LGPD International Transfers: What to Document
An LGPD international transfer record should identify the data, purpose, legal basis, exporter, recipient, country, mechanism, safeguards, retention, and review owner. Brazil’s ANPD Resolution CD ANPD 19 of August 23, 2024 and ANPD international-transfer guidance provide the regulatory starting point, while the LGPD supplies principles and legal bases. A region choice alone is not a transfer mechanism.
Build the record around the actual flow. Include cloud storage, backups, support access, monitoring, subprocessors, queues, keys, and incident tooling. If a recipient or country is unknown, mark the transfer unresolved and stop the production claim until the owner and qualified counsel close the gap.
What belongs in an LGPD transfer record
Start with the controller or operator role, data subjects, data categories, purpose, legal basis, and necessity. Then name each recipient and processing country. Do not write “international cloud” as the recipient. Name the provider, service, account, feature, support path, and subprocessor where the evidence permits.
| Record field | Question answered | Owner |
|---|---|---|
| Purpose and necessity | Why is the data leaving Brazil? | Business and privacy |
| Data and subjects | What categories and people are involved? | Data owner |
| Recipient and country | Who receives or accesses it? | Procurement and security |
| Mechanism | What permits the transfer? | Privacy counsel |
| Safeguards | How is risk reduced? | Security |
| Retention and review | When is the decision revisited? | Governance |
Make the record versioned and dated. ANPD guidance and provider terms can change. Keep a reference to the configuration and contract evidence without placing the underlying booking data into the record.
How ANPD mechanisms fit the review
Use the ANPD regulation and international-transfer page to identify the mechanism that fits the transfer and parties. The correct route may depend on an adequacy decision, contractual safeguards, corporate rules, certification, or another mechanism recognized by the current regulation. Do not copy an exhaustive list from memory; check the current ANPD text on the draft date.
Distinguish a mechanism from a safeguard. A contractual clause may define duties, while encryption, least privilege, regional storage, logging, and incident response reduce practical exposure. Both belong in the record, but one does not substitute for the other.
The São Paulo home region article describes local hosting as a policy default. The cross-border support risk register extends the same analysis to human access.
Why necessity and purpose matter
LGPD principles include purpose, adequacy, necessity, security, prevention, and accountability. A transfer record should explain why the foreign recipient is needed and why the data set is proportionate. If a local service can perform the purpose without a transfer, document why the selected route remains necessary or choose the local route.
For a booking and attribution system, the platform that owns the appointment can remain the source of truth. Downstream reporting may need only an opaque appointment reference, generic campaign dimensions, status, and approved totals. An advertising route must receive separate policy and legal review. Never send patient name, email, phone, hashed identifiers, service or treatment details, or notes to an advertising platform.
Use an allowlist and reject unknown fields. A destination should not receive a complete booking object because one report might need one field. Minimize the record before queueing, logging, and backup.
Cloud, support, and subprocessor map
A regional database does not prove that a cloud deployment is local. Check object storage, backups, logs, keys, support, monitoring, billing, abuse review, and incident systems. Ask providers where staff can access data and whether support tickets or attachments are stored outside Brazil.
| Surface | Location evidence | Decision |
|---|---|---|
| Primary records | Region and service docs | Allow only verified region |
| Backups | Vault and restore target | Map separately |
| Keys | Key manager and operators | Record control and recovery |
| Support | Countries and tools | Assess transfer and access |
| Subprocessors | Vendor list and notices | Track change owner |
Use regional backups and keys for technical evidence. If a provider cannot supply enough information, state the uncertainty and request a contract or architecture decision rather than assuming local processing.
Safeguards and evidence
Record safeguards that exist in configuration and process. Encryption at rest and in transit, key separation, role-based access, MFA, support approval, tenant isolation, audit logging, and tested restore can all be relevant. Avoid saying that one control makes the transfer lawful or eliminates risk.
- Configure the approved home region.
- Restrict service locations and replication.
- Use unique identities and MFA.
- Limit support access to a ticket and expiry.
- Redact monitoring and error content.
- Record transfers and administrative access.
- Test deletion and restore.
- Review vendor and subprocessor changes.
Preserve evidence of the control, test date, result, owner, and exception. A planned safeguard should be marked pending until it is implemented. A vendor brochure is background evidence, not a configuration test.
Tenant approval checklist
Before processing begins, the Brazilian tenant or controller should approve the purpose and necessity. Privacy counsel should validate the transfer mechanism and legal basis. Security and procurement should verify provider terms, regions, subprocessors, support access, and safeguards.
- Data inventory and purpose are current.
- Recipient and country are explicit.
- Mechanism is supported by current ANPD text.
- Safeguards and exceptions are documented.
- Backups, keys, logs, support, and incident tools are mapped.
- Advertising routes are separately reviewed and default off.
- Review date and owner are assigned.
- Unresolved transfer facts block the residency claim.
When the transfer is not necessary or cannot be evidenced, keep the data in the approved local boundary and revisit the product requirement.
FAQ
What is the first verification step for LGPD international data transfer?
Identify the data, purpose, recipient, country, and processing role. Then consult current ANPD regulation and guidance to select a mechanism and document safeguards.
Which source or configuration detail could change this answer?
ANPD rules, adequacy decisions, contract clauses, provider regions, support countries, subprocessors, and the data category can change the review. Recheck after a vendor or legal update.
What must be approved before a production claim or outbound action?
The controller, privacy owner, counsel, security owner, and procurement owner should approve purpose, mechanism, safeguards, vendor scope, retention, and review cadence.
References
- Autoridade Nacional de Proteção de Dados, Resolution CD ANPD 19 of 23 August 2024, retrieved 2026-08-15, https://www.gov.br/anpd/pt-br/acesso-a-informacao/institucional/atos-normativos/regulamentacoes_anpd/resolucao-cd-anpd-no-19-de-23-de-agosto-de-2024
- Autoridade Nacional de Proteção de Dados, International Data Transfers, retrieved 2026-08-15, https://www.gov.br/anpd/pt-br/assuntos/assuntos-internacionais/transferencia-internacional-de-dados
- Presidência da República Federativa do Brasil, Lei Geral de Proteção de Dados Pessoais, retrieved 2026-08-15, https://www.planalto.gov.br/ccivil_03/_ato2015-2018/2018/lei/l13709compilado.htm
Related articles
How to Run a Tabletop Exercise for Breach Notification
A breach-notification tabletop should test roles, facts, evidence, risk assessment, communications, recovery, and post-exercise actions…
Proposed HIPAA Security Rule Changes for Incident Plans
As of August 15, 2026, distinguish the HIPAA Security Rule currently in effect from proposed modifications. Prepare incident,…
HIPAA Contingency Plans: Backup, Restore, and Testing
A HIPAA contingency plan should cover backup, disaster recovery, emergency mode, restore testing, recovery objectives, and evidence. The…