Brazil recognizes EU adequacy for personal data
Brazil’s ANPD approved Resolution CD/ANPD No. 32/2026, recognizing the EU as adequate for LGPD data transfers.
Brazil’s National Data Protection Authority approved Resolution CD/ANPD No. 32/2026 and formally recognized the European Union as an adequate destination for international personal data transfers under the LGPD. The decision also enables a mutual adequacy framework between companies in Brazil and the EU, excluding public security contexts.
Brazil’s National Data Protection Authority approved Resolution CD/ANPD No. 32/2026 and formally recognized the European Union as an adequate destination for international personal data transfers under the LGPD. According to Global Compliance Map, the measure also opens the door to a mutual adequacy framework between companies in Brazil and the EU, with an explicit exclusion for public security contexts.
What changes with Resolution CD/ANPD No. 32/2026?
The resolution allows companies in Brazil and the European Union to rely on a mutual adequacy scheme for international personal data transfers instead of depending solely on contractual clauses or other transfer mechanisms. Global Compliance Map placed that change alongside the European Union’s adequacy decision regarding Brazil.
That formal recognition changes how data flows between the two jurisdictions are framed. In practical terms, adequacy becomes the main mechanism identified in the cited analysis for that transfer corridor, except in cases carved out by the public security exception.
Who does this apply to in practice?
The LGPD applies to any company that processes personal data of individuals located in Brazil, regardless of where the company is established. That is how LBM Advogados describes the rule, while also linking it to obligations for companies and subsidiaries in Peru when they handle data belonging to Brazilian data subjects.
That extraterritorial reach is what makes the resolution relevant for regional operations. A company in Peru that receives, processes, or stores data from people located in Brazil falls under the LGPD’s requirements if it handles that information, no matter which jurisdiction it operates from.
What happens with incidents and data breaches?
Under the LGPD, security incidents and personal data breaches must be reported to the ANPD, even if the failure occurs outside Brazil but affects data belonging to Brazilian data subjects. The LBM Advogados document says this can include breaches in infrastructure or operations located in Peru, or in providers used from Peru.
For companies with cross-border ties, the issue is not limited to where the technical incident started. What matters is whether the breach compromises data of people located in Brazil, because that is what triggers the reporting obligation to the ANPD, regardless of where the system or third party is located.
What does Peru require for these transfers?
In Peru, international personal data transfers must be reported to the General Directorate for Transparency, Access to Public Information and Personal Data Protection for registration in the National Registry. Mi Firma Digital says that report includes information on the cross-border flow, including data exports from Peru to controllers or processors located in Brazil and subject to the LGPD.
That leaves companies facing a dual compliance layer when they operate between the two countries. On one side, they must meet the LGPD requirements for data belonging to Brazilian data subjects. On the other, they must comply with Peru’s registration and reporting rules for international transfers.
Sources
- Regulatory Compliance in Brazil: Essential Requirements for Foreign Companieslbm-legal.com.br· LBM Advogados
- Flujo transfronterizo de datos personales en Perúmifirmadigital.pe· Mi Firma Digital
- EU Adequacy Decision for Brazilglobalcompliancemap.com· Global Compliance Map



