News

12 months on: the countdown for adapting to Brazil’s International Data Transfer Regulation

12 months on: the countdown for adapting to Brazil’s International Data Transfer Regulation

In August 2024, Brazil’s National Data Protection Authority (ANPD) published Resolution CD/ANPD no. 19/2024 (known as the ‘International Data Transfer Regulation’), marking an important milestone. Last year, for the first time, companies were given a clear framework on how to handle international data transfers under the LGPD, Brazil’s data protection law.

🔐 In addition to the Regulation, the ANPD also released Brazil’s own set of Standard Contractual Clauses (in short, ‘SCCs’), providing organisations with practical templates to frame cross-border data transfers.

📆 At the time, companies were given a 12-month window to adjust. That transition period now comes to an end. By 23 August 2025, companies that transfer personal data from Brazil abroad will need to ensure they are aligned with the new rules.

🧐 What are the implications in practice?

  • In cases where transfers fall within the scope of the Regulation, contracts must incorporate the ANPD-approved SCCs (either as an annex to an existing agreement or as a standalone document). The core clauses cannot be modified, but parties may choose to add supplementary provisions if they so wish, provided that they do not contradict the original text issued by the Authority.
  • Organisations should be prepared to explain in clear, understandable terms why the transfer is taking place, where the data is going, and how it will be protected. The ANPD also expects controllers to be able to provide data subjects with the full text of the SCCs upon request, unless doing so would disclose private or confidential business information.
  • In addition to the SCCs, companies may rely on alternative mechanisms such as adequacy decisions, binding corporate rules, or seek ANPD approval for bespoke clauses. These, however, usually require more planning, regulatory dialogue, and in some cases, are not yet available in practice.
  • Over the years, the ANPD has shown increasing readiness to enforce the LGPD. This means that missing the deadline could potentially expose companies to the risk of investigations, fines, or reputational harm.

🌎 For global businesses, the good news is that Brazil’s rules will not feel completely foreign. Although the SCCs published by the ANPD have been tailored to the local regulatory context, the overall approach will feel familiar to organisations that already operate under the GDPR.

✅ As such, the real challenge lies in implementation. Aligning contracts, notices, and internal procedures can be time-consuming for organisations that operate across multiple jurisdictions. Now is the time to:

  1. Review contracts involving data exports from Brazil.
  2. Assess data transfers and confirm whether Brazilian SCCs or other mechanisms apply.
  3. Make the necessary updates to internal policies, privacy notices, and procedures.

👉 In short: By 23 August, companies will need to have their contracts and processes aligned with Brazil’s new rules on international data transfers.

At MyData-TRUST, we support organisations through this final stretch by making sure that SCCs are correctly incorporated into contracts. With the deadline just days away, the priority is to have the right clauses in place to move forward with confidence.


Author: Laura Mello Laufer