Portugal
Part of the European Union, so bloc-wide rules apply here too. Checked yesterday.
The answer
Portugal follows the normal European rule: personal data may leave once you have the right paperwork in place. Two Portuguese walls override that. Online betting data must sit inside Portugal for ten years. Tax and invoicing records must stay in Portugal or the rest of Europe unless the tax office gives you written permission first. The privacy regulator is busy but almost never fines.
Data governance in Portugal
The eight things that decide how you handle data about people in Portugal. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Europe's General Data Protection Regulation reaches any company that offers goods or services to people in Portugal, even with no office and no staff here. There is no revenue or headcount threshold to hide behind. If your company has no base anywhere in Europe you must appoint a representative inside Europe, though that person does not have to be in Portugal. Portugal's own version of the law tried to add its own rule about who is covered, and the regulator publicly refuses to apply that part.
The Portuguese implementing statute is Lei n.º 58/2019 of 8 August 2019. Its Article 2 states that the statute applies to processing carried out in national territory whatever the nature of the controller, and extends to controllers established outside the European Union where they offer goods or services to data subjects in Portugal. In Deliberação/2019/494 of 3 September 2019 the national regulator decided not to apply Article 2(1) and 2(2) in the cases it handles, on the ground that the territorial scope of the Regulation is set by Article 3 of the Regulation itself and a member state cannot narrow it, widen it or restate it. In practice, therefore, scope is decided by Article 3 of the Regulation and by Article 27 on European representatives, not by the Portuguese text. Health regulator guidance restates the same territorial wording, which is why a naive reading of the Portuguese statute alone will mislead you.
Sources
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2019/494 — Desaplicação, na apreciação de casos concretos, de algumas normas da Lei 58/2019
cnpd.pt
“Desaplicação ... do artigo 2.º, n.os 1 e 2, do artigo 20.º, n.º 1, do artigo 23.º, do artigo 28.º, n.º 3, alínea a), do artigo 37.º, n.º 1, alíneas a), h) e k), e n.º 2, do artigo 38.º, n.º 1, alínea b), e n.º 2, do artigo 39.º, n.os 1 e 3, do artigo 61.º, n.º 2, e do artigo 62.º, n.º 2, da Lei 58/2019.”
Link checked 18 August 2026
- Official sourceEntidade Reguladora da SaúdeDireito à proteção de dados pessoais, à reserva da vida privada — guia sobre os direitos dos utentes
ers.pt
“A 8 de agosto, foi publicada a Lei n.º 58/2019, que assegura a execução, na ordem jurídica nacional, do RGPD, aplicando-se aos tratamentos de dados pessoais realizados no território nacional.”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
Where the data is allowed to live
In general yes, with paperwork, exactly as anywhere else in Europe. Storage outside Portugal but inside Europe is free. Two Portuguese industries break that pattern. Online gambling firms must install the system that registers Portuguese players inside Portugal and must store ten years of betting data inside Portugal. Every business in Portugal must keep its tax and invoicing records in Portugal or the rest of Europe unless the tax office approves a move further afield.
Sector by sector, checked on 18 August 2026. ONLINE GAMBLING — the hardest wall in the country. The Legal Framework for Online Games and Betting requires licensed operators to install the entry-and-registration infrastructure in national territory, to store gambling activity data in national territory for ten years, and to keep every component of the technical gaming system in premises the regulator can enter at any time, with remote access from the regulator's own offices whatever the location of the equipment. Rating: a copy must stay in the country. TAX, INVOICING AND ACCOUNTING RECORDS — a real and widely missed rule. Books, records and supporting documents must be kept for ten calendar years at premises inside Portugal; electronic archiving escapes the national-premises rule only if complete online access to the data is guaranteed. An electronic archive may sit anywhere in the European Union without asking. Outside the European Union it needs prior authorisation from the tax office, and locating the invoicing software itself in a third country needs a separate prior authorisation plus a user account that lets the tax office query the live system in real time from terminals inside Portugal. Rating: data can leave with paperwork, with a case-by-case government permission for third countries. BANKING, PAYMENTS, INSURANCE AND SECURITIES — no Portuguese localisation rule found, checked 18 August 2026. These firms are governed by the European Union's Digital Operational Resilience Act since 17 January 2025, which requires you to disclose where data is processed, to keep audit and exit rights, and imposes no storage location. The Banco de Portugal published a notice in December 2025 on registering and reporting outsourcing arrangements; we could not open the bank's own site to verify its text and treat it as a reporting duty, not a location duty. Rating: data can leave with paperwork, low-to-medium confidence. HEALTH — no localisation rule found, checked 18 August 2026. What Portugal adds instead is secrecy and traceability: health and genetic data may only be handled on a need-to-know basis by people bound by professional secrecy, and the patient must be told about every access to their record. Rating: data can leave with paperwork. TELECOMS — no localisation rule found, checked 18 August 2026. The obligation runs the other way: connection data must be erased or anonymised once it is no longer needed to carry the communication. GOVERNMENT — no binding localisation rule found. The National Sovereign Cloud Plan approved on 14 May 2026 sorts public data and processes by importance and attaches security rules to each level, rather than naming a country. Public bodies must classify their processes by 30 June 2027. Rating: data can leave with paperwork today, with an obvious route to something stricter through procurement rules. EDUCATION, DEFENCE, MAPPING AND GEOSPATIAL DATA — no rule found, checked 18 August 2026, medium confidence. We did not locate a mapping or aerial-imagery storage restriction on an official site. At European level, Regulation (EU) 2018/1807 forbids member states from imposing storage location rules on non-personal data except on public-security grounds, which is one reason Portugal's walls are drawn around gambling supervision and tax inspection rather than around data as such.
Sources
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalDecreto-Lei n.º 66/2015 — Regime Jurídico dos Jogos e Apostas Online, consolidated text published by the gambling regulator, Article 34
srij.turismodeportugal.pt
“c) Assegurar que a infraestrutura de entrada e registo se encontra instalada em território nacional e contém toda a informação sobre todas as operações relacionadas com a atividade de jogos e apostas online; d) Armazenar em território nacional os dados relacionados com a atividade de jogos e apostas online pelo período de 10 anos.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraCódigo do Imposto sobre o Valor Acrescentado, Article 52 — obligation to archive and keep records
info.portaldasfinancas.gov.pt
“arquivar e conservar em boa ordem durante os 10 anos civis subsequentes ... em estabelecimento ou instalação situado em território nacional ... deverão solicitar autorização prévia.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraElaboração de faturas e localização de arquivo fora da União Europeia
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceGoverno de PortugalComunicado do Conselho de Ministros de 14 de maio de 2026 — approval of the Plano Nacional de Nuvem Soberana
portugal.gov.pt
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on the free flow of non-personal data
eur-lex.europa.eu
Link checked 18 August 2026
Sending data out of the country
For personal data leaving Europe, Portugal uses the standard European toolkit: send it to an approved country, or sign the European Commission's standard contract, or use approved group-wide rules, and write down why the destination is safe. For tax and invoicing archives the extra step is Portuguese: you ask the tax office for permission before the archive or the billing software moves outside Europe. Portugal's regulator has already fined a public body for relying on the standard contract alone.
European layer, verified 18 August 2026. Approved destinations are Andorra, Argentina, Brazil (new, 26 January 2026, mutual), Canada for commercial bodies, the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States but only for organisations self-certified under the European Union-United States Data Privacy Framework, plus the European Patent Organisation. None has been withdrawn or suspended. The 2021 standard contractual clauses remain the operative set and are unamended; the promised new clauses for importers already directly caught by the Regulation are still not adopted. Binding corporate rules remain available. The narrow derogations, including consent, are not a basis for routine or bulk transfers. A transfer impact assessment is still expected. The Data Privacy Framework is the most time-sensitive item on this page. It is in force and legally valid today, but the General Court dismissed the Latombe challenge on 3 September 2025 and an appeal to the Court of Justice was lodged on 31 October 2025 and is pending; separately, on 31 July 2026 the European Data Protection Board formally asked the Commission to examine whether changes to United States oversight bodies affect the decision's validity. The Commission has neither suspended nor revoked it. Never build a single-mechanism architecture on it. Portuguese layer. In December 2022 the national regulator fined the national statistics institute 4.3 million euro (roughly 4.7 million United States dollars) over the 2021 census, and one of the five findings was an unlawful transfer: the contract with a United States provider contained the Commission's standard clauses but no supplementary measures against access by that country's authorities. The lesson is that in Portugal the paperwork alone is not treated as sufficient. For tax records the model is different again: inside the European Union, no permission; outside, a case-by-case authorisation from the tax office, requested electronically, in which you identify the third country and show the legal conditions are met.
Sources
- Official sourceComissão Nacional de Proteção de DadosCNPD sanciona INE por cinco contraordenações — 4.3 million euro fine including an unlawful transfer finding
cnpd.pt
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraPerguntas frequentes sobre o Decreto-Lei n.º 28/2019 — prior authorisation for invoicing systems located in third countries
info.portaldasfinancas.gov.pt
“O pedido de autorização prévia para localização do sistema informático de faturação em país terceiro deve ser efetuado por via eletrónica ... O sujeito passivo deverá criar um utilizador com acesso ao sistema informático em tempo real a partir de terminais localizados em território nacional.”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — current list
commission.europa.eu
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionCommission Implementing Decision (EU) 2021/914 — standard contractual clauses
eur-lex.europa.eu
Link checked 18 August 2026
The regulator, and whether it actually acts
The National Data Protection Commission enforces the privacy rules. It is real, staffed and working: in 2025 it opened 3,201 new files, took 262 final decisions and handled 472 reported data breaches. But it issued only two fines that year, worth 47,000 euro in total (about 51,000 United States dollars), down from 90 fines the year before, and its own annual report blames a shortage of staff. It also runs with five of its seven seats filled. Other regulators police the sector rules and are fully operational.
The regulator's own activity report for 2025, approved on 24 March 2026, is unusually candid. Headcount rose from 28 to 36 people after nineteen recruitments, which the report still calls insufficient. Two members left in August and September 2025 and had not been replaced by the date the report was approved, leaving a five-member body chaired by Paula Cristina Meira Lourenço. In 2025 it opened 3,201 files (up 12 percent), of which 2,037 were investigations; it started 88 administrative-offence proceedings; it issued 267 draft accusations and 262 final decisions; it adopted 480 decisions in data-breach files; and it gave 85 formal opinions on draft laws. It applied two fines totalling 47,000 euro, one against a local authority and one against a private company for unsolicited marketing messages, and it states that the 88 open proceedings could have produced 90 fines had they been completed. So the machine works and the tap is nearly closed; the correct planning assumption is that fines will rebound as staffing improves, and that in the meantime the real risk is an order to stop processing rather than a cheque. The regulator is willing to use blunt powers. In June 2022 it ordered every telecommunications provider to delete, within 72 hours, all data retained under the provision the Constitutional Court had just struck down. In December 2022 it fined a public body 4.3 million euro. Other enforcers: the gambling regulator inside Turismo de Portugal licenses and audits online operators and can enter the premises hosting the gaming system; the tax office authorises and can refuse third-country archives; the communications regulator supervises telecoms; the National Cybersecurity Centre runs the incident regime; the central bank, the insurance authority and the securities commission supervise financial firms. Rating: active, with the honest caveat about fine volume.
Sources
- Official sourceComissão Nacional de Proteção de DadosRelatório de Atividades 2025, approved 24 March 2026 — caseload, staffing, composition and fines
cnpd.pt
“No ano de 2025, a CNPD aplicou 2 coimas, no valor de 47.000€ ... o órgão colegial CNPD era (e é) composto por 5 (cinco) Membros ... 36 trabalhadores é ainda um [número insuficiente].”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosCNPD ordena eliminação dos dados das comunicações conservados ao abrigo de norma declarada inconstitucional, 9 June 2022
cnpd.pt
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosCNPD homepage — news items dated 21 to 27 July 2026 evidencing current activity
cnpd.pt
Link checked 18 August 2026
How long you must keep it — and when to delete it
There is a floor and a ceiling and they pull in opposite directions. The floor: tax books, invoices and supporting documents must be kept for ten calendar years, and online betting data for ten years inside Portugal. The ceiling: Europe's rule says delete personal data once the purpose is spent, and the telecoms law says connection data must be erased or made anonymous as soon as it is no longer needed to carry the call or message. Where the two collide, the specific legal duty to keep a record wins for that record only.
Floors verified on official sources. Ten calendar years for books, records and supporting documents under the value added tax code, kept in good order and, on paper, at premises inside Portugal. Ten years inside Portugal for online gambling activity data. Health records carry secrecy and access-notification duties rather than a single national deletion date. Ceilings. Under the electronic communications privacy statute, traffic data must be erased or anonymised when no longer needed to transmit the communication; processing for billing is allowed only until the end of the period in which the bill can lawfully be contested or payment claimed; anything beyond that, such as marketing or value-added services, needs the subscriber's prior consent, revocable at any time. How the conflict is resolved. Portugal does not have a single tie-break rule. In practice the answer is the ordinary European one: a specific statutory duty to keep a document is a legal obligation that justifies keeping it, but only that document, only for the stated period and only for that purpose. The trap is treating a ten-year tax duty as permission to keep the whole customer database for ten years. There is no longer a blanket duty on telecommunications operators to keep everyone's connection records: the Constitutional Court struck that down in April 2022 and the regulator ordered the stored data deleted.
Sources
- Official sourceAutoridade Tributária e AduaneiraCódigo do Imposto sobre o Valor Acrescentado, Article 52 — ten-year archive duty
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceANACOMLei n.º 41/2004, de 18 de agosto, Article 6 — traffic data, full text published by the communications regulator
anacom.pt
“os dados de tráfego ... devem ser eliminados ou tornados anónimos quando deixem de ser necessários para efeitos da transmissão da comunicação ... O tratamento referido no número anterior apenas é lícito até final do período durante o qual a factura pode ser legalmente contestada ou o pagamento reclamado.”
Link checked 18 August 2026
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalRegime Jurídico dos Jogos e Apostas Online, Article 34(d) — ten years of gambling data stored in national territory
srij.turismodeportugal.pt
Link checked 18 August 2026
If something goes wrong
Count at least two clocks, and three if you run critical infrastructure. Privacy breaches go to the National Data Protection Commission within 72 hours, and to affected people without undue delay when the risk to them is high. Telecoms providers have their own European duty to report within 24 hours. Under Portugal's new cybersecurity law, important and essential organisations warn the National Cybersecurity Centre early, then file a fuller report, on the pattern set by Europe's network security directive.
Clock one, privacy. The 72-hour deadline to notify the supervisory authority and the duty to warn individuals where the risk is high come straight from the European Regulation and are enforced by the national commission, which took 480 decisions in breach files in 2025 and recorded 472 breach reports, 42 percent more than the year before. Human error was the leading cause with 128 cases, phishing second with 72. Clock two, telecoms. Providers of publicly available electronic communications services report personal data breaches under the European rules made for that sector, which set a 24-hour first notification to the competent authority. Clock three, cybersecurity. The new national cybersecurity regime, approved by decree-law published on 4 December 2025 under a parliamentary authorisation of 22 October 2025, transposes Europe's second network and information security directive. That directive's pattern is an early warning within 24 hours, a fuller incident notification within 72 hours and a final report within one month, and registration of in-scope organisations with the national centre. We could not open the official Portuguese text to confirm each deadline as enacted, so treat the Portuguese specifics as medium confidence. The overlap is the operational risk. One ransomware incident at a Portuguese telecoms firm can trigger all three clocks, run by three different authorities, with the shortest one being 24 hours.
Sources
- Official sourceComissão Nacional de Proteção de DadosRelatório de Atividades 2025 — 472 breach notifications in 2025 and 480 decisions in breach files
cnpd.pt
Link checked 18 August 2026
- Official sourceEstrutura de missão para a transição digital / digital.gov.ptGoverno aprova Regime Jurídico da Cibersegurança Nacional — decree-law approved 11 November 2025 under Lei n.º 59/2025
digital.gov.pt
Link checked 18 August 2026
- Official sourceLink may be brokenDiário da RepúblicaDecreto-Lei n.º 125/2025, de 4 de dezembro — national cybersecurity legal regime
diariodarepublica.pt
Link checked 18 August 2026
What catches people out
Five things that cost people their weekend. A child can consent from 13 in Portugal, not 16. Every look at a patient's health record must be traceable and the patient must be told. Misusing or peeking at personal data is a crime here, not just a fine, and it attaches to the individual. Your invoicing software must be on the tax office's approved list, and moving it or the archive outside Europe needs permission first. And nine chunks of the Portuguese privacy statute are printed in the law but the regulator refuses to apply them.
One. Age of consent. Portugal set 13 as the minimum age at which a child can consent to online services, the lowest band the European Regulation allows and three years below the default. The education ministry's own guidance confirms it and adds that services should verify age using secure authentication. If your global product assumes 16, you are over-blocking Portuguese teenagers; if it assumes 13 everywhere, you are under-protecting children elsewhere. Two. Health data traceability. Access to health and genetic data runs on a need-to-know principle, must be handled by someone bound by professional secrecy, and the person the data is about must be notified of any access to it, with the organisation responsible for providing the traceability and notification mechanism. Very few electronic record systems ship with this switched on. Three. Criminal liability. The Portuguese privacy statute creates criminal offences, including using data in a way incompatible with the purpose it was collected for, improper access to personal data, and breach of the duty of secrecy. On top of that the Criminal Code punishes revealing a secret learned through your job with up to one year in prison or a fine. These attach to people, not only companies, and no cyber-insurance policy fixes them. Four. The tax stack. Invoicing software used in Portugal must be certified in advance by the tax office and appear on its published list. Paper accounting archives must be at premises in Portugal. An electronic archive may sit anywhere in the European Union, but outside it you need prior authorisation, and if the invoicing system itself sits in a third country you must create a tax-office user account able to query the live system in real time from terminals inside Portugal. Foreign software-as-a-service billing platforms fail this test more often than anything else on this page. Five. The statute you cannot trust to a text search. Since September 2019 the regulator has publicly refused to apply nine sets of provisions of the national implementing statute, including its scope rule, parts of the fining rules and two transitional provisions, on the ground that they contradict the European Regulation. They remain printed in the law. A search of the statute will therefore return rules that will not be enforced, and advice built on them is wrong in both directions. Sixth, smaller: you must tell the regulator who your data protection officer is. Portugal set no deadline for doing so, which is exactly why organisations forget.
Sources
- Official sourceDireção-Geral da Educação, Ministério da EducaçãoRGPD — Consentimento de menores, 13 anos
dge.mec.pt
“Portugal optou pelos 13 anos como idade mínima para o consentimento requerida pelo RGPD.”
Link checked 18 August 2026
- Official sourceEntidade Reguladora da SaúdeHealth regulator guide — Article 29 of Lei n.º 58/2019 on health and genetic data, secrecy and access notification; criminal offences
ers.pt
“o titular dos dados deve ser notificado de qualquer acesso realizado aos seus dados pessoais, cabendo ao responsável pelo tratamento assegurar a disponibilização desse mecanismo de rastreabilidade e notificação.”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2025/267 — clarifications on the data protection officer regime, approved 1 April 2025
cnpd.pt
“a constituição do EPD, por nomeação obrigatória ou a nomeação voluntária, a sua publicitação ... e a sua comunicação à CNPD é um dever legal das entidades responsáveis pelo tratamento de dados e dos subcontratantes.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraTax office frequently asked questions — certified invoicing software and third-country locations
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2019/494 — provisions of the national statute the regulator will not apply
cnpd.pt
Link checked 18 August 2026
What's changing next
Three things land in the next year or so. Public bodies must sort their data and systems by importance under the sovereign cloud plan, with the sorting due by the middle of 2027. The new cybersecurity regime is being switched on, with registration and incident duties for many more organisations. And the privacy regulator is hiring, so the near-zero fine count of 2025 is unlikely to last. Separately, Europe's rule that cloud switching must be free of charge starts in January 2027.
Dated items. 12 January 2027: under the European Data Act all cloud switching charges and data egress fees must fall to zero. 30 June 2027: Portuguese public bodies must have classified their processes, data and systems under the National Sovereign Cloud Plan approved on 14 May 2026, with the qualification methodology set by the state transformation agency and the National Cybersecurity Centre. Through 2026 and 2027: staged application of the national cybersecurity regime published on 4 December 2025, including registration with the National Cybersecurity Centre. Also live: the appeal against the European Union-United States Data Privacy Framework before the Court of Justice, and the European Data Protection Board's letter of 31 July 2026 asking the Commission to re-examine that framework. Dormant switches, which matter more than pending bills. First, general retention of everyone's telephone and internet connection records. Parliament has legislated for it before, the Constitutional Court struck the rules down in April 2022 and struck down a replacement in December 2023, and the 2024 statute deliberately replaced blanket retention with judge-ordered preservation in serious-crime cases. Political pressure to try again is constant, and a new law could be passed and in force within weeks. Second, the tax office's authorisation power: it decides whether your archive or invoicing system may sit outside Europe, it can attach conditions, and nothing stops it tightening its practice without new legislation. Third, the gambling regulator's power to require that every component of the technical gaming system be somewhere it can reach, which is an access rule that can be exercised as a location rule. Fourth, sovereign cloud classification: the plan is deliberately risk-based rather than location-based today, but the classification exercise is exactly the machinery through which a location rule could be introduced later at procurement level, with no new statute.
Sources
- Official sourceGoverno de PortugalCouncil of Ministers communiqué, 14 May 2026 — sovereign cloud plan, classification of public processes by 30 June 2027
portugal.gov.pt
Link checked 18 August 2026
- Official sourcedigital.gov.ptPlano Nacional de Nuvem Soberana
digital.gov.pt
Link checked 18 August 2026
- Official sourceTribunal ConstitucionalAcórdão n.º 268/2022 — blanket retention of communications data unconstitutional
tribunalconstitucional.pt
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionData Act, Regulation (EU) 2023/2854 — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries3 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Regime Jurídico dos Jogos e Apostas Online, aprovado pelo Decreto-Lei n.º 66/2015, de 29 de abril
Act of parliament · Decreto-Lei n.º 66/2015, artigos 32.º e 34.º
Portugal's hardest storage rule. A licensed online gambling operator must install the system that registers Portuguese players inside Portugal, store ten years of betting data inside Portugal, and keep every part of the gaming system somewhere the regulator can walk in or log in at any moment.
Enforced by Gambling Regulation and Inspection Service
Transfer model: No restriction
What it makes you do
- Keep the data in the countryThe entry-and-registration infrastructure must be installed in national territory and must hold the information on every gambling operation.
- Keep data for a minimum period — 10 yearsGambling activity data must be stored in national territory for ten years.
- Independent auditEvery component of the technical gaming system must sit in premises the regulator can enter at any time, and the regulator must be able to reach any component remotely from its own offices whatever the location. Certification and homologation before launch, periodic audits after.
- Hold a security certificateSecurity controls must follow the ISO 27001 international standard.
- Keep records of processingFull logging of every player action, every operation and every change to the platform.
What it costs if you get it wrong
- Loss of your licenceFailure to keep meeting the technical system requirements.
- Order to stopRefusal of homologation or withdrawal of approval of the technical system.
Sources
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalConsolidated Regime Jurídico dos Jogos e Apostas Online, Articles 32 and 34, version dated 31 March 2020
srij.turismodeportugal.pt
“a) Ter localizados todos os componentes do sistema técnico de jogo em instalações às quais a entidade de controlo, inspeção e regulação possa, a todo o momento, aceder.”
Link checked 18 August 2026
- Official sourceServiço de Regulação e Inspeção de Jogos, Turismo de PortugalObrigações das entidades — operator duties published by the gambling regulator
srij.turismodeportugal.pt
Link checked 18 August 2026
Lei n.º 41/2004, de 18 de agosto — tratamento de dados pessoais e proteção da privacidade no setor das comunicações eletrónicas
Act of parliament · Lei n.º 41/2004, artigos 3.º, 4.º e 6.º
Portugal's telecoms privacy law contains no storage location rule. It works the other way: connection data must be deleted or anonymised as soon as it is no longer needed to carry the communication, and kept for billing only while the bill can still be disputed.
Enforced by National Communications Authority
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Delete data after a periodTraffic data must be erased or made anonymous once it is no longer needed to transmit the communication. Billing use is lawful only until the period for contesting the bill or claiming payment ends.
- Get consentMarketing or value-added use of traffic and location data needs prior consent, revocable at any time.
- Secure the dataProviders must warn subscribers free of charge where there is a particular risk of a network security breach.
- Report breaches to the regulator — within 24 hoursTelecoms-specific breach reporting under the European rules for that sector. Deadline not separately re-verified against a Portuguese source in this run.
What it costs if you get it wrong
- Fixed maximum fineAdministrative offences supervised by the communications regulator. Amounts not verified in this run.
Sources
- Official sourceANACOMLei n.º 41/2004, full text published by the communications regulator
anacom.pt
“os dados de tráfego ... devem ser eliminados ou tornados anónimos quando deixem de ser necessários para efeitos da transmissão da comunicação.”
Link checked 18 August 2026
Lei n.º 32/2008, de 17 de julho — conservação de dados gerados no contexto da oferta de serviços de comunicações eletrónicas
Act of parliament · Lei n.º 32/2008, artigos 4.º, 6.º e 9.º; Acórdão do Tribunal Constitucional n.º 268/2022
The law telling telephone and internet providers to keep everyone's connection records is still printed in the statute book but cannot be enforced: the Constitutional Court struck the core provisions down in April 2022 and the regulator ordered the stored data deleted within 72 hours. A 2024 statute replaced blanket retention with judge-ordered preservation in serious criminal cases.
Enforced by National Data Protection Commission
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep data for a minimum periodThe blanket one-year retention duty is unenforceable. Since February 2024 traffic and location data may be preserved only where a judge of the Supreme Court's criminal divisions authorises it for a serious crime, with a decision due within 72 hours.
Sources
- Official sourceTribunal ConstitucionalAcórdão n.º 268/2022 do Tribunal Constitucional, 19 April 2022
tribunalconstitucional.pt
“Declarar a inconstitucionalidade, com força obrigatória geral, da norma constante do artigo 4.º da Lei n.º 32/2008, de 17 de julho, conjugada com o artigo 6.º da mesma lei.”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosRegulator orders deletion of retained communications data, 9 June 2022
cnpd.pt
Link checked 18 August 2026
- Official sourceLink may be brokenDiário da RepúblicaLei n.º 18/2024, de 5 de fevereiro — access to metadata for criminal investigation
diariodarepublica.pt
Link checked 18 August 2026
- Secondary sourceGarriguesAnalysis of Lei n.º 18/2024 — judge-ordered preservation replaces blanket retention
garrigues.com
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Lei n.º 58/2019, de 8 de agosto — assegura a execução, na ordem jurídica nacional, do Regulamento Geral sobre a Proteção de Dados
Act of parliament · Lei n.º 58/2019
Portugal's implementation of the European rules. It adds a low age of digital consent, strong secrecy and access-notification duties for health data, and criminal offences that attach to individuals. Several of its provisions are printed in the law but not applied by the regulator.
Enforced by National Data Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 13Portugal set the lowest age band Europe allows. Above 13 a child may consent alone to online services.
- Appoint a data protection officerCompulsory for the State, the autonomous regions, municipalities and public institutes. The officer's name must be communicated to the regulator; Portugal set no deadline for doing so.
- Tell people what you doHealth and genetic data: the person must be notified of any access to their records.
- Keep logsHealth and genetic data: the controller must provide a traceability mechanism recording who accessed what.
- Extra vendor secrecy termsStaff, contractors, students and researchers with access to health or genetic data are bound by a statutory duty of secrecy, wider than an ordinary processor agreement.
- Secure the data
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover (about $22 million at the floor) — about $22 millionThe European Regulation's upper tier, applied by the national regulator.
- Criminal liability: Prison or fine; the Criminal Code punishes revealing a secret learned through your job with up to one year in prison or a fine of up to 240 daysUsing data in a way incompatible with the collection purpose, improper access to personal data, breach of the duty of secrecy.
Sources
- Official sourceEntidade Reguladora da SaúdeHealth regulator guide quoting Article 29 of Lei n.º 58/2019 and the criminal offences in Articles 46, 47 and 51
ers.pt
Link checked 18 August 2026
- Official sourceDireção-Geral da EducaçãoAge of consent set at 13 in Portugal
dge.mec.pt
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2025/267 — data protection officer duties, approved 1 April 2025
cnpd.pt
Link checked 18 August 2026
Deliberação/2019/494 da Comissão Nacional de Proteção de Dados — desaplicação de normas da Lei n.º 58/2019
Regulator guideline · Deliberação/2019/494
The regulator announced in September 2019 that it will not apply nine sets of provisions of the national privacy statute, including its scope rule and parts of its fining rules, because European law takes precedence. They are still printed in the statute, so a text search of Portuguese law returns rules that are not enforced.
Enforced by National Data Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
Sources
- Official sourceComissão Nacional de Proteção de DadosDeliberação/2019/494, approved 3 September 2019
cnpd.pt
“o legislador não pode copiar o texto do regulamento quando desnecessário nem interpretá-lo ou acrescentar condições adicionais.”
Link checked 18 August 2026
- Official sourceComissão Nacional de Proteção de DadosCNPD decision archive listing Deliberação 494/2019 and the related Deliberação 495/2019 on fines against public bodies
cnpd.pt
Link checked 18 August 2026
Código do IVA, artigo 52.º, e Decreto-Lei n.º 28/2019, de 15 de fevereiro (processamento de faturas e arquivo de documentos)
Act of parliament · CIVA art. 52; Decreto-Lei n.º 28/2019, arts. 5, 19 to 21
Every business in Portugal must keep ten years of invoices and accounting records, on premises in Portugal unless it is an electronic archive with guaranteed online access. Archives may sit anywhere in Europe, but going outside Europe needs written permission from the tax office first, and so does putting your billing software there.
Enforced by Tax and Customs Authority
Transfer model: Approval each time · Accepted routes: Government sign-off needed
What it makes you do
- Keep data for a minimum period — 10 yearsTen calendar years for books, records and supporting documents.
- Keep the data in the countryRecords must be kept at premises in national territory; electronic archiving escapes this only where complete online access to the data is guaranteed. An archive elsewhere in the European Union is free; outside it needs prior authorisation from the tax office.
- Register or notifyInvoicing software must be certified in advance by the tax office and appear on its published list of certified programs.
- Independent auditIf the invoicing system sits in a third country you must give the tax office a user account able to query the live system in real time from terminals inside Portugal, including download.
What it costs if you get it wrong
- Fixed maximum fine: Tax-offence fines under the general tax penalty regimeFailure to archive, to use certified software, or to obtain authorisation for a third-country location.
Sources
- Official sourceAutoridade Tributária e AduaneiraCódigo do IVA, Article 52
info.portaldasfinancas.gov.pt
“arquivar e conservar em boa ordem durante os 10 anos civis subsequentes ... em estabelecimento ou instalação situado em território nacional.”
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraElaboração de faturas e localização de arquivo fora da União Europeia
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
- Official sourceAutoridade Tributária e AduaneiraTax office frequently asked questions on Decreto-Lei n.º 28/2019
info.portaldasfinancas.gov.pt
Link checked 18 August 2026
Regime Jurídico da Cibersegurança, aprovado por decreto-lei publicado em 4 de dezembro de 2025 ao abrigo da autorização legislativa da Lei n.º 59/2025
Act of parliament · Decreto-Lei n.º 125/2025, de 4 de dezembro; Lei n.º 59/2025, de 22 de outubro
Portugal's transposition of Europe's second network and information security directive, published in December 2025. It brings many more organisations into a registration and incident-reporting regime run by the National Cybersecurity Centre. It contains no storage location rule that we could find.
Enforced by National Cybersecurity Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Register or notifyEssential and important entities must register with the National Cybersecurity Centre. Portuguese deadlines not verified against an official text in this run.
- Report cyber incidents — within 24 hoursEarly warning within 24 hours on the European network security directive's pattern, then a fuller notification within 72 hours and a final report within one month.
- Secure the data
What it costs if you get it wrong
- Fixed maximum fine: Up to €10 million or 2% of worldwide turnover for essential entities under the European directive's framework — about $11 millionFailure to manage cyber risk or to report an incident. Portuguese amounts not verified in this run.
Sources
- Official sourcedigital.gov.ptGoverno aprova Regime Jurídico da Cibersegurança Nacional
digital.gov.pt
Link checked 18 August 2026
- Official sourceLink may be brokenDiário da RepúblicaDecreto-Lei n.º 125/2025, de 4 de dezembro
diariodarepublica.pt
Link checked 18 August 2026
Plano Nacional de Nuvem Soberana
Government policy document · Resolução do Conselho de Ministros approved at the Council of Ministers of 14 May 2026
Portugal's sovereign cloud plan, approved in May 2026, is risk-based rather than location-based: it sorts public data by importance instead of naming a country, while pointing public bodies towards European and national capabilities. Public bodies must complete the classification by 30 June 2027.
Enforced by National Cybersecurity Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Prove the data stays under local control — from 30 June 2027Public bodies must classify their processes, data and systems by level of importance and match security rules to each level. The methodology is set by the state transformation agency together with the National Cybersecurity Centre.
Sources
- Official sourceGoverno de PortugalCouncil of Ministers communiqué of 14 May 2026 approving the plan
portugal.gov.pt
“dados e processos são classificados por níveis de importância, com regras de segurança adequadas a cada caso.”
Link checked 18 August 2026
- Official sourcedigital.gov.ptCloud in the public administration — sovereign cloud plan and the 2026-2027 digital transformation strategy
digital.gov.pt
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Regulamento Geral sobre a Proteção de Dados — Regulamento (UE) 2016/679
Directly binding regulation · Regulation (EU) 2016/679
Europe's general data protection law. It never says where data must be stored. It says what you must have in place before personal data leaves Europe, and it reaches companies outside Europe that target people in Portugal.
Enforced by National Data Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Put a transfer safeguard in placeA valid instrument plus a documented assessment of the destination country's surveillance laws.
- Report breaches to the regulator — within 72 hours
- Tell affected peopleWithout undue delay where the risk to individuals is high.
- Appoint a local representativeRequired where the controller has no establishment in Europe. Need not be located in Portugal.
- Keep records of processing
- Assess high-risk projects
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover, whichever is higher (about $22 million at the floor) — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator's order.
- Order to stopOrder to stop processing or to suspend flows to a country outside Europe.
Sources
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation, official consolidated text
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — current list, verified 18 August 2026
commission.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact entry-into-force date, registration deadlines, incident-reporting deadlines and fine levels of the new national cybersecurity regime published on 4 December 2025
The official gazette site serves its texts only to browsers running JavaScript and the National Cybersecurity Centre's site is behind bot protection. Both defeated every fetch attempt on 18 August 2026. The deadlines given follow the European directive's pattern, not a verified Portuguese text.
The content of the Bank of Portugal notice of December 2025 on outsourcing registers and reporting, and whether it says anything about data location
The bank's own website returned a bot-protection challenge to every request. We treat it as a reporting and register duty only. No banking localisation rule is asserted.
Whether the insurance and securities regulators impose cloud or outsourcing location conditions
Not separately verified in this run. Their rules were not opened on their own sites, so the statement that no localisation exists in insurance and securities is a not-found result, not a proven negative.
Whether the consolidated online gambling law published by the regulator, whose text is dated 31 March 2020, reflects amendments made after that date
The regulator publishes this consolidation itself and lists no newer version, but we could not confirm from the gazette that Articles 32 and 34 are unamended since 2020.
Whether the regulator's 2019 decision not to apply nine sets of provisions of the national privacy statute is still being applied in 2026
The decision is published and has never been withdrawn as far as we can see, and Parliament has not amended the provisions. We found no 2025 or 2026 statement restating it, so this is inference from silence.
The fine counts per year read from a chart in the regulator's 2025 annual report (90 in 2024, 71, 60, 23 and 15 in earlier years)
The 2025 figure of two fines worth 47,000 euro is stated in words in the report. The earlier yearly figures come from a bar chart whose labels extract imperfectly from the PDF, so the year-to-number mapping is our reading.
That no localisation rule exists for health records, education data, mapping and geospatial data or defence data in Portugal
Searched on 18 August 2026 and none found on official sites. This is an absence of evidence. Health carries strong secrecy, need-to-know and access-notification duties instead.
The exact period during which a telecoms bill can be contested, which sets the ceiling on keeping billing data
The statute defines the ceiling by reference to that period rather than by a number of months, and we did not verify the underlying consumer-law period against an official source.
Whether the two vacant seats on the data protection commission were filled between 24 March 2026 and 18 August 2026
The vacancy is evidenced up to the date its annual report was approved. We cannot prove a negative for the months since.
Whether the 24-hour telecoms breach-reporting deadline applies in Portugal exactly as set out in the European sector rules
Asserted from the European instrument for that sector, not from a Portuguese regulator page opened in this run.
60-day cadence. Portugal has four switches that can flip without a long consultation: a new attempt at general telecoms data retention, tightening of the tax office's third-country authorisation practice, the gambling regulator's access power used as a location power, and the sovereign cloud classification hardening into procurement-level localisation. The privacy regulator's fine volume is also expected to rebound as it staffs up, which changes the risk picture without any change in the law.
Freshness and refresh
Freshness
Checked yesterday — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Put this next to another country
Portugal versus
Compare