Monthly Update – January 2026
Happy new year! Privacy is on more roadmaps than ever. We are receiving a steady stream of requests from teams looking for support as regulators and guidance keep evolving.
Here is the January snapshot: three developments you can act on now, plus what to watch next.
EU-Brazil data transfers just got easier
New SCCs: still delayed
What the EDPB has planned for 2026
1. EU-Brazil data transfers just got easier
What happened:
On 26 January 2026, the European Commission formally adopted its adequacy decision for Brazil (Implementing Decision (EU) 2026/179), recognising that Brazil's General Data Protection Law (the LGPD) provides a level of personal data protection essentially equivalent to the GDPR. Brazil simultaneously adopted its own adequacy decision recognising the EU, through Resolution CD/ANPD No. 32/2026. This makes the EU-Brazil relationship the first fully mutual adequacy recognition under the GDPR.
What this means for you:
No SCCs or transfer impact assessments are needed for in-scope transfers between the EU and Brazil. Data can flow freely in both directions, as long as the recipient is a Brazilian controller or processor subject to the LGPD.
If you work with teams, customer support, cloud services, or vendors in Brazil, this reduces friction and increases legal certainty for your cross-border operations.
You still need to record the transfer basis (reliance on adequacy), keep your Article 30 records up to date, and honour your other GDPR obligations. Adequacy is a transfer tool, not a blanket compliance exemption.
In plain terms: Brazil can now be treated similarly to an EEA destination from a transfer-mechanism perspective, while your general GDPR compliance duties continue to apply in full.
2. New SCCs: still delayed
What happened:
The European Commission has been working on a new set of standard contractual clauses (SCCs) designed for a specific gap in the current framework: situations where the data importer is based outside the EEA but is already directly subject to the GDPR under Article 3(2). Think of a non-EEA vendor that targets EU users and has appointed an EU Representative.
This exact scenario was not covered by the 2021 SCCs, which were drafted for importers who are not subject to the GDPR. The Commission originally planned to publish a draft in Q2 2025. As of mid-2026, those clauses have still not been published.
What this means for you:
The existing 2021 SCCs remain the main tool for transfers to third countries without an adequacy decision. They continue to be widely used and remain valid.
Do not assume that because a vendor claims GDPR applicability under Article 3(2), no transfer tool is needed. You still need a valid transfer mechanism in place.
If you rely on vendors outside the EEA who claim GDPR applicability under Article 3(2), flag those transfers now. When the Commission does publish the new clauses, you will want to be ready to update your agreements quickly.
For a broader overview of where EU-US data transfers currently stand, see our post: EU-US Data Transfers: Where Things Stand and What to Do Now.
3. What the EDPB has planned for 2026
What happened:
The EDPB signalled several new guidelines and updates for 2026. As of mid-2026, here is where things stand on the topics that matter most for startups and scale-ups:
AI Act and GDPR interplay: Joint guidelines with the Commission are in development, targeted for adoption in 2026.
DSA and GDPR interplay: Guidelines already adopted in 2025. Public consultation completed.
DMA and GDPR interplay: First set of joint guidelines adopted in 2025, with public consultation ongoing.
Consent or Pay models: Guidelines in development. This will be particularly relevant for businesses that rely on advertising or subscription models.
Scientific research: Draft guidelines published in April 2026 (Guidelines 1/2026), currently open for public consultation.
Anonymisation and pseudonymisation: Both sets of guidelines in active development. The EDPB has signalled these are a priority following the September 2025 CJEU ruling on pseudonymised data, which we covered in our September 2025 Monthly Update.
DPO guidelines: Long-awaited guidance on Data Protection Officers remains pending.
What this means for you:
If you work with AI, advertising, content moderation, or R&D, you will want to stay close to these developments. Several of these guidelines are likely to reshape what good practice looks like across the EU, before formal enforcement catches up.
That's a wrap!
From Brazil's adequacy decision to the still-pending SCC updates and the EDPB's busy guidance agenda, 2026 is already setting the direction for privacy compliance.
Whether you are transferring data internationally, preparing for AI-related requirements, or assessing how "consent or pay" models hold up under GDPR, staying on top of new developments now will make decisions easier and reduce rework later.
Need help translating these developments into practical next steps? Reach out and we will help you figure out what actually applies to your business.
We take great care in providing information to you, but please be aware of the fact that these blogposts can not be considered a substitute for professional legal advice, nor do they create an attorney-client relationship.