Latin America Brazil

LGPD International Transfers: Resolution 19/2024 Rules

Brazil's international data transfer regime: ANPD Resolution 19/2024, Brazilian SCCs and the adaptation deadline, adequacy, BCN global norms, and contract steps.

Regulation

LGPD Articles 33-36 (Law No. 13.709/2018); ANPD Resolution CD/ANPD No. 19/2024

Max Penalty

Unlawful transfers: up to 2% of Brazil revenue capped at R$50 million per infraction, plus blocking or deletion of the transferred data

Enforcing Authority

Autoridade Nacional de Protecao de Dados (ANPD)

Official Source

www.gov.br

Executive Summary

  • LGPD Articles 33-36 restrict transfers of personal data out of Brazil to enumerated mechanisms; ANPD Resolution 19/2024 (August 2024) finally operationalized them.
  • The three main instruments are: adequacy decisions by the ANPD, Brazilian standard contractual clauses (SCCs) published as an annex to the Resolution, and global corporate norms (BCN, the BCR equivalent) approved by the ANPD.
  • The Brazilian SCCs must be adopted verbatim, no material edits, and contracts predating the Resolution had until late August 2025 to incorporate them.
  • EU SCCs do not satisfy Brazilian law by themselves; the Resolution allows the ANPD to recognize equivalent clauses from other regimes, but recognition is not automatic.
  • Consent remains a fallback basis for transfers (specific and highlighted, with prior information), along with necessity grounds, but instruments are the sustainable path for recurring vendor flows.

For six years the LGPD’s transfer chapter was a promise; Resolution 19/2024 made it enforceable paper with a deadline that has already passed. The practical consequence is blunt: every contract that moves Brazilian personal data abroad needs Brazilian SCCs (or an approved BCN, or a to-date-nonexistent adequacy decision), and the EU paperwork multinationals reflexively point to does not count. Transfer compliance in Brazil is now a document-production exercise, exactly the kind regulators find easiest to check.

ProvisionLGPD Arts. 33-36; ANPD Resolution 19/2024
InstrumentsANPD adequacy; Brazilian SCCs; BCN (global corporate norms)
SCC ruleVerbatim adoption; no material edits; no filing needed
Legacy deadlineAugust 22, 2025 (12-month adaptation window)
FallbacksSpecific highlighted consent; necessity grounds

Closing the transfer gap

Inventory the border crossings. The data map should flag every flow leaving Brazil, cloud regions, SaaS vendors, intra-group access, with the instrument (or gap) per flow.

Paper the vendors with Brazilian SCCs. Add the Resolution 19/2024 annex to DPAs as a Brazil module alongside EU SCCs; new vendor templates should include it by default, and legacy contracts past the August 2025 deadline get prioritized by data sensitivity.

Groups: weigh BCN versus SCC mesh. Heavy intra-group flows justify a BCN application; otherwise a hub-and-spoke SCC set is faster. Either way the encarregado should own the register.

Keep the diff from GDPR explicit. Transfer mechanics are the sharpest LGPD/GDPR divergence; the US-company guide covers the importing-side view, and the full LGPD guide the rest of the program.

Cross-border tracker and pixel flows from your Brazilian pages are visible from outside: map them with a free scan.

Frequently Asked Questions

What counts as an international transfer under the LGPD?

Transferring personal data to a foreign country or an international organization, including intra-group flows (Brazilian subsidiary to US parent), cloud hosting outside Brazil, and vendor access from abroad. Resolution 19/2024 clarifies that mere transit or the collection of data directly from the data subject by a foreign controller (a Brazilian consumer buying from a US website) is treated differently from a Brazil-side exporter handing data over. The exporter analysis, who is transferring to whom, on which instrument, is the first documented step.

How do the Brazilian SCCs work, and can we modify them?

The SCCs are annexed to Resolution 19/2024 and must be incorporated without material modification, additions are permitted only if they do not conflict. They cover controller-to-controller and controller-to-processor scenarios in a single set (unlike the EU's modular four). Signing them requires no ANPD approval or filing; they operate automatically once executed. Existing contracts had a 12-month adaptation window, until August 22, 2025, to incorporate them, so any legacy vendor contract still relying on EU SCCs alone for the Brazil leg is now out of compliance.

Do EU SCCs or other foreign clauses count for anything?

Not by themselves. The Resolution created a pathway for the ANPD to recognize 'equivalent' standard clauses from other jurisdictions or international organizations, on request and after analysis, but until the ANPD grants recognition to a specific set, EU SCCs are just a foreign contract. Multinationals therefore run dual paper: EU SCCs for GDPR legs, Brazilian SCCs for LGPD legs, often in one master agreement with two annexes. The same logic applies to frameworks like the EU-US DPF: helpful evidence, not a Brazilian mechanism.

What are BCNs (global corporate norms)?

The Brazilian analogue of Binding Corporate Rules: group-wide binding policies approved by the ANPD that authorize intra-group transfers without per-contract clauses. Resolution 19/2024 sets the content requirements, binding effect on all group members, enforceable data subject rights, training, audit, and a compliance structure, and the approval procedure. As with BCRs, expect a long approval runway; they suit large groups with heavy intra-group flows, while the SCCs remain the default for everyone else.

Is there an adequacy list, and where do consent and necessity fit?

The ANPD can declare countries or organizations adequate based on their legal regime; it has been analyzing candidates (the EU/EEA being the obvious first tier) but companies should not build on anticipated adequacy. Absent adequacy or instruments, Article 33 allows transfers on specific and highlighted consent (informed of the international character in advance), or necessity grounds: legal obligation, contract execution, judicial proceedings, life protection, and public-policy execution. Consent works for one-off situations; it is fragile for recurring operational flows because revocation strands the pipeline.

Regulatory Crosswalk

GDPR Chapter VEU SCCsAPEC CBPR

Organizations subject to this regulation often operate under these overlapping frameworks. BD Emerson maps controls across frameworks to reduce duplicated compliance effort.

Evaluate your compliance posture now

BD Emerson's automated scanner audits your public-facing properties against your applicable regulations in minutes, not weeks.