🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
PT · run data-protection-2026-08-04 v13-gdpri-1.0.0
content: ai_generated 9 sources retrieved model claude-sonnet-5 ·

Portugal

PT schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 30 claims · 9 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
30Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Lead Signal

The Portuguese Constitutional Court has confirmed the CNPD's €1.25 million fine against the Municipality of Lisbon, upholding findings that the municipality unlawfully processed protesters' sensitive personal data and transferred it to the Russian Embassy. The confirmation extends a multi-year CNPD enforcement escalation that began with a €400,000 fine against Hospital do Barreiro in 2018, Portugal's first GDPR sanction, for deficient health-data access controls and security measures. That escalation continued through a €4.3 million fine against the national statistics institute INE, where the CNPD found the agency's 2021 Census data protection impact assessment insufficient, breaching GDPR Article 35. The CNPD is also understood to have fined the Municipality of Setúbal €170,000 in 2022 for data protection violations. Judicial confirmation of the Lisbon fine strengthens the CNPD's fining authority going forward.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Fully GDPR-aligned; sole national DPA identified with statutory basis and active enforcement record.

Primary frameworkRegulation (EU) 2016/679 (GDPR) as implemented by Law No. 58/2019
Traffic-light rationale — GreenFully GDPR-aligned; sole national DPA identified with statutory basis and active enforcement record.

Sub-modules (5)

Regulator And AuthorityGreen

CNPD is confirmed as the national supervisory authority with a constitutional and statutory mandate to supervise data protection compliance.

Claims: CLM-PT-a3f8b2c1

Act And InstrumentsGreen

GDPR and Law No. 58/2019 are both fully applicable; CNPD has disapplied conflicting national provisions.

Claims: CLM-PT-b7e2d914, CLM-PT-c4f1a836

Material ScopeGreen

Material scope covers all processing activity carried out in Portugal irrespective of controller's public/private nature.

Claims: CLM-PT-d9e3b217

Territorial ScopeAmber

No Portugal-specific derogation from GDPR Art 3 territorial scope was identified in research; general GDPR extraterritorial rules apply.

Absence provenance: not recorded. Searched: Portugal GDPR territorial scope derogation Article 3.

Regulator Registration And FilingAmber

No general controller registration/filing regime found (GDPR abolished blanket notification); sector rules (e.g. video surveillance) impose specific restrictions rather than a filing obligation.

Claims: CLM-PT-e1a4c908

Category narrative59 words

Portugal operates a GDPR-aligned omnibus regime. The CNPD (Comissão Nacional de Proteção de Dados) is the sole national supervisory authority, and Law No. 58/2019 (the GDPR Implementation Law) sits alongside the directly-applicable GDPR. The CNPD has, via Decision 494/2019, disapplied several provisions of the national law it considers contrary to GDPR, giving the Regulation practical primacy in supervisory practice.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedDataGuidanceThe CNPD's general duty is to supervise and monitor compliance with data protection law with strict respect for the Constitution of the Portuguese Republic.
  2. ConfirmedDataGuidanceBoth the GDPR and Law No. 58/2019 (the GDPR Implementation Law) are fully applicable in Portugal.
  3. ConfirmedDataGuidanceIn September 2019 the CNPD approved Decision No. 494/2019, disapplying certain articles of the GDPR Implementation Law (including Art 28(3) on employee consent, Art 39(1) on fine determination, and Art 20(1) on right to information) to preserve GDPR primacy.
  4. ConfirmedIAPPThe scope of the GDPR Implementation Law encompasses all processing activity carried out in Portugal, regardless of the private or public nature of the controller, including processing for legal-obligation compliance or public-interest missions.
  5. ConfirmedIAPPVideo surveillance is restricted to protection of people and assets; cameras may not target public roads, client/worker-reserved interior areas, or capture ATM keypads.

#

GDPR bases apply directly; national elaborations exist for consent age and health/genetic data with active CNPD oversight.

Primary frameworkGDPR Arts 6-9; Law No. 58/2019
Traffic-light rationale — GreenGDPR bases apply directly; national elaborations exist for consent age and health/genetic data with active CNPD oversight.

Sub-modules (4)

Lawful BasesGreen

GDPR Art 6 bases apply; CNPD disapplied Law 58/2019 Art 28(3) on employee consent as GDPR-inconsistent.

Claims: CLM-PT-f2b5d613

Special CategoriesAmber

Law 58/2019 Art 29 imposes a data-subject notification duty whenever health or genetic data is accessed, going further than GDPR baseline and drawing CNPD/legal-commentary scrutiny.

Claims: CLM-PT-c9e2a536

Pseudonymisation And AnonymisationAmber

No Portugal-specific pseudonymisation/anonymisation safe-harbour beyond GDPR Recitals/Art 4(5) was identified.

Absence provenance: not recorded. Searched: Portugal CNPD pseudonymisation anonymisation guidance.

Category narrative28 words

Lawful processing follows GDPR Art 6 with Portugal-specific elaborations on consent age and special-category (health/genetic) data, some of which the CNPD itself has disapplied where conflicting with GDPR.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedDataGuidanceCNPD Decision 494/2019 disapplies Article 28(3) of the GDPR Implementation Law concerning employee consent to data processing as inconsistent with GDPR.
  2. ConfirmedIAPPThe age of digital consent in Portugal is 13 years old; processing personal data of a child under 13 is only lawful if a representative has consented through a means of secure authentication.
  3. ConfirmedEUR-LexGDPR Article 8 permits Member States to set the digital consent age between 13 and 16; Portugal has adopted the lower permissible bound of 13.
  4. ProbableDataGuidanceArticle 29 of the GDPR Implementation Law requires data controllers to notify data subjects whenever their health or genetic data is accessed, including access by occupational-medicine personnel.

#

Core GDPR rights operative with documented enforcement; some national qualifications on erasure/access timing.

Primary frameworkGDPR Arts 12-22; Law No. 58/2019
Traffic-light rationale — GreenCore GDPR rights operative with documented enforcement; some national qualifications on erasure/access timing.

Sub-modules (5)

Access RightGreen

CNPD has fined controllers (e.g., Hospital do Barreiro, €20,000 in 2019) for noncompliance with the right of access.

Claims: CLM-PT-d4f8b721

Rectification And ErasureAmber

The right to be forgotten under Portuguese law can only be exercised once the applicable retention period has elapsed.

Claims: CLM-PT-e7a1c384

Restriction And ObjectionAmber

Information/access rights under GDPR Arts 13-15 cannot be exercised where a statutory secrecy duty opposable to the data subject applies.

Claims: CLM-PT-f0b6d928

Data PortabilityAmber

No Portugal-specific derogation from GDPR Art 20 portability was identified.

Absence provenance: not recorded. Searched: Portugal data portability derogation Lei 58/2019.

Deadlines And Response WindowsAmber

No Portugal-specific deviation from the GDPR one-month (extendable) response window was identified in research.

Absence provenance: not recorded. Searched: Portugal CNPD statutory response deadline data subject request.

Category narrative40 words

Data subject rights follow the GDPR framework, with Portugal-specific limits: secrecy-duty exceptions to information/access rights, and a right-to-erasure that only becomes exercisable at the end of the applicable statutory retention period. Enforcement history shows the CNPD actively sanctioning access-right violations.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedIAPPIn 2019 the CNPD applied a fine of €20,000 for noncompliance with a data subject's right of access, alongside two €2,000 fines for GDPR Article 13 violations.
  2. ProbableIAPPUnder the GDPR Implementation Law, the right to be forgotten can only be exercised at the end of the applicable retention period.
  3. ProbableIAPPThe rights to information and access under GDPR Articles 13-15 cannot be exercised where the controller or processor is subject to a secrecy duty opposable to the data subject.

#

Strong enforcement record on DPIA/security failures evidences an operative, active accountability regime; ROPA and joint-controller specifics not independently confirmed.

Primary frameworkGDPR Arts 24-39; Law No. 58/2019
Traffic-light rationale — GreenStrong enforcement record on DPIA/security failures evidences an operative, active accountability regime; ROPA and joint-controller specifics not independently confirmed.

Sub-modules (7)

Accountability And DpiaGreen

CNPD fined the National Statistics Institute (INE) €4.3M in part for lack of a valid DPIA covering the 2021 Census.

Claims: CLM-PT-a1c3e567

Dpo RequirementsAmber

DPOs must be appointed on professional qualities/specialised knowledge and exercise functions with technical autonomy; CNPD has criticised national-law-added DPO functions as inconsistent with GDPR.

Claims: CLM-PT-b8d4f210

Ropa RequirementsAmber

No Portugal-specific ROPA elaboration beyond GDPR Art 30 was identified.

Absence provenance: not recorded. Searched: Portugal CNPD records of processing activities guidance.

Joint Controller ArrangementsAmber

No Portugal-specific joint-controller guidance beyond GDPR Art 26 was identified in research.

Absence provenance: not recorded. Searched: Portugal CNPD joint controller guidance.

Security MeasuresGreen

CNPD's first GDPR fine (Hospital do Barreiro, €400,000/€100,000 component under Art 32) targeted deficient technical and organisational security measures for health data access.

Claims: CLM-PT-c5e9a743

Breach NotificationAmber

General GDPR Arts 33-34 breach-notification timelines apply; no Portugal-specific deviation identified. CNPD has used Art 58(2)(j) corrective powers (data-flow suspension) in lieu of/alongside breach process in the INE case.

Claims: CLM-PT-d2f6b085

Retention And DisposalGreen

Retention is governed by sector-specific statutory periods or, absent one, by the period necessary for the processing purpose; social-security contribution data for retirement purposes may be retained indefinitely subject to adequate safeguards.

Claims: CLM-PT-e3a7c419

Category narrative43 words

Controller/processor duties track GDPR Arts 24-39. Enforcement history (INE Census 2021, Hospital do Barreiro) shows the CNPD actively pursuing DPIA, security-measures, and accountability failures. DPO appointment rules broadly track GDPR but the CNPD has criticized national-law additions to DPO functions as ultra vires.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedEuropean Data Protection BoardThe CNPD found the INE's DPIA for the 2021 Census 'limited in scope, and insufficient in relation to the data processing', breaching GDPR Art 35(1)-(3)(b), as part of a €4.3 million fine.
  2. ProbableIAPPThe DPO must be appointed based on professional qualities and specialised knowledge of data protection law and practice, and exercises the function with technical autonomy; the CNPD has noted that additional statutory DPO functions beyond GDPR constitute a violation of the Regulation.
  3. ConfirmedIAPPThe CNPD fined Hospital do Barreiro €100,000 under GDPR Article 32(1)(b) for failing to ensure confidentiality, integrity, availability and resilience of processing systems, including a lack of regular security testing.
  4. ConfirmedEuropean Data Protection BoardUsing Article 58(2)(j) GDPR corrective powers, the CNPD ordered the INE to suspend, within 12 hours, all data flows to the US and any other third country lacking an adequate level of protection.
  5. ProbableIAPPPersonal data relating to social security contributions for retirement purposes may be retained indefinitely, provided adequate technical and organisational measures guarantee data subject rights.

#

Transfer mechanisms are operative and enforced (SCC/TIA scrutiny confirmed), but PT has no independent adequacy-granting/receiving competence, and no PT-specific data-localisation mandate was found.

Primary frameworkGDPR Arts 44-49 (Chapter V)
Traffic-light rationale — AmberTransfer mechanisms are operative and enforced (SCC/TIA scrutiny confirmed), but PT has no independent adequacy-granting/receiving competence, and no PT-specific data-localisation mandate was found.

Sub-modules (6)

Transfer MechanismsAmber

SCCs, BCRs and Art 49 derogations are available per GDPR Chapter V; CNPD actively enforces against inadequate supplementary safeguards.

Claims: CLM-PT-f4b8d652

Adequacy ReceivedAmber

Adequacy is an EU-level competence, not a PT-national one; no PT-specific adequacy-received finding applies (would duplicate EU-level JID).

Absence provenance: not recorded. Searched: Portugal national adequacy decisions received.

Adequacy GrantedAmber

Adequacy-granting is an EU Commission competence; no separate PT-national adequacy-granted determination exists.

Absence provenance: not recorded. Searched: Portugal national adequacy decisions granted.

Sccs And BcrsRed

SCC use was confirmed in the INE case; the controller authorised SCC-based transfers to the US without adopting supplementary safeguards.

Claims: CLM-PT-a9c1e376

Transfer Impact AssessmentRed

CNPD enforcement in the INE case highlighted absence of a transfer impact assessment/supplementary measures for US-bound SCC transfers post-Schrems II.

Claims: CLM-PT-b0d5f218

Data LocalisationAmber

No general PT data-localisation mandate was identified; the CNPD's INE order was a case-specific corrective suspension, not a standing localisation law.

Absence provenance: not recorded. Searched: Portugal data localisation law personal data.

Category narrative63 words

As an EU Member State, Portugal's transfer regime operates within the GDPR Chapter V framework (adequacy decisions, SCCs, BCRs, derogations) administered at EU level; the CNPD applies these mechanisms directly, as shown in the INE case where SCC use without Schrems-II supplementary measures triggered enforcement. Adequacy decisions themselves are an EU (not PT-national) competence, so PT-specific 'received'/'granted' adequacy findings are not separately meaningful.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEuropean Data Protection BoardGDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, Art 49 derogations) apply directly in Portugal and are actively enforced by the CNPD.
  2. ConfirmedEuropean Data Protection BoardThe INE controller contractually authorised its processor to transfer data to the US under SCCs without adopting any supplementary measures, and permitted onward sub-processing in third countries lacking equivalent protection.
  3. ConfirmedEuropean Data Protection BoardThe CNPD identified the controller's lack of control over and knowledge of respondents' data once it entered the processor's network, and full processor control of encryption/decryption tools, as an aggravating factor in its transfer-related infringement finding.

#

Health and employment overlays are well evidenced; financial, credit, education and insurance sectoral overlays could not be confirmed and are flagged as gaps.

Primary frameworkGDPR; Law No. 58/2019; Decree-Law 125/2025 (NIS2); Law No. 59/2025
Traffic-light rationale — AmberHealth and employment overlays are well evidenced; financial, credit, education and insurance sectoral overlays could not be confirmed and are flagged as gaps.

Sub-modules (7)

Financial Sector OverlayRed

No PT-specific financial-sector DP overlay (banking secrecy vs GDPR interaction) was found in this research pass.

Absence provenance: not recorded. Searched: Portugal financial sector data protection overlay CNPD banking secrecy.

Health Sector OverlayGreen

Law 58/2019 Art 29 imposes health/genetic-data access-notification duties; historic CNPD enforcement (Hospital do Barreiro) targeted health-data security gaps.

Claims: CLM-PT-c9e2a536

Telecoms And EprivacyAmber

Telecoms/cyber overlay is evolving through NIS2 transposition and DSA implementation, both subject to CNPD opinions.

Claims: CLM-PT-c3e9a746

Employment DataAmber

Law 58/2019 Art 28(3) on employee consent to processing was disapplied by CNPD Decision 494/2019 as GDPR-inconsistent.

Claims: CLM-PT-f2b5d613

Credit And ScoringRed

No PT-specific credit-scoring DP overlay was found in this research pass.

Absence provenance: not recorded. Searched: Portugal credit scoring data protection CNPD.

EducationRed

No PT-specific education-sector DP overlay distinct from the general children's-online-safety bill was found.

Absence provenance: not recorded. Searched: Portugal education sector data protection CNPD schools.

InsuranceRed

No PT-specific insurance-sector DP overlay was found in this research pass.

Absence provenance: not recorded. Searched: Portugal insurance sector data protection CNPD.

Category narrative50 words

Sectoral overlays confirmed in research center on health data (statutory notification duties, historic hospital enforcement) and employment data (disapplied consent provision). Telecoms/cyber overlay is expanding via NIS2 transposition (Decree-Law 125/2025, Law 59/2025) and DSA implementation (ANACOM). Financial-sector, credit-scoring, education-sector and insurance-sector DP overlays were not evidenced in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableDataGuidancePortugal's Decree-Law 125/2025 transposes the NIS2 Directive, imposing new cybersecurity obligations on public and private entities, with CNCS and ANACOM given specific cybersecurity roles.

#

Only a general EU-level enforcement-coordination signal was confirmed; no PT-specific adtech instrument evidenced across any sub-module.

Primary frameworkePrivacy Directive 2002/58/EC; GDPR
Traffic-light rationale — RedOnly a general EU-level enforcement-coordination signal was confirmed; no PT-specific adtech instrument evidenced across any sub-module.

Sub-modules (6)

Cookies And TrackersAmber

The CNPD participates in the EDPB's 2026 Coordinated Enforcement Framework assessing GDPR transparency/information obligations, which bears on cookie/tracker consent practices, but no PT-specific cookie statute was found.

Claims: CLM-PT-d5f0b862

Dark PatternsRed

No PT-specific dark-pattern prohibition was found in this research pass.

Absence provenance: not recorded. Searched: Portugal CNPD dark patterns guidance.

Opt Out SignalsRed

No PT-specific recognition of Global Privacy Control or equivalent opt-out signals was found.

Absence provenance: not recorded. Searched: Portugal Global Privacy Control opt-out signal CNPD.

Clean Rooms And DcrRed

No PT-specific clean-room/data-collaboration-room rule was found.

Absence provenance: not recorded. Searched: Portugal data clean room CNPD guidance.

Cross Context AdvertisingRed

No PT-specific cross-context-advertising ('sale'/'share') rule analogous to US state law was found; general GDPR consent/legitimate-interest rules apply.

Absence provenance: not recorded. Searched: Portugal cross-context advertising data protection.

Direct MarketingRed

No PT-specific direct-marketing suppression/consent rule beyond general GDPR Art 21 objection right was found in this research pass.

Absence provenance: not recorded. Searched: Portugal direct marketing consent suppression list CNPD.

Category narrative51 words

No Portugal-specific cookie/tracker statute, dark-pattern prohibition, opt-out-signal recognition, clean-room rule, or cross-context-advertising rule distinct from general GDPR/ePrivacy was identified in this research pass. The 2026 EDPB Coordinated Enforcement Framework (CEF), in which the CNPD participates as one of 25 DPAs, targets GDPR transparency/information obligations relevant to commercial data practices including adtech.

No periodic updates recorded against this sub-brief.

Sources and claims (1)
  1. ProbableDataGuidanceThe EDPB launched the 2026 Coordinated Enforcement Framework (CEF) to assess compliance with GDPR transparency and information obligations, involving 25 DPAs including the CNPD in enforcement and fact-finding actions.

#

Institutional AI/biometric governance activity confirmed (working groups, national AI agenda) but no binding PT-specific ADM/biometric/genetic statute identified.

Primary frameworkGDPR Art 22; EU AI Act (interface)
Traffic-light rationale — AmberInstitutional AI/biometric governance activity confirmed (working groups, national AI agenda) but no binding PT-specific ADM/biometric/genetic statute identified.

Sub-modules (6)

Profiling RestrictionsAmber

No PT-specific profiling restriction beyond GDPR Art 22 was identified.

Absence provenance: not recorded. Searched: Portugal CNPD profiling restrictions guidance.

Automated Decision Making TransparencyAmber

No PT-specific ADM transparency/explanation-right instrument beyond GDPR Art 22 was identified.

Absence provenance: not recorded. Searched: Portugal automated decision making transparency CNPD.

Ai Risk AssessmentsAmber

Portugal's National AI Agenda focuses on infrastructure, innovation, talent and ethics, including AI research and public-sector training actions.

Claims: CLM-PT-e6a1c953

Biometric RegimeAmber

The CNPD's RLPD has formed internal working groups addressing biometrics, AI, video surveillance and data transfers, indicating active regulatory attention but no confirmed standalone biometric statute.

Claims: CLM-PT-f7b2d086

Genetic DataAmber

Law 58/2019 Art 29 imposes specific processing conditions and access-notification duties for genetic data.

Claims: CLM-PT-c9e2a536

State Surveillance CarveoutsRed

No PT-specific state-surveillance/national-security carve-out analysis was identified in this research pass.

Absence provenance: not recorded. Searched: Portugal national security data protection carveout CNPD.

Category narrative49 words

Portugal has no PT-specific Art 22 ADM/profiling statute or ADM-transparency instrument confirmed in research; however, the CNPD has formed internal working groups (RLPD) covering biometrics, AI, video surveillance and data transfers, and Portugal has launched a National AI Agenda. General GDPR Art 22 and EU AI Act interfaces apply.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ProbableDataGuidancePortugal's National AI Agenda focuses on infrastructure, innovation, talent, and ethics, with key actions to promote AI research, collaboration, and public-sector training.
  2. ProbableDataGuidanceThe CNPD's internal RLPD structure has formed working groups to address privacy issues in biometrics, AI, video surveillance, and data transfers.

#

Core age-of-consent rule is in force and confirmed; the more expansive children's-online-safety bill remains pending, and education-settings/dependent-adults sub-modules are unevidenced.

Primary frameworkGDPR Art 8; Law No. 58/2019; Bill 398/XVII/1 (pending)
Traffic-light rationale — AmberCore age-of-consent rule is in force and confirmed; the more expansive children's-online-safety bill remains pending, and education-settings/dependent-adults sub-modules are unevidenced.

Sub-modules (5)

Age VerificationAmber

The AEPD and CNPD have jointly called for urgent adoption of age-verification systems, aligned with data-protection rules, to prevent minors' access to adult content.

Claims: CLM-PT-a2c6e419

Minor Profiling BansAmber

Pending Bill 398/XVII/1 aims to protect children online by setting age limits and requiring parental consent; the CNPD has issued an opinion emphasizing GDPR compliance.

Claims: CLM-PT-b5d9f632

Education SettingsRed

No PT-specific education-settings children's-data rule was identified in this research pass.

Absence provenance: not recorded. Searched: Portugal education settings children data protection CNPD.

Dependent AdultsRed

No PT-specific dependent-adults (elderly/incapacitated) data-protection provision was identified in this research pass.

Absence provenance: not recorded. Searched: Portugal dependent adults data protection vulnerable groups CNPD.

Category narrative65 words

The digital consent age is 13, with secure-authentication verification for parental consent below that age. A pending Bill (398/XVII/1) seeks to strengthen online protection of minors by setting age limits and requiring parental consent, and has received a CNPD opinion emphasizing GDPR compliance. Iberian cooperation (AEPD-CNPD) has called for age-verification systems to prevent minors accessing adult content. No PT-specific education-settings or dependent-adults provisions were identified.

No periodic updates recorded against this sub-brief.

Sources and claims (2)
  1. ProbableAgencia Española de Protección de Datos (AEPD)The AEPD and CNPD called for the urgent adoption of measures enabling detection of problematic digital-device use and prevention of minors' access to adult content through age-verification systems aligned with data-protection regulations.
  2. ProbableDataGuidanceBill 398/XVII/1, aimed at protecting children online in Portugal, sets age limits and requires parental consent, with the CNPD issuing an opinion emphasizing GDPR compliance.

#

Sustained, escalating enforcement record (multiple seven-figure fines, judicial confirmation) demonstrates an active and empowered regulator.

Primary frameworkGDPR Arts 58, 77-84; Law No. 58/2019
Traffic-light rationale — GreenSustained, escalating enforcement record (multiple seven-figure fines, judicial confirmation) demonstrates an active and empowered regulator.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

CNPD exercises full Art 58(2) corrective powers (including emergency transfer-suspension orders) and can levy fines up to €20 million or 4% of global turnover for the most serious infringements.

Claims: CLM-PT-c8e3a175, CLM-PT-d2f6b085

Enforcement Activity IndexGreen

Multiple significant fines issued 2018-2026: Hospital do Barreiro (2018), INE Census (2022, €4.3M), Setúbal Municipality (2022, €170,000), Lisbon Municipality (€1.25M, Constitutional-Court-confirmed 2026).

Claims: CLM-PT-e9f4b287, CLM-PT-a1c3e567, CLM-PT-f6b3d924, CLM-PT-b4e8c051

Regulator Funding And CapacityRed

No specific CNPD funding/headcount data was identified in this research pass.

Absence provenance: not recorded. Searched: CNPD budget headcount funding capacity Portugal.

Collective Redress And Class ActionsRed

No PT-specific collective-redress/class-action mechanism for data protection was independently confirmed in this research pass.

Absence provenance: not recorded. Searched: Portugal collective redress class action data protection ação popular.

Private Right Of ActionAmber

GDPR Arts 77-79 and 82 grant data subjects a right to lodge complaints, seek judicial remedy, and claim compensation; no PT-specific expansion or restriction was identified.

Absence provenance: not recorded. Searched: Portugal private right of action data protection GDPR Article 82.

Recent Developments 180DGreen

Within the last 180 days: the Portuguese Constitutional Court confirmed the CNPD's €1.25M Lisbon Municipality fine; the EDPB launched its 2026 CEF (transparency/information obligations); CNPD issued an opinion on Bill 398/XVII/1 protecting minors online; NIS2 transposition continued via Decree-Law 125/2025 and Law 59/2025 with CNPD opinions on both the DSA and NIS2 implementation bills; CNPD signed cooperation instruments with Morocco's CNDP and with CNCS.

Claims: CLM-PT-b4e8c051, CLM-PT-d5f0b862, CLM-PT-b5d9f632, CLM-PT-c3e9a746

Category narrative99 words

The CNPD holds full GDPR Art 58 investigative/corrective powers and Art 83 fining authority (up to €20M / 4% global turnover for the most serious offences, per the national implementing law). Enforcement activity is well-documented: Hospital do Barreiro (€400,000 aggregate, 2018 - first PT GDPR fine), INE Census 2021 (€4.3M, 2022), Setúbal Municipality (€170,000, 2022), and Lisbon Municipality (€1.25M, for processing protestors' sensitive data transferred to the Russian Embassy), with the Constitutional Court confirming the Lisbon fine in early 2026. No PT-specific collective-redress/class-action mechanism was independently confirmed in this pass; GDPR Art 79/82 judicial-remedy and compensation rights apply generally.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedIAPPLarge companies may be subject, for very serious offences, to fines between €5,000 and €20 million or 4% of total worldwide annual turnover, whichever is higher, under the GDPR Implementation Law.
  2. ConfirmedIAPPIn 2018 the CNPD applied a major fine of €400,000 to Hospital do Barreiro, Portugal's first GDPR fine, for deficient health-data access controls and security measures.
  3. ProbableDataGuidanceThe CNPD fined the Municipality of Setúbal €170,000 in 2022 for data protection violations.
  4. ConfirmedDataGuidanceThe Portuguese Constitutional Court confirmed the CNPD's €1.25 million fine against the Municipality of Lisbon for GDPR violations related to the processing of protestors' sensitive personal data and its transfer to the Russian Embassy.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Portugal
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 30 claim(s), 9 source(s) in the cumulative register.