For six years the LGPD’s transfer chapter was a promise; Resolution 19/2024 made it enforceable paper with a deadline that has already passed. The practical consequence is blunt: every contract that moves Brazilian personal data abroad needs Brazilian SCCs (or an approved BCN, or a to-date-nonexistent adequacy decision), and the EU paperwork multinationals reflexively point to does not count. Transfer compliance in Brazil is now a document-production exercise, exactly the kind regulators find easiest to check.
| Provision | LGPD Arts. 33-36; ANPD Resolution 19/2024 |
|---|---|
| Instruments | ANPD adequacy; Brazilian SCCs; BCN (global corporate norms) |
| SCC rule | Verbatim adoption; no material edits; no filing needed |
| Legacy deadline | August 22, 2025 (12-month adaptation window) |
| Fallbacks | Specific highlighted consent; necessity grounds |
Closing the transfer gap
Inventory the border crossings. The data map should flag every flow leaving Brazil, cloud regions, SaaS vendors, intra-group access, with the instrument (or gap) per flow.
Paper the vendors with Brazilian SCCs. Add the Resolution 19/2024 annex to DPAs as a Brazil module alongside EU SCCs; new vendor templates should include it by default, and legacy contracts past the August 2025 deadline get prioritized by data sensitivity.
Groups: weigh BCN versus SCC mesh. Heavy intra-group flows justify a BCN application; otherwise a hub-and-spoke SCC set is faster. Either way the encarregado should own the register.
Keep the diff from GDPR explicit. Transfer mechanics are the sharpest LGPD/GDPR divergence; the US-company guide covers the importing-side view, and the full LGPD guide the rest of the program.
Cross-border tracker and pixel flows from your Brazilian pages are visible from outside: map them with a free scan.