International Data Transfer
ecently, the Brazilian National Data Protection Authority (ANPD) issued Resolution nº 19/24, which approved the regulation that addresses international data transfers in Brazil.
What characterizes an international data transfer?
According to ANPD's regulation, international data transfer refers to the sending of personal data to a foreign country or to an international organization of which the country is a member.
Examples of common business situations that may involve international data transfer include:
Sharing of HR databases between companies of the same group (head office-subsidiary);
Storage of data in data centers physically located abroad;
Outsourcing of customer service to a foreign company;
Hiring of a foreign cloud computing provider.
services_
Creation of documentation to provide transparency for international data transfers performed by the exporter, to be made available on the website. Establish an efficient procedure to meet requests from data subjects requiring the full clauses used in international data transfer.
Incorporate standard contractual clauses or specific clauses into existing contracts with data importers. Review contracts to ensure all agents comply with new obligations and responsibilities.
Verify if transfers are being made to countries or international organizations with adequacy decisions recognized by the ANPD.
Evaluate the need for using standard contractual clauses. Implement approved standard clauses or propose the creation of specific clauses, if necessary.
Verify if recipient countries have adequacy decisions recognized by the ANPD or other international authorities. If necessary, identify additional legal requirements applicable to each destination.
Identify the legal bases for each transfer, according to Articles 7, 11, and 33 of the LGPD (e.g., consent, compliance with legal obligation, contract, etc.).
Identify all processing agents (data importers) involved in international transfer operations. Determine data location and verify which countries or international organizations are involved.
Identification of all personal data collected and processed, classifying it by type (sensitive and non-sensitive), origin, purposes, and lifecycle.