Brazil Adequacy Decision, Commission Implementing Decision (EU) 2026/179
Commission Implementing Decision (EU) 2026/179
In force since .
A cross border transfer rule binding public and private bodies.
- Criminal exposure
- No
- Private right of action
- No
- Obligation class
- Transfer
- Audit expectation
- periodic
- Who audits it
- Regulator
As of .
What it requires
- A transfer of personal data from the European Union to a controller or processor in Brazil subject to the General Data Protection Law (LGPD) may take place on the basis of Article 1 of the Decision, without any specific authorization (Article 45(1) of Regulation (EU) 2016/679).
- A transfer to a controller or processor in Brazil that is not subject to the General Data Protection Law (LGPD) is outside the finding in Article 1.
Who enforces it
Enforcement body
The competent authorities of the Member States, which exercise their powers under Article 58 of Regulation (EU) 2016/679 over transfers within the scope of Article 1 and inform the Commission (Article 2), and the Commission, which monitors the application of the legal framework and may suspend, repeal or amend the Decision (Article 3).
What this law does
Article 1 provides that, for the purpose of Article 45 of Regulation (EU) 2016/679, Brazil ensures an adequate level of protection for personal data transferred from the European Union to controllers and processors in Brazil subject to the General Data Protection Law (LGPD). The Decision cites the LGPD as Law No 13.709 of , the General Data Protection Law (Lei Geral de Proteção de Dados Pessoais).
Article 2 requires a Member State whose competent authorities exercise their powers under Article 58 of Regulation (EU) 2016/679 over data transfers within the scope of Article 1 to inform the Commission without delay. Article 3(1) requires the Commission to monitor continuously the application of the legal framework upon which the Decision is based with a view to assessing whether Brazil continues to ensure an adequate level of protection within the meaning of Article 1.
Article 3(2) requires the Member States and the Commission to inform each other of cases where the Brazilian Data Protection Authority (Agência Nacional de Proteção de Dados, ANPD), or any other competent Brazilian authority, fails to ensure compliance with the legal framework upon which the Decision is based.
Article 3(4) requires the Commission, after four years from the date of the notification of the Decision to the Member States and subsequently at least every four years, to evaluate the finding in Article 1 on the basis of all available information, including the information received as part of the review carried out together with the relevant Brazilian authorities.
Article 3(5) provides that, where the Commission has indications that an adequate level of protection is no longer ensured, it informs the competent Brazilian authorities and may suspend, repeal, or amend the Decision. Article 3(6) provides that the Commission may also suspend, repeal, or amend the Decision if the lack of cooperation of the Brazilian government prevents the Commission from determining whether the finding in Article 1 is affected. Article 4 provides that the Decision is addressed to the Member States.
When LexLint raises it
When your app profile says your app crawls the web, trains models, deploys a chatbot, sends automated outreach, processes voice recordings or processes biometric data.