LGPD Chapter V — Statutory framework and permitted transfer mechanisms
Brazil's Lei Geral de Proteção de Dados Pessoais (LGPD, Law No. 13.709 of August 14, 2018) governs international transfers of personal data, principally in Chapter V (Articles 33–36) of the statute. The LGPD defines "international transfer of data" as the transfer of personal data to a foreign country, or to an international organization of which Brazil is a member (Art. 5, XV). Jurisdiction is triggered on any of three grounds under Art. 3: (i) the processing occurs in Brazil; (ii) the processing aims to offer goods/services to, or to process data of, individuals located in Brazil; or (iii) the data were collected in Brazilian territory. LGPD applies to international transfers regardless of technical means, location of the exporter/importer, or data storage location.
Article 33 — Nine statutory transfer mechanisms. Article 33 permits an international transfer of personal data only in the following cases:
I. Adequacy decision. Transfer to a country or international organization recognized by the Autoridade Nacional de Proteção de Dados (ANPD) as providing an adequate level of data protection. As of January 26, 2026, ANPD has issued its first adequacy decision, recognizing the European Union (including EEA/EFTA states) as adequate under Resolution CD/ANPD No. 32/2026, enabling direct transfers to these jurisdictions without SCCs or other contractual safeguards. As of June 2026, no other adequacy decisions have been made for additional countries or organizations.
II. Contractual and corporate safeguards. Transfers may be made where the controller demonstrates guarantees of LGPD compliance in the form of:
- (a) Specific contractual clauses (bespoke, subject to ANPD approval);
- (b) Standard contractual clauses (SCCs), using the mandatory ANPD model (Resolution 19/2024, Annex II);
- (c) Binding corporate rules (BCRs), subject to ANPD approval;
- (d) Seals, certificates, and codes of conduct regularly issued — although as of June 2026, ANPD has not yet operationalized this mechanism for international transfer, so it is unavailable in practice.
Contractual mechanisms are set by Resolution CD/ANPD No. 19/2024. The SCCs are prescriptive and unmodifiable; controllers using them had a 12-month implementation period from August 23, 2024. ANPD has not approved any specific contractual clauses or BCRs as of June 2026.
III–IX. Statutory derogations and consent. The statute allows transfer in these further scenarios:
- III. International legal cooperation;
- IV. Protection of life or physical safety;
- V. ANPD authorization (case-by-case);
- VI. Legal or regulatory compliance, contract, or exercise of rights in proceedings;
- VII. Credit protection;
- VIII. Data subject’s specific and prominent consent (with enhanced notice);
- IX. Where necessary to fulfill hypotheses in Art. 7, II (legal obligation), V (contract), or VI (proceedings).
ANPD’s regulatory and supervisory role. Article 35 grants ANPD the authority to set the content of contractual safeguards, approve BCRs, and regulate other mechanisms. Article 36 makes original exporters jointly and severally liable for onward transfers by foreign recipients.
Recent update — EU adequacy. ANPD’s first adequacy decision (Resolution CD/ANPD No. 32/2026, effective January 26, 2026) allows personal data to be freely transferred to the EU, EEA, and EFTA, subject to periodic review. Controllers should continue to monitor ANPD’s official website for future adequacy decisions or regulatory amendments affecting other jurisdictions or mechanisms.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD) Source: Resolução CD/ANPD nº 19, de 23 de agosto de 2024 (International Data Transfer Regulation) Source: Resolução CD/ANPD nº 32, de 26 de janeiro de 2026 (EU adequacy)
Adequacy decisions — LGPD Art. 34 evaluation criteria and Resolution 19/2024 procedure
Under LGPD Art. 33, I, an international transfer of personal data is permitted when the destination is a country or international organization that provides a degree of protection of personal data adequate to that provided in the LGPD, as recognized by a formal adequacy decision issued by ANPD. Article 34 sets out the criteria ANPD must consider when evaluating adequacy:
- The general and sectoral legislation in force in the destination country or international organization;
- The nature of the data being transferred;
- Adherence to general data-protection principles and to the rights of data subjects as provided in the LGPD (Art. 6 principles and Chapter III rights);
- The existence of security safeguards for the data; and
- Other specific circumstances related to the transfer.
This assessment is holistic: ANPD examines not only the text of foreign statutes and regulations but also the practical enforcement posture, supervisory-authority independence, and data-subject remedies in the destination jurisdiction.
Resolution CD/ANPD No. 19/2024 — Adequacy decision procedure. ANPD operationalized the adequacy framework through Resolution CD/ANPD No. 19 of August 23, 2024 (the International Data Transfer Regulation). Article 13 of Annex I to the Resolution establishes the procedure for issuing an adequacy decision:
- Initiation. The process may be initiated ex officio by ANPD's Board of Directors or at the request of interested parties.
- Technical and legal analysis. ANPD's International Affairs Coordination (Coordenação de Assuntos Internacionais, CAI/CGRII) conducts a detailed evaluation of the destination jurisdiction's data-protection regime against the Art. 34 criteria.
- Federal Attorney opinion. The Specialized Federal Attorney's Office (Procuradoria Federal Especializada) must express its views on the legal sufficiency of the adequacy finding.
- Ministry of Foreign Affairs notification. The Ministry of Foreign Affairs (Ministério das Relações Exteriores) is notified at the outset of the case and is permitted to present a statement within the scope of its legal competencies, ensuring alignment with Brazil's foreign-policy interests.
- Board of Directors deliberation. The adequacy decision is subject to final deliberation by ANPD's Board of Directors in accordance with ANPD's Internal Regulations. The decision is entered by Resolution of the Board of Directors and published on ANPD's website.
Article 13, § 3 authorizes the Board of Directors to issue supplementary regulations regarding (i) the procedures for issuing an adequacy decision, (ii) periodic reassessment of protection levels, and (iii) review of adequacy decisions. This allows ANPD to suspend or revoke an adequacy decision if the destination jurisdiction's data-protection regime deteriorates or diverges from LGPD standards.
Adequacy decisions issued to date. As of the publication date of Resolution 19/2024 in August 2024, ANPD had not yet issued any adequacy decisions recognizing foreign countries or international organizations. The ANPD International Affairs page states that the website will be updated when adequacy decisions are taken.
In May 2026, one search result on the ANPD International Affairs page mentioned that "the European Union has been deemed an adequate international body by ANPD's Board of Directors through the publication of Resolution No. 32/2026." Unable to confirm as of 2026-05-30 the existence, effective date, territorial scope, or conditions of any such adequacy decision. Controllers considering reliance on a Brazil–EU adequacy bridge should verify the current list of adequacy decisions published by ANPD and review the full text of any Resolution for sectoral exclusions, onward-transfer conditions, and periodic-review obligations.
Effect of an adequacy decision. When ANPD recognizes a destination as adequate, controllers in Brazil may transfer personal data to that jurisdiction under Art. 33, I without implementing the contractual safeguards required by Art. 33, II (standard contractual clauses, specific contractual clauses, or binding corporate rules). The controller remains subject to all other LGPD obligations, including the data-minimization and purpose-limitation requirements in Art. 6 and the transparency obligations in Chapter III. If the transfer involves onward transfer from the adequate jurisdiction to a third country that does not itself hold an adequacy decision from ANPD, the controller must ensure that the onward transfer is covered by one of the mechanisms in Art. 33, II–IX or obtain separate adequacy confirmation.
Reciprocal adequacy and EU–Brazil developments. ANPD's adequacy evaluation under Art. 34 runs in parallel with adequacy assessments conducted by foreign data-protection authorities. The existing section of this guide notes that the European Commission published a preliminary draft adequacy decision recognizing Brazil in September 2025. If both ANPD and the European Commission issue reciprocal adequacy decisions, personal data may flow EU↔Brazil without additional contractual instruments, subject to any conditions, exclusions, or sector-specific carve-outs stated in the respective adequacy decisions. Controllers operating in both jurisdictions should monitor ANPD's published adequacy decisions at gov.br/anpd and the European Commission's adequacy decisions under GDPR Art. 45.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD, Art. 33, I and Art. 34)
Source: ANPD International Affairs — Adequacy decisions status
Standard contractual clauses — Resolution 19/2024 Annex II requirements and implementation deadline
Brazil's standard contractual clauses (SCCs) under LGPD Art. 33, II(b) are the primary operational mechanism for international data transfers in the absence of an adequacy decision. Resolution CD/ANPD No. 19 of August 23, 2024 operationalizes the SCC framework through Annex I (the procedural regulation) and Annex II (the model SCC text itself), establishing mandatory clauses that controllers must adopt without modification.
Article 15 of Annex I — Mandatory adoption of Annex II model clauses without alteration. Resolution 19/2024, Article 15 of Annex I provides that the standard contractual clauses prepared and approved by ANPD in the form of Annex II "establish minimum guarantees and valid conditions for carrying out an international data transfer based on item II(b) of Article 33" of the LGPD. The SCCs are predefined by ANPD and may be incorporated into existing contracts; they establish minimum safeguards ensuring that personal data continues to be protected in accordance with LGPD standards even when transferred to countries with different data-protection regimes.
No-modification requirement. The validity of an international data transfer under the SCC mechanism presupposes the full adoption of the text of the standard contractual clauses available in Annex II, with no alterations whatsoever, through a contractual instrument signed between the exporter (the Brazilian processing agent) and the importer (the foreign recipient). Controllers may either execute the SCCs as a standalone agreement or include them into a broader contract. If the SCCs are included within a broader agreement, any additional clauses or provisions set forth in the broader contractual instrument or related contracts signed between the parties may not exclude, modify, or contradict, directly or indirectly, the provisions of the standard contractual clauses.
When the SCCs are incorporated into a broader agreement, Sections I, II, and III of Annex II must be completed (identifying the parties, the transfer, and key details) and included as annexes to the contract signed by the exporter and importer. The 22 substantive clauses that follow these three sections remain fixed and unmodifiable.
12-month implementation deadline for controllers already relying on contractual clauses. Resolution 19/2024, Article 2, sole paragraph establishes a transitional period: data processing agents that were already using contractual clauses to perform international data transfers at the time Resolution 19/2024 was published (August 23, 2024) were required to incorporate the SCCs approved by ANPD into their respective contractual instruments within 12 months, counted from the publication date of the Resolution. That 12-month deadline expired on August 23, 2025. As of June 2026, all controllers relying on standard contractual clauses for transfers under LGPD Art. 33, II(b) must use the Annex II model without modification.
Content of the Annex II model SCCs. The Annex II standard contractual clauses comprise three informational sections (identification of the parties as exporter and importer; description of the transfer, including categories of data subjects, types of personal data, processing purposes, and duration; and onward-transfer options) followed by 22 substantive clauses. Key substantive obligations include:
- Clause 4 — Compliance with LGPD principles and data-subject rights. The importer must comply with the LGPD's data-protection principles (Art. 6) and respect the rights of data subjects (Chapter III), including transparency, purpose limitation, data minimization, and accuracy.
- Clause 19 — Access-request notification. The importer must notify the exporter and the data subject of any access request by public authorities related to the transferred personal data, except where prohibited by the law of the country of processing. The importer must adopt available legal measures, including judicial actions, to protect the rights of data subjects whenever there is adequate legal basis to challenge the lawfulness of the access request. The importer must maintain a record of access requests, including date, requestor, purpose, type of data requested, number of requests received, and legal measures adopted.
- Clause 21 — Data-processing security. Parties must implement security measures guaranteeing sufficient protection of the personal data subject to the transfer, taking into account the state of the art, implementation costs, the nature, scope, context, and purposes of processing, and the risks of varying likelihood and severity to the rights and freedoms of data subjects.
- Clause 23 — Notification of breach or inability to comply. If the importer violates the safeguards and guarantees in the clauses or is unable to comply with them, the exporter must be notified immediately (subject to the access-request prohibition in Clause 19.1). Upon receiving notice or discovering non-compliance, the exporter must adopt appropriate measures to ensure protection of data-subject rights and conformity of the transfer with Brazilian legislation and the clauses, including requesting return of the personal data, transfer to a third party, or deletion.
- Clause 24 — Brazilian law and jurisdiction. Brazilian law applies to the SCCs, and any controversy between the parties arising from the clauses must be resolved before the competent courts of Brazil, subject to any forum-selection clause the parties elect in Section IV.
Transparency and data-subject access. Under Resolution 19/2024, Article 17 of Annex I, the controller must make available to the data subject, upon request, the full text of the clauses used to carry out the international data transfer, subject to protection of trade secrets and industrial secrets. The deadline for responding to the request is 15 days, unless a different deadline is established by specific ANPD regulation. The controller must also publish on its website a document in Portuguese, in simple, clear, precise, and accessible language, containing information about the international data transfer, including the form, duration, and specific purpose of the transfer; the categories of data transferred; the responsibilities of the processing agents and the security measures adopted; and other information prescribed in Article 17, § 2.
Relationship to specific contractual clauses and equivalent SCCs. Standard contractual clauses are distinct from specific contractual clauses (Art. 33, II(a)) and equivalent standard contractual clauses (foreign SCCs recognized by ANPD as equivalent to the Annex II model). Specific contractual clauses may be used only in exceptional situations, when it is impracticable to use the standard contractual clauses for reasons of fact or law duly proven by the interested party; they require prior approval by ANPD's Board of Directors following technical review by the International Affairs Coordination (CAI/CGRII) and a legal opinion from the Specialized Federal Attorney's Office. As of the Resolution 19/2024 publication in August 2024, ANPD had not approved any specific contractual clauses. Equivalent standard contractual clauses from other jurisdictions (for example, the European Commission's SCCs under GDPR Art. 46(2)(c) or the UK IDTA) may be recognized by ANPD as equivalent to the Annex II model through a Board of Directors resolution following public consultation and analysis; ANPD had not recognized any foreign SCCs as equivalent as of August 2024.
Controllers wishing to transfer personal data from Brazil to a jurisdiction that lacks an ANPD adequacy decision under Art. 33, I should prioritize the Annex II standard contractual clauses as the primary mechanism. Where the standard clauses are impracticable for documented operational or legal reasons, the controller may petition ANPD for approval of specific contractual clauses under the Chapter VI procedure in Annex I, submitting the full text of the proposed clauses, incorporation documents, a detailed description of the transfer (countries, categories of data, purposes, security measures), and an analysis demonstrating compatibility with LGPD principles and data-subject rights.
Source: ANPD International Affairs — Standard Contractual Clauses FAQs
Binding corporate rules — Resolution 19/2024 Arts. 25–28 approval procedure and Art. 50 LGPD privacy governance linkage
Binding corporate rules (BCRs, normas corporativas globais) under LGPD Art. 33, II(c) are the specialized mechanism for intra-group international data transfers within multinational corporate groups and conglomerates. Unlike standard contractual clauses, which govern bilateral controller-to-processor or controller-to-controller transfers, BCRs establish a unified data-protection framework binding all group members that subscribe to it, enabling streamlined cross-border transfers within the same corporate family. Resolution CD/ANPD No. 19 of August 23, 2024 operationalizes the BCR framework through Articles 25–28 of Annex I, setting binding requirements and the Board of Directors approval procedure.
Article 25 — Scope and binding nature. BCRs are intended for international data transfers between organizations within the same group or conglomerate of companies (grupo ou conglomerado de empresas), and are binding on the members of the group that subscribe to them (Art. 25). A BCR constitutes a valid mechanism for carrying out international personal data transfers only for the organizations or countries covered by the binding corporate rules (Art. 25, sole paragraph). Controllers must therefore clearly define the territorial and entity scope of the BCR: which legal entities in which jurisdictions are bound, and whether the BCR covers all processing activities of those entities or only specified categories of data or processing purposes. A BCR does not authorize transfers to third parties outside the corporate group unless the third-party transfer is itself covered by one of the other Art. 33 mechanisms (adequacy, SCCs, or specific contractual clauses).
Article 26 — Mandatory linkage to LGPD Art. 50 privacy governance program. BCRs must be linked to the establishment and implementation of a privacy governance program that meets the minimum conditions established in LGPD Art. 50, § 2 (Art. 26). This is a threshold requirement: ANPD will not approve a BCR application unless the applicant group demonstrates a functioning privacy governance program covering all entities subscribing to the BCR.
LGPD Art. 50, § 2 prescribes seven mandatory elements for a qualifying privacy governance program:
(a) Demonstrate the controller's commitment to adopt internal processes and policies that ensure comprehensive compliance with norms and good practices relating to the protection of personal data; (b) Apply to the entire set of personal data under the controller's control, regardless of the mode of collection; (c) Be adapted to the structure, scale, and volume of the controller's operations, as well as to the sensitivity of the data processed; (d) Establish adequate policies and safeguards based on a systematic process of assessment of impacts and risks to privacy (data-protection impact assessments); (e) Aim to establish a relationship of trust with the data subject through transparent action and mechanisms ensuring data-subject participation; (f) Be integrated into the controller's general governance structure and establish and apply internal and external supervision mechanisms; and (g) Include incident-response and remediation plans.
The corporate group submitting a BCR application must submit documentary evidence of each element: privacy policies, DPIA frameworks, incident-response plans, supervisory-committee charters, and training records. ANPD's International Affairs Coordination (CAI/CGRII) will verify that the privacy governance program is operational across all entities subscribing to the BCR, not merely aspirational.
Article 27 — Substantive content requirements for the BCR. In addition to satisfying the Art. 26 privacy-governance prerequisite, BCRs must include eight mandatory substantive provisions (Art. 27):
I. Guarantees of compliance with LGPD principles (Art. 6: purpose, adequacy, necessity, free access, data quality, transparency, security, prevention, non-discrimination, and accountability) and data-subject rights (LGPD Chapter III: confirmation of processing, access, correction, anonymization/blocking/deletion, portability, information about sharing, information about the possibility of denying consent and its consequences, and revocation of consent);
II. Identification of the responsible entity (entidade responsável) — a legal entity with headquarters in Brazil that is liable for any violation of the binding corporate rules, even if the violation arises from an act committed by a group member based in another country. The responsible entity serves as the ANPD enforcement point and the data-subject point of contact within Brazil. The responsible entity must have legal capacity and assets sufficient to satisfy potential LGPD administrative fines and civil damages;
III. Specification of the categories of personal data subject to the BCR and the categories of data subjects (e.g., employees, customers, suppliers, website visitors);
IV. Description of the international data transfers covered by the BCR, including the countries of destination and the processing purposes;
V. Security and organizational measures adopted to protect personal data, including technical safeguards (encryption, pseudonymization, access controls) and organizational safeguards (role-based access, periodic audits, privacy training);
VI. Procedures and deadlines for responding to data-subject requests to exercise their LGPD Chapter III rights. Under Art. 27, § 2, these requests must be answered within the time period provided in LGPD (15 days from the date of the request under LGPD Art. 18, § 3, unless ANPD establishes a different deadline by specific regulation);
VII. Mechanisms for transparency and communication with data subjects, including the availability of the BCR text (or a summary in clear language) on the responsible entity's website and the designation of a contact point for data-subject inquiries; and
VIII. Provision for notification to ANPD in case of changes in the guarantees presented as sufficient for observance of LGPD principles, data-subject rights, and the data-protection regime, especially when a group member is subject to a legal determination of another country that prevents compliance with the binding corporate rules. Art. 27, § 1 requires the BCR to provide for immediate notification to the responsible entity whenever a group member located in another country is subject to a legal determination that prevents compliance with the BCR, except where express legal prohibition prevents such notification (parallel to the SCC access-request notification rule in Annex II, Clause 19). This addresses conflicts-of-law scenarios: a group member subject to a foreign government access demand, a blocking statute, or a data-localization requirement that conflicts with the BCR's data-transfer permissions must notify the Brazilian responsible entity so it can assess LGPD compliance and whether to suspend transfers to that jurisdiction.
Article 28 — ANPD Board of Directors approval requirement. BCRs must be submitted to ANPD for approval, following the procedure described in Resolution 19/2024, Chapter VIII (Art. 28). The procedure mirrors that for specific contractual clauses:
1. Submission via ANPD's Electronic Information System (SEI). The applicant must file the approval request through ANPD's online portal (confirmed in search result 1, index 1-27 and 5-14). Standing to request BCR approval is limited to organizations within the same group or conglomerate of companies (search result 8, index 8-9–8-10).
2. Required documentation (Art. 29). The application must include: — The full text of the binding corporate rules; — Incorporation documents of the processing agent or of the group members (demonstrating corporate-group relationship); — A detailed description of the transfers covered, including the countries involved and the categories of personal data; — The security measures implemented to protect the data; — An analysis demonstrating that the BCR is compatible with LGPD principles, data-subject rights, and the LGPD data-protection regime; and — Evidence of the Art. 50, § 2 privacy governance program (policies, DPIA framework, incident-response plan, supervisory mechanisms, training records).
3. Technical and legal analysis by CAI/CGRII. ANPD's International Affairs Coordination conducts a detailed evaluation of the BCR against the Art. 27 substantive requirements and the Art. 50, § 2 privacy-governance prerequisites (search result 1, index 1-9).
4. Specialized Federal Attorney opinion. The Procuradoria Federal Especializada (Specialized Federal Attorney's Office) must express its legal views on the sufficiency of the BCR (search result 1, index 1-9).
5. Board of Directors deliberation. The BCR approval is subject to final deliberation by ANPD's Board of Directors. Approval is by Resolution of the Board of Directors, published on ANPD's website (search result 1, index 1-9; search result 5, index 5-6).
6. Publication. Under Art. 31 of Resolution 19/2024, ANPD will publish on its website a list of approved BCRs, indicating the applicant, the approval date, and the Board of Directors decision, along with other information deemed necessary by the responsible technical area. ANPD will publish the full text of the BCR when such rules may be employed by other processing agents, subject to protection of trade and industrial secrets (search result 8, index 8-20–8-22). This allows other corporate groups to use an approved BCR as a template if ANPD determines the BCR is sufficiently generic.
BCRs approved to date. As of the publication of Resolution 19/2024 in August 2024, no binding corporate rules had been approved by ANPD's Board of Directors (search result 1, index 1-10; search result 5, index 5-7; search result 5, index 5-22). Controllers seeking BCR approval should monitor ANPD's International Affairs page at gov.br/anpd for updates on approved BCRs and any supplementary guidance issued by ANPD on the application procedure.
Practical considerations for multinational groups. BCRs are the preferred mechanism when a corporate group conducts frequent or systematic intra-group cross-border transfers (HR data of employees across multiple countries, centralized customer databases, shared IT infrastructure, global research and development activities). The up-front investment is significant — drafting the BCR text, implementing the Art. 50, § 2 privacy governance program, preparing the application documentation, and navigating ANPD's approval process — but once approved, the BCR authorizes ongoing transfers without executing separate contracts for each transfer or each group entity. Multinational groups operating in both Brazil and the European Union should consider whether to prepare parallel BCRs (one approved by a lead EU supervisory authority under GDPR Art. 47 and one approved by ANPD under LGPD Art. 33, II(c)) or to seek ANPD recognition of an existing EU-approved BCR as an "equivalent" instrument. As of August 2024, Resolution 19/2024 does not provide an express equivalence procedure for foreign BCRs, though ANPD retains discretion to recognize foreign BCRs on a case-by-case basis.
Groups that do not yet have the privacy-governance infrastructure required by Art. 50, § 2 should prioritize implementation of standard contractual clauses under Resolution 19/2024, Annex II as the interim transfer mechanism, then petition for BCR approval once the privacy governance program is operational and demonstrable.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD, Art. 33, II(c) and Art. 50, § 2)
Source: ANPD International Affairs — Binding Corporate Rules FAQs
Specific consent for international transfers — LGPD Art. 33, VIII heightened standard and prior-information requirement
Brazil's LGPD permits international data transfers under Article 33, VIII when the data subject has provided specific and prominent consent for the transfer, with prior information about the international character of the operation, clearly distinguishing the transfer from other processing purposes. This consent-based mechanism is one of nine permitted transfer methods enumerated in Art. 33 and operates independently of adequacy decisions or contractual safeguards.
Heightened consent standard beyond Art. 7, I general consent. Article 33, VIII imposes a higher bar than the general consent standard in Art. 7, I, which permits processing "mediante o fornecimento de consentimento pelo titular" (by obtaining consent from the data subject). The general consent definition in Art. 5, XII requires that consent be a "manifestação livre, informada e inequívoca pela qual o titular concorda com o tratamento de seus dados pessoais para uma finalidade determinada" (free, informed, and unequivocal manifestation by which the data subject agrees to the processing of their personal data for a specific purpose). Art. 33, VIII adds three additional requirements specific to international transfers:
- Specific consent (consentimento específico) — The controller must obtain consent for the international transfer itself, not only for the underlying processing activity. If the controller has already obtained consent under Art. 7, I for a domestic processing purpose (for example, marketing), that consent does not automatically authorize an international transfer of the same data. The controller must return to the data subject and seek a separate, transfer-specific consent.
- Prominent consent (em destaque) — The consent request for the international transfer must be highlighted or separated from other consent requests or terms-of-service clauses. This mirrors the requirement in Art. 8, § 1 that written consent "deve constar de cláusula destacada das demais cláusulas contratuais" (must appear in a clause that stands out from other contractual clauses). Controllers should present the international-transfer consent request in a separate checkbox, a distinct paragraph with visual emphasis (bold or larger font), or a standalone consent form, rather than burying it in a general privacy policy or bundling it with unrelated consents.
- Prior information about the international character (informação prévia sobre o caráter internacional da operação, distinguindo claramente esta de outras finalidades) — Before the data subject consents, the controller must disclose that the data will be transferred internationally and distinguish the international transfer from the controller's other processing activities. The controller should identify the destination country or countries, the identity of the recipient (importer), and the purpose of the transfer. A compliant consent notice might state: "We will transfer your contact information and purchase history to our U.S. payment processor [name] to complete your transaction. This is an international data transfer to the United States. Do you consent?" The notice must make clear that the transfer is a distinct operation from the underlying processing, so that the data subject understands the cross-border dimension and can evaluate the associated risks.
When Art. 33, VIII consent is appropriate. The specific-consent mechanism is most commonly used for one-off or occasional transfers where the controller does not have a recurring cross-border data flow and implementing standard contractual clauses (Art. 33, II(b)) or obtaining ANPD authorization (Art. 33, V) would be disproportionate. Examples include transferring a job applicant's CV to a hiring manager in a foreign subsidiary, sending a customer's support request to an overseas technical team, or sharing event-registration data with a foreign conference organizer at the registrant's request. Controllers with systematic or high-volume international data flows (for example, cloud-service providers, multinational e-commerce platforms, or intra-group HR data exchanges) should not rely on Art. 33, VIII consent as their primary transfer mechanism; they should instead implement standard contractual clauses under Art. 33, II(b) or seek an adequacy decision under Art. 33, I if the destination jurisdiction is recognized.
Consent revocability and onward-transfer obligations. Under Art. 8, § 5, the data subject may revoke consent at any time, by free and facilitated procedure. If the data subject revokes consent for the international transfer, the controller must cease further transfers and, depending on the circumstances and the data subject's request, may be required to delete or repatriate the data already transferred. The controller remains subject to the onward-transfer liability rule in Art. 36: "o responsável que receber dados pessoais de outro passa a ter, em relação ao titular, as mesmas obrigações que cabiam ao anterior" (the controller who receives personal data from another becomes subject, vis-à-vis the data subject, to the same obligations as the prior controller). If the foreign importer processes the data unlawfully, the Brazilian exporter who obtained the Art. 33, VIII consent remains jointly liable for the violation.
Interaction with Resolution 19/2024 transparency obligations. Although Resolution CD/ANPD No. 19 of August 23, 2024 (the International Data Transfer Regulation) focuses on Art. 33, I (adequacy decisions) and Art. 33, II (contractual mechanisms), its transparency requirements in Article 17 apply to all international transfers, including those based on Art. 33, VIII consent. Under Article 17, § 2, the controller must publish on its website, in Portuguese and in clear language, information about the international data transfer, including the form, duration, and specific purpose of the transfer; the categories of data transferred; the responsibilities of the processing agents; and the security measures adopted. The controller must also provide the data subject, upon request, with a full description of the safeguards applied to the transfer (Article 17, caput), with a 15-day response deadline.
No ANPD regulatory guidance or enforcement decisions as of June 2026. ANPD has not issued specific guidance, model consent forms, or safe-harbor language for the Art. 33, VIII consent mechanism. No published ANPD enforcement action or judicial decision interpreting the specific, prominent, and prior-information requirements of Art. 33, VIII has been identified as of June 1, 2026. Controllers must apply the statutory text in Art. 33, VIII and the general consent principles in Art. 5, XII and Art. 8 directly. When in doubt, controllers should err on the side of greater specificity and prominence in the consent request, explicitly naming the destination country, the recipient, and the transfer purpose in the consent notice itself, rather than cross-referencing a privacy policy.
Source: Lei nº 13.709, de 14 de agosto de 2018 (LGPD, Art. 33, VIII; Art. 5, XII; Art. 8; Art. 36)
Onward transfers and exporter liability — LGPD Art. 36 for international data flows
LGPD Art. 36 — Joint and several liability for onward transfers in international data flows
Article 36 of the Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018) establishes that any entity—controller or processor—that receives personal data from another controller assumes, in relation to the data subject, all the obligations that were incumbent on the prior controller. The text provides:
> "A pessoa responsável que receber dados pessoais de outro passa a ter, em relação ao titular, as mesmas obrigações que cabiam ao anterior; o anterior permanece solidariamente obrigado por violação às normas de proteção de dados pessoais."
This means the Brazilian exporter and the foreign recipient are jointly and severally liable (solidarily liable) for violations of the LGPD. This rule applies to international as well as domestic transfers: if a foreign recipient breaches the LGPD or onward transfers data in a manner inconsistent with Brazilian law, the original Brazilian controller may be held responsible alongside the foreign recipient.
Implications for international transfers
- The foreign importer is bound by the same LGPD obligations as the Brazilian exporter toward the data subject, including transparency, access, erasure, correction, and security safeguards.
- If the foreign importer makes an onward transfer to another party (for example, a sub-processor or affiliate in a third country), the original Brazilian controller's liability persists for any resulting LGPD violation, even if they lack direct control over later transfers.
- Article 36 does not prescribe specific compliance mechanisms for onward transfers (such as contractual audit rights or specific notification clauses). However, in practice, Brazilian exporters relying on mechanisms such as standard contractual clauses (SCCs) or binding corporate rules (BCRs) should ensure these contracts address the risk of unlawful onward transfer—though this is a best practice and not textually mandated by Art. 36 itself.
Contrast with GDPR
While the European Union’s GDPR (Art. 44 ff.) regulates onward transfers with specific contractual safeguards and requires exporters to ensure adequate protection at every stage, the LGPD’s Art. 36 places original-controller liability at the forefront, without prescribing detailed onward-transfer controls. As a result, Brazilian data subjects can seek recourse directly against the Brazilian exporter for breaches downstream in the data flow.
Lack of ANPD guidance as of June 2026
As of June 2026, the Autoridade Nacional de Proteção de Dados (ANPD) has not published specific guidance or enforcement decisions expanding on the meaning or limits of liability under Art. 36 in the context of onward international transfers. Exporters should monitor the ANPD’s official website for future clarification but must apply the statutory text in the meantime.
Transparency and data subject information — Resolution 19/2024 Art. 17 website and access requirements
Controllers relying on any lawful basis for the international transfer of personal data from Brazil under the LGPD (Lei Geral de Proteção de Dados, Law No. 13,709/2018) must meet the transparency and information obligations set by the Autoridade Nacional de Proteção de Dados (ANPD) in Resolution CD/ANPD No. 19, de 23 de agosto de 2024. Article 17 of Annex I to Resolution 19/2024 imposes concrete and detailed requirements for disclosing information about international data transfers, applicable to all transfer mechanisms allowed by Art. 33 LGPD (adequacy, SCCs, BCRs, consent, ANPD authorization, etc.), not just those based on contractual safeguards.
Website publication — mandatory disclosure in clear Portuguese. Article 17, §2 requires controllers to publicly disclose, on their website and in clear, accessible, and precise Portuguese, information on all international transfers of personal data. The notice must include:
- The form, duration, and specific purpose of the transfer;
- The categories of data transferred;
- The identity and responsibilities of the data-exporting and data-importing agents;
- The technical and administrative security measures adopted; and
- Other information determined by ANPD.
This information must be drafted in simple, transparent, and easily understood language. The controller must update this transparency notice if the international transfer arrangement changes (for example, if a new importer or destination country is added, or if the transfer purpose evolves).
Data subject right to access safeguards — 15-day response time. Under Art. 17 (caput), any data subject may request from the controller the full text of the contractual safeguards used to govern an international transfer (such as the SCCs or BCRs adopted under Art. 33, II). The controller must provide this information within 15 days, unless a different timeframe is set by ANPD. Redactions may be applied only to the extent necessary to protect trade secrets or industrial confidentiality.
No exceptions for transfer basis or company size. The obligations in Art. 17 apply to all controllers processing personal data subject to international transfer under the LGPD, regardless of the transfer’s legal basis or the controller’s size, sector, or sophistication. Failure to publish the required information or to respond within the statutory period is an administrative offense, and exposes the controller to ANPD sanction under Art. 52 LGPD.
Interaction with privacy policies and consent notices. The Art. 17 publication is separate from the general privacy policy required under Art. 9 LGPD and from the specific consent notice required under Art. 33, VIII. If the same webpage or document is used, the controller should clearly distinguish between general privacy disclosures and disclosures specific to international transfers, and ensure that all Art. 17 elements are addressed.
Current ANPD guidance and enforcement posture (2026). As of June 2026, ANPD has not issued technical specifications or model templates for the Art. 17 website disclosure, nor have any enforcement decisions been published interpreting this provision. Controllers should rely directly on the text of the Resolution, erring on the side of over-disclosure and simplicity of language.
Transfer impact assessments (TIA) — Resolution 19/2024 Art. 19 risk documentation for SCC and BCR transfers
Brazil's international data transfer regime under Lei Geral de Proteção de Dados (LGPD) now requires controllers to conduct and document a transfer impact assessment (TIA) before transferring personal data to a country not recognized as adequate by the Autoridade Nacional de Proteção de Dados (ANPD), when relying on standard contractual clauses (SCCs) or binding corporate rules (BCRs). This obligation is set out in Article 19 of Resolution CD/ANPD No. 19, de 23 de agosto de 2024 (International Data Transfer Regulation).
Obligation and scope. Article 19, Annex I requires that before any international transfer based on Art. 33, II(b) (SCCs) or Art. 33, II(c) (BCRs), the controller must prepare a risk assessment to evaluate whether the recipient in the destination country can meet all obligations under the SCCs or BCRs and ensure protection of the data subject's rights as provided by the LGPD. The analysis must specifically address obstacles posed by local legislation, regulatory measures, or practices in the destination country. The mandatory assessment must consider:
- The effectiveness of legal and institutional guarantees for personal data protection in the destination country;
- The existence and effectiveness of independent supervisory authorities;
- The possibility of government or public authority access to personal data; and
- Any legal, regulatory, or practical hurdles that could affect the guarantees agreed upon in the transfer instrument.
Resolution 19, Art. 19 does not prescribe a specific assessment format or template as of June 2026. Controllers are expected to keep written documentation of their reasoning and findings supporting the decision to proceed or not with the transfer. ANPD may request access to this documentation at any time, particularly during audits or investigations related to international transfers.
If the assessment finds a risk that would prevent the importer from complying with LGPD-equivalent obligations, the international transfer is not permitted, regardless of the existence of SCCs or BCRs. This bar tracks the express language of Article 19 (§1), which requires the controller to withhold the transfer under such conditions.
Documentation and enforcement. Controllers should keep the assessment up to date if material changes occur (such as amendments to law, changes to contractual terms, or new data flows). There is currently (June 2026) no ANPD-issued model or formal guidance specifying TIA content, nor have enforcement decisions clarified what suffices for adequate risk assessment. Noncompliance can expose controllers to penalties under LGPD Art. 52 (administrative sanctions for violations of LGPD or its regulations), as Resolution CD/ANPD No. 19 is a binding regulation under the statute.
This TIA requirement is grounded explicitly in Brazil's own regulation, and does not incorporate European or foreign risk standards unless separately referenced in ANPD guidance.
Source: Resolução CD/ANPD nº 19, de 23 de agosto de 2024 (Annex I, Art. 19)
Derogations for specific situations — Art. 33, III, IV, VI, VII, IX LGPD alternative transfer bases
Brazil’s Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018) allows international data transfers in several specifically enumerated situations, even where there is no adequacy decision (Art. 33, I), no standard contractual clauses or binding corporate rules (Art. 33, II), and other core bases are not available. These “derogations for specific situations”—found in Article 33, items III, IV, VI, VII, and IX—provide alternative legal grounds for cross-border transfers. The statute itself does not establish a strict hierarchy or fallback precondition: these bases stand on their own and do not textually require proof that other mechanisms are infeasible.
Art. 33, III — International legal cooperation. Transfer is permitted for purposes of international legal cooperation between public intelligence, investigation, and prosecution bodies, according to instruments of international law. For example, criminal investigations facilitated by treaties, letters rogatory, or mutual legal assistance agreements (Art. 33, III).
Art. 33, IV — Protection of life or physical safety. Data may be transferred where necessary to protect the life or physical safety of the data subject or a third party (Art. 33, IV), enabling urgent actions in medical or emergency contexts.
Art. 33, VI — Compliance with legal/regulatory obligations, contracts, or exercise of rights. Transfer is allowed to ensure the controller's legal or regulatory compliance, for execution of a contract or pre-contractual measures at the data subject's request, or for the regular exercise of rights in judicial, administrative, or arbitration proceedings (Art. 33, VI). The wording mirrors LGPD Art. 7, II, V, and VI on legal processing grounds:
> "cumprimento de obrigação legal ou regulatória pelo controlador; execução de contrato ou de procedimentos preliminares relacionados a contrato do qual seja parte o titular...; regular exercício de direitos em processo judicial, administrativo ou arbitral..."
Art. 33, VII — Credit protection. Transfers required for credit protection, as regulated by specific financial-sector legislation, are also permissible (Art. 33, VII), supporting cross-border credit analysis and risk assessment by banks and related institutions, where provided for by law.
Art. 33, IX — Transfers necessary to fulfill Art. 7, II, V, VI bases. This catch-all provision allows transfer when necessary to fulfill the same legal bases as in Art. 7, II (legal/regulatory obligation), V (contract), and VI (exercise of rights), clarifying that transfers justified under those grounds are covered even if not expressly mentioned elsewhere (Art. 33, IX).
The LGPD text does not require controllers to demonstrate that other transfer bases were unavailable, nor to document a necessity analysis as a statutory command. However, including such documentation remains a compliance best practice. As of 2026-06-16, the Autoridade Nacional de Proteção de Dados (ANPD) has not published further regulatory guidance or enforcement decisions interpreting these derogations in detail.
Source: Lei nº 13.709/2018 (LGPD), Art. 33, III–IV, VI–VII, IX
Seals, certificates, and codes of conduct — LGPD Art. 33, II(d) as a transfer mechanism under Resolution 19/2024
LGPD Art. 33, II(d) recognizes the use of seals, certificates, and codes of conduct as a lawful mechanism for international transfer of personal data from Brazil, provided that these have been regularly issued pursuant to requirements of the Autoridade Nacional de Proteção de Dados (ANPD, the Brazilian DPA). Under Art. 33, II(d), a controller may transfer personal data internationally if it can demonstrate guarantees of compliance with LGPD principles and data-subject rights, “in the form of... (d) seals, certificates, and codes of conduct regularly issued.” The mechanism is intended to mirror similar instruments available under the GDPR (Art. 46(2)(e)-(f)), offering a potential alternative to standard contractual clauses (SCCs) and binding corporate rules (BCRs).
Resolution CD/ANPD No. 19/2024 — Regulatory implementation and current status. Articles 22–24 of Resolution 19/2024, Annex I, set forth the initial regulatory framework for the approval and recognition of seals, certificates, and codes of conduct. Article 22 provides that these instruments, if approved by ANPD, can serve as a basis for international data transfers, provided they contain effective and binding commitments to LGPD principles and guarantee enforceable data-subject rights. Article 23 delegates further rulemaking on requirements, procedures, and evaluation criteria to future ANPD resolutions.
Not yet available: text of Article 24 (“indisponibilidade temporária do mecanismo”) Article 24 expressly states that, until ANPD issues the necessary supplementary regulation, controllers cannot rely on seals, certificates, or codes of conduct as the legal basis for international data transfers under Art. 33, II(d): “Enquanto não editado o regulamento específico... as transferências internacionais de dados pessoais não poderão ser fundadas em selos, certificados ou códigos de conduta.” The only permitted pathways for now remain adequacy, SCCs, BCRs, specific contractual clauses, statutory derogations, or data subject consent. Seals, certificates, or codes may be created for other LGPD compliance purposes, but they do not confer transfer authorization.
Future developments and practitioner guidance. The legal and procedural standards for seals, certificates, and codes of conduct as a transfer mechanism will be specified in a future, currently unscheduled, ANPD resolution. Practitioners interested in developing sectoral codes of conduct or pursuing third-party certification for data transfers should monitor ANPD’s official page on international data transfers and the meetings and public consultation dockets for proposed guidance. As of 2026-06-16, no organization or industry group has had a seal, certificate, or code of conduct formally recognized by ANPD as a valid mechanism for international transfer under Art. 33, II(d).
Source: Lei nº 13.709/2018 (LGPD), Art. 33, II(d) Source: Resolução CD/ANPD nº 19, de 23 de agosto de 2024 (Annex I, Arts. 22–24)
European Union adequacy decision — Resolução CD/ANPD nº 32/2026 and permitted data flows to the EEA
On 26 January 2026, the Autoridade Nacional de Proteção de Dados (ANPD), Brazil’s national data-protection authority, issued Resolução CD/ANPD nº 32/2026, designating the European Union (and by extension, the European Economic Area and EFTA states) as an "adequate" jurisdiction under Article 33(I) of the LGPD. This is Brazil’s first adequacy decision since the LGPD’s entry into force, and it enables Brazilian controllers to transfer personal data to entities located in the EU and EEA/EFTA without the need for standard contractual clauses, BCRs, or other contractual or organizational safeguards otherwise required for cross-border transfers.
Legal basis and scope. Article 1 of the Resolution declares the EU and EFTA member states—including Norway, Iceland, Liechtenstein, and Switzerland—as providing an adequate level of personal data protection. Article 2 states the adequacy finding applies to all personal data transfers to legal or natural persons in these territories, regardless of the sector or purpose of processing, except for any country or sector subsequently excluded by ANPD in future review procedures. The adequacy status does not distinguish among EU or EFTA jurisdictions—if a country is covered by a standing EU/EEA adequacy finding, it is covered by Brazil’s decision.
Requirements and onward transfers. Controllers transferring data under this adequacy mechanism must still comply with all other requirements of the LGPD, including data-minimization, purpose-limitation, transparency, and upholding data-subject rights (Art. 6 and Chapter III LGPD). The adequacy designation relieves the controller of the obligation to implement standard contractual clauses (SCCs), binding corporate rules (BCRs), or seek ANPD approval for each transfer. Onward transfers from an EU or EFTA country to a third country not recognized as adequate by ANPD must comply with LGPD and may require separate safeguards—mirroring the European model in Art. 44 GDPR and tracking Brazil’s own Art. 36 liability rule.
Review and modification. The Resolution calls for periodic review of the adequacy status. If the EU materially changes its data-protection regime or ANPD determines that the level of protection is no longer adequate, the adequacy designation may be suspended or revoked in whole or in part. Controllers relying on the adequacy decision should monitor ANPD’s website for updates and for any sectoral or geographical carve-outs added in the future.
Relationship to the European Commission’s adequacy for Brazil. This Resolution is intended to be reciprocal to the European Commission’s adequacy decision for Brazil pursuant to GDPR Art. 45, published in September 2025. As of June 2026, both jurisdictions recognize each other as adequate for purposes of cross-border personal-data transfers, eliminating the need for additional legal instruments for routine processing operations between responsible parties in Brazil and the EU/EEA.
Controllers should maintain documentation of the reliance on the adequacy mechanism for international data transfers, and update contracts and privacy notices to reflect the lawful transfer basis. When planning new high-risk processing activities involving EU or EFTA personal data, controllers should consult both ANPD and European Data Protection Board (EDPB) guidance for best practices.
Source: Resolução CD/ANPD nº 32, de 26 de janeiro de 2026 Source: LGPD, Art. 33(I)
Specific contractual clauses for international data transfers — Art. 33, II(a) LGPD and Resolution 19/2024 bespoke mechanism
Brazil’s General Data Protection Law (LGPD, Law No. 13.709/2018) allows international personal data transfers based on "specific contractual clauses" under Art. 33, II(a), as further regulated by Chapters VI–VII of Resolution CD/ANPD No. 19/2024. This mechanism is distinct from the standard contractual clauses (SCCs, Annex II model), and exists for situations where SCCs cannot be used for legal or practical reasons, but tailored contracts may provide adequate safeguards.
When can specific contractual clauses be used? Specific contractual clauses are permitted when (1) it is impracticable to use the SCCs due to “factual or legal circumstances,” and (2) the clauses guarantee standards of data protection equivalent to the LGPD and the SCC model (Resolution 19/2024, Art. 18 and Art. 20). Controllers must justify in their application why the SCCs are not feasible for the transfer—in practice, this might apply to highly bespoke commercial arrangements, service chains with atypical allocations of risk, or novel data flows not anticipated in the SCC template.
Approval procedure and documentation requirements. Prior approval from the ANPD Board of Directors is mandatory (Art. 20). The applicant (usually the controller, though a processor may support) must submit a petition through ANPD’s Electronic Information System (SEI), including:
- The draft specific contractual clauses, in both Portuguese and the working language of the transfer parties;
- Incorporation or identification documents for the parties;
- A full description of the transfers (countries, categories of data, processing purposes, duration, data subjects);
- Description of the security measures implemented;
- Analysis justifying why the SCCs cannot be used and how the proposed clauses ensure LGPD-equivalent safeguards;
- Any supporting documents relevant to the risk profile or need for deviation from the SCC model (Art. 20, I–VIII).
ANPD technical and legal analysis. The International Affairs Coordination of ANPD reviews whether the proposed clauses meet the substantive requirements of Annex I, Art. 18, focusing on enforceability, audit/access, data-subject rights, and supervisory authority intervention. The Specialized Federal Attorney’s Office must also issue a legal opinion. The Board of Directors grants or denies approval by published resolution.
No published approvals as of June 2026. As of 2026-06-16, no specific contractual clauses have been approved or published by ANPD. Nonetheless, practitioners should ensure any proposed clauses mirror the SCC guarantees as closely as feasible, and document rigorously the rationale for deviation.
Source: Lei nº 13.709/2018 (LGPD), Art. 33, II(a) Source: Resolução CD/ANPD nº 19, de 23 de agosto de 2024 (Annex I, Arts. 18–20)
Enforcement and remedies for unlawful international transfers — Art. 52 LGPD and Resolution 19/2024 procedures
Administrative enforcement and remedies for international data transfer violations
A controller or processor who violates Brazil’s rules for international data transfers—under Chapter V of the LGPD (Lei nº 13.709/2018) and its regulatory implementation in Resolution CD/ANPD No. 19 of August 23, 2024—may face administrative investigation and sanctions by the Autoridade Nacional de Proteção de Dados (ANPD), as well as civil liability. This section describes the enforcement and remedies mechanisms available to data subjects and regulators as of June 2026.
ANPD’s oversight and investigative authority
The LGPD designates ANPD as the national data-protection authority empowered to oversee, guide, and sanction compliance with data-protection rules, including those applicable to international transfers (Art. 55-A and 55-B, LGPD). Any data subject, representative association, or interested party may submit an administrative complaint to the ANPD regarding suspected unlawful international transfers, either via the online complaint portal or in writing (Art. 55-J, LGPD; Art. 36, Resolution 19/2024). Complaints may allege, for example, transfer without valid SCCs or BCRs, transfers to a country lacking adequacy recognition, or failure to provide required transparency information under Resolution 19/2024, Art. 17.
ANPD’s procedures and sanctions for international transfer breaches
Upon receipt of a complaint or by its own initiative, ANPD may launch an investigation (fiscalização), require the controller to provide information and evidence, and conduct on-site or remote audits of transfer documentation and risk assessments (Art. 55-J, III; Art. 36 & 38, Resolution 19/2024). If ANPD determines that an international transfer was unlawful—whether due to absence of a valid legal basis, missing mandated contractual safeguards, or inadequate transparency—it may impose the administrative sanctions catalogued in Art. 52, §§ 1–5 LGPD:
- Warning, with a deadline for adopting corrective measures;
- One-time fine of up to 2% of the group’s revenue in Brazil, capped at R$50 million per infraction;
- Daily fine, up to the same cap;
- Public disclosure of the violation, after confirmation and completion of defense procedures;
- Blocking the personal data to which the infraction relates until regularization;
- Deletion of the personal data to which the infraction relates;
- Suspension or prohibition of the international data transfer.
ANPD may prioritize non-monetary remedies for first-time or low-risk violations. Resolution 19/2024, Art. 38 specifies that repeated or grave violations of transfer rules may result in suspension of the right to use a transfer mechanism.
Data subject’s private right and judicial remedies
In addition to ANPD’s administrative oversight, any data subject whose rights are infringed by an unlawful cross-border transfer may bring a civil suit for compensation under Art. 42–45 LGPD. They are not required to exhaust administrative remedies before turning to court. Under Art. 42, §1 LGPD, controllers and processors who participate in the data-processing chain may be held jointly and severally liable for damages. The precise scope of liability for foreign recipients will depend on Brazilian judicial interpretation and the factual circumstances of the transfer.
Source: Lei nº 13.709/2018 (LGPD), Arts. 52–55-J Source: Resolução CD/ANPD nº 19, de 23 de agosto de 2024 (Arts. 36, 38)
Documentation and recordkeeping obligations for international transfers
Maintaining documentation is mandatory under Brazilian data protection law for all international data transfers. Controllers (those who determine the purposes and means of processing, Art. 5, VI LGPD) and operators (processors) must keep clear records of the transfer mechanism used (adequacy, SCCs, BCRs, consent, ANPD authorization, derogation), any transfer impact assessments (TIA) performed, and relevant contractual clauses.
Accountability recordkeeping — Art. 4, §2 of Resolution 19/2024. The core requirement is set by Resolução CD/ANPD nº 19/2024, Art. 4, §2: every data processing agent is obliged to “adopt measures capable of proving observance and compliance with the data protection norms and the effectiveness of those measures.” ANPD expects a written compliance record, proportionate to the risk and to the features of the data transfer: records of which transfer mechanism was relied on; the full executed SCC or BCR text if used; and, for SCC/BCR transfers, a documented TIA.
Specific SCC requirement — Clause 8(h), Annex II of Resolution 19/2024. The Annex II model of Brazil’s standard contractual clauses (SCCs) includes an explicit recordkeeping mandate: “Manter registro das operações de tratamento dos Dados Pessoais objeto da Transferência Internacional de Dados regida por estas Cláusulas, e apresentar a documentação pertinente à ANPD, quando solicitado.” Both exporter and importer are responsible for maintaining records of the processing operations covered by the SCCs and must provide all supporting documentation to ANPD on request.
Scope and minimum contents. Required documentation includes:
- the complete text of the executed SCCs or BCRs or any bespoke transfer instrument;
- the TIA and any related risk assessment or adequacy analysis;
- details of the transfer (data categories, countries, importer’s identity, purposes);
- for adequacy or derogation reliance, written rationale for use and evidence that conditions were met.
Neither the LGPD nor Resolution 19/2024 prescribes a minimum document retention period for international transfer records as of June 2026. As such, controllers should determine retention based on internal risk policy and sector obligations, but must be able to retrieve documentation for as long as the data processing is ongoing or if requested by ANPD.
Source: Resolução CD/ANPD nº 19/2024, Art. 4, §2; Annex II, Clause 8(h) Unable to confirm as of 2026-06-16 if any explicit minimum retention period is mandated in statute or regulation.