LGPD Outsourcing
Definition
LGPD Outsourcing
LGPD outsourcing is the practice of engaging a provider to process personal data covered by Brazil’s general data protection law. It borrows the controller and operator structure from European law, which makes it familiar, and its enforcement culture is what differs.
Familiar is not the same as identical.
The vocabulary maps closely enough that a European privacy team can read the Brazilian law without a translator for the concepts — the roles, the lawful bases and the data subject rights all rhyme.
Where it matters is in the details of enforcement, the supervisory authority’s priorities, and the fact that Brazil is a substantial nearshore delivery market in its own right.
Key takeaways
- Brazil’s General Data Protection Law took effect on 18 September 2020.
- It uses a controller and operator split closely comparable to Europe’s controller and processor.
- The operator processes on the controller’s behalf and does not set the purposes.
- Brazilian delivery centres serve both domestic clients and nearshore buyers in the Americas.
How it works
The law is Brazil’s General Data Protection Law, known by its Portuguese initials. AWS records that the Brazilian General Data Protection Law (“LGPD”) went into effect on 18 September 2020.
Its structure will be recognisable to anyone who has worked with European rules. A controller decides how and why personal data is processed — an operator carries out processing on the controller’s behalf.
Cloud arrangements make the split explicit. AWS describes a model in which it secures the infrastructure while customers and APN partners, acting either as data controllers or data processors, are responsible for any personal data they put on the cloud.
The comparison with Europe is the fastest way to understand the obligations.
European law requires that processing by a processor be governed by a contract setting out the subject-matter and duration of the processing, the nature and purpose of the processing, the type of personal data and categories of data subjects.
Brazilian practice expects equivalent contractual specificity. A buyer already running European processor contracts has most of the drafting work done.
| Brazil | Europe | |
|---|---|---|
| Decides purposes | Controller | Controller |
| Processes on instruction | Operator | Processor |
| Effective from | 18 September 2020 | 25 May 2018 |
| Supervisory body | National data protection authority | National authorities per state |
| Practical drafting | Equivalent contractual specificity | Prescribed contract contents |
The useful implication is commercial — if your organisation already meets European standards, Brazilian requirements are an adaptation rather than a rebuild.
Examples
Brazilian processing arrangements arise both from serving Brazilian consumers and from using Brazilian delivery capacity, and the two raise different questions. Each case below shows the rule meeting a delivery model it was not drafted for.
A US company uses a São Paulo delivery centre for customer support. Brazilian residents’ data is being handled in Brazil, which is the simplest case the law contemplates.
A European group extends its existing processor contracts to a Brazilian operator. The structural similarity means amendment rather than redrafting, which is why nearshore Latin America expansion is often smoother than expected.
A retailer serving Brazilian customers processes their data in Manila. The law follows the data subject, so location of processing does not remove the obligation.
A provider positions Brazilian compliance as a selling point across the region. That is fair, though LATAM BPO markets each have their own regimes and Brazil’s does not cover them.
Related terms
Latin American privacy law sits alongside European law and the regional delivery markets that make it commercially relevant. Every definition here is minimal, and each states the boundary rather than implying it.
- GDPR (General Data Protection Regulation): the European regime this law’s structure closely resembles.
- Compliance outsourcing: buying regulatory capability, distinct from meeting a specific national law.
- Data Privacy Act Philippines: another national regime governing a large delivery market.
- Nearshore Latin America: the delivery model that makes Brazilian law relevant to North American buyers.
- LATAM BPO: the regional industry, spanning jurisdictions with separate privacy laws.
- Vendor management outsourcing: running supplier assurance across multiple regimes.
- Regulated outsourcing: sector rules layering above general data protection law.
FAQ
When did the LGPD take effect?
On 18 September 2020. Enforcement provisions and the supervisory authority’s activity developed over the period following that date.
What is an operator under the LGPD?
The party processing personal data on the controller’s behalf. It corresponds closely to the processor role in European data protection law.
Is LGPD compliance the same as GDPR compliance?
No, though the structures are close. European compliance gives a strong starting position, and the Brazilian law still has to be assessed on its own terms.
Does it apply if processing happens outside Brazil?
Yes, where the processing concerns individuals in Brazil or data collected there. Offshore delivery does not remove the obligation.
Does it cover other Latin American countries?
No. Other regional markets have their own data protection laws, and Brazilian compliance does not extend across them.
What should be in an operator contract?
The same specificity a European processor contract requires: scope, duration, purpose, data types, data subjects and each party’s obligations.
Review verified partners in the Outsource Accelerator directory and check the instructions you give are the ones being followed.







Independent




