News and developments
The EU's New Anti-Corruption Directive: The Potential Exposure for Brazilian Companies
The regulatory environment for combating corruption in the European Union (“EU”) has shifted to a more stringent standard, requiring companies to strengthen their governance and compliance structures. The enactment of Directive (EU) 2026/1021 (the “Directive”) unifies the treatment of the matter across the EU and increases companies' exposure to sanctions.
The Directive establishes a common framework for corruption offenses, in both the public and private sectors. Although addressed to the Member States, which must transpose it into national law by June 1st, 2028, it defines the offenses and the applicable levels of sanctions, giving companies time to prepare before the national rules take effect.
For companies based outside the EU, including Brazilian companies, the potential extraterritorial reach of the Directive deserves closer attention than it has so far received. There are two distinct fact patterns common to Brazilian companies with a European footprint: direct operations in the EU market, and corporate groups where a Brazilian entity sits downstream of a European parent. Both cases could potentially trigger EU jurisdiction, and Brazilian companies must be ready.
Main aspects of the Directive
The Directive requires Member States to criminalize, in a harmonized manner, a common set of corruption offenses. These include active and passive corruption, as well as conduct that not all legal systems treat as a standalone offense, such as illicit enrichment resulting from corruption and trading in influence. The Directive covers corruption in both the public and private sectors.
The Directive is not limited to the criminal sphere. On the preventive and institutional level, Member States are required to adopt a national anti-corruption strategy, establish specialized bodies for prevention and enforcement, carry out periodic sector-based risk assessments, and strengthen whistleblower protection. Although addressed to the Member States, these measures are likely to shape the enforcement environment in which companies operate, requiring an effective commitment to detecting and investigating the offenses established by the Directive.
The Directive sets out two layers of jurisdiction, and the distinction between them is highly relevant. The first layer is mandatory: every Member State must claim jurisdiction where the offense was committed, wholly or partly, in its territory, or where the offender is one of its nationals (Article 18(1)). This is the conventional territorial and nationality basis. It is not, by itself, the source of exposure that Brazilian companies should be tracking.
The second layer is where the real extension lies – though, at present, it is optional. A Member State may extend its jurisdiction to offenses committed outside its territory, and must notify the Commission when it does so. Two scenarios matter for legal entities (Article 18(2)):
a. the offense benefits a legal person established in that State's territory; or
b. the offense benefits a legal person in connection with business carried out, in whole or in part, on that State's territory.
These two scenarios capture two different exposure profiles relevant to Brazilian companies.
The first applies to Brazilian companies operating in the European market. Where a Brazilian company does business – including distribution, franchising, licensing, or direct sales, that is carried out in whole or in part on the territory – in a Member State that has adopted this basis, an act of corruption benefiting that business could fall within that State's jurisdiction. This holds regardless of where the corrupt act itself took place.
The second carries a greater potential impact, and applies to Brazilian subsidiaries of European parent companies. This is the less obvious exposure – the one most likely to be missed by a risk assessment built around the subsidiary's own jurisdiction.
Where a corrupt act occurs entirely in Brazil and benefits the Brazilian subsidiary directly, the analysis does not necessarily stop there. If that benefit is understood to flow, through the group's commercial and financial structure, to the European parent, the Directive opens a further possibility: a Member State that has adopted this basis could assert jurisdiction over the offense, even though no part of the conduct occurred on EU soil.
The Directive does not expressly resolve whether “benefit” extends to indirect benefit flowing through a corporate group, or is limited to a direct benefit to the EU-established entity itself. This is an interpretation that a Member State could reasonably advance, and companies should treat it as a risk to monitor.
What turns this jurisdictional possibility into substantive exposure is a separate provision, which allows a legal entity to be held liable where a lack of supervision or control by its leadership enabled someone under its authority to commit an offense for the company's benefit (Article 13(2)). In practice, a European parent can be held liable if oversight failures at headquarters level are shown to have enabled the Brazilian subsidiary's conduct. A group with weak visibility over compliance controls at the subsidiary level could be exposed.
Because this provision will be adopted at each Member State's discretion, the practical consequence is that exposure might not be uniform across the EU – it will depend on which Member States the group's operations, distribution, or corporate structure touch, and on which of those States choose the extended jurisdictional basis. A risk mapping exercise built only around where the company is formally established would likely miss this.
Corporate liability and sanctions
The Directive strengthens the liability regime for legal entities within the European Union. To that end, Member States must ensure that a company can be held liable when an offense is committed for its benefit by someone in a leading position. Liability also extends to cases in which unlawful conduct, carried out by a subordinate, was made possible by a failure of supervision or control on the part of management – the same mechanism, discussed above, that can connect a European parent's oversight of a Brazilian subsidiary to its own criminal exposure.
Fines are the main financial sanction applicable to legal entities and may reach significant levels. For the most serious offenses, the fines imposed may reach 5% of the company's worldwide turnover or a fixed amount of up to EUR 40 million, depending on the criterion adopted by each Member State. This ceiling applies to corruption in the public and private sectors and to misappropriation, while trading in influence, obstruction of justice, and enrichment resulting from corruption offenses are subject to a limit of 3% of worldwide turnover or EUR 24 million.
In addition to monetary sanctions, the Directive provides for measures that can affect a company's own operational capacity, such as exclusion from public financing, participation in public tenders (debarment), and the revocation of licenses and authorizations.
Conclusion
The Directive raises the exposure of companies operating in the European market, particularly through two developments: the potential for extended jurisdiction, which can reach conduct with no physical connection to EU territory, and the liability of the legal entity when the offense results from a failure of internal supervision.
For Brazilian companies, this means that the relevant question is no longer only “do we operate in the EU?”, but “does our business touch EU territory in a way covered by the new Directive?” or “does our corporate structure include a European entity whose benefit could be implicated?” In addition, for groups structured around a European parent with Brazilian operations, the question becomes whether headquarters-level oversight of the subsidiary's compliance controls is documented well enough to withstand scrutiny under the Directive.
The periodic review of compliance programs takes on particular importance in this scenario and now needs to extend beyond the company's own jurisdiction, to map where, within the group, EU-connected exposure actually sits. This assessment may be conducted internally or through the engagement of an external law firm, an option that adds an independent analysis of the program's effectiveness.
The transposition deadline of June 1, 2028 gives companies operating in Brazil, and corporate groups with a European parent, time to carry out this alignment. During this period, companies should consider reviewing risk mappings in light of the broadened range of offenses and jurisdictional bases; strengthening internal supervision and control mechanisms across the corporate group; and monitoring the national transposition processes in the jurisdictions where the group operates or does business.
Authors: Salim Saud, Caroline Rosa, Leonardo Kozlowski and Sofia Maddi.
