{
 "jurisdiction_id": "PT",
 "jurisdiction": "Portugal",
 "url": "https://dataprotection.gi/jurisdictions/portugal/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 30,
  "sub_modules": 57,
  "source_register": 9
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned; sole national DPA identified with statutory basis and active enforcement record.",
   "claims": [
    {
     "statement": "The CNPD's general duty is to supervise and monitor compliance with data protection law with strict respect for the Constitution of the Portuguese Republic.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Both the GDPR and Law No. 58/2019 (the GDPR Implementation Law) are fully applicable in Portugal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In September 2019 the CNPD approved Decision No. 494/2019, disapplying certain articles of the GDPR Implementation Law (including Art 28(3) on employee consent, Art 39(1) on fine determination, and Art 20(1) on right to information) to preserve GDPR primacy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The scope of the GDPR Implementation Law encompasses all processing activity carried out in Portugal, regardless of the private or public nature of the controller, including processing for legal-obligation compliance or public-interest missions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Video surveillance is restricted to protection of people and assets; cameras may not target public roads, client/worker-reserved interior areas, or capture ATM keypads.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "GDPR bases apply directly; national elaborations exist for consent age and health/genetic data with active CNPD oversight.",
   "claims": [
    {
     "statement": "CNPD Decision 494/2019 disapplies Article 28(3) of the GDPR Implementation Law concerning employee consent to data processing as inconsistent with GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The age of digital consent in Portugal is 13 years old; processing personal data of a child under 13 is only lawful if a representative has consented through a means of secure authentication.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 8 permits Member States to set the digital consent age between 13 and 16; Portugal has adopted the lower permissible bound of 13.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Article 29 of the GDPR Implementation Law requires data controllers to notify data subjects whenever their health or genetic data is accessed, including access by occupational-medicine personnel.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/portugal-data-subject-notification-obligations-and-surrounding-legal-issues",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Core GDPR rights operative with documented enforcement; some national qualifications on erasure/access timing.",
   "claims": [
    {
     "statement": "In 2019 the CNPD applied a fine of €20,000 for noncompliance with a data subject's right of access, alongside two €2,000 fines for GDPR Article 13 violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the GDPR Implementation Law, the right to be forgotten can only be exercised at the end of the applicable retention period.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The rights to information and access under GDPR Articles 13-15 cannot be exercised where the controller or processor is subject to a secrecy duty opposable to the data subject.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong enforcement record on DPIA/security failures evidences an operative, active accountability regime; ROPA and joint-controller specifics not independently confirmed.",
   "claims": [
    {
     "statement": "The CNPD found the INE's DPIA for the 2021 Census 'limited in scope, and insufficient in relation to the data processing', breaching GDPR Art 35(1)-(3)(b), as part of a €4.3 million fine.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/portuguese-supervisory-authority-fines-portuguese-national-statistics_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPO must be appointed based on professional qualities and specialised knowledge of data protection law and practice, and exercises the function with technical autonomy; the CNPD has noted that additional statutory DPO functions beyond GDPR constitute a violation of the Regulation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CNPD fined Hospital do Barreiro €100,000 under GDPR Article 32(1)(b) for failing to ensure confidentiality, integrity, availability and resilience of processing systems, including a lack of regular security testing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/first-gdpr-fine-in-portugal-issued-against-hospital-for-three-violations",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Using Article 58(2)(j) GDPR corrective powers, the CNPD ordered the INE to suspend, within 12 hours, all data flows to the US and any other third country lacking an adequate level of protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/portuguese-supervisory-authority-fines-portuguese-national-statistics_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Personal data relating to social security contributions for retirement purposes may be retained indefinitely, provided adequate technical and organisational measures guarantee data subject rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms are operative and enforced (SCC/TIA scrutiny confirmed), but PT has no independent adequacy-granting/receiving competence, and no PT-specific data-localisation mandate was found.",
   "claims": [
    {
     "statement": "GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art 49 derogations) apply directly in Portugal and are actively enforced by the CNPD.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/portuguese-supervisory-authority-fines-portuguese-national-statistics_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The INE controller contractually authorised its processor to transfer data to the US under SCCs without adopting any supplementary measures, and permitted onward sub-processing in third countries lacking equivalent protection.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/portuguese-supervisory-authority-fines-portuguese-national-statistics_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CNPD identified the controller's lack of control over and knowledge of respondents' data once it entered the processor's network, and full processor control of encryption/decryption tools, as an aggravating factor in its transfer-related infringement finding.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2022/portuguese-supervisory-authority-fines-portuguese-national-statistics_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Health and employment overlays are well evidenced; financial, credit, education and insurance sectoral overlays could not be confirmed and are flagged as gaps.",
   "claims": [
    {
     "statement": "Portugal's Decree-Law 125/2025 transposes the NIS2 Directive, imposing new cybersecurity obligations on public and private entities, with CNCS and ANACOM given specific cybersecurity roles.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "red",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Only a general EU-level enforcement-coordination signal was confirmed; no PT-specific adtech instrument evidenced across any sub-module.",
   "claims": [
    {
     "statement": "The EDPB launched the 2026 Coordinated Enforcement Framework (CEF) to assess compliance with GDPR transparency and information obligations, involving 25 DPAs including the CNPD in enforcement and fact-finding actions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Institutional AI/biometric governance activity confirmed (working groups, national AI agenda) but no binding PT-specific ADM/biometric/genetic statute identified.",
   "claims": [
    {
     "statement": "Portugal's National AI Agenda focuses on infrastructure, innovation, talent, and ethics, with key actions to promote AI research, collaboration, and public-sector training.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CNPD's internal RLPD structure has formed working groups to address privacy issues in biometrics, AI, video surveillance, and data transfers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core age-of-consent rule is in force and confirmed; the more expansive children's-online-safety bill remains pending, and education-settings/dependent-adults sub-modules are unevidenced.",
   "claims": [
    {
     "statement": "The AEPD and CNPD called for the urgent adoption of measures enabling detection of problematic digital-device use and prevention of minors' access to adult content through age-verification systems aligned with data-protection regulations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "Agencia Española de Protección de Datos (AEPD)",
     "source_url": "https://www.aepd.es/en/press-and-communication/press-releases/aepd-and-cnpd-express-concern-about-increase-digital-violence-and-its-consequences",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Bill 398/XVII/1, aimed at protecting children online in Portugal, sets age limits and requires parental consent, with the CNPD issuing an opinion emphasizing GDPR compliance.",
     "regulatory_stage": "proposed",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/6244",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/portugal/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Sustained, escalating enforcement record (multiple seven-figure fines, judicial confirmation) demonstrates an active and empowered regulator.",
   "claims": [
    {
     "statement": "Large companies may be subject, for very serious offences, to fines between €5,000 and €20 million or 4% of total worldwide annual turnover, whichever is higher, under the GDPR Implementation Law.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In 2018 the CNPD applied a major fine of €400,000 to Hospital do Barreiro, Portugal's first GDPR fine, for deficient health-data access controls and security measures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/portugals-data-protection-law-went-into-effect",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The CNPD fined the Municipality of Setúbal €170,000 in 2022 for data protection violations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/portugal-cnpd-fines-municipality-setubal-eu170000",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Portuguese Constitutional Court confirmed the CNPD's €1.25 million fine against the Municipality of Lisbon for GDPR violations related to the processing of protestors' sensitive personal data and its transfer to the Russian Embassy.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/portugal-constitutional-court-confirms-cnpds-decision",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}