Summary
A European enterprise engages a software consultancy. Part of the consultancy’s team works from Brazil, inside systems the enterprise hosts. That access is processing of personal data by a party in a third country, so the enterprise, as controller, needs a processor it can hold to GDPR Art. 28 and a valid basis for the transfer under Chapter V.
SolerWorks is that processor. It is a Brazilian company that contracts directly with the enterprise under an Art. 28 data processing agreement, binds every engineer before access is issued, and keeps the records the controller needs. The transfer rests on the European Commission’s adequacy decision for Brazil of January 2026 under Art. 45, with the Standard Contractual Clauses incorporated as a fallback.
Parties and roles
The enterprise
- Role under the GDPR
- Controller
- Role under the LGPD
- Controlador
- Contract with the enterprise
- Not applicable. It is the enterprise.
SolerWorks
- Role under the GDPR
- Processor, Art. 28
- Role under the LGPD
- Operador
- Contract with the enterprise
- Data processing agreement
The delivery partner
- Role under the GDPR
- None. It receives no personal data and holds no credentials in the controller’s environment.
- Role under the LGPD
- None
- Contract with the enterprise
- Commercial services agreement
Each engineer
- Role under the GDPR
- Person acting under the processor’s authority, Art. 29
- Role under the LGPD
- Acts on the controller’s instructions, Art. 39
- Contract with the enterprise
- None. Contracted by SolerWorks and bound by a signed security and privacy undertaking.
The commercial relationship and the data protection relationship are deliberately separate. The enterprise buys services from the delivery partner and pays the partner. It pays SolerWorks nothing. The full model is set out in how it works.
The processor agreement
The data processing agreement between the enterprise and SolerWorks carries each element Art. 28(3) requires.
Documented instructions. Processing only on the controller’s instructions, given through the controller’s own ticketing, work-management and access-control systems.
Confidentiality. Every engineer signs a security and privacy undertaking before the controller issues access.
Security. Technical and organizational measures are listed in an annex, each with the party that operates it.
Sub-processors. None at signature. Any addition needs the controller’s prior written consent and carries the same obligations.
Assistance. Data subject requests are forwarded to the controller. SolerWorks assists with Arts. 32 to 36, including impact assessments.
Breach notification. Notice to the controller without undue delay, within a fixed period that protects the controller’s 72-hour window under Art. 33(1).
Return and deletion. Access is revoked and SolerWorks certifies in writing that nothing is retained.
Audit. Information on request, starting with the completed security questionnaire, the personnel register and the Art. 30(2) record. On-site audit where that is not sufficient.
The transfer basis
Remote access from Brazil to personal data held in the European Economic Area is a transfer under Chapter V, even where no copy leaves the controller’s systems.
- Primary basis: Art. 45. In January 2026 the European Commission adopted an adequacy decision for Brazil. Transfers to recipients in Brazil covered by the decision need no further authorization or safeguard.
- Reciprocity. Brazil’s authority, the ANPD, recognized the European Union under the LGPD’s international transfer rules, so the flow is covered in both directions.
- Fallback: Art. 46(2)(c). The agreement incorporates the Standard Contractual Clauses of Implementing Decision (EU) 2021/914, Module Two, controller to processor. They apply automatically if the adequacy decision is repealed, suspended or annulled, or does not cover a given transfer.
- No onward transfer. SolerWorks does not transfer personal data to any other country without the controller’s prior written authorization.
An adequacy decision addresses the transfer. It does not replace the Art. 28 agreement. Both are needed, and this structure provides both.
Where personal data sits
All processing takes place inside the controller’s environment. Engineers reach it only with credentials the controller issues, through the virtual desktop, VPN or managed devices the controller designates. SolerWorks does not host, store, copy, back up or transmit the personal data, and engineers may not hold it on any local device.
Two consequences follow for your assessment. The controller keeps the means of control: provisioning, logging, monitoring and revocation. And detection of events inside the environment depends on the controller’s own monitoring, which the agreement records. The technical detail is in the architecture page.
Sub-processors
SolerWorks uses no hosting, storage, analytics or AI provider for the controller’s personal data. SolerWorks engages no sub-processor. The engineers are its own authorized personnel under Art. 29: SolerWorks contracts each of them in its own name and they act on its instructions. The delivery partner is outside the processing chain. It receives no personal data and holds no credentials in the controller’s environment. The current declaration and change notifications are in the trust center.
Questions counsel ask
Why is SolerWorks the processor and not the delivery partner?
The enterprise needs an accountable processor established where the work is done, with a named privacy contact, records and the capacity to sign and perform Art. 28 terms. Most consultancies do not maintain that in Brazil. SolerWorks does, and carries those obligations directly to the controller.
Does the structure create a joint controllership?
No. The controller alone determines purposes and means. SolerWorks acts only on documented instructions, and the partner does not process the data at all.
Are the engineers employees of SolerWorks?
SolerWorks is each engineer’s only contracting party. It engages them in its own name, as an employee or as an individual service provider, whichever Brazilian law requires for the role. That is why they act under SolerWorks’ authority under Art. 29 and are not sub-processors. The controller and the delivery partner direct the work itself: scope, priorities and output.
What happens if the adequacy decision falls away?
The Standard Contractual Clauses, Module Two, apply from that moment without a new signature. They are already incorporated by reference and completed in an annex.
How is the Art. 30 record handled?
SolerWorks keeps a processor record under Art. 30(2) and LGPD Art. 37 for each controller and engagement, and provides a copy on request.
Which law governs the agreement?
The law of the controller’s Member State, with its courts having jurisdiction, without prejudice to the rights of data subjects.
Documents on request
The data processing agreement and the engineer undertaking are shared with verified reviewers through the audit dossier request. The security pack, processing record, incident protocol, audit response cover and deletion certificate can be read now in the trust center.
This explainer describes how SolerWorks structures its service. It is general information for your counsel’s review, and the executed agreements govern.