8/26/2024
Last Friday (August 23, 2024), the National Data Protection Authority (ANPD) published the Resolution No. 19, approving the International Data Transfer Regulation.
Through those new rules, the ANPD further regulates articles 33 to 36 of the Brazilian General Personal Data Protection Law (LGPD), establishing guidelines and general requirements for cross-border transfers of personal data, as well as the definition of the responsibilities of data controllers and operators.
In addition, the regulation clarifies the scope of legal obligations and limitations involving transactions between data processing agents, including subcontractors.
The new regulation aims to guarantee an adequate level of protection for data subjects, even when data is transferred across borders, aligning the country’s practices with global privacy and information security standards.
The new regulation will cover contractual provisions amongst companies that are currently conducting business in Brazil and practices involving data controllers/processors and subcontractors in operations involving international transfer of data.
Data processing agents relying on contractual clauses to carry out international transfers of data will have 12 (twelve) months to comply with the regulation, in particular to incorporate the contractual clauses template (as approved by the ANPD) into their contractual instruments.
What were the main regulatory provisions introduced?

Definitions of data importer (ie. the agent who receives personal data transferred from another country), data exporter (ie. the agent who transfers personal data to another country) and the liable entity (Brazilian company liable for violations of binding corporate rules, even if committed by a member of the group in third country).

Certain requirements for the international transfer of data:


Specific contractual clauses (drawn up for a particular transfer with the approval of the ANPD), standard contractual clauses – SCCs (as to the template pre-approved by the ANPD) and binding corporate rules (rules to be adopted by business groups for intra-group transfers) that must be adopted as a guarantee for the international transfer of personal data. It is also specified the contexts in which each of them will be applied.
Important: any changes to specific contractual clauses must be communicated immediately to the ANPD, so their implementation depends on the agency’s prior authorization.

The ANPD may recognize the equivalence of international SCCs vis-a-vis the clauses provided for in the new ANPD regulation.

Clear criteria has been established for assessing foreign entities that provide an adequate level of personal data protection, under the terms of the LGPD, such as the analysis of the country’s/body’s data protection rules, the nature of the data transferred, the compliance level with regard to principles and data subjects’ rights set out in the LGPD, the security measures adopted, as well as the judicial and institutional guarantees for data protection and other circumstances specific to the transfer.

Definition of the responsibility of data exporters and importers to ensure the compliance of data processing in operations involving the international transfer of personal data.

Definition of the necessary transparency measures in international transfers of personal data, such as the processing agents’ obligation to maintain a website with clear and up-to-date information on these transactions. The website must contain details of the types of data transferred, the countries of destination, the purposes of the data processing and the guarantees applied to protect the personal data of the data subjects.
Companies will have a deadline of 12 (twelve) months from the date of publication of the Resolution No. 19 to adapt their practices to the new rules. A transition period is designed to allow organizations to make the required adaptations to their processes, contracts and privacy policies to meet the new requirements established by the ANPD.
Our clients and partners are advised to carry out a detailed review of existing processing contracts and global corporate standards to ensure compliance with the new regulations.
Given the new requirements, an internal audit is likely to be necessary to assess the compliance of international personal data transfer operations and adjust business practices as required.
Our Privacy and Data Protection team at L.O. Baptista is fully available to assist clients and organisations in taking the priority steps to ensure compliance with the Resolution ANPD No. 19/2024.
Co authored by: Fabricio Polido, Denise de Araujo Berzin Reupke and Larissa Fernandes Ackerman