Electronic Transactions Law, Protection of Personal Electronic Data
Lei n.º 3/2017, de 9 de Janeiro, arts. 63(1)-(2), (5), 64, 65(1), (3) (dever de protecção de dados)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Keep any personal data you collect, process, or disclose electronically accurate, complete, and up to date.
- Specify the purpose for collecting personal data and your identity as the processor before collecting it, and limit any later use to that stated purpose.
- Protect personal data against risk, loss, unauthorised access, destruction, unauthorised use, modification, or disclosure.
- Do not access another party's personal data in a computerised archive, file, record, or database, and do not transfer personal data between information systems belonging to distinct services or institutions, without a legal instrument or judicial decision authorising it.
- Designate one or more individuals responsible for compliance with this chapter's data protection principles.
- Remain responsible for personal data in your possession or custody, including data you transferred to a third party for processing.
What it reaches
Obligation class
Disclosure, Security, Access restriction, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 2 applies the Law to natural and legal persons, public or private, that apply information and communication technologies in their activities, including electronic or commercial transactions and electronic government. Article 63(1) requires any data controller who electronically collects, processes, or discloses personal data to keep it accurate, complete, and up to date.
Article 63(2) requires the objectives for which personal data are collected and the data processor's identity to be specified before collection, and limits later use to those stated objectives. Article 63(5) requires the data processor to protect personal data against risk, loss, unauthorised access, destruction, use, modification, or disclosure.
Article 63(7) applies this chapter without prejudice to the article 40 rules on electronic advertising and marketing and to any specific legislation on electronic data protection, and article 63(8) exempts electronic collection, processing, or disclosure of personal data for journalism, artistic or literary expression, or when decided by the competent authorities to safeguard public security and national defence.
Article 64 bars accessing computerised archives, files, records, or databases to learn a third party's personal data, and bars transferring personal data between information systems belonging to distinct services or institutions, except where established by legal instrument or judicial decision. Article 65(1) requires the data processor to designate one or more individuals responsible for compliance with this chapter's principles.
Article 65(3) makes the data processor responsible for personal information in its possession or custody, including information transferred to a third party for processing, subject to the same article 40, journalism, artistic-expression, and public-security exemptions as article 63.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreach
Read the law
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.