LGPD (Brazil) applicability under Supabase DPA #48657
Replies: 1 comment
|
Not from the Supabase team, so questions 1 and 2 still need them for a contractual commitment. But three of these have a determinable answer from published sources, and one of them cuts against the assumption in your question 4. I run a legal case management system on similar infrastructure, so this is the same analysis I had to do. Question 4 first, because it is the one that changes the planYes. Hosting in
Region selection governs where the primary Postgres instance, Auth and Storage objects sit. It does not govern the subprocessors, and the subprocessors are what trigger art. 33. The part that matters for the mechanism you end up needing: the ANPD has issued exactly one adequacy decision so far, Resolução CD/ANPD nº 32, de 26 de janeiro de 2026, covering the EU member states, Iceland, Liechtenstein, Norway and the EU institutions, under art. 33, I. There is no adequacy decision for the United States. So any subprocessor established there needs a mechanism under art. 33, II, not the adequacy route. Worth pulling the current subprocessor list and mapping each entry against that before signing anything. Supabase also publishes a Transfer Impact Assessment in their legal downloads, which is written for the GDPR analysis but gives you the same underlying facts. Question 1: the DPA does reach the LGPDThe omission you noticed is not exclusionary. The definition is open:
"Including (without limitation)" makes that list exemplificative. The LGPD is an applicable law relating to the privacy and security of personal data, so it falls inside the general clause and Supabase's processor obligations under the DPA run to it. That settles the obligations. It does not by itself give you a transfer mechanism, which is a separate requirement and the subject of question 2. Question 2: no Brazil addendum, but the hook is already in the contractThere is no Brazil-specific addendum alongside the EU SCCs, the UK Addendum and the Swiss Addendum. Two things fill the gap, and the second is the one I would build on. Clause 12.1(b), read with Schedule 2 paragraph 4, extends the SCC machinery to non-EU exporters whose law requires adequate safeguards, allowing the clauses to be adapted to reference the exporter jurisdiction's law and supervisory authority. And the same provision commits the parties to promptly enter into a supplementary agreement where an alternative transfer mechanism becomes available under the exporter jurisdiction's law. That is precisely our situation. Resolução CD/ANPD nº 19, de 23 de agosto de 2024 approved the Brazilian Cláusulas-Padrão Contratuais, and the window to incorporate them into existing contracts closed twelve months after publication, in August 2025. So the alternative mechanism exists, it is mandatory for transfers relying on standard clauses, and the DPA already obliges Supabase to sit down and paper it. One caveat I would not gloss over. The regulation also admits cláusulas-padrão equivalentes, foreign clauses recognised by the ANPD as equivalent. That would be the natural route for the EU SCCs already in Schedule 2. But per the ANPD's own page, no such equivalence decision has been published to date. Until one is, I would not assume the Schedule 2 SCCs discharge the art. 33 requirement on their own. That reframes the ask to Supabase: not "do you have a Brazil addendum", but "will you execute the ANPD Cláusulas-Padrão Contratuais as the supplementary agreement contemplated by Clause 12.1(b)". Question 3: Schedule 1 supports it, it does not discharge itArt. 46 imposes an obligation of result, security measures apt to protect the data, without prescribing a standard or a certification. So no annex satisfies it by itself. Schedule 1 is evidence for the assessment you have to make and document as controller. Supabase's SOC 2 report is stronger evidence for the same purpose. Neither transfers the obligation: under the LGPD you remain the controller, and the measures inside your own deployment (RLS, key custody, who on your team can read a case file) sit outside Schedule 1 entirely and are usually where the real exposure is. One thing outside your four questionsFor a firm specifically, the LGPD is not the only layer. Client case data is also covered by professional secrecy under the OAB rules and art. 154 of the Penal Code, and that obligation is not delegable to a processor. Depending on the case types you handle, it can drive encryption and access decisions that go beyond what any DPA will give you. @supabase team, the two that genuinely need you: confirmation that the LGPD is treated as an Applicable Data Protection Law under the general definition, and whether you are willing to execute the ANPD Cláusulas-Padrão Contratuais under Clause 12.1(b). Both are reasonable asks with the adequacy decision for the EU now in place and none for the US. Reading of published documents, not legal advice, and not a substitute for your own assessment. The DPA quotes are from the version currently published at supabase.com/legal/dpa; check it against the version Supabase presents you, since these get revised. |
Uh oh!
There was an error while loading. Please reload this page.
Hi everyone,
We're a Brazilian law firm evaluating Supabase Pro to host an internal legal case management system that will process personal data and information related to judicial proceedings.
As part of our legal due diligence before migrating production data, we're reviewing the Supabase Data Processing Addendum (DPA) and would appreciate clarification from the Supabase team regarding compliance with Brazil's General Data Protection Law (LGPD – Law No. 13,709/2018).
Although the DPA defines "Applicable Data Protection Laws" as including the GDPR, Swiss Data Protection Laws, and certain US laws, it does not expressly mention the LGPD.
Could someone from the Supabase team please clarify the following?
Does the current DPA apply to Brazilian customers and support compliance with the LGPD, even though the LGPD is not expressly listed?
Is there any Brazil-specific addendum or contractual mechanism for Brazilian customers, similar to the EU SCCs, the UK Addendum, or the Swiss Addendum?
Are the technical and organizational measures described in Schedule 1 (encryption, access controls, incident response, backups, etc.) intended to satisfy the information security requirements set out in Article 46 et seq. of the LGPD?
If we host our project in the São Paulo (sa-east-1) region, which subprocessors may still receive personal data outside Brazil? In other words, does hosting in São Paulo still involve international data transfers under the LGPD due to the subprocessors listed in Schedule 3?
We're looking for clarification to support our internal compliance assessment before deploying a production system that will process confidential client data.
Thank you in advance.
All reactions