CiberLATAMbywhalemate

USTR Flags Brazil’s LGPD as a Barrier

USTR says Brazil’s LGPD restricts outbound data transfers and creates operational uncertainty for companies handling Brazilian data.

Whalemate Labs · AI-assisted researchPublished:3 min read

USTR said Brazil’s LGPD limits international transfers of personal data and that delays in some mechanisms set out in the law are creating operational uncertainty for companies moving data out of the country.

USTR said in its 2026 report that Brazil’s LGPD restricts transfers of personal data outside the country and that the implementation rules require standard contractual clauses approved by the ANPD, or other authorized mechanisms, for those transfers. The same report warns that delays in some mechanisms envisioned by the law have left companies facing operational uncertainty and forced them to review contracts and data protection practices when handling information from people in Brazil.

What changed for companies handling data from Brazil?

The main requirement is that companies transferring personal data outside Brazil must adjust contracts and internal controls to align with the LGPD and with the mechanisms accepted by the ANPD. According to USTR, since August 2025 U.S. companies working with data from people in Brazil have also had to designate a Data Protection Officer under the law.

That requirement can extend to subsidiaries or operations in other countries, including Chile, when they process data belonging to Brazilian data subjects. In practice, the report treats the LGPD as a rule that does not stop at Brazil’s borders. It affects multinational structures that centralize or share information across different jurisdictions.

What role does EU adequacy play?

The European Commission has recognized that Brazil’s data protection framework under the LGPD provides an adequate level of protection. That allows personal data to move from the European Economic Area to Brazil without standard contractual clauses or additional safeguards, except in areas such as public security and defense. Global Compliance Map reported that the ANPD also adopted Resolution CD/ANPD No. 32/2026.

That resolution formalizes recognition of the European Union’s adequacy decision for international transfers under the LGPD. For organizations with operations in Brazil and the EU, the change makes it easier to rely on mutual adequacy instead of contractual tools to move data. It may also affect business groups with a presence in Chile that exchange information with both markets.

Why does this matter in Latin America?

A global data governance consultancy already presents the LGPD as one of the most complete privacy frameworks in Latin America. The same consultancy offers services for companies operating at the same time under the LGPD and under the regimes in Argentina, Chile, Colombia and Peru, which reflects the need to coordinate obligations across countries.

In that context, an article on digital sovereignty in the region places Brazil alongside Mexico, Chile, Colombia and Argentina as countries with personal data protection laws. It also notes that regional companies must adapt their operations to those frameworks when handling information across multiple jurisdictions. In addition, a regional compliance executive in the technology industry said the spread of new requirements in Chile, Colombia and Peru is forcing companies to adjust operations and compliance models by country, reinforcing coordination between the LGPD and Chile’s new law when handling data across different jurisdictions.

Sources

View all