Skip to the content
Global Data RulesData governance rules, country by country

Portugal

Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.

The answer

Depends on your industryWork: HighEnforcement: Active

Portugal follows the normal European rule: personal data may leave once you have the right paperwork in place. Two Portuguese walls override that. Online betting data must sit inside Portugal for ten years. Tax and invoicing records must stay in Portugal or the rest of Europe unless the tax office gives you written permission first. The privacy regulator is busy but almost never fines.

Data governance in Portugal

The eight things that decide how you handle data about people in Portugal. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Europe's General Data Protection Regulation reaches any company that offers goods or services to people in Portugal, even with no office and no staff here. There is no revenue or headcount threshold to hide behind. If your company has no base anywhere in Europe you must appoint a representative inside Europe, though that person does not have to be in Portugal. Portugal's own version of the law tried to add its own rule about who is covered, and the regulator publicly refuses to apply that part.

High confidenceBloc rulesNational rulesAppoint a local representative

Where the data is allowed to live

In general yes, with paperwork, exactly as anywhere else in Europe. Storage outside Portugal but inside Europe is free. Two Portuguese industries break that pattern. Online gambling firms must install the system that registers Portuguese players inside Portugal and must store ten years of betting data inside Portugal. Every business in Portugal must keep its tax and invoicing records in Portugal or the rest of Europe unless the tax office approves a move further afield.

High confidenceDepends on your industryA copy must stayYes, with paperworkOnline gamingFinanceHealth and social careTelecomsGovernment

Sending data out of the country

For personal data leaving Europe, Portugal uses the standard European toolkit: send it to an approved country, or sign the European Commission's standard contract, or use approved group-wide rules, and write down why the destination is safe. For tax and invoicing archives the extra step is Portuguese: you ask the tax office for permission before the archive or the billing software moves outside Europe. Portugal's regulator has already fined a public body for relying on the standard contract alone.

High confidenceAllowlistApproval each timeOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesGovernment sign-off neededPut a transfer safeguard in place

The regulator, and whether it actually acts

The National Data Protection Commission enforces the privacy rules. It is real, staffed and working: in 2025 it opened 3,201 new files, took 262 final decisions and handled 472 reported data breaches. But it issued only two fines that year, worth 47,000 euro in total (about 51,000 United States dollars), down from 90 fines the year before, and its own annual report blames a shortage of staff. It also runs with five of its seven seats filled. Other regulators police the sector rules and are fully operational.

High confidenceActiveOrder to stopRegulator

How long you must keep it — and when to delete it

There is a floor and a ceiling and they pull in opposite directions. The floor: tax books, invoices and supporting documents must be kept for ten calendar years, and online betting data for ten years inside Portugal. The ceiling: Europe's rule says delete personal data once the purpose is spent, and the telecoms law says connection data must be erased or made anonymous as soon as it is no longer needed to carry the call or message. Where the two collide, the specific legal duty to keep a record wins for that record only.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

If something goes wrong

Count at least two clocks, and three if you run critical infrastructure. Privacy breaches go to the National Data Protection Commission within 72 hours, and to affected people without undue delay when the risk to them is high. Telecoms providers have their own European duty to report within 24 hours. Under Portugal's new cybersecurity law, important and essential organisations warn the National Cybersecurity Centre early, then file a fuller report, on the pattern set by Europe's network security directive.

Medium confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What catches people out

Five things that cost people their weekend. A child can consent from 13 in Portugal, not 16. Every look at a patient's health record must be traceable and the patient must be told. Misusing or peeking at personal data is a crime here, not just a fine, and it attaches to the individual. Your invoicing software must be on the tax office's approved list, and moving it or the archive outside Europe needs permission first. And nine chunks of the Portuguese privacy statute are printed in the law but the regulator refuses to apply them.

High confidenceGet a parent's consent for childrenAppoint a data protection officerRegister or notifyKeep logsCriminal liabilityUnenforceable

What's changing next

Three things land in the next year or so. Public bodies must sort their data and systems by importance under the sovereign cloud plan, with the sorting due by the middle of 2027. The new cybersecurity regime is being switched on, with registration and incident duties for many more organisations. And the privacy regulator is hiring, so the near-zero fine count of 2025 is unlikely to last. Separately, Europe's rule that cloud switching must be free of charge starts in January 2027.

Medium confidenceProposedPartly in forceProve the data stays under local controlMake switching cloud provider possible

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries3 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Regime Jurídico dos Jogos e Apostas Online, aprovado pelo Decreto-Lei n.º 66/2015, de 29 de abril

Act of parliament · Decreto-Lei n.º 66/2015, artigos 32.º e 34.º

In forceA copy must stay

Portugal's hardest storage rule. A licensed online gambling operator must install the system that registers Portuguese players inside Portugal, store ten years of betting data inside Portugal, and keep every part of the gaming system somewhere the regulator can walk in or log in at any moment.

In force since 28 June 2015

Enforced by Gambling Regulation and Inspection Service

Transfer model: No restriction

High confidence
Telecoms

Lei n.º 41/2004, de 18 de agosto — tratamento de dados pessoais e proteção da privacidade no setor das comunicações eletrónicas

Act of parliament · Lei n.º 41/2004, artigos 3.º, 4.º e 6.º

In forceYes, with paperwork

Portugal's telecoms privacy law contains no storage location rule. It works the other way: connection data must be deleted or anonymised as soon as it is no longer needed to carry the communication, and kept for billing only while the bill can still be disputed.

In force since 19 August 2004

Enforced by National Communications Authority

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence
Telecoms

Lei n.º 32/2008, de 17 de julho — conservação de dados gerados no contexto da oferta de serviços de comunicações eletrónicas

Act of parliament · Lei n.º 32/2008, artigos 4.º, 6.º e 9.º; Acórdão do Tribunal Constitucional n.º 268/2022

UnenforceableYes, with paperwork

The law telling telephone and internet providers to keep everyone's connection records is still printed in the statute book but cannot be enforced: the Constitutional Court struck the core provisions down in April 2022 and the regulator ordered the stored data deleted within 72 hours. A 2024 statute replaced blanket retention with judge-ordered preservation in serious criminal cases.

In force since 15 August 2008

Enforced by National Data Protection Commission

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Lei n.º 58/2019, de 8 de agosto — assegura a execução, na ordem jurídica nacional, do Regulamento Geral sobre a Proteção de Dados

Act of parliament · Lei n.º 58/2019

In forceYes, with paperwork

Portugal's implementation of the European rules. It adds a low age of digital consent, strong secrecy and access-notification duties for health data, and criminal offences that attach to individuals. Several of its provisions are printed in the law but not applied by the regulator.

In force since 9 August 2019

Enforced by National Data Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Deliberação/2019/494 da Comissão Nacional de Proteção de Dados — desaplicação de normas da Lei n.º 58/2019

Regulator guideline · Deliberação/2019/494

UnenforceableYes, with paperwork

The regulator announced in September 2019 that it will not apply nine sets of provisions of the national privacy statute, including its scope rule and parts of its fining rules, because European law takes precedence. They are still printed in the statute, so a text search of Portuguese law returns rules that are not enforced.

In force since 3 September 2019

Enforced by National Data Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Medium confidence

Código do IVA, artigo 52.º, e Decreto-Lei n.º 28/2019, de 15 de fevereiro (processamento de faturas e arquivo de documentos)

Act of parliament · CIVA art. 52; Decreto-Lei n.º 28/2019, arts. 5, 19 to 21

In forceYes, with paperwork

Every business in Portugal must keep ten years of invoices and accounting records, on premises in Portugal unless it is an electronic archive with guaranteed online access. Archives may sit anywhere in Europe, but going outside Europe needs written permission from the tax office first, and so does putting your billing software there.

In force since 16 February 2019But only enforceable from 1 January 2020

Enforced by Tax and Customs Authority

Transfer model: Approval each time · Accepted routes: Government sign-off needed

High confidence

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Regulamento Geral sobre a Proteção de Dados — Regulamento (UE) 2016/679

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

Europe's general data protection law. It never says where data must be stored. It says what you must have in place before personal data leaves Europe, and it reaches companies outside Europe that target people in Portugal.

In force since 24 May 2016But only enforceable from 25 May 2018

Enforced by National Data Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Who you would hear from

  • Comissão Nacional de Proteção de Dados

    General data protection law across the private and public sectors

    Fully operational and publishing continuously through July 2026. Chaired by Paula Cristina Meira Lourenço, but running with five of seven seats filled since two members left in August and September 2025 and were not replaced. Staff rose from 28 to 36 in 2025 and the commission itself calls that insufficient. In 2025 it opened 3,201 files, issued 262 final decisions and 267 draft accusations, handled 472 breach notifications, started 88 administrative-offence proceedings and imposed just 2 fines totalling 47,000 euro, against 90 fines the previous year. Expect corrective orders more often than fines.

  • Autoridade Tributária e Aduaneira

    Invoicing software certification, archive location authorisations, ten-year record keeping

    Runs the electronic authorisation process for archives and invoicing systems located outside the European Union and publishes the list of certified invoicing programs.

  • Serviço de Regulação e Inspeção de Jogos, Turismo de Portugal

    Online gambling licensing, technical system certification and inspection

    Licenses operators, certifies and homologates gaming systems, audits them periodically and publishes consolidated legislation. Holds a statutory right of entry and remote access to every component of a licensed operator's gaming system.

  • Autoridade Nacional de Comunicações

    Electronic communications, including the sector privacy statute and digital services coordination

    Active; met the data protection regulator in July 2026 on implementation of the European digital services rules. Its site blocks automated fetching, so link checks may fail even where the address is correct.

  • Centro Nacional de Cibersegurança

    Cyber incident reporting, registration of essential and important entities, sovereign cloud classification methodology

    Operational, but its website sits behind bot protection that defeated every automated fetch attempt in this run, so its published guidance could not be quoted directly.

  • Banco de Portugal

    Banking and payments supervision, outsourcing registers and notifications

    Operational and issuing notices, including one in December 2025 on registering and reporting outsourcing arrangements. Its site is behind bot protection and could not be opened in this run, so its content is reported at medium confidence.

  • Autoridade de Supervisão de Seguros e Fundos de Pensões

    Insurance and pension funds, including outsourcing and cloud use by insurers

    Operational. Its outsourcing and cloud rules were not separately verified in this run; no localisation requirement was found.

  • Comissão do Mercado de Valores Mobiliários

    Securities markets and investment firms

    Operational. Since January 2025 the operational resilience rules for financial firms come mainly from European law. No Portuguese localisation requirement was found.

  • Entidade Reguladora da Saúde

    Health service providers, including patients' data protection rights

    Publishes guidance on patients' data protection rights, including the duty to notify a patient of every access to their record.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact entry-into-force date, registration deadlines, incident-reporting deadlines and fine levels of the new national cybersecurity regime published on 4 December 2025

    The official gazette site serves its texts only to browsers running JavaScript and the National Cybersecurity Centre's site is behind bot protection. Both defeated every fetch attempt on 18 August 2026. The deadlines given follow the European directive's pattern, not a verified Portuguese text.

  • The content of the Bank of Portugal notice of December 2025 on outsourcing registers and reporting, and whether it says anything about data location

    The bank's own website returned a bot-protection challenge to every request. We treat it as a reporting and register duty only. No banking localisation rule is asserted.

  • Whether the insurance and securities regulators impose cloud or outsourcing location conditions

    Not separately verified in this run. Their rules were not opened on their own sites, so the statement that no localisation exists in insurance and securities is a not-found result, not a proven negative.

  • Whether the consolidated online gambling law published by the regulator, whose text is dated 31 March 2020, reflects amendments made after that date

    The regulator publishes this consolidation itself and lists no newer version, but we could not confirm from the gazette that Articles 32 and 34 are unamended since 2020.

  • Whether the regulator's 2019 decision not to apply nine sets of provisions of the national privacy statute is still being applied in 2026

    The decision is published and has never been withdrawn as far as we can see, and Parliament has not amended the provisions. We found no 2025 or 2026 statement restating it, so this is inference from silence.

  • The fine counts per year read from a chart in the regulator's 2025 annual report (90 in 2024, 71, 60, 23 and 15 in earlier years)

    The 2025 figure of two fines worth 47,000 euro is stated in words in the report. The earlier yearly figures come from a bar chart whose labels extract imperfectly from the PDF, so the year-to-number mapping is our reading.

  • That no localisation rule exists for health records, education data, mapping and geospatial data or defence data in Portugal

    Searched on 18 August 2026 and none found on official sites. This is an absence of evidence. Health carries strong secrecy, need-to-know and access-notification duties instead.

  • The exact period during which a telecoms bill can be contested, which sets the ceiling on keeping billing data

    The statute defines the ceiling by reference to that period rather than by a number of months, and we did not verify the underlying consumer-law period against an official source.

  • Whether the two vacant seats on the data protection commission were filled between 24 March 2026 and 18 August 2026

    The vacancy is evidenced up to the date its annual report was approved. We cannot prove a negative for the months since.

  • Whether the 24-hour telecoms breach-reporting deadline applies in Portugal exactly as set out in the European sector rules

    Asserted from the European instrument for that sector, not from a Portuguese regulator page opened in this run.

60-day cadence. Portugal has four switches that can flip without a long consultation: a new attempt at general telecoms data retention, tightening of the tax office's third-country authorisation practice, the gambling regulator's access power used as a location power, and the sovereign cloud classification hardening into procurement-level localisation. The privacy regulator's fine volume is also expected to rebound as it staffs up, which changes the risk picture without any change in the law.

Freshness and refresh

Freshness

Checked yesterday — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Put this next to another country

Portugal versus

Compare

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.