Skip to content

Compliance

Outsourcing to Brazil under the GDPR, without shortcuts

Brazil holds no European Union adequacy decision. Any processing of European personal data from Brazil requires standard contractual clauses and a transfer impact assessment.

Corpshore Portugal editorial team

Written by the team that builds these operations. No individual byline: this is internally reviewed work, not personal opinion.

Published

Outsourcing to Brazil under the GDPR, without shortcuts

Does the LGPD solve the problem?

It helps, but it does not substitute. Brazil's data protection law brought the local framework substantially closer to the European one, which makes a transfer impact assessment easier to conclude favourably. It does not, however, create the adequacy decision the European Commission has not issued.

In practice that means anyone telling you the LGPD removes the need for standard contractual clauses is wrong, and that this is a good question to put to any supplier in the first meeting.

What do you actually need in place?

A data processing agreement, the European Commission standard contractual clauses in the modules applicable to the controller to processor relationship, and a documented transfer impact assessment.

The assessment is not a form. It analyses the destination country's legal framework, including authority access to data, and concludes whether the contractual safeguards suffice in the specific case. The supplier may prepare it, but the decision to proceed rests with the controller, which is the client.

How do you shrink the scope of the problem?

Minimise what leaves. Many operations can run in Brazil on pseudonymised data or on a restricted subset, keeping what is specially sensitive in Portugal. The boundary is defined by data category, before the operation opens, and written down.

For health data and most of the public sector, the honest answer is that the European-only model is the only defensible one, and that the saving does not justify the risk.

What does a transfer impact assessment have to contain?

Four things, and none of them is a generic compliance statement. First, a concrete description of the transfer: which data categories leave, whose, how often, for what purpose and how long they stay at the destination. An assessment that cannot list this has assessed nothing.

Second, an analysis of the destination country's legal framework, with specific attention to public authority access powers and the remedies available to a European data subject. Third, the supplementary measures, technical and organisational, that reduce the identified risk. Fourth, a reasoned conclusion, dated and attributed.

The part most often missing is the third. Encryption in transit and at rest, logged access control, pseudonymisation where the process allows it, and limiting what is replicated to the destination: these are the measures that turn an uncomfortable conclusion into a defensible one, and they have to exist in practice rather than only in the document.

Who is responsible for what, exactly?

The client is the controller and the supplier is the processor, in the overwhelming majority of these relationships. That means the client determines the purposes and the essential means, and answers to the data subject and to the supervisory authority. The supplier processes only on documented instructions.

In practice the supplier prepares the impact assessment, because it knows the operation and the destination better than anyone. But the decision to proceed is signed by the client, and a supplier offering to take that decision is offering something it legally cannot give.

The processing agreement should say who does what when something goes wrong: who notifies a data breach and within what deadline, who answers a subject access request, who bears the cost of an audit, and what happens to the data at the end of the contract. These are the clauses nobody reads until they need them.

What changes if the operation is mixed?

The design changes, and for the better. In a mixed operation, the tier handling identifiable data stays in Portugal and the tier handling volume works on a reduced or pseudonymised set in Brazil. The boundary is defined by data category and case type, and written down before the operation opens.

The practical effect is that the impact assessment covers a much smaller set of data, which makes it easier to conclude favourably and easier to defend. It also reduces the impact of any change in the destination's legal context, because less is exposed.

The cost is operational: routing by case type needs clear rules and discipline, and there are always cases that straddle the boundary. It is worth deciding in advance what happens to those, rather than leaving the decision to the operator in the moment, which is how data boundaries dissolve in practice.

How often is it reassessed?

At least annually, and whenever something material changes. Material means: a change in the destination's legal framework, a change in the data categories transferred, a change of subprocessor, or a European court decision affecting the basis of the transfer. The standard contractual clauses require this.

It is worth writing into the contract who reassesses, within what period, and what happens if the conclusion changes. A contract requiring reassessment but silent on what to do with an unfavourable result leaves both parties looking at each other at the worst possible moment.

In practice this means keeping a credible exit plan: knowing how long it would take to bring the operation back inside the European Economic Area and what it would cost. Anyone who cannot answer that question does not have a managed transfer, they have a dependency.

What does this cost and how long does it take?

The complete framework, built from scratch, typically takes between four and eight weeks: one to describe the transfer, two to three for the legal analysis and supplementary measures, and the rest in legal review and signature. It is lawyer and operations work at the same time, and compressing it is the most common way to end up with a document that does not survive an inspection.

In direct cost, for a mid-sized operation, it usually lands below what is saved in the first quarter. It is a start-up expense rather than a recurring one, and the annual reassessment is a fraction of it provided the first piece of work was done properly.

The usual miscalculation is treating this as a cost of the outsourcing project rather than a condition of its existence. If the business case only works by ignoring the four to eight weeks and the legal cost, the business case does not work, and it is better to find that out before signing than at the first audit.

Which technical measures count as supplementary?

Strong encryption in transit and at rest, with key management held inside the European Economic Area and out of reach of the processor in the destination country. It is the most cited measure and the most frequently only half implemented, because key management ends up in the same place as the data.

Pseudonymisation applied before transfer, so that the additional information needed to re-identify stays at origin. For many back office processes this is workable and substantially reduces risk, although the data remains personal data for legal purposes.

Access control on the least-privilege principle with full logging, so that it is possible to demonstrate who accessed which data and when. Without logging, it is impossible to answer a data subject request or demonstrate compliance in an inspection.

And organisational measures that count as much as the technical ones: policies for responding to authority requests with mandatory escalation to the European entity, documented team training, and a contractual commitment to notify the controller before any disclosure, where local law permits it.

How do you answer a data subject request?

Within the statutory one-month deadline, extendable in complex cases, and with the content the law requires rather than just a confirmation. For international transfers there is an additional element: the data subject has the right to know which countries their data was transferred to and under what safeguards.

In practice this requires the operation to be able to answer the question before it is asked. An up-to-date record of processing activities, with destinations and transfer instruments identified, turns a subject request into a ten-minute exercise rather than a two-week investigation.

The contract should say who does what. Typically the processor assists and the controller answers, with internal deadlines shorter than the statutory one so there is room. A contract saying only that the processor will cooperate is deferring an argument to the worst possible moment.

It is worth rehearsing this once before it happens for real. A test request walked end to end reveals where information does not exist, who does not know they have a role, and how long the process actually takes. It costs a morning and prevents a breach.

Frequently asked questions

Does Brazil have adequacy?
No. It requires standard contractual clauses and a transfer impact assessment.
Who carries out the impact assessment?
Usually the supplier prepares and the client decides, because responsibility sits with the controller.
Does pseudonymisation solve everything?
It reduces risk and scope, but pseudonymised data is still personal data and the obligations remain.
What if the country context changes?
The clauses require reassessment. The contract should say who reassesses and within what period.
Which clause modules apply?
Usually the controller to processor module, according to the parties' actual relationship.
Is a processing agreement enough on its own?
Not for transfers outside the EEA. The clauses and the impact assessment have to be added.
Which data is best not sent?
Health data, public sector data and special categories. For those, the European-only model is the defensible one.
Do subprocessors have to be named?
They do, and the subprocessing chain must be declared and subject to authorisation.

Let us look at the numbers for your case

Tell us which processes you want to outsource, in which languages and at what volume. We come back with a euro estimate and an operating design, with no commitment.

We reply within 6 hours on working days. If you would rather write: info@corpshore.solutions