CNPD Deliberacao 2019/494, Disapplication of Lei 58/2019 Provisions in Portugal
CNPD Deliberacao n.o 2019/494, de 3 de setembro de 2019; Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018, effective 3 September 2019.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect the CNPD to decline to apply Lei 58/2019's own restriction on employee consent (Article 28(3)(a)) in its enforcement practice, treating the General Data Protection Regulation (GDPR) Article 6 and 9(2)(a) consent baseline as controlling instead for a person in Portugal.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Lei 58/2019's Seccao III (Articles 46-54) creates a series of criminal offenses distinct from CNPD's administrative fines: using personal data incompatibly with its collection purpose, unauthorized access, diverting data, falsifying or destroying data, inserting false data, breaching a duty of secrecy, and disobeying a CNPD order, generally punishable by imprisonment up to one year or a fine up to 120 day-fines, doubled (up to two years or 240 day-fines) where the data is a special category under GDPR Articles 9-10, and up to four years for falsifying or destroying data causing particularly serious damage (Article 49).
Penalty structure
Lei 58/2019 Articles 37-38 had attempted a lower, differentiated national fine scale by legal-person status: very serious infringements from EUR 5,000 to 20,000,000 or 4% of turnover for a large company, EUR 2,000 to 2,000,000 or 4% for an SME, and EUR 1,000 to 500,000 for a natural person, roughly halved for serious infringements, plus a mandatory prior CNPD warning (Article 39(3)) before a non-intentional infringement could be fined at all. CNPD Deliberacao 2019/494 disapplied these national provisions as incompatible with GDPR primacy, so the undiluted GDPR Article 83(5) ceiling recorded here controls in practice, with a lower EUR 10,000,000/2% tier (Article 83(4)) for a narrower set of controller and processor obligations.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
CNPD, Comissao Nacional de Protecao de Dados
Enforcement record
CNPD's own Relatorio de Atividades 2025 (approved 24 March 2026): in 2025 the CNPD applied 2 fines totaling EUR 47,000, against a public entity (local administration) and a private entity (unauthorized SPAM advertising). The report's own multi-year fine-count chart shows a sharp decline (90 fines in 2023, 23 in 2024, 2 in 2025), which the report itself attributes largely to insufficient staff resources for handling contraordenacao proceedings; the CNPD instituted 88 such proceedings in 2025 that could have produced up to 90 fines had they concluded that year. median_fine and p90_fine are omitted given only 2 fines in the period.
- As of
- 2 September 2026
- Trend
- Falling
- Currency
- EUR
- Source link
- https://www.cnpd.pt/media/v50frkwy/relatorio-atividades-de-2025.pdf
- Fines per year
- 47,000
- Actions per year
- 2
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The CNPD is Portugal's supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. In Deliberacao n.o 2019/494 of 3 September 2019, the CNPD announced it will not apply a defined set of Lei 58/2019's own provisions in its enforcement practice, reasoning that an EU regulation has direct effect and primacy over conflicting national law under Article 288 TFEU and settled CJEU case law.
Three independent secondary paraphrases of the deliberation (Lexology, Garrigues, Recording Law) agree the CNPD disapplies Article 28(3)(a) (restricting employee consent to processing that would grant a legal or economic advantage) and a penalties-framework provision in the Article 37 to 39 range (differentiated fine ceilings by company size, and a prior-warning requirement for negligent infringements); the three sources diverge on the rest of the disapplied list (Articles 61(2), 62(2), and 20(1) are each named by only some of the three), so only what all three corroborate is recorded here, without asserting a complete article list.
The deliberation's own primary text has not been located in readable form. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsprocesses_biometricsprocesses_voice
Read the law
Three independent secondary paraphrases of CNPD Deliberacao 2019/494 (Lexology, Garrigues, Recording Law)
the primary Portuguese-language deliberation text is not reproduced
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.