LGPD and GDPR for Companies With a Structure Abroad
Quick answer
Yes. The LGPD reaches processing carried out in Brazil, aimed at people in Brazil or involving data collected here (art. 3). The GDPR reaches those with an establishment in the European Union or serving data subjects there. A structure abroad can be subject to both laws and needs a legal basis to transfer data.
- LGPD simple fine (ceiling per infraction)
- BRL 50,000,000.00limit per infraction
- LGPD ceiling on revenue in Brazil
- 2%
- GDPR, art. 83, paragraph 4
- EUR 10,000,000 or 2%
- GDPR, art. 83, paragraph 5
- EUR 20,000,000 or 4%
- GDPR breach notification deadline
- 72 hourswhere feasible
- 01Does the LGPD apply to a company headquartered abroad?
- 02Does the GDPR apply to a company outside the European Union?
- 03When do the LGPD and the GDPR apply at the same time?
- 04How do you transfer data from Brazil to the structure abroad?
- 05How do you transfer data from the European Union to another country?
- 06Do I need a data protection officer (DPO) and a representative in the Union?
- 07What are the fines?
- 08How do you organize compliance for a company with an offshore structure?

Yes. A company with a structure abroad can be subject to both the LGPD and the GDPR at the same time, even without a seat in Brazil or the European Union. The LGPD reaches processing carried out in Brazil, aimed at people here or involving data collected here. The GDPR reaches those with an establishment in the Union or serving data subjects there (both in art. 3).

Does the LGPD apply to a company headquartered abroad?
It does, when the processing fits one of the three scenarios in art. 3 of Law No. 13,709/2018 (Lei 13.709/2018). The law applies regardless of the medium, the country of the company's seat and the country where the data is located, as long as:
- •the processing operation is carried out in Brazilian territory;
- •the activity aims to offer or supply goods or services, or to process data of individuals located in Brazilian territory; or
- •the data was collected in Brazilian territory, which includes data of a data subject who is in Brazil at the time of collection (art. 3, § 1).
CD/ANPD Resolution No. 19/2024 repeats this logic for international transfers and adds that the application of the law does not depend on the medium, the country of the agents' seat or the country where the data is located (art. 7, sole paragraph). It also says the LGPD applies to data coming from abroad when it is processed in Brazil (art. 8), with limited exceptions, such as mere transit without communication with a Brazilian agent.
A holding company or an LLC abroad that sells or provides services to people in Brazil, or that collects customer data here, may fall into these scenarios. Under the wording of art. 3, the location of the seat does not take the company outside the law.
Does the GDPR apply to a company outside the European Union?
It applies in two main cases, set out in art. 3 of Regulation (EU) 2016/679:
- •Establishment in the Union (paragraph 1): the regulation applies to processing carried out in the context of the activities of an establishment of the controller or processor in the Union, whether the processing takes place inside or outside it.
- •Data subjects in the Union (paragraph 2): it applies to the processing of data of data subjects who are in the Union, carried out by someone not established there, when the processing relates to offering goods or services to those data subjects (even free of charge) or to monitoring their behavior in the Union.
Anyone who falls under paragraph 2 must, as a rule, designate a representative in the Union in writing (art. 27). The exception applies to occasional processing that does not involve special categories of data on a large scale and is unlikely to result in a risk to people's rights. Do not assume your operation fits the exception without analysis.
When do the LGPD and the GDPR apply at the same time?
When the same company processes data of people in Brazil and people in the Union. Each law applies to its own slice. The table shows the points that weigh most for an international structure.
| Point | LGPD (Law 13,709/2018) | GDPR (Regulation 2016/679) |
|---|---|---|
| Territorial scope | Art. 3: processing in Brazil, offering to people in Brazil or collection in Brazil | Art. 3: establishment in the Union or data subjects in the Union |
| International transfer | Arts. 33 to 36 | Arts. 44 to 49 |
| Basis for transferring | Adequacy, safeguards (standard clauses, specific clauses, global corporate rules, seals and codes), or the scenarios of art. 33 | Adequacy decision (art. 45), appropriate safeguards (art. 46) or derogations (art. 49) |
| Data protection officer | Officer appointed by the controller (art. 41) | Officer designated in the cases of art. 37, paragraph 1 |
| Security incident | Notice to the ANPD and the data subject, within a period set by the ANPD (art. 48) | Notice to the authority without undue delay and, where feasible, within 72 hours (art. 33) |
How do you transfer data from Brazil to the structure abroad?
The LGPD allows international transfers only in the cases of art. 33. The ones companies use most are:
- •Country with adequate protection (item I): the ANPD (Brazil's National Data Protection Authority) assesses the country's level of protection (art. 34). CD/ANPD Resolution No. 32/2026 recognized the European Union as a body with an adequate level of protection. The decision covers the Member States, Iceland, Liechtenstein and Norway, and the Union's institutions (art. 1). It does not apply to purposes exclusively related to public security, defense and criminal activities (art. 2).
- •Safeguards offered by the controller (item II): specific contractual clauses, standard contractual clauses, global corporate rules, or seals, certificates and codes of conduct.
- •Specific and prominent consent (item VIII): the data subject must be informed beforehand of the international nature of the operation, which must be distinct from other purposes.
The Regulation approved by CD/ANPD Resolution No. 19/2024 details the standard clauses. A transfer relying on them is valid only if the text of Annex II is adopted in full and unchanged, in a contract between the exporter and the importer (art. 16). No other clause of the contract or of related contracts may exclude, modify or contradict those clauses (art. 16, § 2). Those who already used contractual clauses had up to 12 months from the publication of the Resolution to incorporate the standard clauses (art. 1, sole paragraph, of the Resolution).
Specific contractual clauses depend on ANPD approval and are approved only when the transfer cannot use the standard clauses, due to proven exceptional circumstances (art. 21, § 1). That is why the standard path is the standard clause.
How do you transfer data from the European Union to another country?
Art. 44 of the GDPR sets the general rule: any transfer of data to a third country or international organization takes place only if the conditions of Chapter V are met. There are three tiers:
- •Adequacy decision (art. 45): the Commission decides that the third country ensures an adequate level of protection. The transfer does not require specific authorization. The Commission publishes the list of these decisions (art. 45, paragraph 8).
- •Appropriate safeguards (art. 46): without an adequacy decision, the controller or processor must provide safeguards, such as binding corporate rules (art. 47), standard clauses adopted by the Commission or by a supervisory authority, a code of conduct or certification.
- •Derogations (art. 49): specific situations, such as explicit consent after being informed of the risks, or necessity to perform a contract with the data subject.
If the destination country of your structure is not on the Commission's adequacy list, the path is art. 46. Check the current list before signing the contract.
Note art. 48: judicial or administrative decisions of a third country requiring data transfers are recognized or enforced only if based on an international agreement in force with the Union or a Member State.
Do I need a data protection officer (DPO) and a representative in the Union?
Brazil. The controller must appoint an officer for the processing of personal data, with identity and contact details made public, preferably on the website (LGPD, art. 41, § 1). Paragraph 3 of art. 41 allows the ANPD to set exemption cases based on the nature and size of the entity or the volume of operations. Check the current rule before concluding that your company is exempt.
European Union. The GDPR requires a data protection officer when processing is carried out by a public authority, when the core activities require regular and systematic monitoring of data subjects on a large scale, or when they involve special categories of data and data on criminal convictions on a large scale (art. 37, paragraph 1). A corporate group may designate a single officer, as long as the officer is easily accessible from each establishment (art. 37, paragraph 2).
Representative. A representative in the Union, in turn, is required by art. 27 for anyone who falls under art. 3, paragraph 2 and does not fit the exception.
What are the fines?
The amounts below are those in the laws themselves. They are ceilings, and the actual sanction depends on the case.
| Rule | Ceiling | Note |
|---|---|---|
| LGPD, art. 52, II | 2% of the revenue of the legal entity, group or conglomerate in Brazil in the last fiscal year, excluding taxes, capped at BRL 50,000,000.00 per infraction | Simple fine |
| GDPR, art. 83, paragraph 4 | Up to EUR 10,000,000 or 2% of total worldwide annual turnover of the preceding financial year, whichever is higher | Obligations under arts. 8, 11, 25 to 39, 42 and 43, among others |
| GDPR, art. 83, paragraph 5 | Up to EUR 20,000,000 or 4% of total worldwide annual turnover of the preceding financial year, whichever is higher | Processing principles, data subjects' rights and transfers under arts. 44 to 49, among others |
The LGPD provides for sanctions beyond the fine, such as a warning, a daily fine, publicizing the infraction, blocking and deletion of the data, suspension of the database or of the processing activity, and partial or total prohibition of processing activities (art. 52). The ANPD applies sanctions after a procedure with full right of defense and considers, among other criteria, severity, good faith, the advantage gained and repeat offenses (art. 52, § 1).
Transfers outside the rules of arts. 44 to 49 of the GDPR fall under the higher ceiling of art. 83, paragraph 5.
How do you organize compliance for a company with an offshore structure?
- •Map the data. List which personal data the structure processes, whose (people in Brazil, in the Union or both), for what purpose and where it is stored.
- •Identify each company's role. Controller and processor are different roles under the LGPD. The processor handles data according to the controller's instructions (art. 39).
- •Choose the transfer mechanism. Adequacy, standard clauses or another basis provided in art. 33 of the LGPD and Chapter V of the GDPR.
- •Adjust the contracts between group companies. For the ANPD's standard clauses, adopt the text of Annex II without changes.
- •Keep a record of operations. The LGPD requires a record of processing operations (art. 37), especially when based on legitimate interest.
- •Prepare the incident plan. Define who assesses the incident and who notifies the ANPD and the European authority.
- •Designate an officer and, where applicable, a representative in the Union.
- •Review the corporate structure. The design of the group defines who is the controller and who is liable. See the guide on international shareholder agreements and the content on hiring an international remote team, which also involves personal data.
For the other side of compliance for structures abroad, read Receita enforcement of offshores and see the compliance and corporate structures services.
Need consulting?
Talk to a specialist via WhatsApp and clear your doubts about offshore structuring.
Talk on WhatsApp
Dr. Heitor Miguel
Attorney registered at OAB/SP 252,633. MBA in Business Law and M&A from FGV. Specialist in International Law and iGaming. President of the International Law Commission at OAB/SBC. Deal Maker of the Year 2014 – IAE Awards.
Does the LGPD apply to an offshore company with no seat in Brazil?
Yes, if the processing is carried out in Brazil, aims to offer goods or services to people in Brazil or uses data collected in Brazil. Art. 3 of Law 13,709/2018 applies regardless of the country of the seat and the country where the data is located.
Does the GDPR apply to a Brazilian company that sells to the European Union?
It may. Art. 3, paragraph 2, applies the regulation to those not established in the Union when the processing relates to offering goods or services to data subjects who are in the Union, or to monitoring their behavior there. In that case, as a rule, there must be a representative in the Union (art. 27).
Does transferring data from Brazil to the European Union require contractual clauses?
Not necessarily. CD/ANPD Resolution No. 32/2026 recognized the European Union as a body with adequate protection, which allows the transfer under art. 33, I, of the LGPD. The other mechanisms in art. 33 remain available (art. 5 of the Resolution). The decision does not cover purposes exclusively related to public security, defense and criminal activities.
Can I change the ANPD's standard contractual clauses?
No. For the transfer to be valid under them, the text of Annex II of CD/ANPD Resolution No. 19/2024 must be adopted in full and unchanged (art. 16). Other clauses in the contract cannot exclude, modify or contradict the standard clauses.
What is the maximum LGPD fine?
The simple fine under art. 52, II, is up to 2% of the revenue of the legal entity, group or conglomerate in Brazil in the last fiscal year, excluding taxes, capped at BRL 50,000,000.00 per infraction. The law also provides for other sanctions, such as a warning, and blocking and deletion of the data.
What is the maximum GDPR fine?
It depends on the infraction. Art. 83, paragraph 4, provides for up to EUR 10,000,000 or 2% of total worldwide annual turnover, and paragraph 5 provides for up to EUR 20,000,000 or 4%, in both cases whichever is higher. Violations of the transfer rules of arts. 44 to 49 fall under the ceiling of EUR 20,000,000 or 4%.
Does a small company need a data protection officer?
Under the LGPD, art. 41 requires the controller to appoint an officer, and paragraph 3 allows the ANPD to set exemption cases based on the nature and size of the entity or the volume of operations. Check the current rule. Under the GDPR, art. 37, paragraph 1, requires one only when processing is carried out by a public authority or when the core activities involve regular and systematic monitoring on a large scale or special categories of data on a large scale.
- Research
Law No. 13,709/2018 (LGPD)
www.planalto.gov.br
- Research
CD/ANPD Resolution No. 19/2024
www.gov.br
- Research
CD/ANPD Resolution No. 32/2026, in the Federal Official Gazette
www.in.gov.br
- Research
Regulation (EU) 2016/679 (GDPR), Publications Office of the European Union
op.europa.eu
- Research
National Data Protection Authority (ANPD)
www.gov.br


