Skip to the content
Global Data RulesData governance rules, country by country

Portugal

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Portugal — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

You can send Portuguese data abroad once you have the right paperwork. That is the normal European rule. Two Portuguese rules override it. Online betting data must sit inside Portugal for ten years. Tax and invoicing records must stay in Portugal or the rest of Europe. To move them further, you need written permission from the tax office first. The privacy regulator is busy but almost never fines.

Data governance in Portugal

The eight things that decide how you handle data about people in Portugal. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes, it reaches you even with no office in Portugal. Europe's General Data Protection Regulation covers any company that offers goods or services to people in Portugal. There is no revenue or staff-count threshold. If your company has no base anywhere in Europe, you must appoint a representative inside Europe. That person does not have to be in Portugal. Portugal's own version of the law tried to add its own rule about who is covered. The regulator publicly refuses to apply that part.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, with paperwork, just like anywhere else in Europe. Storing data elsewhere in Europe carries no extra rules. Two Portuguese industries break that pattern. Online gambling firms must install the system that registers Portuguese players inside Portugal. They must also store ten years of betting data inside Portugal. Every business in Portugal must keep its tax and invoicing records in Portugal or the rest of Europe. To move them further away, you need the tax office's approval.

What to do: Plan for a database inside Portugal: this data is not allowed to leave.

Sending data out of the country

For personal data leaving Europe, Portugal uses the standard European routes. Send it to an officially approved country. Or sign the European Commission's standard contract. Or use approved group-wide rules. With the last two, write down why the destination country is safe. Tax and invoicing archives add a Portuguese step. You ask the tax office for permission before the archive or the billing software moves outside Europe. Portugal's regulator has already fined a public body for relying on the standard contract alone.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The National Data Protection Commission enforces the privacy rules. It is real, staffed and working. In 2025 it opened 3,201 new files, took 262 final decisions and handled 472 reported data breaches. But it issued only two fines that year, worth 47,000 euro in total (about 51,000 United States dollars). That is down from 90 fines the year before. Its own annual report blames a shortage of staff. It also runs with five of its seven seats filled. Other regulators police the industry rules and are fully working.

What it costs if you get it wrong:
Order to stop

How long you must keep it — and when to delete it

There is a minimum and a maximum, and they pull in opposite directions. The minimum: tax books, invoices and supporting documents must be kept for ten calendar years. Online betting data must be kept for ten years inside Portugal. The maximum: Europe's rule says delete personal data once you no longer need it. The telecoms law says connection data must be erased or made anonymous as soon as it is no longer needed to carry the call or message. When the two clash, the specific duty to keep a record wins for that record only.

What you have to do here:
Keep data for a minimum period · Delete data after a period

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count at least two clocks, and three if you run critical infrastructure. Data breaches go to the National Data Protection Commission within 72 hours. You must also tell affected people without undue delay when the risk to them is high. Telecoms providers have their own European duty to report within 24 hours. Under Portugal's new cybersecurity law, important and essential organisations warn the National Cybersecurity Centre early, then file a fuller report. That follows the pattern set by Europe's network security directive.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

Not fully verified — see “What we're not sure about” below.

What catches people out

Five things that cost people their weekend. A child can consent from 13 in Portugal, not 16. Every look at a patient's health record must be traceable, and the patient must be told. Misusing or peeking at personal data is a crime here, not just a fine, and the person who did it is charged. Your invoicing software must be on the tax office's approved list. Moving it or the archive outside Europe needs permission first. And nine chunks of the Portuguese privacy law are printed in the statute but the regulator refuses to apply them.

What you have to do here:
Get a parent's consent for children · Appoint a data protection officer · Register or notify · Keep logs
What it costs if you get it wrong:
Criminal liability

What's changing next

Three things land in the next year or so. Public bodies must sort their data and systems by importance under the sovereign cloud plan. That sorting is due by 30 June 2027. The new cybersecurity law is being switched on, with registration and incident duties for many more organisations. And the privacy regulator is hiring, so the near-zero fine count of 2025 is unlikely to last. Separately, Europe's rule that cloud switching must be free of charge starts in January 2027.

What you have to do here:
Prove the data stays under local control · Make switching cloud provider possible

What to do: Diarise 30 June 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries2 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data needs a copy kept in the country

Official name: Regime Jurídico dos Jogos e Apostas Online, aprovado pelo Decreto-Lei n.º 66/2015, de 29 de abril · Decreto-Lei n.º 66/2015, artigos 32.º e 34.º · Act of parliament

In forceA copy must stay

Portugal's strictest storage rule. A licensed online gambling operator must install the system that registers Portuguese players inside Portugal. It must store ten years of betting data inside Portugal. Every part of the gaming system must sit somewhere the regulator can walk in or log in at any moment.

In force since 28 June 2015

Enforced by Gambling Regulation and Inspection Service

How this country controls where data goes: No restriction

Telecoms

Telecoms rules

Official name: Lei n.º 41/2004, de 18 de agosto — tratamento de dados pessoais e proteção da privacidade no setor das comunicações eletrónicas · Lei n.º 41/2004, artigos 3.º, 4.º e 6.º · Act of parliament

In forceYes, with paperwork

Portugal's telecoms privacy law says nothing about where data must be stored. It works the other way. Connection data must be deleted or made anonymous as soon as it is no longer needed to carry the communication. You may keep it for billing only while the bill can still be disputed.

In force since 19 August 2004

Enforced by National Communications Authority

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Lei n.º 58/2019, de 8 de agosto — assegura a execução, na ordem jurídica nacional, do Regulamento Geral sobre a Proteção de Dados · Lei n.º 58/2019 · Act of parliament

In forceYes, with paperwork

Portugal's version of the European rules. It sets a low age at which children can consent on their own. It adds strong secrecy and access-notification duties for health data. It creates crimes that individual people can be charged with. Several of its rules are printed in the law but the regulator does not apply them.

In force since 9 August 2019

Enforced by National Data Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Record-keeping rules for tax and accounts

Official name: Código do IVA, artigo 52.º, e Decreto-Lei n.º 28/2019, de 15 de fevereiro (processamento de faturas e arquivo de documentos) · CIVA art. 52; Decreto-Lei n.º 28/2019, arts. 5, 19 to 21 · Act of parliament

In forceYes, with paperwork

Every business in Portugal must keep ten years of invoices and accounting records. They must be on premises in Portugal, unless it is an electronic archive with guaranteed online access. Archives may sit anywhere in Europe. Going outside Europe needs written permission from the tax office first. So does putting your billing software there.

In force since 16 February 2019Enforced from 1 January 2020

Enforced by Tax and Customs Authority

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Cyber security rules

Official name: Regime Jurídico da Cibersegurança, aprovado por decreto-lei publicado em 4 de dezembro de 2025 ao abrigo da autorização legislativa da Lei n.º 59/2025 · Decreto-Lei n.º 125/2025, de 4 de dezembro; Lei n.º 59/2025, de 22 de outubro · Act of parliament

Partly in forceYes — store it anywhere

Portugal's version of Europe's second network and information security directive, published in December 2025. It brings many more organisations into registration and incident reporting run by the National Cybersecurity Centre. We found no rule in it about where data must be stored.

In force since 5 December 2025

Enforced by National Cybersecurity Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Regulamento Geral sobre a Proteção de Dados — Regulamento (UE) 2016/679 · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

Europe's general data protection law. It never says where data must be stored. It says what you must have in place before personal data leaves Europe. It also reaches companies outside Europe that target people in Portugal.

In force since 24 May 2016Enforced from 25 May 2018

Enforced by National Data Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

On the books, but not enforceable2 rules

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

General data protection law

Official name: Deliberação/2019/494 da Comissão Nacional de Proteção de Dados — desaplicação de normas da Lei n.º 58/2019 · Deliberação/2019/494 · Regulator guideline

UnenforceableYes, with paperwork

In September 2019 the regulator announced it will not apply nine sets of rules in the national privacy law. They include its scope rule and parts of its fining rules. The reason is that European law comes first. They are still printed in the statute. So a text search of Portuguese law returns rules that are not enforced.

In force since 3 September 2019

Enforced by National Data Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Not fully verified — see “What we're not sure about” below.
Telecoms

Internet and platform rules

Official name: Lei n.º 32/2008, de 17 de julho — conservação de dados gerados no contexto da oferta de serviços de comunicações eletrónicas · Lei n.º 32/2008, artigos 4.º, 6.º e 9.º; Acórdão do Tribunal Constitucional n.º 268/2022 · Act of parliament

UnenforceableYes, with paperwork

The law telling telephone and internet providers to keep everyone's connection records is still printed in the statute book. It cannot be enforced. The Constitutional Court struck the core rules down in April 2022. The regulator then ordered the stored data deleted within 72 hours. A 2024 law replaced blanket keeping with judge-ordered preservation in serious criminal cases.

In force since 15 August 2008

Enforced by National Data Protection Commission

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed

Who you would hear from

  • Comissão Nacional de Proteção de Dados

    General data protection law across the private and public sectors

    Fully working and publishing continuously through July 2026. Chaired by Paula Cristina Meira Lourenço. It has run with five of seven seats filled since two members left in August and September 2025 and were not replaced. Staff rose from 28 to 36 in 2025, and the commission itself calls that insufficient. In 2025 it opened 3,201 files. It issued 262 final decisions and 267 draft accusations. It handled 472 breach notifications and started 88 administrative-offence cases. It imposed just 2 fines totalling 47,000 euro, against 90 fines the previous year. Expect orders to fix things more often than fines.

  • Autoridade Tributária e Aduaneira

    Invoicing software certification, archive location authorisations, ten-year record keeping

    Runs the online permission process for archives and invoicing systems located outside the European Union. Publishes the list of certified invoicing programs.

  • Serviço de Regulação e Inspeção de Jogos, Turismo de Portugal

    Online gambling licensing, technical system certification and inspection

    Licenses operators. Certifies and approves gaming systems, and audits them regularly. Publishes consolidated legislation. It has a legal right to enter premises and to reach every part of a licensed operator's gaming system remotely.

  • Autoridade Nacional de Comunicações

    Electronic communications, including the sector privacy statute and digital services coordination

    Active. It met the data protection regulator in July 2026 about applying the European digital services rules.

  • Centro Nacional de Cibersegurança

    Cyber incident reporting, registration of essential and important entities, sovereign cloud classification methodology

    We could not open it, so we cannot quote its published guidance directly.

  • Banco de Portugal

    Banking and payments supervision, outsourcing registers and notifications

    Working and issuing notices. One from December 2025 covers registering and reporting outsourcing deals. Its site blocks automated access and we could not open it, so its content is reported at medium confidence.

  • Autoridade de Supervisão de Seguros e Fundos de Pensões

    Insurance and pension funds, including outsourcing and cloud use by insurers

    Working. We did not separately check its outsourcing and cloud rules. We found no requirement to keep data in the country.

  • Comissão do Mercado de Valores Mobiliários

    Securities markets and investment firms

    Working. Since January 2025 the operational resilience rules for financial firms come mainly from European law. We found no Portuguese requirement to keep data in the country.

  • Entidade Reguladora da Saúde

    Health service providers, including patients' data protection rights

    Publishes guidance on patients' data protection rights, including the duty to notify a patient of every access to their record.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact entry-into-force date, registration deadlines, incident-reporting deadlines and fine levels of the new national cybersecurity regime published on 4 December 2025

    We could not confirm the Portuguese deadlines against a government source. The deadlines shown follow the European directive's pattern. Check the Portuguese text before you rely on them.

  • The content of the Bank of Portugal notice of December 2025 on outsourcing registers and reporting, and whether it says anything about data location

    We could not confirm this against the bank's own website, which blocks automated access. We treat the notice as a reporting and registration duty only. We do not claim any banking rule about keeping data in the country. If you are a bank, check with the Banco de Portugal.

  • Whether the insurance and securities regulators impose cloud or outsourcing location conditions

    We could not confirm the insurance and securities rules against those regulators' own sites. So our statement that nothing forces data to stay in Portugal is unverified for those two industries. Check before you rely on it.

  • Whether the consolidated online gambling law published by the regulator, whose text is dated 31 March 2020, reflects amendments made after that date

    The regulator publishes this consolidated text itself and lists no newer version. But we could not confirm from the official gazette that Articles 32 and 34 are unchanged since 2020.

  • Whether the regulator's 2019 decision not to apply nine sets of provisions of the national privacy statute is still being applied in 2026

    The decision is published and we found no sign it has been withdrawn. Parliament has not changed the rules either. But we found no 2025 or 2026 statement repeating it. So this is inference from silence.

  • The fine counts per year read from a chart in the regulator's 2025 annual report (90 in 2024, 71, 60, 23 and 15 in earlier years)

    The 2025 figure of two fines worth 47,000 euro is written out in words in the report. The earlier yearly figures come from a bar chart. Its labels do not extract cleanly from the PDF, so the year-to-number mapping is our reading.

  • That no localisation rule exists for health records, education data, mapping and geospatial data or defence data in Portugal

    We found no health rule forcing data to stay in Portugal, searched on 18 August 2026 on official sites. That is an absence of evidence, not proof. Health data does carry strong secrecy, need-to-know and access-notification duties. If you work in health, check before you rely on this.

  • The exact period during which a telecoms bill can be contested, which sets the ceiling on keeping billing data

    The law sets the limit by pointing at the period for disputing a bill, rather than giving a number of months. We did not check that underlying consumer-law period against an official source.

  • Whether the two vacant seats on the data protection commission were filled between 24 March 2026 and 18 August 2026

    We can only show the two seats were vacant up to the date the annual report was approved. We cannot prove they are still vacant in the months since.

  • Whether the 24-hour telecoms breach-reporting deadline applies in Portugal exactly as set out in the European sector rules

    This comes from the European rules for that industry, not from a Portuguese regulator page we were able to open. Check with the Portuguese communications regulator before you rely on the deadline.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.