Insights21 Sep 2026 · 4 min read

Brazil has GDPR adequacy. Here is what it means for US agencies serving European clients.

The EU recognized Brazil as adequate under GDPR in January 2026. Here is how US and international agencies can use it to close European enterprise accounts.

On 26 January 2026, the European Commission adopted Implementing Decision (EU) 2026/179. It recognizes Brazil as providing a level of data protection essentially equivalent to the GDPR. Brazil’s data protection authority, the ANPD, issued a reciprocal decision recognizing the EU (Resolution CD/ANPD No. 32/2026). Personal data can now move from the EEA to Brazil without Standard Contractual Clauses or any other Chapter V safeguard.

Most coverage stops there. For US and international agencies with engineering teams in Latin America, that is where it starts.

The problem adequacy does not solve on its own

A European client’s DPO does not assess where your engineers sit. They assess who signs the DPA and where that entity is established.

If the contracting processor is a US company, the transfer runs to the United States. That transfer needs either certification under the EU-US Data Privacy Framework or SCCs backed by a transfer impact assessment. Many mid-sized agencies have neither in place. Procurement stalls. Legal review runs for months. Some accounts never close.

The team may be in São Paulo. The paper still says Delaware.

What changes when the processor is Brazilian

When a Brazilian entity signs the DPA, the transfer lands in an adequate jurisdiction. The client exports under Article 45 of the GDPR. No SCCs are needed as the transfer mechanism, and no transfer impact assessment is needed for the Brazil leg. The procurement file gets shorter and the review cycle gets faster.

BeforeA US company signs the DPAEU clientControllerEuropeTransfer to the USDPF, or SCCs plus a TIAUS agencyProcessorUnited StatesAccess from BrazilThrough the US contractEngineersThe delivery teamBrazilAfterA Brazilian company signs the DPAEU clientControllerEuropeTransfer to BrazilAdequacy decision, Art. 45SolerWorksProcessorSão PauloAccess from BrazilUnder a SolerWorks undertakingEngineersThe delivery teamBrazil
Who signs the DPA decides where the transfer lands. The team is in Brazil either way.

The processor contract itself remains. Article 28 still requires defined processing instructions, security measures, breach notification, sub-processor controls and audit rights. Adequacy removes the transfer problem. The DPA still has to be built correctly.

What European procurement will still ask for

Expect five items in the review file:

  1. A DPA under Article 28, signed by the processing entity.
  2. A technical and organizational measures annex.
  3. A current sub-processor list.
  4. A breach notification commitment with a defined window.
  5. A data access map showing where personal data is accessed from.

The last item decides the outcome. If personal data is accessed from outside Brazil, those flows are onward transfers and need their own mechanism. The access path has to keep every engineer’s access to personal data inside Brazil.

How agencies are putting it to work

The structure that holds up in enterprise review has three parties and three agreements:

  • Agency and enterprise sign the client agreement. The agency keeps full direction of scope, technical management and deliverables.
  • Brazilian entity and enterprise sign the data processing agreement. The entity acts as processor inside an adequate jurisdiction.
  • Agency and Brazilian entity sign a partner master services agreement, with a one-page order form for each client account.
Tripartite delivery architectureThree contracts connect the enterprise client, the partner and SolerWorks. The delivery team works inside the client environment.Enterprise clientController. Pays the partner.PartnerSources, hires and directs the teamSolerWorksDPA signatory and processorDelivery teamWorks inside the client environmentCONTRACT 1Client agreementPartner and clientCONTRACT 2Data Processing AgreementSolerWorks and clientMaster Services AgreementCONTRACT 3 · Partner and SolerWorks

Swipe sideways to see the full diagram.

The agency does not incorporate abroad. The client gets a DPA its DPO can approve. SolerWorks runs this structure from São Paulo as a cross-border compliance gateway. We do not recruit, screen or staff engineers: the agency contracts and pays its own team.

Frequently asked questions

Do we still need SCCs for transfers to Brazil?

Not as the transfer mechanism, for transfers within the scope of the adequacy decision.

Does adequacy exclude sensitive data?

No. The decision does not restrict the categories of personal data it covers. The GDPR’s rules on special category data still apply to the processing itself.

Does this help if our developers are in Colombia or Mexico?

Not directly. The decision covers Brazil. Access from other countries is an onward transfer and needs its own mechanism. Argentina and Uruguay hold separate EU adequacy decisions.

How long will adequacy last?

The GDPR requires the Commission to review each adequacy decision at least every four years. If a decision is ever suspended or repealed, the Standard Contractual Clauses built into the SolerWorks DPA apply from that moment, with no new signature.

Do we need to open a Brazilian company?

No. SolerWorks is the Brazilian entity. It signs the DPA with your client, so you do not incorporate abroad.

Bringing engineers in Brazil into a European account?

SolerWorks handles the agreements, controls and audit evidence your client’s security and legal teams need to say yes.