EU Adequacy Decision for Brazil
Commission decision recognising Brazil (LGPD) as providing adequate protection, allowing EEA-to-Brazil transfers without additional safeguards.
| Jurisdiction | European Union |
|---|---|
| Category | Privacy & Data Protection |
| Status | Active |
| Effective date | |
| Latest development |
Recent developments
- — Hunton Andrews Kurth reports that Brazil and the EU reached agreement on mutual adequacy in personal data protection, enabling free flow of personal data without additional transfer mechanisms and highlighting the November 2025 EDPB opinion that paved the way for the final decision.[14][11] (source)
- — Crowell & Moring analyzes the EU–Brazil mutual adequacy as a key milestone for global data flows and Latin America’s digital positioning, noting that recognition of “essentially equivalent” protection frameworks will significantly ease and legally secure personal data transfers and deepen EU–Mercosur ties.[10][1] (source)
- — The European Commission’s adequacy decisions page confirms the adoption of an adequacy decision for Brazil and describes the mutual EU–Brazil recognition as creating one of the largest areas of free and secure personal data flows worldwide under GDPR and Brazil’s LGPD.[1][3] (source)
- — Medialaws examines the mutual adequacy decisions between Brazil and the EU, explaining how the EC implementing decision of 26 January 2026 and ANPD Resolution CD/ANPD No. 32/2026 together build the largest area of free and secure personal data flows and clarifying scope limits (e.g., exclusions for public security and criminal investigations).[5][7] (source)
- — IAPP discusses what changes and what does not following the EU–Brazil mutual adequacy, noting that routine commercial and HR data transfers become simpler and lower risk, but organizations must still address areas not covered by the decisions and maintain internal compliance with GDPR and the LGPD.[13][9] (source)
- — Sheppard Mullin details practical implications of the EU–Brazil adequacy decisions, stressing that organizations can now transfer personal data between the EU and Brazil without standard contractual clauses or other safeguards, while transfers for public security, national defense, state security, or criminal investigations remain outside the decisions’ scope.[12][8] (source)
- — White & Case’s client alert describes the mutual adequacy decisions announced on 27 January 2026 as ushering in a new era of transatlantic data transfers, emphasizing that the EC’s Article 45 GDPR decision and ANPD Resolution CD/ANPD No. 32/2026 enable unrestricted personal data flows and will reduce compliance burdens for companies active in both jurisdictions.[2][9] (source)
- — dsn group explains what changes in practice with the EU–Brazil adequacy decisions, highlighting that controllers and processors can now rely directly on the decisions for cross‑border transfers, which simplifies data export strategies, reduces documentation overhead, and may reshape outsourcing and cloud service choices involving Brazilian providers.[9][4] (source)
- — Mayer Brown characterizes the mutual adequacy decision as Brazil’s first‑ever adequacy recognition and the EU’s most comprehensive GDPR adequacy to date, covering public and private sectors and unlocking data‑driven activities across a combined consumer base of about 670 million people while confirming exclusions for sensitive public‑security‑related transfers.[4][5] (source)
- — Baker McKenzie outlines Resolution CD/ANPD No. 32/2026, noting that Brazil’s data protection authority formally recognizes the EU’s adequacy for international transfers under the LGPD and that, in parallel with the EU decision on Brazil, businesses in both regions can now rely on mutual adequacy instead of contractual or other transfer tools, except in carved‑out public‑security contexts.[8][6] (source)
Related regulations
- EU AI Act - Annex III High-Risk System Requirements (2 Dec 2027) — European Union, Upcoming, effective 2027-12-02
- EU Data Act — European Union, Phased, effective 2025-09-12
- EU Cyber Resilience Act (CRA) — European Union, Phased, effective 2027-12-11
- EU AI Act - GPAI Model Obligations (2 Aug 2025) and Enforcement (2 Aug 2026) — European Union, Active, effective 2025-08-02
- EU Digital Omnibus on AI (Regulation (EU) 2026/1744) — European Union, Active, effective 2026-07-27
- EU AI Act - Synthetic Media Transparency and New Prohibitions (2 Dec 2026) — European Union, Upcoming, effective 2026-12-02
- EU AI Act - Annex I High-Risk Systems (2 Aug 2028) — European Union, Upcoming, effective 2028-08-02
- EU Cyber Resilience Act - Vulnerability and Incident Reporting (11 Sep 2026) — European Union, Active, effective 2026-09-11
Put it into practice
- Generate the policy: LGPD policy generator (generatepolicy.com)
- Buy the policy pack: Brazil LGPD Compliance Policy (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)
Browse all regulations · Compliance deadlines · Latest updates