Quick Answer: How can personal data be transferred internationally under the LGPD?
Article 33 of Brazil's LGPD permits international transfers only in specified situations. For global businesses, the most important routes include an ANPD adequacy decision or documented safeguards such as ANPD standard contractual clauses, ANPD-approved equivalent standard clauses, specific contractual clauses approved by ANPD, or binding corporate rules approved by ANPD. Article 33 also contains other statutory routes, including specific highlighted consent for the international transfer and certain necessity-based situations. Resolution CD/ANPD No. 19/2024 regulates the main institutional and contractual mechanisms. As of August 19, 2026, ANPD's official repository lists the European Union as adequate; it does not list the United States.
Key Takeaways
- International transfer is a separate compliance question. A lawful processing basis under Article 7 does not automatically resolve Article 33.
- The EU is currently the major adequacy route. ANPD lists the European Union as adequate under Resolution No. 32/2026.
- U.S. transfers need a separate mechanism analysis. The United States is not listed in ANPD's current adequacy repository.
- Brazilian SCCs are already operational. Resolution 19/2024 includes ANPD clauses in Annex II and required implementation without modification when used as the mechanism.
- Do not only map server location. Vendors, subprocessors, affiliates, support access, engineering access, backups, and global security tools can create cross-border flows.
International transfers are one of the most important LGPD topics for a company operating globally because modern systems rarely keep every processing operation inside one jurisdiction.
A Brazilian customer may use a U.S.-hosted SaaS platform, send support tickets to a European support team, have telemetry analyzed by an observability provider in another country, be authenticated through a global identity platform, and have backup copies stored in a different region. Each step can matter to the transfer analysis.
What Counts as an International Data Transfer Under the LGPD?
Article 5(XV) of the LGPD defines an international data transfer as the transfer of personal data to a foreign country or to an international organization of which a country is a member.
Resolution 19/2024 adds operational definitions used to structure transfer relationships, including the concepts of exporter and importer. In practice, a transfer inventory should identify at least:
Article 33: The Legal Routes for International Transfers
Article 33 contains several distinct situations in which an international transfer can be permitted. A company should not compress all of them into the vague idea of “consent or SCCs.”
| Article 33 route | What it means | Typical relevance to business |
|---|---|---|
| Adequacy | Destination country or international organization has an adequate protection level recognized for LGPD purposes. | Important for recurring business transfers to an adequate jurisdiction. |
| Contractual / organizational safeguards | Controller demonstrates safeguards through mechanisms such as specific clauses, standard contractual clauses, or binding corporate rules. | Core route for many recurring commercial transfers to non-adequate destinations. |
| International legal cooperation | Necessary for international legal cooperation between specified public intelligence, investigation, and prosecution bodies. | Primarily public-sector / law-enforcement context. |
| Protection of life or physical safety | Transfer is necessary to protect life or physical safety of the data subject or a third party. | Exceptional necessity scenario. |
| ANPD authorization | The national authority authorizes the transfer. | Depends on applicable regulatory process. |
| International cooperation commitment | Transfer results from a commitment made in an international cooperation agreement. | Context-specific, often institutional/public-sector. |
| Public policy / legal public-service attribution | Transfer is necessary to execute public policy or a legal public-service function, with applicable publicity. | Public-sector context. |
| Specific highlighted consent | Data subject specifically and prominently consents to the international transfer after being informed of its international nature and separated from other purposes. | Possible route, but should not be treated as the default for routine infrastructure transfers. |
| Certain Article 7 necessity situations | Article 33(IX) refers to the situations in Article 7(II), (V), and (VI): legal/regulatory obligation, contract-related necessity, and regular exercise of rights. | Can be relevant depending on the exact transfer and legal facts. |
A company should document both why the underlying processing is lawful and why the international transfer is permitted. These are connected but not identical questions. Article 7 addresses legal bases for ordinary personal-data processing, while Article 33 contains the international-transfer framework.
What Resolution CD/ANPD No. 19/2024 Changed
Resolution CD/ANPD No. 19 of August 23, 2024 created the detailed International Data Transfer Regulation and supplied the practical framework needed to use several of the mechanisms already contemplated by the LGPD.
The regulation addresses:
- adequacy decisions;
- ANPD standard contractual clauses;
- foreign or international standard clauses recognized as equivalent by ANPD;
- specific contractual clauses;
- binding corporate rules; and
- procedures for submitting and publishing approved mechanisms.
It also creates a public repository model so organizations can check which adequacy decisions, equivalent clauses, specific clauses, and binding corporate rules have actually been approved.
The Main Transfer Mechanisms in 2026
Adequacy Decisions
An adequacy decision means ANPD has recognized a country or international organization as providing a level of protection adequate for LGPD purposes. ANPD explains that transfers to an adequate destination can occur without an additional international-transfer mechanism.
As of August 19, 2026, ANPD's official repository identifies the European Union as adequate through Resolution No. 32/2026.
ANPD Standard Contractual Clauses
Resolution 19/2024 includes Brazilian standard contractual clauses in Annex II. ANPD's official guidance states that, when used as the transfer mechanism, these clauses must be implemented without modification.
The regulation provided a 12-month transition period from publication to implement the clauses. By August 2026, that transition period has already elapsed. Organizations relying on this mechanism should therefore review whether their current contracts actually contain the required Brazilian clauses in the required form.
Equivalent Standard Contractual Clauses
ANPD can recognize standard clauses adopted by another country or international organization as equivalent to the Brazilian standard contractual clauses. If ANPD recognizes them, organizations can use the recognized clauses subject to any conditions in the approval.
However, ANPD's current official repository states that no equivalent standard contractual clauses have yet been recognized by the Board of Directors.
Specific Contractual Clauses
Specific contractual clauses are intended for exceptional situations where use of ANPD standard contractual clauses is demonstrably unfeasible for factual or legal reasons.
Prior ANPD approval is required. ANPD's current repository says no specific contractual clauses have yet been approved.
Binding Corporate Rules
Binding corporate rules can support international transfers between entities in the same corporate group or conglomerate. ANPD states that these rules must be submitted for prior approval, accompanied by details of the transfers, countries, security measures, and a privacy governance program aligned with Article 50 of the LGPD.
As of this article's review date, ANPD's repository says no binding corporate rules have yet been approved.
2026 Major Update: Brazil and the European Union Now Have Mutual Adequacy
In January 2026, ANPD recognized the European Union as adequate through Resolution No. 32/2026. The European Commission also adopted Implementing Decision (EU) 2026/179 recognizing Brazil as providing an adequate level of protection for personal data transferred from the EU to controllers and processors in Brazil that are subject to the LGPD.
This creates a significantly simpler transfer route for covered Brazil–EU flows. ANPD explains that a transfer to a destination covered by its adequacy decision does not require an additional international-transfer mechanism.
Adequacy does not remove the rest of the LGPD. A company still needs lawful processing, transparency, purpose limitation, minimization, security, retention, rights handling, and appropriate governance.
Official references: ANPD International Affairs and Commission Implementing Decision (EU) 2026/179.
What About Transfers From Brazil to the United States?
This is one of the most commercially important questions for foreign SaaS, cloud, e-commerce, marketing, support, and technology companies.
As of August 19, 2026, ANPD's official adequacy repository identifies the European Union as adequate and does not list the United States. That means a company should not label a Brazil-to-U.S. transfer as “adequate” merely because the U.S. recipient has a privacy program or because another jurisdiction has recognized a U.S. framework.
ANPD expressly states that adequacy decisions issued by other countries are not valid for Brazil. Therefore, a transfer to the United States should be reviewed against another Article 33 route that actually fits the facts.
Practical Decision Path for a Recurring Brazil → U.S. Business Transfer
- Confirm the LGPD applies to the underlying processing.
- Identify the actual international flow: exporter, importer, destination, purpose, data, systems, onward recipients.
- Check ANPD adequacy: if the destination is not covered, continue the mechanism analysis.
- Assess whether ANPD standard contractual clauses fit the relationship and can be incorporated without modification.
- Check whether another Article 33 route genuinely applies to the specific transfer.
- Document technical and organizational safeguards rather than treating contract language as the entire control.
- Review onward transfers and subprocessors so the mechanism covers the real chain, not only the first recipient.
- Make transparency match reality by explaining relevant international processing clearly to data subjects.
How to Build an International Transfer Inventory
A transfer inventory should be more operational than a list of countries. The objective is to allow the privacy, legal, procurement, security, and engineering teams to answer exactly what happens to Brazilian personal data.
Cloud Hosting: Region Is Only the Beginning
A global cloud contract can create multiple cross-border scenarios. The production database might be in Brazil, while platform support, account administration, observability, abuse prevention, telemetry, or disaster recovery involve teams or systems outside Brazil.
The practical question is therefore not just: “Where is the server?”
It is:
- Who can access Brazilian personal data?
- From which countries?
- Which service components replicate or export data?
- Where are logs and backups processed?
- Which subprocessors receive the information?
- What happens during support or incident response?
- What transfer route applies to each material flow?
This is why the international-transfer inventory should be connected directly to the SaaS data map or the e-commerce vendor map, rather than maintained as an isolated legal spreadsheet.
What Should Be in a Transfer Contract Review?
Where a contractual mechanism is used, the review should go beyond confirming that a clause titled “International Data Transfers” exists.
| Review area | Questions | Evidence |
|---|---|---|
| Mechanism | Which exact Article 33 route supports the transfer? | Clause set, adequacy decision, approval, or documented statutory basis. |
| Scope | Which transfers and services are actually covered? | Transfer schedule, services, systems, purposes. |
| Roles | Who is exporter/importer, controller/operator? | Role matrix and contract language. |
| Onward transfer | Can the importer send data to additional recipients? | Subprocessor list, affiliate list, authorization/change process. |
| Security | What technical and organizational safeguards apply? | Security schedule, access controls, encryption, audit evidence. |
| Rights | Can the exporter and importer support data-subject rights? | Operational procedure and assistance terms. |
| Incident response | How quickly must the importer/operator escalate an incident? | Contractual deadline, contacts, incident information requirements. |
| Deletion / return | What happens at termination and in backups? | Retention/deletion schedule and termination procedure. |
Five Common International Transfer Mistakes
1. “We use GDPR SCCs, so Brazil is covered.”
Not automatically. ANPD has a separate Brazilian SCC framework, and its current repository says no foreign standard clause set has yet been recognized as equivalent.
2. “The United States has strong privacy laws, so it must be adequate.”
Adequacy under the LGPD is an ANPD decision, not a company self-assessment. ANPD's current repository does not list the United States.
3. “The cloud region is Brazil, so there is no transfer.”
That conclusion can miss foreign support access, logging, telemetry, subprocessors, backups, and affiliate access.
4. “Our privacy policy says data may be processed globally, so that solves it.”
Transparency is necessary, but a disclosure does not replace the Article 33 mechanism, safeguards, and operational evidence.
5. “Consent covers every international vendor.”
Specific international-transfer consent has demanding statutory conditions and should not be treated as a generic checkbox for recurring infrastructure or a substitute for a mechanism analysis.
Need to see where transfer review fits in the full compliance program?
Use our 25-point LGPD Compliance Checklist for Foreign Companies to connect international transfers to scope, data mapping, roles, legal bases, vendor governance, rights, retention, security, and incident response.
A Practical 30-Day Transfer Remediation Sequence
| Week | Focus | Deliverables |
|---|---|---|
| Week 1 | Discover | Vendors, affiliates, cloud, countries, support access, backups, AI, analytics, subprocessors. |
| Week 2 | Classify | Exporter/importer, roles, data categories, purposes, Article 7 basis, Article 33 route, adequacy check. |
| Week 3 | Remediate | Brazilian SCCs where appropriate, contract gaps, subprocessor controls, transparency, security safeguards. |
| Week 4 | Evidence & governance | Transfer register, contract repository, approval evidence, review dates, procurement triggers, vendor change process. |
This sequence is a practical implementation model, not a guarantee that complex multinational transfer arrangements can be completely resolved within 30 days. Specific contractual clauses, binding corporate rules, sensitive processing, public-sector transfers, sector regulations, or complex corporate structures may require specialized Brazilian legal review.
Build a Documented International Transfer Review
The Brazil LGPD Compliance Playbook — 2026 Edition includes an International Transfer Review worksheet, Vendor Privacy and Security Review, Processing Inventory / ROPA, DPA Checklist, 100-point compliance audit, and a 30-day implementation roadmap for global businesses.
Frequently Asked Questions
What is an international data transfer under the LGPD?
Article 5 defines it as a transfer of personal data to a foreign country or an international organization of which a country is a member. In practice, organizations should map the exporter, importer, destination, data, purpose, recipients, onward flows, and Article 33 route.
Which countries currently have an ANPD adequacy decision?
As of August 19, 2026, ANPD's official transfer repository identifies the European Union as adequate through Resolution No. 32/2026. ANPD states that it will update the repository when additional adequacy decisions are issued.
Is the United States currently adequate under LGPD?
As of this article's review date, ANPD's official repository lists the European Union and does not list the United States. A Brazil-to-U.S. transfer should therefore be assessed for another applicable Article 33 route.
Can we use ANPD's Brazilian Standard Contractual Clauses?
Yes. They are contained in Annex II of Resolution 19/2024. ANPD states that they must be implemented without modification when used as that transfer mechanism. The original 12-month transition period from publication has already elapsed by 2026.
Can we simply use EU GDPR SCCs for Brazil?
Do not assume that. ANPD can recognize foreign standard clauses as equivalent, but as of August 19, 2026 its official repository states that no equivalent standard contractual clauses have been approved by the Board of Directors.
Have specific contractual clauses or Brazilian BCRs been approved yet?
According to ANPD's current official repository, no specific contractual clauses or binding corporate rules have been approved by the Board of Directors as of this article's review date.
Does EU–Brazil adequacy mean LGPD and GDPR are now the same?
No. Adequacy simplifies covered international data transfers. It does not merge the laws or remove the separate processing, transparency, rights, security, retention, governance, and enforcement requirements of each regime.
Is a foreign support team's access to Brazilian personal data relevant?
It can be. Organizations should not limit their transfer map to storage location. If personal data is made available to a recipient or processing environment in another country, the flow should be analyzed under the regulation and the actual facts.
Official Sources Used for This Guide
- Law No. 13,709/2018 — LGPD, current compiled text Primary statutory source for the definition of international transfer and Articles 33–36.
- ANPD — International Affairs / International Data Transfers Official English-language overview of Resolution 19/2024, transfer mechanisms, approval status, and adequacy repository.
- ANPD — Transferência Internacional de Dados Official Portuguese repository and mechanism guidance, including the Brazilian SCC transition and current approval status.
- ANPD — Current Regulations Official regulatory index showing Resolution No. 32/2026 and other current ANPD rules.
- European Commission Implementing Decision (EU) 2026/179 Official EU legal source recognizing Brazil as adequate for covered GDPR transfers to controllers and processors in Brazil subject to the LGPD.