Brazil’s Standard Contractual Clauses Change the Paperwork Behind Global Data Flows
Brazil’s international-transfer regulation gives the LGPD its own contractual machinery. Global companies cannot assume that EU clauses or a general data-processing agreement automatically do the job.
On 23 August 2024, Brazil’s National Data Protection Authority issued Resolution CD/ANPD No. 19. The regulation establishes procedures for international transfers under the LGPD and approves Brazilian standard contractual clauses.
The change is operationally important because personal data rarely stays inside one country. Customer support, analytics, identity, fraud detection, hosting and disaster recovery can all move or expose Brazilian data across borders. The new framework requires organisations to know which transfers occur and which legal mechanism supports each one.
A lawful purpose and a transfer mechanism are separate questions
An international transfer must have a legitimate, specific and informed purpose. It must also be supported by a valid basis for processing under the LGPD and a permitted transfer mechanism.
The regulation addresses adequacy decisions, standard contractual clauses, specific contractual clauses and global corporate rules. Other statutory mechanisms remain available where their conditions are met.
This two-layer analysis matters. Consent or contractual necessity may support the processing activity, but it does not automatically provide the safeguards required for the international movement of the data.
The Brazilian clauses are not an optional template
Where a transfer relies on the ANPD’s standard contractual clauses, the approved wording must be adopted in full and without alteration. The clauses can form a standalone agreement or be attached to a broader commercial contract, but conflicting terms elsewhere cannot dilute them.
Organisations already using contractual safeguards were given 12 months from publication to incorporate the Brazilian clauses into their instruments. That deadline fell on 23 August 2025. By 2026, an inventory that still says only “SCCs in place” is not enough: it must identify which clauses, between which parties, for which transfer and under which national framework.
The regulation also allows the ANPD to recognise equivalent standard clauses. Until recognition is granted, organisations should not assume that European Commission clauses, UK addenda or internal templates are legally interchangeable with the Brazilian text.
Transparency reaches the public website
The controller must make information about international transfers available in Portuguese, using clear and accessible language. That information includes the purpose and duration, destination country, controller identity, shared use, responsibilities, security measures and data-subject rights.
On request, the controller must generally provide the full clauses used for the transfer within 15 days, subject to protection of commercial and industrial secrets.
This connects contract governance to privacy notices and rights handling. If the legal team updates a transfer agreement but the public notice, request workflow and vendor register remain unchanged, the organisation has created inconsistent evidence.
Global corporate rules require real governance
Multinational groups may seek approval for global corporate rules. These are not merely a policy posted on an intranet. The submission needs to describe the transfers, countries, safeguards and privacy-governance programme that make the rules binding and effective across the group.
Specific contractual clauses are also possible, but they require ANPD approval and are intended for exceptional situations in which the standard clauses cannot reasonably be used.
What to review now
- Map Brazilian data from collection to every overseas hosting, support and analytics location.
- Identify the exporter, importer, controller and processor roles for each transfer.
- Record both the processing basis and the international-transfer mechanism.
- Locate contracts that were signed before Resolution No. 19 and verify that they were remediated.
- Compare privacy notices with the actual destination countries and recipients.
- Create a process to answer requests for the clauses within 15 days.
- Ensure onward transfers remain subject to equivalent protections.
- Monitor future ANPD adequacy and equivalence decisions.
Brazil’s rules add another national layer to the global transfer architecture. The efficient response is not to negotiate every flow from scratch. It is to maintain one accurate transfer inventory and attach the correct jurisdiction-specific mechanism to each relationship.
Official sources
- Brazilian ANPD: Resolution CD/ANPD No. 19 of 23 August 2024
- Brazilian ANPD: International Data Transfers
This article provides general information and is not legal advice.
Continue the series: LATAM Cyber & Digital Law Series index


