support tickets to a European support team, have telemetry analyzed by an observability provider in another country, be authenticated through a global identity platform, and have backup copies stored in a different region. Each step can matter to the transfer analysis.

What Counts as an International Data Transfer Under the LGPD?

Article 5(XV) of the LGPD defines an international data transfer as the transfer of personal data to a foreign country or to an international organization of which a country is a member.

Resolution 19/2024 adds operational definitions used to structure transfer relationships, including the concepts of exporter and importer. In practice, a transfer inventory should identify at least:

ExporterWho sends or makes the data available internationally?
ImporterWho receives or accesses the data abroad?
DestinationWhich country or international organization?
PurposeWhy does the cross-border processing occur?
MechanismWhich Article 33 route supports it?
Operational point: “Our database is in São Paulo” does not necessarily mean there are no international data flows. If a team or service provider abroad receives data or is given access to personal data, the flow should be analyzed rather than excluded merely because the primary database remains in Brazil.

Article 33: The Legal Routes for International Transfers

Article 33 contains several distinct situations in which an international transfer can be permitted. A company should not compress all of them into the vague idea of “consent or SCCs.”

Article 33 route What it means Typical relevance to business
Adequacy Destination country or international organization has an adequate protection level recognized for LGPD purposes. Important for recurring business transfers to an adequate jurisdiction.
Contractual / organizational safeguards Controller demonstrates safeguards through mechanisms such as specific clauses, standard contractual clauses, or binding corporate rules. Core route for many recurring commercial transfers to non-adequate destinations.
International legal cooperation Necessary for international legal cooperation between specified public intelligence, investigation, and prosecution bodies. Primarily public-sector / law-enforcement context.
Protection of life or physical safety Transfer is necessary to protect life or physical safety of the data subject or a third party. Exceptional necessity scenario.
ANPD authorization The national authority authorizes the transfer. Depends on applicable regulatory process.
International cooperation commitment Transfer results from a commitment made in an international cooperation agreement. Context-specific, often institutional/public-sector.
Public policy / legal public-service attribution Transfer is necessary to execute public policy or a legal public-service function, with applicable publicity. Public-sector context.
Specific highlighted consent Data subject specifically and prominently consents to the international transfer after being informed of its international nature and separated from other purposes. Possible route, but should not be treated as the default for routine infrastructure transfers.
Certain Article 7 necessity situations Article 33(IX) refers to the situations in Article 7(II), (V), and (VI): legal/regulatory obligation, contract-related necessity, and regular exercise of rights. Can be relevant depending on the exact transfer and legal facts.
Important distinction

A company should document both why the underlying processing is lawful and why the international transfer is permitted. These are connected but not identical questions. Article 7 addresses legal bases for ordinary personal-data processing, while Article 33 contains the international-transfer framework.

Read the current compiled LGPD .

What Resolution CD/ANPD No. 19/2024 Changed

Resolution CD/ANPD No. 19 of August 23, 2024 created the detailed International Data Transfer Regulation and supplied the practical framework needed to use several of the mechanisms already contemplated by the LGPD.

The regulation addresses:

  • adequacy decisions;
  • ANPD standard contractual clauses;
  • foreign or international standard clauses recognized as equivalent by ANPD;
  • specific contractual clauses;
  • binding corporate rules; and
  • procedures for submitting and publishing approved mechanisms.

It also creates a public repository model so organizations can check which adequacy decisions, equivalent clauses, specific clauses, and binding corporate rules have actually been approved.

The Main Transfer Mechanisms in 2026

1

Adequacy Decisions

Currently operational

An adequacy decision means ANPD has recognized a country or international organization as providing a level of protection adequate for LGPD purposes. ANPD explains that transfers to an adequate destination can occur without an additional international-transfer mechanism.

As of August 19, 2026, ANPD's official repository identifies the European Union as adequate through Resolution No. 32/2026.

Document: destination, scope of adequacy decision, parties, processing purpose, data categories, date checked, and link/version of the applicable decision.
2

ANPD Standard Contractual Clauses

Currently operational

Resolution 19/2024 includes Brazilian standard contractual clauses in Annex II. ANPD's official guidance states that, when used as the transfer mechanism, these clauses must be implemented without modification.

The regulation provided a 12-month transition period from publication to implement the clauses. By August 2026, that transition period has already elapsed. Organizations relying on this mechanism should therefore review whether their current contracts actually contain the required Brazilian clauses in the required form.

Document: signed clause set, covered transfers, exporter/importer roles, underlying service agreement, security measures, onward-transfer conditions, and change-management process.
3

Equivalent Standard Contractual Clauses

No ANPD approval listed as of Aug. 19, 2026

ANPD can recognize standard clauses adopted by another country or international organization as equivalent to the Brazilian standard contractual clauses. If ANPD recognizes them, organizations can use the recognized clauses subject to any conditions in the approval.

However, ANPD's current official repository states that no equivalent standard contractual clauses have yet been recognized by the Board of Directors.

Practical effect: do not assume GDPR SCCs, another country's clauses, or a global DPA are automatically equivalent under Brazil's transfer regulation.
4

Specific Contractual Clauses

No ANPD approval listed as of Aug. 19, 2026

Specific contractual clauses are intended for exceptional situations where use of ANPD standard contractual clauses is demonstrably unfeasible for factual or legal reasons.

Prior ANPD approval is required. ANPD's current repository says no specific contractual clauses have yet been approved.

Practical effect: this is not a mechanism a company can simply draft internally and declare valid. The approval process is part of the mechanism.
5

Binding Corporate Rules

No ANPD approval listed as of Aug. 19, 2026

Binding corporate rules can support international transfers between entities in the same corporate group or conglomerate. ANPD states that these rules must be submitted for prior approval, accompanied by details of the transfers, countries, security measures, and a privacy governance program aligned with Article 50 of the LGPD.

As of this article's review date, ANPD's repository says no binding corporate rules have yet been approved.

Practical effect: global groups should not assume GDPR-approved BCRs automatically operate as Brazilian BCRs.
2026 repository check: ANPD currently reports no Board decisions approving equivalent standard clauses, specific contractual clauses, or binding corporate rules. The repository should be checked again before relying on this statement, because ANPD says it will update the list as new decisions are issued.

2026 Major Update: Brazil and the European Union Now Have Mutual Adequacy

In January 2026, ANPD recognized the European Union as adequate through Resolution No. 32/2026. The European Commission also adopted Implementing Decision (EU) 2026/179 recognizing Brazil as providing an adequate level of protection for personal data transferred from the EU to controllers and processors in Brazil that are subject to the LGPD.

This creates a significantly simpler transfer route for covered Brazil–EU flows. ANPD explains that a transfer to a destination covered by its adequacy decision does not require an additional international-transfer mechanism.

Adequacy does not remove the rest of the LGPD. A company still needs lawful processing, transparency, purpose limitation, minimization, security, retention, rights handling, and appropriate governance.

Official references: ANPD International Affairs and Commission Implementing Decision (EU) 2026/179.

What About Transfers From Brazil to the United States?

This is one of the most commercially important questions for foreign SaaS, cloud, e-commerce, marketing, support, and technology companies.

As of August 19, 2026, ANPD's official adequacy repository identifies the European Union as adequate and does not list the United States. That means a company should not label a Brazil-to-U.S. transfer as “adequate” merely because the U.S. recipient has a privacy program or because another jurisdiction has recognized a U.S. framework.

ANPD expressly states that adequacy decisions issued by other countries are not valid for Brazil. Therefore, a transfer to the United States should be reviewed against another Article 33 route that actually fits the facts.

Practical Decision Path for a Recurring Brazil → U.S. Business Transfer

  1. Confirm the LGPD applies to the underlying processing.
  2. Identify the actual international flow: exporter, importer, destination, purpose, data, systems, onward recipients.
  3. Check ANPD adequacy: if the destination is not covered, continue the mechanism analysis.
  4. Assess whether ANPD standard contractual clauses fit the relationship and can be incorporated without modification.
  5. Check whether another Article 33 route genuinely applies to the specific transfer.
  6. Document technical and organizational safeguards rather than treating contract language as the entire control.
  7. Review onward transfers and subprocessors so the mechanism covers the real chain, not only the first recipient.
  8. Make transparency match reality by explaining relevant international processing clearly to data subjects.
Do not use “specific consent for international transfer” as a universal escape hatch. Article 33(VIII) has its own requirements: the consent must be specific and highlighted, the data subject must receive prior information about the international nature of the operation, and the transfer must be clearly distinguished from other purposes. For routine infrastructure, cloud, and vendor relationships, obtain advice on the mechanism that best matches the actual processing.

How to Build an International Transfer Inventory

A transfer inventory should be more operational than a list of countries. The objective is to allow the privacy, legal, procurement, security, and engineering teams to answer exactly what happens to Brazilian personal data.

Business activityWhich process causes the international flow—cloud hosting, support, analytics, payroll, CRM, AI, fraud, email, security, affiliate sharing?
ExporterWhich controller or operator makes the personal data available internationally?
ImporterWhich foreign organization receives or can access the data?
CountriesPrimary destination plus support, backup, affiliate, and subprocessor locations.
Data subjectsCustomers, users, leads, employees, contractors, children, patients, or other groups.
Data categoriesOrdinary personal data, sensitive data, credentials, support content, behavioral data, financial information, identifiers.
Purpose and legal basisWhy the underlying processing occurs and which LGPD basis supports it.
Article 33 routeAdequacy, Brazilian SCCs, another applicable statutory route, or an ANPD-approved mechanism.
Contract and safeguardsClauses, security commitments, audit/evidence, deletion, incident escalation, access controls, encryption and governance.
Onward transfersWhich subprocessors, affiliates, or downstream providers can receive the personal data after the first importer?
TransparencyWhere and how affected individuals are informed about the international processing.
Review dateLast confirmation of mechanism, destination, contract, vendors, adequacy status and ANPD repository.

Cloud Hosting: Region Is Only the Beginning

A global cloud contract can create multiple cross-border scenarios. The production database might be in Brazil, while platform support, account administration, observability, abuse prevention, telemetry, or disaster recovery involve teams or systems outside Brazil.

The practical question is therefore not just: “Where is the server?”

It is:

  • Who can access Brazilian personal data?
  • From which countries?
  • Which service components replicate or export data?
  • Where are logs and backups processed?
  • Which subprocessors receive the information?
  • What happens during support or incident response?
  • What transfer route applies to each material flow?

This is why the international-transfer inventory should be connected directly to the SaaS data map or the e-commerce vendor map, rather than maintained as an isolated legal spreadsheet.

What Should Be in a Transfer Contract Review?

Where a contractual mechanism is used, the review should go beyond confirming that a clause titled “International Data Transfers” exists.

Review area Questions Evidence
MechanismWhich exact Article 33 route supports the transfer?Clause set, adequacy decision, approval, or documented statutory basis.
ScopeWhich transfers and services are actually covered?Transfer schedule, services, systems, purposes.
RolesWho is exporter/importer, controller/operator?Role matrix and contract language.
Onward transferCan the importer send data to additional recipients?Subprocessor list, affiliate list, authorization/change process.
SecurityWhat technical and organizational safeguards apply?Security schedule, access controls, encryption, audit evidence.
RightsCan the exporter and importer support data-subject rights?Operational procedure and assistance terms.
Incident responseHow quickly must the importer/operator escalate an incident?Contractual deadline, contacts, incident information requirements.
Deletion / returnWhat happens at termination and in backups?Retention/deletion schedule and termination procedure.

Five Common International Transfer Mistakes

1. “We use GDPR SCCs, so Brazil is covered.”

Not automatically. ANPD has a separate Brazilian SCC framework, and its current repository says no foreign standard clause set has yet been recognized as equivalent.

2. “The United States has strong privacy laws, so it must be adequate.”

Adequacy under the LGPD is an ANPD decision, not a company self-assessment. ANPD's current repository does not list the United States.

3. “The cloud region is Brazil, so there is no transfer.”

That conclusion can miss foreign support access, logging, telemetry, subprocessors, backups, and affiliate access.

4. “Our privacy policy says data may be processed globally, so that solves it.”

Transparency is necessary, but a disclosure does not replace the Article 33 mechanism, safeguards, and operational evidence.

5. “Consent covers every international vendor.”

Specific international-transfer consent has demanding statutory conditions and should not be treated as a generic checkbox for recurring infrastructure or a substitute for a mechanism analysis.

Need to see where transfer review fits in the full compliance program?

Use our 25-point LGPD Compliance Checklist for Foreign Companies to connect international transfers to scope, data mapping, roles, legal bases, vendor governance, rights, retention, security, and incident response.

A Practical 30-Day Transfer Remediation Sequence

Week Focus Deliverables
Week 1 Discover Vendors, affiliates, cloud, countries, support access, backups, AI, analytics, subprocessors.
Week 2 Classify Exporter/importer, roles, data categories, purposes, Article 7 basis, Article 33 route, adequacy check.
Week 3 Remediate Brazilian SCCs where appropriate, contract gaps, subprocessor controls, transparency, security safeguards.
Week 4 Evidence & governance Transfer register, contract repository, approval evidence, review dates, procurement triggers, vendor change process.

This sequence is a practical implementation model, not a guarantee that complex multinational transfer arrangements can be completely resolved within 30 days. Specific contractual clauses, binding corporate rules, sensitive processing, public-sector transfers, sector regulations, or complex corporate structures may require specialized Brazilian legal review.

Build a Documented International Transfer Review

The Brazil LGPD Compliance Playbook — 2026 Edition includes an International Transfer Review worksheet, Vendor Privacy and Security Review, Processing Inventory / ROPA, DPA Checklist, 100-point compliance audit, and a 30-day implementation roadmap for global businesses.

International Transfer Review Vendor review worksheet 100-point compliance audit 16 implementation tools
Get the Brazil LGPD Compliance Playbook · $47

Frequently Asked Questions

What is an international data transfer under the LGPD?

Article 5 defines it as a transfer of personal data to a foreign country or an international organization of which a country is a member. In practice, organizations should map the exporter, importer, destination, data, purpose, recipients, onward flows, and Article 33 route.

Which countries currently have an ANPD adequacy decision?

As of August 19, 2026, ANPD's official transfer repository identifies the European Union as adequate through Resolution No. 32/2026. ANPD states that it will update the repository when additional adequacy decisions are issued.

Is the United States currently adequate under LGPD?

As of this article's review date, ANPD's official repository lists the European Union and does not list the United States. A Brazil-to-U.S. transfer should therefore be assessed for another applicable Article 33 route.

Can we use ANPD's Brazilian Standard Contractual Clauses?

Yes. They are contained in Annex II of Resolution 19/2024. ANPD states that they must be implemented without modification when used as that transfer mechanism. The original 12-month transition period from publication has already elapsed by 2026.

Can we simply use EU GDPR SCCs for Brazil?

Do not assume that. ANPD can recognize foreign standard clauses as equivalent, but as of August 19, 2026 its official repository states that no equivalent standard contractual clauses have been approved by the Board of Directors.

Have specific contractual clauses or Brazilian BCRs been approved yet?

According to ANPD's current official repository, no specific contractual clauses or binding corporate rules have been approved by the Board of Directors as of this article's review date.

Does EU–Brazil adequacy mean LGPD and GDPR are now the same?

No. Adequacy simplifies covered international data transfers. It does not merge the laws or remove the separate processing, transparency, rights, security, retention, governance, and enforcement requirements of each regime.

Is a foreign support team's access to Brazilian personal data relevant?

It can be. Organizations should not limit their transfer map to storage location. If personal data is made available to a recipient or processing environment in another country, the flow should be analyzed under the regulation and the actual facts.

Official Sources Used for This Guide

Editorial note: This article is an independent educational resource, not legal advice. It was reviewed against official Brazilian and European Union sources available on August 19, 2026. International-transfer status can change quickly because ANPD can issue new adequacy decisions and approve equivalent clauses, specific clauses, or binding corporate rules. Always check the current ANPD repository before relying on the status described here, and obtain qualified Brazilian legal advice for your organization's actual transfer architecture.