On 26 January 2026, the European Commission adopted Implementing Decision (EU) 2026/179. It recognizes Brazil as providing a level of data protection essentially equivalent to the GDPR. Brazil’s data protection authority, the ANPD, issued a reciprocal decision recognizing the EU (Resolution CD/ANPD No. 32/2026). Personal data can now move from the EEA to Brazil without Standard Contractual Clauses or any other Chapter V safeguard.
Most coverage stops there. For US and international agencies with engineering teams in Latin America, that is where it starts.
The problem adequacy does not solve on its own
A European client’s DPO does not assess where your engineers sit. They assess who signs the DPA and where that entity is established.
If the contracting processor is a US company, the transfer runs to the United States. That transfer needs either certification under the EU-US Data Privacy Framework or SCCs backed by a transfer impact assessment. Many mid-sized agencies have neither in place. Procurement stalls. Legal review runs for months. Some accounts never close.
The team may be in São Paulo. The paper still says Delaware.
What changes when the processor is Brazilian
When a Brazilian entity signs the DPA, the transfer lands in an adequate jurisdiction. The client exports under Article 45 of the GDPR. No SCCs are needed as the transfer mechanism, and no transfer impact assessment is needed for the Brazil leg. The procurement file gets shorter and the review cycle gets faster.
The processor contract itself remains. Article 28 still requires defined processing instructions, security measures, breach notification, sub-processor controls and audit rights. Adequacy removes the transfer problem. The DPA still has to be built correctly.
What European procurement will still ask for
Expect five items in the review file:
- A DPA under Article 28, signed by the processing entity.
- A technical and organizational measures annex.
- A current sub-processor list.
- A breach notification commitment with a defined window.
- A data access map showing where personal data is accessed from.
The last item decides the outcome. If personal data is accessed from outside Brazil, those flows are onward transfers and need their own mechanism. The access path has to keep every engineer’s access to personal data inside Brazil.
How agencies are putting it to work
The structure that holds up in enterprise review has three parties and three agreements:
- Agency and enterprise sign the client agreement. The agency keeps full direction of scope, technical management and deliverables.
- Brazilian entity and enterprise sign the data processing agreement. The entity acts as processor inside an adequate jurisdiction.
- Agency and Brazilian entity sign a partner master services agreement, with a one-page order form for each client account.
Swipe sideways to see the full diagram.
The agency does not incorporate abroad. The client gets a DPA its DPO can approve. SolerWorks runs this structure from São Paulo as a cross-border compliance gateway. We do not recruit, screen or staff engineers: the agency contracts and pays its own team.
Frequently asked questions
Do we still need SCCs for transfers to Brazil?
Not as the transfer mechanism, for transfers within the scope of the adequacy decision.
Does adequacy exclude sensitive data?
No. The decision does not restrict the categories of personal data it covers. The GDPR’s rules on special category data still apply to the processing itself.
Does this help if our developers are in Colombia or Mexico?
Not directly. The decision covers Brazil. Access from other countries is an onward transfer and needs its own mechanism. Argentina and Uruguay hold separate EU adequacy decisions.
How long will adequacy last?
The GDPR requires the Commission to review each adequacy decision at least every four years. If a decision is ever suspended or repealed, the Standard Contractual Clauses built into the SolerWorks DPA apply from that moment, with no new signature.
Do we need to open a Brazilian company?
No. SolerWorks is the Brazilian entity. It signs the DPA with your client, so you do not incorporate abroad.