Portugal
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Portugal — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send Portuguese data abroad once you have the right paperwork. That is the normal European rule. Two Portuguese rules override it. Online betting data must sit inside Portugal for ten years. Tax and invoicing records must stay in Portugal or the rest of Europe. To move them further, you need written permission from the tax office first. The privacy regulator is busy but almost never fines.
Data governance in Portugal
The eight things that decide how you handle data about people in Portugal. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes, it reaches you even with no office in Portugal. Europe's General Data Protection Regulation covers any company that offers goods or services to people in Portugal. There is no revenue or staff-count threshold. If your company has no base anywhere in Europe, you must appoint a representative inside Europe. That person does not have to be in Portugal. Portugal's own version of the law tried to add its own rule about who is covered. The regulator publicly refuses to apply that part.
- What you have to do here:
- Appoint a representative
The Portuguese law is Lei n.º 58/2019 of 8 August 2019. Its Article 2 says the law covers any use of data in Portugal, whoever is doing it. It also says it covers companies based outside the European Union that offer goods or services to people in Portugal. In Deliberação/2019/494 of 3 September 2019 the national regulator decided not to apply Article 2(1) and 2(2) in the cases it handles. Its reason was that Article 3 of the European Regulation already sets who is covered. A member state cannot narrow it, widen it or restate it. So who is covered is decided by Article 3 of the Regulation. When you need a European representative is decided by Article 27 of the Regulation. The Portuguese text decides neither. Health regulator guidance repeats the same Portuguese wording. That is why reading the Portuguese law on its own will mislead you.
Sources
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2019/494 — Desaplicação, na apreciação de casos concretos, de algumas normas da Lei 58/2019
cnpd.pt
“Desaplicação ... do artigo 2.º, n.os 1 e 2, do artigo 20.º, n.º 1, do artigo 23.º, do artigo 28.º, n.º 3, alínea a), do artigo 37.º, n.º 1, alíneas a), h) e k), e n.º 2, do artigo 38.º, n.º 1, alínea b), e n.º 2, do artigo 39.º, n.os 1 e 3, do artigo 61.º, n.º 2, e do artigo 62.º, n.º 2, da Lei 58/2019.”
Link checked 18 August 2026
- Official sourceEntidade Reguladora da SaúdeDireito à proteção de dados pessoais, à reserva da vida privada — guia sobre os direitos dos utentes
ers.pt
“A 8 de agosto, foi publicada a Lei n.º 58/2019, que assegura a execução, na ordem jurídica nacional, do RGPD, aplicando-se aos tratamentos de dados pessoais realizados no território nacional.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
Yes, with paperwork, just like anywhere else in Europe. Storing data elsewhere in Europe carries no extra rules. Two Portuguese industries break that pattern. Online gambling firms must install the system that registers Portuguese players inside Portugal. They must also store ten years of betting data inside Portugal. Every business in Portugal must keep its tax and invoicing records in Portugal or the rest of Europe. To move them further away, you need the tax office's approval.
Industry by industry, checked on 18 August 2026. ONLINE GAMBLING has the strictest rule in the country. The Legal Framework for Online Games and Betting covers licensed operators. They must install the entry-and-registration system in Portugal. They must store gambling activity data in Portugal for ten years. Every part of the technical gaming system must sit in premises the regulator can enter at any time. The regulator must also be able to reach it remotely from its own offices, wherever the equipment is. Rating: a copy must stay in the country TAX, INVOICING AND ACCOUNTING RECORDS is a real rule that people miss. Books, records and supporting documents must be kept for ten calendar years at premises inside Portugal. An electronic archive escapes that only if you guarantee complete online access to the data. An electronic archive may sit anywhere in the European Union without asking. Outside the European Union you need the tax office's permission first. Putting the invoicing software itself outside the European Union needs a second, separate permission. You must also give the tax office an account that can query the live system in real time from terminals inside Portugal. Rating: data can leave only if conditions are met, with government permission decided case by case for countries outside the European Union. BANKING, PAYMENTS, INSURANCE AND SECURITIES: we found no Portuguese rule keeping data in the country, checked 18 August 2026. These firms follow the European Union's Digital Operational Resilience Act, which started on 17 January 2025. It makes you say where data is handled and keep audit and exit rights. It sets no storage location. The Banco de Portugal published a notice in December 2025 about registering and reporting outsourcing deals. We could not open the bank's own site to check the text. We treat it as a reporting duty, not a location duty. Rating: data can leave only if conditions are met, low-to-medium confidence. HEALTH: we found no rule keeping data in the country, checked 18 August 2026. Portugal adds secrecy and traceability instead. Health and genetic data may only be handled on a need-to-know basis. The people handling it must be bound by professional secrecy. The patient must be told about every access to their record. Rating: data can leave only if conditions are met TELECOMS: we found no rule keeping data in the country, checked 18 August 2026. The duty runs the other way. Connection data must be erased or made anonymous once it is no longer needed to carry the communication. GOVERNMENT: we found no binding rule keeping data in the country. The National Sovereign Cloud Plan was approved on 14 May 2026. It sorts public data and work by importance and attaches security rules to each level. It does not name a country. Public bodies must classify their work by 30 June 2027. Rating: data can leave only if conditions are met today. Buying rules are the obvious route to something stricter later. EDUCATION, DEFENCE, MAPPING AND GEOSPATIAL DATA: we found no rule, checked 18 August 2026, medium confidence. We did not find a mapping or aerial-imagery storage restriction on an official site. At European level, Regulation (EU) 2018/1807 stops member states from making storage location rules for data that is not about people. The only exception is public security. That is one reason Portugal's rules are drawn around gambling supervision and tax inspection instead.
Sources
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalDecreto-Lei n.º 66/2015 — Regime Jurídico dos Jogos e Apostas Online, consolidated text published by the gambling regulator, Article 34
srij.turismodeportugal.pt
“c) Assegurar que a infraestrutura de entrada e registo se encontra instalada em território nacional e contém toda a informação sobre todas as operações relacionadas com a atividade de jogos e apostas online; d) Armazenar em território nacional os dados relacionados com a atividade de jogos e apostas online pelo período de 10 anos.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraCódigo do Imposto sobre o Valor Acrescentado, Article 52 — obligation to archive and keep records
info.portaldasfinancas.gov.pt
“arquivar e conservar em boa ordem durante os 10 anos civis subsequentes ... em estabelecimento ou instalação situado em território nacional ... deverão solicitar autorização prévia.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraElaboração de faturas e localização de arquivo fora da União Europeia
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceGoverno de PortugalComunicado do Conselho de Ministros de 14 de maio de 2026 — approval of the Plano Nacional de Nuvem Soberana
portugal.gov.pt
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Plan for a database inside Portugal: this data is not allowed to leave.
Sending data out of the country
For personal data leaving Europe, Portugal uses the standard European routes. Send it to an officially approved country. Or sign the European Commission's standard contract. Or use approved group-wide rules. With the last two, write down why the destination country is safe. Tax and invoicing archives add a Portuguese step. You ask the tax office for permission before the archive or the billing software moves outside Europe. Portugal's regulator has already fined a public body for relying on the standard contract alone.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed
European layer, checked 18 August 2026. The officially approved destinations are Andorra, Argentina, Brazil, Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea, Switzerland, the United Kingdom, Uruguay, and the European Patent Organisation. Brazil is new, approved on 26 January 2026, and that approval runs both ways. South Korea's first review was confirmed on 23 July 2026. The United Kingdom's approval was renewed on 19 December 2025 and runs to 2031. The United States counts only for organisations that have self-certified under the European Union-United States Data Privacy Framework. None has been withdrawn or suspended. The 2021 standard contractual clauses are still the set in use and are unchanged. New clauses were promised for recipients already directly covered by the Regulation. They are still not adopted. Approved group-wide rules remain available. The narrow exceptions, including consent, cannot be used for routine or bulk transfers. You are still expected to write a transfer impact assessment. The Data Privacy Framework is the item on this page most likely to change. It is in force and legally valid today. The General Court dismissed the Latombe challenge on 3 September 2025. An appeal to the Court of Justice was lodged on 31 October 2025 and is pending. Separately, the European Data Protection Board wrote to the Commission on 31 July 2026. It asked the Commission to examine whether changes to United States oversight bodies affect the decision's validity. The Commission has neither suspended nor revoked it. Do not make it your only route. Portuguese layer. In December 2022 the national regulator fined the national statistics institute 4.3 million euro (roughly 4.7 million United States dollars) over the 2021 census. One of the five findings was an unlawful transfer. The contract with a United States supplier used the Commission's standard clauses. It had no extra measures against access by that country's authorities. In Portugal, the paperwork on its own is not treated as enough. Tax records work differently again. Inside the European Union you need no permission. Outside it, you ask the tax office case by case. You apply electronically, name the country and show the legal conditions are met.
Sources
- Official sourceComissão Nacional de Proteção de DadosCNPD sanciona INE por cinco contraordenações — 4.3 million euro fine including an unlawful transfer finding
cnpd.pt
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraPerguntas frequentes sobre o Decreto-Lei n.º 28/2019 — prior authorisation for invoicing systems located in third countries
info.portaldasfinancas.gov.pt
“O pedido de autorização prévia para localização do sistema informático de faturação em país terceiro deve ser efetuado por via eletrónica ... O sujeito passivo deverá criar um utilizador com acesso ao sistema informático em tempo real a partir de terminais localizados em território nacional.”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — current list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The National Data Protection Commission enforces the privacy rules. It is real, staffed and working. In 2025 it opened 3,201 new files, took 262 final decisions and handled 472 reported data breaches. But it issued only two fines that year, worth 47,000 euro in total (about 51,000 United States dollars). That is down from 90 fines the year before. Its own annual report blames a shortage of staff. It also runs with five of its seven seats filled. Other regulators police the industry rules and are fully working.
- What it costs if you get it wrong:
- Order to stop
The regulator's own activity report for 2025 was approved on 24 March 2026. It is unusually honest. Headcount rose from 28 to 36 people after nineteen recruitments. The report still calls that insufficient. Two members left in August and September 2025 and had not been replaced when the report was approved. That leaves a five-member body chaired by Paula Cristina Meira Lourenço. In 2025 it opened 3,201 files, up 12 percent. Of those, 2,037 were investigations. It started 88 administrative-offence cases. It issued 267 draft accusations and 262 final decisions. It took 480 decisions in data-breach files. It gave 85 formal opinions on draft laws. It applied two fines totalling 47,000 euro. One was against a local authority. The other was against a private company for unsolicited marketing messages. The report says the 88 open cases could have produced 90 fines had they been finished. So the machine works but almost nothing comes out of it. Plan for fines to rebound as staffing improves. Until then, your real risk is an order to stop using the data, not a bill. The regulator will use blunt powers. In June 2022 it ordered every telecommunications provider to delete all data kept under the rule the Constitutional Court had just struck down. It gave them 72 hours. In December 2022 it fined a public body 4.3 million euro. Other enforcers. The gambling regulator inside Turismo de Portugal licenses and audits online operators. It can enter the premises holding the gaming system. The tax office approves or refuses archives outside the European Union. The communications regulator supervises telecoms. The National Cybersecurity Centre runs incident reporting. The central bank, the insurance authority and the securities commission supervise financial firms. Rating: active, with the honest warning about how few fines it issues.
Sources
- Official sourceComissão Nacional de Proteção de DadosRelatório de Atividades 2025, approved 24 March 2026 — caseload, staffing, composition and fines
cnpd.pt
“No ano de 2025, a CNPD aplicou 2 coimas, no valor de 47.000€ ... o órgão colegial CNPD era (e é) composto por 5 (cinco) Membros ... 36 trabalhadores é ainda um [número insuficiente].”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosCNPD ordena eliminação dos dados das comunicações conservados ao abrigo de norma declarada inconstitucional, 9 June 2022
cnpd.pt
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosCNPD homepage — news items dated 21 to 27 July 2026 evidencing current activity
cnpd.pt
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a minimum and a maximum, and they pull in opposite directions. The minimum: tax books, invoices and supporting documents must be kept for ten calendar years. Online betting data must be kept for ten years inside Portugal. The maximum: Europe's rule says delete personal data once you no longer need it. The telecoms law says connection data must be erased or made anonymous as soon as it is no longer needed to carry the call or message. When the two clash, the specific duty to keep a record wins for that record only.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period
Minimums, checked against official sources. Ten calendar years for books, records and supporting documents under the value added tax code. They must be kept in good order. On paper, they must be at premises inside Portugal. Ten years inside Portugal for online gambling activity data. Health records carry secrecy and access-notification duties instead of a single national deletion date. Maximums. Under the electronic communications privacy law, traffic data must be erased or made anonymous when it is no longer needed to carry the communication. You may keep it for billing only until the period for disputing the bill or claiming payment ends. Anything beyond that, such as marketing or extra services, needs the subscriber's consent first. The subscriber can withdraw that consent at any time. How the clash is resolved. Portugal has no single tie-break rule. The answer is the ordinary European one. A specific legal duty to keep a document is a lawful reason to keep it. But only that document, only for the stated period and only for that purpose. The trap is treating a ten-year tax duty as permission to keep your whole customer database for ten years. Telephone and internet companies no longer have to keep everyone's connection records. The Constitutional Court struck that down in April 2022. The regulator then ordered the stored data deleted.
Sources
- Official sourceAutoridade Tributária e AduaneiraCódigo do Imposto sobre o Valor Acrescentado, Article 52 — ten-year archive duty
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceANACOMLei n.º 41/2004, de 18 de agosto, Article 6 — traffic data, full text published by the communications regulator
anacom.pt
“os dados de tráfego ... devem ser eliminados ou tornados anónimos quando deixem de ser necessários para efeitos da transmissão da comunicação ... O tratamento referido no número anterior apenas é lícito até final do período durante o qual a factura pode ser legalmente contestada ou o pagamento reclamado.”
Link checked 18 August 2026
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalRegime Jurídico dos Jogos e Apostas Online, Article 34(d) — ten years of gambling data stored in national territory
srij.turismodeportugal.pt
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count at least two clocks, and three if you run critical infrastructure. Data breaches go to the National Data Protection Commission within 72 hours. You must also tell affected people without undue delay when the risk to them is high. Telecoms providers have their own European duty to report within 24 hours. Under Portugal's new cybersecurity law, important and essential organisations warn the National Cybersecurity Centre early, then file a fuller report. That follows the pattern set by Europe's network security directive.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
Clock one, privacy. You have 72 hours to tell the supervisory authority. You must warn individuals where the risk to them is high. Both come straight from the European Regulation. The national commission enforces them. In 2025 it took 480 decisions in breach files and recorded 472 breach reports, 42 percent more than the year before. Human error was the leading cause with 128 cases. Phishing was second with 72. Clock two, telecoms. Companies providing public electronic communications services report personal data breaches under the European rules for that industry. Those rules set a 24-hour first notification to the competent authority. Clock three, cybersecurity. Portugal's new national cybersecurity law was published as a decree-law on 4 December 2025. It rests on a parliamentary authorisation of 22 October 2025. It brings in Europe's second network and information security directive. That directive's pattern is an early warning within 24 hours, a fuller notification within 72 hours and a final report within one month. Covered organisations must also register with the national centre. We could not open the official Portuguese text to confirm each deadline as enacted. Treat the Portuguese details as medium confidence. The overlap is the real operational risk. One ransomware attack at a Portuguese telecoms firm can start all three clocks. Three different authorities are involved. The shortest deadline is 24 hours.
Sources
- Official sourceComissão Nacional de Proteção de DadosRelatório de Atividades 2025 — 472 breach notifications in 2025 and 480 decisions in breach files
cnpd.pt
Link checked 18 August 2026
- Official sourceEstrutura de missão para a transição digital / digital.gov.ptGoverno aprova Regime Jurídico da Cibersegurança Nacional — decree-law approved 11 November 2025 under Lei n.º 59/2025
digital.gov.pt
Link checked 18 August 2026
- Official sourceLink may be brokenDiário da RepúblicaDecreto-Lei n.º 125/2025, de 4 de dezembro — national cybersecurity legal regime
diariodarepublica.pt
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
Not fully verified — see “What we're not sure about” below.What catches people out
Five things that cost people their weekend. A child can consent from 13 in Portugal, not 16. Every look at a patient's health record must be traceable, and the patient must be told. Misusing or peeking at personal data is a crime here, not just a fine, and the person who did it is charged. Your invoicing software must be on the tax office's approved list. Moving it or the archive outside Europe needs permission first. And nine chunks of the Portuguese privacy law are printed in the statute but the regulator refuses to apply them.
- What you have to do here:
- Get a parent's consent for children · Appoint a data protection officer · Register or notify · Keep logs
- What it costs if you get it wrong:
- Criminal liability
One. Age of consent. Portugal set 13 as the youngest age at which a child can agree to online services. That is the lowest the European Regulation allows and three years below the default. The education ministry's guidance confirms it. It adds that services should check age using secure log-in. If your global product assumes 16, you are blocking Portuguese teenagers who are allowed in. If it assumes 13 everywhere, you are under-protecting children elsewhere. Two. Health data traceability. Access to health and genetic data runs on a need-to-know basis. It must be handled by someone bound by professional secrecy. The person the data is about must be told of any access to it. Your company has to provide the tracking and notification tool. Very few electronic record systems come with this switched on. Three. Criminal liability. The Portuguese privacy law creates crimes. They include using data in a way that does not match why it was collected, improper access to personal data, and breaking the duty of secrecy. The Criminal Code also punishes revealing a secret you learned through your job. That carries up to one year in prison or a fine. These attach to people, not only companies. No cyber-insurance policy fixes them. Four. The tax stack. Invoicing software used in Portugal must be approved in advance by the tax office and appear on its published list. Paper accounting archives must be at premises in Portugal. An electronic archive may sit anywhere in the European Union. Outside it you need permission first. If the invoicing system itself sits outside the European Union, you must create a tax office account. That account must be able to query the live system in real time from terminals inside Portugal. Foreign cloud billing platforms fail this test more often than anything else on this page. Five. The law you cannot trust to a text search. Since September 2019 the regulator has publicly refused to apply nine sets of rules in the national law. They include its scope rule, parts of the fining rules and two transitional rules. The regulator says they contradict the European Regulation. They are still printed in the statute. A search of Portuguese law will return rules that will not be enforced. Advice built on them is wrong in both directions. Six, smaller. You must tell the regulator who your data protection officer is. Portugal set no deadline for doing so. That is exactly why companies forget.
Sources
- Official sourceDireção-Geral da Educação, Ministério da EducaçãoRGPD — Consentimento de menores, 13 anos
dge.mec.pt
“Portugal optou pelos 13 anos como idade mínima para o consentimento requerida pelo RGPD.”
Link checked 18 August 2026
- Official sourceEntidade Reguladora da SaúdeHealth regulator guide — Article 29 of Lei n.º 58/2019 on health and genetic data, secrecy and access notification; criminal offences
ers.pt
“o titular dos dados deve ser notificado de qualquer acesso realizado aos seus dados pessoais, cabendo ao responsável pelo tratamento assegurar a disponibilização desse mecanismo de rastreabilidade e notificação.”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2025/267 — clarifications on the data protection officer regime, approved 1 April 2025
cnpd.pt
“a constituição do EPD, por nomeação obrigatória ou a nomeação voluntária, a sua publicitação ... e a sua comunicação à CNPD é um dever legal das entidades responsáveis pelo tratamento de dados e dos subcontratantes.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraTax office frequently asked questions — certified invoicing software and third-country locations
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2019/494 — provisions of the national statute the regulator will not apply
cnpd.pt
Link checked 18 August 2026
What's changing next
Three things land in the next year or so. Public bodies must sort their data and systems by importance under the sovereign cloud plan. That sorting is due by 30 June 2027. The new cybersecurity law is being switched on, with registration and incident duties for many more organisations. And the privacy regulator is hiring, so the near-zero fine count of 2025 is unlikely to last. Separately, Europe's rule that cloud switching must be free of charge starts in January 2027.
- What you have to do here:
- Prove the data stays under local control · Make switching cloud provider possible
Dated items. 12 January 2027: under the European Data Act, all cloud switching charges and data export fees must fall to zero. 30 June 2027: Portuguese public bodies must have classified their work, data and systems under the National Sovereign Cloud Plan approved on 14 May 2026. The state transformation agency and the National Cybersecurity Centre set the method. Through 2026 and 2027: the national cybersecurity law published on 4 December 2025 comes into force in stages. That includes registering with the National Cybersecurity Centre. Also live: the appeal against the European Union-United States Data Privacy Framework before the Court of Justice. And the European Data Protection Board's letter of 31 July 2026 asking the Commission to look at that decision again. Powers that already exist and could be switched on. These matter more than pending bills. First, keeping everyone's telephone and internet connection records. Parliament has legislated for it before. The Constitutional Court struck the rules down in April 2022 and struck down a replacement in December 2023. The 2024 law deliberately swapped blanket keeping for judge-ordered preservation in serious-crime cases. Political pressure to try again is constant. A new law could be passed and in force within weeks. Second, the tax office's permission power. It decides whether your archive or invoicing system may sit outside Europe. It can attach conditions. Nothing stops it tightening its practice without new legislation. Third, the gambling regulator's power to demand that every part of the technical gaming system sit somewhere it can reach. That is an access rule that can be used as a location rule. Fourth, sovereign cloud classification. The plan sorts by risk rather than by country today. But the sorting exercise is exactly the machinery for adding a location rule later through buying rules, with no new statute.
Sources
- Official sourceGoverno de PortugalCouncil of Ministers communiqué, 14 May 2026 — sovereign cloud plan, classification of public processes by 30 June 2027
portugal.gov.pt
Link checked 18 August 2026
- Official sourcedigital.gov.ptPlano Nacional de Nuvem Soberana
digital.gov.pt
Link checked 18 August 2026
- Official sourceTribunal ConstitucionalAcórdão n.º 268/2022 — blanket retention of communications data unconstitutional
tribunalconstitucional.pt
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionData Act, Regulation (EU) 2023/2854 — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 30 June 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries2 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data needs a copy kept in the country
Official name: Regime Jurídico dos Jogos e Apostas Online, aprovado pelo Decreto-Lei n.º 66/2015, de 29 de abril · Decreto-Lei n.º 66/2015, artigos 32.º e 34.º · Act of parliament
Portugal's strictest storage rule. A licensed online gambling operator must install the system that registers Portuguese players inside Portugal. It must store ten years of betting data inside Portugal. Every part of the gaming system must sit somewhere the regulator can walk in or log in at any moment.
Enforced by Gambling Regulation and Inspection Service
How this country controls where data goes: No restriction
What you have to do
- Keep the data in the countryThe entry-and-registration system must be installed in Portugal. It must hold the information on every gambling operation.
- Keep data for a minimum period — 10 yearsGambling activity data must be stored in Portugal for ten years.
- Independent auditEvery part of the technical gaming system must sit in premises the regulator can enter at any time. The regulator must also be able to reach any part of it remotely from its own offices, wherever it is. The system must be certified and approved before launch, and audited regularly afterwards.
- Hold a security certificateSecurity controls must follow the ISO 27001 international standard.
- Keep records of how you use dataFull logging of every player action, every operation and every change to the platform.
What it costs if you get it wrong
- Loss of your licenceFailure to keep meeting the technical system requirements.
- Order to stopRefusal of homologation or withdrawal of approval of the technical system.
Sources
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalConsolidated Regime Jurídico dos Jogos e Apostas Online, Articles 32 and 34, version dated 31 March 2020
srij.turismodeportugal.pt
“a) Ter localizados todos os componentes do sistema técnico de jogo em instalações às quais a entidade de controlo, inspeção e regulação possa, a todo o momento, aceder.”
Link checked 18 August 2026
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalObrigações das entidades — operator duties published by the gambling regulator
srij.turismodeportugal.pt
Link checked 18 August 2026
Telecoms rules
Official name: Lei n.º 41/2004, de 18 de agosto — tratamento de dados pessoais e proteção da privacidade no setor das comunicações eletrónicas · Lei n.º 41/2004, artigos 3.º, 4.º e 6.º · Act of parliament
Portugal's telecoms privacy law says nothing about where data must be stored. It works the other way. Connection data must be deleted or made anonymous as soon as it is no longer needed to carry the communication. You may keep it for billing only while the bill can still be disputed.
Enforced by National Communications Authority
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Delete data after a periodTraffic data must be erased or made anonymous once it is no longer needed to carry the communication. You may use it for billing only until the period for disputing the bill or claiming payment ends.
- Get consentUsing traffic and location data for marketing or extra services needs consent first. The person can withdraw that consent at any time.
- Secure the dataProviders must warn subscribers free of charge where there is a particular risk of a network security breach.
- Report breaches to the regulator — within 24 hoursTelecoms breach reporting follows the European rules for that industry. We did not re-check the deadline against a Portuguese source.
What it costs if you get it wrong
- Fixed maximum fineAdministrative offences supervised by the communications regulator. Amounts not verified in this run.
Sources
- Official sourceANACOMLei n.º 41/2004, full text published by the communications regulator
anacom.pt
“os dados de tráfego ... devem ser eliminados ou tornados anónimos quando deixem de ser necessários para efeitos da transmissão da comunicação.”
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Lei n.º 58/2019, de 8 de agosto — assegura a execução, na ordem jurídica nacional, do Regulamento Geral sobre a Proteção de Dados · Lei n.º 58/2019 · Act of parliament
Portugal's version of the European rules. It sets a low age at which children can consent on their own. It adds strong secrecy and access-notification duties for health data. It creates crimes that individual people can be charged with. Several of its rules are printed in the law but the regulator does not apply them.
Enforced by National Data Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 13Portugal set the lowest age band Europe allows. Above 13 a child may consent alone to online services.
- Appoint a data protection officerCompulsory for the State, the autonomous regions, municipalities and public institutes. You must tell the regulator the officer's name. Portugal set no deadline for doing so.
- Tell people what you doHealth and genetic data: the person must be notified of any access to their records.
- Keep logsHealth and genetic data: you must provide a way to record who accessed what.
- Extra vendor secrecy termsStaff, contractors, students and researchers who can see health or genetic data are bound by a legal duty of secrecy. It goes wider than an ordinary supplier contract.
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover (about $22 million at the floor) — about $22 millionThe European Regulation's upper tier, applied by the national regulator.
- Criminal liability: Prison or fine; the Criminal Code punishes revealing a secret learned through your job with up to one year in prison or a fine of up to 240 daysUsing data in a way incompatible with the collection purpose, improper access to personal data, breach of the duty of secrecy.
Sources
- Official sourceEntidade Reguladora da SaúdeHealth regulator guide quoting Article 29 of Lei n.º 58/2019 and the criminal offences in Articles 46, 47 and 51
ers.pt
Link checked 18 August 2026
- Official sourceDireção-Geral da EducaçãoAge of consent set at 13 in Portugal
dge.mec.pt
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2025/267 — data protection officer duties, approved 1 April 2025
cnpd.pt
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Código do IVA, artigo 52.º, e Decreto-Lei n.º 28/2019, de 15 de fevereiro (processamento de faturas e arquivo de documentos) · CIVA art. 52; Decreto-Lei n.º 28/2019, arts. 5, 19 to 21 · Act of parliament
Every business in Portugal must keep ten years of invoices and accounting records. They must be on premises in Portugal, unless it is an electronic archive with guaranteed online access. Archives may sit anywhere in Europe. Going outside Europe needs written permission from the tax office first. So does putting your billing software there.
Enforced by Tax and Customs Authority
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep data for a minimum period — 10 yearsTen calendar years for books, records and supporting documents.
- Keep the data in the countryRecords must be kept at premises in Portugal. An electronic archive escapes this only if complete online access to the data is guaranteed. An archive elsewhere in the European Union needs no permission. Outside it, you need the tax office's permission first.
- Register or notifyInvoicing software must be approved in advance by the tax office and appear on its published list of certified programs.
- Independent auditIf the invoicing system sits outside the European Union, you must give the tax office an account. It must be able to query the live system in real time from terminals inside Portugal, and to download from it.
What it costs if you get it wrong
- Fixed maximum fine: Tax-offence fines under the general tax penalty regimeFailure to archive, to use certified software, or to obtain authorisation for a third-country location.
Sources
- Official sourceAutoridade Tributária e AduaneiraCódigo do IVA, Article 52
info.portaldasfinancas.gov.pt
“arquivar e conservar em boa ordem durante os 10 anos civis subsequentes ... em estabelecimento ou instalação situado em território nacional.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraElaboração de faturas e localização de arquivo fora da União Europeia
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraTax office frequently asked questions on Decreto-Lei n.º 28/2019
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
Cyber security rules
Official name: Regime Jurídico da Cibersegurança, aprovado por decreto-lei publicado em 4 de dezembro de 2025 ao abrigo da autorização legislativa da Lei n.º 59/2025 · Decreto-Lei n.º 125/2025, de 4 de dezembro; Lei n.º 59/2025, de 22 de outubro · Act of parliament
Portugal's version of Europe's second network and information security directive, published in December 2025. It brings many more organisations into registration and incident reporting run by the National Cybersecurity Centre. We found no rule in it about where data must be stored.
Enforced by National Cybersecurity Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Register or notifyEssential and important organisations must register with the National Cybersecurity Centre. We could not check the Portuguese deadlines against an official text.
- Report cyber incidents — within 24 hoursEarly warning within 24 hours, following the European network security directive. Then a fuller notification within 72 hours and a final report within one month.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: Up to €10 million or 2% of worldwide turnover for essential entities under the European directive's framework — about $11 millionFailure to manage cyber risk or to report an incident. Portuguese amounts not verified in this run.
Sources
- Official sourcedigital.gov.ptGoverno aprova Regime Jurídico da Cibersegurança Nacional
digital.gov.pt
Link checked 18 August 2026
- Official sourceLink may be brokenDiário da RepúblicaDecreto-Lei n.º 125/2025, de 4 de dezembro
diariodarepublica.pt
Link checked 18 August 2026
Government data needs a sovereign cloud
Official name: Plano Nacional de Nuvem Soberana · Resolução do Conselho de Ministros approved at the Council of Ministers of 14 May 2026 · Government policy document
Portugal's sovereign cloud plan was approved in May 2026. It sorts public data by importance instead of naming a country. It points public bodies towards European and national services. Public bodies must finish the sorting by 30 June 2027.
That is a long gap: the duty is real law today, but no penalty can follow until 30 June 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by National Cybersecurity Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Prove the data stays under local control — from 30 June 2027Public bodies must sort their work, data and systems by level of importance. They must match security rules to each level. The state transformation agency and the National Cybersecurity Centre set the method.
Sources
- Official sourceGoverno de PortugalCouncil of Ministers communiqué of 14 May 2026 approving the plan
portugal.gov.pt
“dados e processos são classificados por níveis de importância, com regras de segurança adequadas a cada caso.”
Link checked 18 August 2026
- Official sourcedigital.gov.ptCloud in the public administration — sovereign cloud plan and the 2026-2027 digital transformation strategy
digital.gov.pt
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Regulamento Geral sobre a Proteção de Dados — Regulamento (UE) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation
Europe's general data protection law. It never says where data must be stored. It says what you must have in place before personal data leaves Europe. It also reaches companies outside Europe that target people in Portugal.
Enforced by National Data Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Put a transfer safeguard in placeYou need an approved transfer route plus a written assessment of the destination country's surveillance laws.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithout undue delay where the risk to individuals is high.
- Appoint a representativeRequired if your company has no base in Europe. The representative does not have to be in Portugal.
- Keep records of how you use data
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher (about $22 million at the floor) — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator's order.
- Order to stopOrder to stop processing or to suspend flows to a country outside Europe.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, official consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — current list, verified 18 August 2026
commission.europa.eu
Link checked 18 August 2026
On the books, but not enforceable2 rules
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
General data protection law
Official name: Deliberação/2019/494 da Comissão Nacional de Proteção de Dados — desaplicação de normas da Lei n.º 58/2019 · Deliberação/2019/494 · Regulator guideline
In September 2019 the regulator announced it will not apply nine sets of rules in the national privacy law. They include its scope rule and parts of its fining rules. The reason is that European law comes first. They are still printed in the statute. So a text search of Portuguese law returns rules that are not enforced.
Enforced by National Data Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
Sources
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2019/494, approved 3 September 2019
cnpd.pt
“o legislador não pode copiar o texto do regulamento quando desnecessário nem interpretá-lo ou acrescentar condições adicionais.”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosCNPD decision archive listing Deliberação 494/2019 and the related Deliberação 495/2019 on fines against public bodies
cnpd.pt
Link checked 18 August 2026
Internet and platform rules
Official name: Lei n.º 32/2008, de 17 de julho — conservação de dados gerados no contexto da oferta de serviços de comunicações eletrónicas · Lei n.º 32/2008, artigos 4.º, 6.º e 9.º; Acórdão do Tribunal Constitucional n.º 268/2022 · Act of parliament
The law telling telephone and internet providers to keep everyone's connection records is still printed in the statute book. It cannot be enforced. The Constitutional Court struck the core rules down in April 2022. The regulator then ordered the stored data deleted within 72 hours. A 2024 law replaced blanket keeping with judge-ordered preservation in serious criminal cases.
Enforced by National Data Protection Commission
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed
What you have to do
- Keep data for a minimum periodThe blanket one-year keeping duty cannot be enforced. Since February 2024, traffic and location data may be preserved only for a serious crime. A judge of the Supreme Court's criminal divisions must authorise it. The decision is due within 72 hours.
Sources
- Official sourceTribunal ConstitucionalAcórdão n.º 268/2022 do Tribunal Constitucional, 19 April 2022
tribunalconstitucional.pt
“Declarar a inconstitucionalidade, com força obrigatória geral, da norma constante do artigo 4.º da Lei n.º 32/2008, de 17 de julho, conjugada com o artigo 6.º da mesma lei.”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosRegulator orders deletion of retained communications data, 9 June 2022
cnpd.pt
Link checked 18 August 2026
- Official sourceLink may be brokenDiário da RepúblicaLei n.º 18/2024, de 5 de fevereiro — access to metadata for criminal investigation
diariodarepublica.pt
Link checked 18 August 2026
- Secondary sourceGarriguesAnalysis of Lei n.º 18/2024 — judge-ordered preservation replaces blanket retention
garrigues.com
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact entry-into-force date, registration deadlines, incident-reporting deadlines and fine levels of the new national cybersecurity regime published on 4 December 2025
We could not confirm the Portuguese deadlines against a government source. The deadlines shown follow the European directive's pattern. Check the Portuguese text before you rely on them.
The content of the Bank of Portugal notice of December 2025 on outsourcing registers and reporting, and whether it says anything about data location
We could not confirm this against the bank's own website, which blocks automated access. We treat the notice as a reporting and registration duty only. We do not claim any banking rule about keeping data in the country. If you are a bank, check with the Banco de Portugal.
Whether the insurance and securities regulators impose cloud or outsourcing location conditions
We could not confirm the insurance and securities rules against those regulators' own sites. So our statement that nothing forces data to stay in Portugal is unverified for those two industries. Check before you rely on it.
Whether the consolidated online gambling law published by the regulator, whose text is dated 31 March 2020, reflects amendments made after that date
The regulator publishes this consolidated text itself and lists no newer version. But we could not confirm from the official gazette that Articles 32 and 34 are unchanged since 2020.
Whether the regulator's 2019 decision not to apply nine sets of provisions of the national privacy statute is still being applied in 2026
The decision is published and we found no sign it has been withdrawn. Parliament has not changed the rules either. But we found no 2025 or 2026 statement repeating it. So this is inference from silence.
The fine counts per year read from a chart in the regulator's 2025 annual report (90 in 2024, 71, 60, 23 and 15 in earlier years)
The 2025 figure of two fines worth 47,000 euro is written out in words in the report. The earlier yearly figures come from a bar chart. Its labels do not extract cleanly from the PDF, so the year-to-number mapping is our reading.
That no localisation rule exists for health records, education data, mapping and geospatial data or defence data in Portugal
We found no health rule forcing data to stay in Portugal, searched on 18 August 2026 on official sites. That is an absence of evidence, not proof. Health data does carry strong secrecy, need-to-know and access-notification duties. If you work in health, check before you rely on this.
The exact period during which a telecoms bill can be contested, which sets the ceiling on keeping billing data
The law sets the limit by pointing at the period for disputing a bill, rather than giving a number of months. We did not check that underlying consumer-law period against an official source.
Whether the two vacant seats on the data protection commission were filled between 24 March 2026 and 18 August 2026
We can only show the two seats were vacant up to the date the annual report was approved. We cannot prove they are still vacant in the months since.
Whether the 24-hour telecoms breach-reporting deadline applies in Portugal exactly as set out in the European sector rules
This comes from the European rules for that industry, not from a Portuguese regulator page we were able to open. Check with the Portuguese communications regulator before you rely on the deadline.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.