Law / Portugal

Portugal

European Union law applies in Portugal Portugal is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Portugal, described on this page below, applies here too.

14 of 16 named instruments researched to a stage, across five of the six areas of law we track: 14 in force. As of 15 September 2026.

When they take effect13 of 14 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 3 instruments (3 in force) 2019: 3 instruments (3 in force) 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 0 instruments 2023: 3 instruments (3 in force) 2024: 0 instruments 2025: 0 instruments 2026: 2 instruments (2 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 3
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 2

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 in force

Research summary (145 words)

Portugal's private-sector regime is the General Data Protection Regulation (GDPR) plus Lei n.o 58/2019, de 8 de agosto (Lei de Execucao do RGPD), in effect from its 8 August 2019 publication. Portugal is the genuinely divergent jurisdiction: the CNPD, in Deliberacao n.o 2019/494 of 3 September 2019, announced it will decline to apply a set of Lei 58/2019's own provisions in its enforcement decisions on EU-law-primacy grounds, a supervisory stance rather than a repeal, and one that does not bind the courts.

Three independent secondary sources corroborate the disapplication mechanism and two specific provisions (the Article 28(3)(a) employee-consent restriction and part of the Article 37 to 39 penalties framework); they diverge on the rest of the list, so only what is corroborated is recorded here. As at 24 August 2026; no Portuguese court ruling on the deliberation's own validity has been located, and later amendment is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification in Portugal

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the CNPD without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Portugal, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Lei 58/2019 derogation from this timeline is identified.

What it requires

Comprehensive regime

Lei n.o 58/2019, Portuguese GDPR Implementation Law (Lei de Execução do RGPD)

Lei n.o 58/2019, de 8 de agostoDiario da Republica Eletronico, dre.pt, official text listing

In force since 8 August 2019. Binds public and private bodies.

What this law does

Portugal's private-sector regime is the General Data Protection Regulation (GDPR) plus Lei n.o 58/2019, de 8 de agosto (Lei de Execucao do RGPD, GDPR Implementation Law), in effect from its 8 August 2019 publication.

Portugal is genuinely divergent here: the CNPD, in Deliberacao n.o 2019/494 of 3 September 2019, announced it would decline to apply a set of Lei 58/2019's own provisions in its enforcement decisions, on the ground that those provisions restrict the GDPR's direct effect and full effectiveness contrary to the primacy of EU law.

This is not a repeal (the CNPD has no constitutional-court power to strike a provision down) and it does not bind the courts, which remain free to reach their own view if a disapplied provision is litigated; it is a supervisory authority's own prospective enforcement stance, published for transparency.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Portugal

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Portugal outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Lei 58/2019 derogation broadening or narrowing this is identified.

What it requires

Data subject rights

GDPR Article 22 and Lei 58/2019, Automated Decisions in Portugal

Regulation (EU) 2016/679, Art. 22; Lei n.o 58/2019, de 8 de agostoOfficial Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018, effective 8 August 2019. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Lei 58/2019 without narrowing per its own summary.

One of the CNPD's disapplied provisions, Lei 58/2019 Article 20(1) (restricting access rights where a confidentiality or secrecy duty applies against the data subject), sits in this dimension: only one of the three secondary sources names Article 20(1) among the disapplied provisions, so that specific finding is not settled here, and the GDPR Article 12 to 23 baseline is recorded as controlling.

What it requires

Enforcement supervision

CNPD Deliberacao 2019/494, Disapplication of Lei 58/2019 Provisions in Portugal

CNPD Deliberacao n.o 2019/494, de 3 de setembro de 2019; Regulation (EU) 2016/679, Arts. 82-83Three independent secondary paraphrases of CNPD Deliberacao 2019/494 (Lexology, Garrigues, Recording Law)

In force since 25 May 2018, effective 3 September 2019. Binds public and private bodies.

What this law does

The CNPD is Portugal's supervisory authority and enforces General Data Protection Regulation (GDPR) Article 83 fines. In Deliberacao n.o 2019/494 of 3 September 2019, the CNPD announced it will not apply a defined set of Lei 58/2019's own provisions in its enforcement practice, reasoning that an EU regulation has direct effect and primacy over conflicting national law under Article 288 TFEU and settled CJEU case law.

Three independent secondary paraphrases of the deliberation (Lexology, Garrigues, Recording Law) agree the CNPD disapplies Article 28(3)(a) (restricting employee consent to processing that would grant a legal or economic advantage) and a penalties-framework provision in the Article 37 to 39 range (differentiated fine ceilings by company size, and a prior-warning requirement for negligent infringements); the three sources diverge on the rest of the disapplied list (Articles 61(2), 62(2), and 20(1) are each named by only some of the three), so only what all three corroborate is recorded here, without asserting a complete article list.

The deliberation's own primary text has not been located in readable form. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Portugal

Regulation (EU) 2016/679, Art. 9Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Lei 58/2019 provision adding a distinct national biometric-specific derogation is identified; Lei 58/2019's own additions are concentrated in automated-decision rights and the CNPD's disapplication practice rather than a biometric-specific chapter.

No Portugal-specific voiceprint or faceprint case, deliberation, or regulatory guidance was located; this is recorded as nothing located, not as a confirmed absence in Portuguese law.

What it requires

Scraping law3 instruments, 3 in force

Research summary (233 words)

Portugal's computer-misuse law is Lei n.º 109/2009, de 15 de setembro (Lei do Cibercrime), whose Article 6.º punishes unauthorized access to a computer system with imprisonment up to one year or a fine, rising to imprisonment up to three years where a security control was bypassed and to imprisonment from one to five years where the access revealed a trade or industrial secret or produced a considerably high financial benefit.

Portugal's sui generis database right sits in a separate statute from the copyright code, Decreto-Lei n.º 122/2000, de 4 de julho, transposing the EU Database Directive (96/9/EC); unauthorized commercial extraction, communication, or making available of a protected database is a criminal offense under its Article 11.º, carrying imprisonment up to three years or a fine.

Both a general copyright text-and-data-mining exception and a widening of that database-right offense were added by Decreto-Lei n.º 47/2023, de 19 de junho, Portugal's transposition of the EU Digital Single Market Copyright Directive (2019/790): reproduction of a legally accessible work for text and data mining is permitted unless the rights holder has expressly reserved that use through a machine-readable or other adequate means, and a research organization or cultural-heritage institution carries out text and data mining for scientific research without that opt-out limiting it.

No Portugal-specific statute or case law addressing terms-of-service enforceability, robots.txt legal weight, or an unfair-competition doctrine distinct from these three instruments is identified here.

Computer misuse

Lei do Cibercrime Article 6, Illegal Access to a Computer System

Lei n.º 109/2009, de 15 de setembro (Lei do Cibercrime), art. 6.ºDiário da República Eletrónico, dre.pt, official ELI text of Lei n.º 109/2009

In force since 15 October 2009. Binds public and private bodies.

What this law does

Whoever, without legal permission or authorization from the system's owner or another rights holder, accesses a computer system in any way is punished with imprisonment up to one year or a fine up to 120 day-fines.

The penalty rises to imprisonment up to three years or a fine where the access was achieved by breaching a security control, and to imprisonment from one to five years where the access revealed a trade or industrial secret or confidential data protected by law, or produced a considerably high financial benefit.

Producing, selling, distributing, or introducing into a computer system a device, program, executable instruction set, code, or other computer data intended to carry out that unauthorized access is punished under the same penalty.

What it requires

Copyright and text and data mining (TDM)

CDADC Text and Data Mining Exception

CDADC art. 75.º(2)(v)-(w), Text and Data Mining Exception, as amended by Decreto-Lei n.º 47/2023, de 19 de junho, art. 3.ºDiário da República Eletrónico, dre.pt, official ELI text of Decreto-Lei n.º 47/2023

In force since 4 July 2023. Binds public and private bodies.

What this law does

Reproducing a legally accessible protected work for text and data mining is a permitted exception under CDADC Article 75.º(2)(w), unless the rights holder has expressly reserved that use through a machine-readable means, such as optical reading of content made available to the public online, or another adequate means.

A separate, unconditional exception in Article 75.º(2)(v) covers a research organization or a cultural-heritage institution carrying out text and data mining on legally accessible works for scientific research. Article 75.º(3) defines text and data mining as any automated analytical technique aimed at analyzing text and data in digital form to produce information such as patterns, trends, and correlations.

What it requires

Database right

Sui Generis Database Right, Decreto-Lei n.º 122/2000

Decreto-Lei n.º 122/2000, de 4 de julho, arts. 4.º, 11.º e 12.º, art. 11.º as amended by Decreto-Lei n.º 47/2023, de 19 de junho, art. 4.ºDiário da República Eletrónico

In force. Binds public and private bodies.

What this law does

A database whose selection or arrangement of contents is an intellectual creation is protected by copyright under Article 4.º(1) of Decreto-Lei n.º 122/2000, Portugal's transposition of the EU Database Directive (96/9/EC).

A separate sui generis right in Article 12.º gives the database's maker the right to authorize or prohibit extraction or re-utilization of the whole or a substantial part of its contents where obtaining, verifying, or presenting that content represented a substantial investment.

Reproducing, disclosing, communicating, or making available to the public, for direct or indirect commercial purposes, a database protected under Article 4.º(1) or Article 12.º without authorization is a criminal offense under Article 11.º, carrying imprisonment up to three years or a fine; Decreto-Lei n.º 47/2023 widened that offense in 2023 to also cover the sui generis right and to add making available to the public as a covered act, where the original 2000 text reached only a creative, copyright-protected database.

The decree does not state a general commencement day for the diploma; its Article 21.º backdates copyright protection under the diploma to 1 January 1998 but expressly excludes Article 11.º from that backdating, and no other commencement date for Article 11.º is stated in the text, though Decreto-Lei n.º 47/2023 cites the statute in its current wording as still applicable.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (482 words)

Portugal completed its NIS2 transposition on 3 April 2026. The Regime Jurídico da Cibersegurança (RJC), approved by Decreto-Lei n.º 125/2025, de 4 de dezembro, transposes Directive (EU) 2022/2555 and, by its own Article 9(b), repeals the predecessor Regime Jurídico da Segurança do Ciberespaço (RJSC), approved by Lei n.º 46/2018, de 13 de agosto, which had transposed the original NIS Directive.

Decreto-Lei n.º 125/2025 was approved by the Council of Ministers on 5 November 2025, promulgated on 28 November 2025, published on 4 December 2025, and entered into force 120 days later, on 3 April 2026 (Article 11), so it now binds.

The RJC reaches 17 sectors plus a significant part of the Administração Pública, expanding well beyond the critical-infrastructure sectors the RJSC already covered to add IT service management, wastewater, space, manufacturing, postal and courier services, waste management, chemical production, food production and distribution, digital-service provision and research; it excludes national-security, public-security, defence and intelligence-service entities from its scope (Articles 2 and 6).

It classifies an entity as essential or important by sector type (Annexes I and II) and by whether it exceeds the EU medium-enterprise thresholds of Commission Recommendation 2003/361/EC, though a qualified trust service provider, a top-level-domain name registry and a DNS service provider are essential regardless of size (Article 6).

Annex II's digital-services sector names an online marketplace provider, an online search engine provider and a social-networking-services-platform provider expressly; Annex I's digital-infrastructure sector separately and expressly names a cloud-computing-service provider, a data-centre-service provider, a content-delivery-network provider, a trust-service provider and a top-level-domain registry, each reached at the medium-enterprise size threshold or above except the categories the Act designates as essential regardless of size.

The wider sector classes the RJC designates (energy, transport, banking, health, drinking water, public administration and the rest of the Annexes) are a designation and sector class no activity in this vocabulary expresses, so only the digital-provider slice is flagged here.

No Portuguese instrument reviewed here imposes a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; the CNCS's own certification framework, the Quadro Nacional de Certificação da Cibersegurança, is a voluntary scheme under Regulation (EU) 2019/881 rather than a market-placement duty.

Portugal has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and Lei n.º 58/2019's breach-notification duties to the Comissão Nacional de Proteção de Dados (CNPD), both of which sit in the privacy topic rather than here.

The electronic qualification platform through which a covered entity registers (Article 8(7)) awaits its own CNCS regulation and was not yet available as of the CNCS's own 23 July 2026 update to its RJC guidance page, so the registration mechanics, though not the substantive Article 26 to 29 and Article 40 to 44 duties themselves, remain unsettled.

Sector security regimes

Regime Jurídico da Cibersegurança, Cybersecurity Risk-Management Measures and Governance

Decreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 25.º a 29.ºConsolidated text

In force 6 months, effective 3 April 2026. Binds public and private bodies.

What this law does

Article 26 requires an essential or important entity to take appropriate technical, operational and organisational measures to manage the risks to the network and information systems it uses in its operations, and to prevent or minimise an incident's impact on the recipients of its services and on other services, at a security level proportionate to the entity's risk exposure, size and the likelihood and severity of an incident, following a risk matrix the Centro Nacional de Cibersegurança (CNCS) defines and may update.

Article 27 lists the areas those measures must cover: incident handling; business continuity, including backup management, disaster recovery and crisis management; supply-chain security; security in the acquisition, development and maintenance of network and information systems, including vulnerability handling and disclosure; policies to assess the effectiveness of the entity's risk-management measures; basic cyber-hygiene practices and staff training, including for members of top management bodies; cryptography and, where applicable, encryption policy; personnel security, access control and asset management; and multi-factor or continuous authentication, secure communications and secure emergency communication systems.

Article 25 requires the entity's management, direction and administration body to approve the Article 27 measures, supervise their application, ensure compliance with the supervision and enforcement measures of Chapter VI, and ensure regular cybersecurity training; a member of that body may be held liable, by act or omission, on a finding of intent (dolo) or gross negligence (culpa grave), for an infringement under this Decree-Law, and that responsibility may not be delegated except to another member of the same body.

This Decree-Law, Decreto-Lei n.º 125/2025, transposes NIS2 Directive Articles 20 and 21 and, by its own Article 9(b), repeals the Regime Jurídico da Segurança do Ciberespaço approved by Lei n.º 46/2018, de 13 de agosto, the predecessor NIS1 transposition.

What it requires

Vulnerability and incident reporting

Regime Jurídico da Cibersegurança, Significant-Incident Reporting Obligations

Decreto-Lei n.º 125/2025, de 4 de dezembro, Artigos 40.º a 44.ºConsolidated text

In force 6 months, effective 3 April 2026. Binds public and private bodies.

What this law does

Article 40 requires an essential, important or relevant public entity to notify the competent cybersecurity authority of any significant incident, weighed against the number of users affected, the incident's duration, the severity of the service disruption and its economic and social impact.

Article 41 sets three notification types per incident: an initial notification, a notification that the significant impact has ended, and a final report, with an entity whose incident resolves within two hours of detection required only to submit the end-of-impact notification. Article 42 requires the initial notification without undue delay and within 24 hours of concluding a significant incident exists or may exist.

Where necessary, Article 42 also requires an update within 72 hours of that determination, providing an initial assessment of the incident's severity and impact. Article 43 requires the end-of-significant-impact notification without undue delay and within 24 hours of the impact ending.

Article 44 requires the final report within 30 working days of the end-of-impact notification, describing the incident, its impact, the mitigating measures taken and the residual impact still present; an entity may also be asked for an interim report.

This clock differs from the calendar-day early-warning and one-calendar-month pattern used elsewhere in the corpus: Portugal's 30-day final-report deadline runs in working days from the end-of-impact notification rather than in calendar days from the initial notification. This Decree-Law transposes NIS2 Directive Article 23 and, by its own Article 9(b), repeals the Regime Jurídico da Segurança do Ciberespaço approved by Lei n.º 46/2018, de 13 de agosto, the predecessor NIS1 transposition.

What it requires

Age gating law1 instrument, 1 in force

Research summary (146 words)

Portugal has no dedicated adult-content age-verification statute, social-media minor-access restriction, or app-store age-verification requirement on the books as of the date below.

Its principal age-related duty is a design-code style obligation on a video-sharing platform provider: Lei n.º 27/2007, de 30 de julho (Lei da Televisão e dos Serviços Audiovisuais a Pedido), as amended by Lei n.º 74/2020, de 19 de novembro, which transposed the EU Audiovisual Media Services Directive (2018/1808), requires the provider to create and manage a system to verify the age of the platform's users and audience, among other measures to protect children and young people from content that could harm their physical, mental, or moral development.

Breach of that duty is punishable by an administrative fine (coima) of 75,000 to 375,000 euros, and the ERC (Entidade Reguladora para a Comunicação Social) assesses the adequacy and effectiveness of the measures a provider adopts.

Age-appropriate design code

Video-Sharing Platform Age Verification Duty

Lei n.º 27/2007 de 30 de julho (Lei da Televisão e dos Serviços Audiovisuais a Pedido), art. 69.º-C, alínea e), added by Lei n.º 74/2020, de 19 de novembro, art. 3.ºDiário da República Eletrónico

In force since 17 February 2021. Binds private bodies.

What this law does

A video-sharing platform provider must, among other adequate measures, create and manage systems to verify the age of the platform's users and audience, contributing to the protection of children and young people from content that could harm their physical, mental, or moral development, under Article 69.º-C, alínea e), of the Lei da Televisão e dos Serviços Audiovisuais a Pedido.

The same article requires a parental-control system under the end user's own control, and a transparent, easy-to-use, and effective complaint-handling procedure. Breach of Article 69.º-C is punishable by an administrative fine (coima) of 75,000 to 375,000 euros under Article 77.º(1) of the same Act. The ERC (Entidade Reguladora para a Comunicação Social) assesses the adequacy and effectiveness of the measures a provider adopts, under Article 69.º-D.

Note and primary source

News aggregation law2 instruments, 2 in force

Research summary (177 words)

Portugal created a press-publisher neighbouring right and adopted the EU's text-and-data-mining exception through Decreto-Lei n.º 47/2023, de 19 de junho, its transposition of the EU Digital Single Market Copyright Directive (2019/790).

CDADC Article 188.º-A gives a press publisher established in an EU member state the exclusive right to authorize online reproduction, communication to the public, or making available of its press publications, excluding private non-commercial use by individuals, hyperlinking, and the use of isolated terms or very short extracts; the right lapses two years after first publication and does not reach a publication first published before 6 June 2019.

CDADC Article 75.º(2)(w) permits text and data mining of a legally accessible work unless the rights holder has expressly reserved that use through a machine-readable or other adequate means, with an unconditional exception at Article 75.º(2)(v) for a research organization or cultural-heritage institution.

No compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from the CDADC's own copyright and unfair-competition provisions, is identified here.

Press publishers' right

CDADC Article 188.º-A, Press Publisher Online Rights

CDADC art. 188.º-A, Press Publisher Online Rights, added by Decreto-Lei n.º 47/2023, de 19 de junho, art. 5.ºDiário da República Eletrónico, dre.pt, official ELI text of Decreto-Lei n.º 47/2023

In force since 4 July 2023. Binds private bodies.

What this law does

A press publisher established in an EU member state holds the exclusive right to authorize, itself or through its representatives, an information-society service provider's reproduction, communication to the public, or making available of the whole or part of its press publications online, per CDADC Article 188.º-A(1).

That right does not reach a private, non-commercial use by an individual, the establishment of a hyperlink, or the use of isolated terms or very short extracts of a press publication, per Article 188.º-A(2). The right lapses two years after the press publication's first publication, per Article 183.º(6), and does not apply to a press publication first published before 6 June 2019, per the decree's own Article 14.º.

Note and primary source

Text and data mining (TDM) opt-out

CDADC Text and Data Mining Opt-Out for News Aggregation

CDADC art. 75.º(2)(v)-(w) Text and Data Mining Opt-Out for News Aggregation, as amended by Decreto-Lei n.º 47/2023, de 19 de junho, art. 3.ºDiário da República Eletrónico, dre.pt, official ELI text of Decreto-Lei n.º 47/2023

In force since 4 July 2023. Binds public and private bodies.

What this law does

Reproducing a legally accessible protected work, including a press publication, for text and data mining is a permitted exception under CDADC Article 75.º(2)(w), unless the rights holder has expressly reserved that use through a machine-readable means, such as optical reading of content made available to the public online, or another adequate means.

A separate, unconditional exception in Article 75.º(2)(v) covers a research organization or a cultural-heritage institution carrying out text and data mining on legally accessible works for scientific research, without the opt-out that limits the general exception.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.