Cloud Minds Trusted
Blog

LGPD in the Cloud: What Brazilian Businesses Need

By Cloud Minds Trusted

August 17, 2026 · 6 min read

Moving data and workloads to the cloud has given companies of all sizes real agility, but it also raises a recurring question for legal and technical teams: how does Brazil's data protection law, the LGPD, apply when personal data lives on AWS, Azure, or GCP servers? The answer involves concepts like data controller and processor, international data transfers, and shared responsibility, and understanding each one is the first step toward operating in compliance.

Controller and processor: who is responsible for what in the cloud

Brazil's General Data Protection Law (Law No. 13,709/2018, known as LGPD) distinguishes two central roles in personal data processing: the controller, who decides the purposes of processing, and the processor (or operator), who processes data on the controller's behalf.

The ANPD's (Brazil's national data protection authority) Guidance on Data Processing Agents, published in 2021, explains this framework using the exact example of hiring a cloud service: the company that contracts the cloud provider is the data controller, and the cloud provider acts as the processor.

In practice, this means that choosing a cloud provider with a strong security reputation does not transfer legal responsibility to that provider. The contracting company still answers for the legal basis of processing (Article 7 of the LGPD), the purpose of data use, and overall compliance with the law, even though the infrastructure is physically managed by a third party.

International data transfers and ANPD Resolution No. 19/2024

A common question is whether using a cloud provider with servers outside Brazil counts as an international data transfer. Articles 33 through 36 of the LGPD govern this topic, and the prevailing legal reading in the Brazilian market, reflected in analyses such as one published by Conjur in December 2024, is that it does: storing or processing personal data on infrastructure hosted abroad qualifies as an international transfer, even when the operation is simply making access available to data hosted overseas. This is not a formally binding position from the ANPD, but it is the dominant interpretation and the most prudent one to guide procurement decisions.

In August 2024, the ANPD published Resolution CD/ANPD No. 19/2024, which regulates Articles 33 through 36 of the LGPD and approves a standard contractual clauses template for this type of transfer. The resolution establishes four possible mechanisms:

  • An adequacy decision for the destination country or international organization.
  • Standard contractual clauses approved by the ANPD.
  • Specific contractual clauses for the operation, subject to ANPD approval.
  • Global corporate rules, applicable to economic groups, also subject to ANPD approval.

Companies that were using their own custom clauses had twelve months, starting in August 2024, to migrate to the ANPD's standard model without content changes, aside from identifying the parties and the specific transfer details. That deadline passed in August 2025, so it is worth checking whether contracts with cloud vendors have already been updated.

The adequacy decision for the European Union

On January 26, 2026, the ANPD published Resolution CD/ANPD No. 32/2026, recognizing the European Union as the first territory to receive an adequacy decision. This means that for personal data transfers to the EU, no additional mechanism, such as standard contractual clauses, is required: the adequacy decision alone satisfies the legal requirement.

As of now, this is the only adequacy decision in force, and no specific contractual clause or global corporate rule had yet been approved by the ANPD's governing board. In practice, for most Brazilian companies using global cloud providers with data centers outside the EU, standard contractual clauses under Resolution 19/2024 remain the most direct path to compliance.

Shared responsibility in practice

Providers like AWS, Azure, and GCP operate under a shared responsibility model: the provider is responsible for security "of" the cloud, meaning physical infrastructure, virtualization, and hosting layers, while the customer is responsible for security "in" the cloud, including data, identity and access management (IAM) configuration, encryption, and hardening of the services in use.

AWS, for instance, holds certifications such as ISO/IEC 27001:2022, ISO/IEC 27017:2015, and ISO/IEC 27018:2019, and recommends practices like multi-factor authentication (MFA), careful credential management, encryption at rest using AES-256, centralized key management, and audit tools such as CloudTrail. Even so, the provider makes clear that the customer remains ultimately responsible for its own LGPD compliance.

This is not a limitation of the cloud, but an invitation to organize internal roles well: infrastructure can be robust, yet configurations, permissions, and access policies still depend on decisions made by the company itself.

An LGPD cloud compliance checklist

A few practical steps help structure a consistent compliance program:

  • Define the legal basis (Article 7 of the LGPD) for each personal data processing activity carried out in the cloud.
  • Formalize a contract or data processing agreement (DPA) with the provider, including clauses on international transfer where applicable.
  • Map where personal data is stored and processed, identifying whether it leaves Brazil and to which countries.
  • Apply encryption at rest and in transit, with proper key management.
  • Configure MFA and least-privilege IAM policies for access to cloud environments.
  • Maintain an incident response plan that provides for notifying the ANPD and data subjects, in line with applicable regulations.
  • Review contracts and contractual clauses periodically in light of ANPD updates, such as Resolution 19/2024 and Resolution 32/2026.

Certifications and frameworks for evaluating a cloud provider

Before contracting or reviewing a provider, it is worth looking at internationally recognized certifications and frameworks:

  • ISO/IEC 27001:2022, for information security management in general.
  • ISO/IEC 27017:2015, with controls specific to cloud services. A second edition, ISO/IEC 27017:2026, was published in July 2026, though providers such as AWS still hold active certification under the 2015 edition while they transition.
  • ISO/IEC 27018:2019, focused on protecting personal data in public cloud when the provider acts as a processor.
  • NIST Cybersecurity Framework (CSF) 2.0, published in February 2024, organized into six functions: Govern, Identify, Protect, Detect, Respond, and Recover.
  • CSA Cloud Controls Matrix, a de facto market reference for cloud security, currently at version 4.1, which superseded version 4.0.13 in 2026.
  • CIS Benchmarks specific to AWS and Azure, which help validate secure configurations on each platform.

It is worth noting that several publicly disclosed data breaches in Brazil in recent years have been traced to cloud misconfiguration rather than sophisticated attacks. This underscores the value of Cloud Security Posture Management (CSPM) practices and continuous hardening, pairing a provider's certifications with an internal routine of configuration review.

Conclusion

LGPD compliance in the cloud is not an obstacle to adopting services like AWS, Azure, or GCP, but it does require clarity about roles, international transfer mechanisms, and the security configurations that remain the contracting company's responsibility. Understanding the difference between controller and processor, keeping up with ANPD resolutions, and applying a consistent compliance checklist helps turn the cloud into an environment that is both secure and aligned with the law.

If your company wants to review contracts, configurations, and compliance processes for LGPD in the cloud, Cloud Minds Trusted can help structure that assessment with an integrated technical and legal view. Reach out to our team to talk about your organization's situation.

Want to assess your cloud security?

Talk to Cloud Minds Trusted.

Get in touch