Law No. 133/V/2001 on the Protection of Personal Data
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Process personal data lawfully and in good faith, collect it only for specified, explicit and legitimate purposes, keep it accurate and proportionate to those purposes, and do not keep it identifiable for longer than the purposes require.
- Process personal data only where the data subject has unambiguously consented or where processing is necessary for a contract, a legal obligation, the data subject's vital interests, a public interest task, or your or a third party's legitimate interest that does not override the data subject's rights.
- Obtain the CNPD's authorisation under article 23, or point to a legal provision, before combining personal data from different filing systems, and ensure any combination serves a legitimate purpose, avoids discrimination, and carries adequate security measures.
- Implement technical and organisational measures adequate to the risk to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, and choose a processor offering sufficient security guarantees under a written contract that binds them to your instructions.
- Do not process personal data you access in the course of your duties except on the controller's instructions, unless the law requires otherwise, and keep personal data confidential as a matter of professional secrecy, both during and after your role ends.
- Notify the CNPD before carrying out an automated personal data processing operation, and obtain the CNPD's prior authorisation for processing of sensitive data, credit and solvency data, combined data across filing systems, or data reused for a new purpose.
- Publish, through the CNPD's public register, or make available to anyone who asks, the particulars of a processing operation not covered by a legal provision.
What it reaches
Obligation class
Consent, Disclosure, Security, Licensing
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 6 requires personal data to be processed lawfully and in good faith, collected for specific, explicit and legitimate purposes, kept adequate, relevant and not excessive for those purposes, kept accurate and up to date, and kept identifiable for no longer than those purposes require, with the CNPD able to authorise longer retention for historical, statistical or scientific purposes.
Article 7 permits processing only where the data subject has unambiguously consented or where processing is necessary for a contract, a legal obligation, the data subject's vital interests, a public interest task, or the controller's or a third party's legitimate interest that does not override the data subject's rights.
Article 10 subjects combining personal data held in different filing systems, where no legal provision already covers it, to the authorisation of the supervisory authority under article 23, and requires the combination to serve a legitimate purpose, avoid discrimination, and carry adequate security measures.
Article 15 requires the controller to implement technical and organisational measures appropriate to the risk of accidental or unlawful destruction, loss, alteration, unauthorised disclosure or access, to choose a processor offering sufficient security guarantees, and to bind that processor by a written contract limiting it to the controller's instructions.
Article 17 bars anyone with access to personal data under the controller's or processor's authority from processing it except on the controller's instructions, unless the law requires otherwise, and Article 18 binds a controller and anyone who learns of the data in the course of their functions to professional secrecy, including after those functions end.
Article 23 requires the controller to notify the CNPD before carrying out an automated personal data processing operation, and Article 24 additionally requires the CNPD's prior authorisation for processing of the most sensitive data categories, credit and solvency data, combined data across filing systems, or data reused for a new purpose.
Article 27 requires processing that must be authorised or notified to appear in a CNPD register open to consultation, and requires a controller exempt from notification to make the article 26 particulars available to anyone who asks.
Existing manual and automated filing systems had six months from the law's entry into force to come into conformity with its sensitive data and rights provisions, and the law itself entered into force thirty days after its publication, following approval by the Assembleia Nacional on 20 December 2000 and enactment by the President on 10 January 2001.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Official English translation of Law No. 133/V/2001 of 22 January
on the Protection of Individuals with Regard to the Processing of Personal Data, published by the Comissão Nacional de Protecção de Dados (CNPD)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.