Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

Abreu Advogados Av. Infante Dom Henrique 26 1149-096, Lisbon Portugal

Tel: +351 217 231 800 Fax: +351 217 231 899 Email: lisboa@abreuadvogados.com Web: abreuadvogados.com/en/

1. General Overview of Laws and Regulators 1.1 Cybersecurity Regulation Strategy Portugal has shown a consistent commitment to strengthening national cybersecurity. In recent years, the government adopted the National Cybersecurity Strategy for 2019–2023; however, no updated version has lately been issued. Given the increasingly complex geopolitical envi - ronment and the rapid pace of technological devel - opment, the law transposing the NIS2 Directive is pushing the government to design a new National Cybersecurity Strategy. This updated strategy will set out the framework, priorities, strategic objectives and governance model, clarifying the roles and respon - sibilities of national stakeholders. According to the National Digital Strategy Action Plan for 2026–2027, this instrument will be prepared and implemented by the National Cybersecurity Centre (hereafter, CNCS) and the National Security Office by the second half of 2027. On another note, the CNCS Cybersecurity Report 2025 – Risks & Conflicts noted a clear rise in both the volume and sophistication of cybersecurity inci - dents throughout 2024, driven by extensive phishing and smishing campaigns, diverse social-engineering tactics, and the exploitation of system vulnerabilities. The Report concluded with the need for operators to strengthen both technical and human capabilities and to develop cyber-resilience strategies that take the entire value chain into account.

1.2 Cybersecurity Laws The Portuguese cybersecurity legal framework heavily derives from EU legislation, which has played a promi - nent role in harmonising and ensuring a high standard for cybersecurity in the EU. Accordingly, for each prin - cipal statute pertaining to cybersecurity in Portugal, a summary follows which outlines the respective sub - ject matter, scope of application, and (extra)territorial reach. Regulation (EU) 2016/679 of 27 April 2016 on the Protection of Natural Persons With Regard to the Processing of Personal Data and on the Free Movement of Such Data (the “General Data Protection Regulation” – GDPR) This was implemented by Law No 58/2019 of August 8th. Subject matter Controllers and processors must assess the inherent risk of data processing operations and adopt appro - priate technical and organisational security measures in order to safeguard the processing of personal data and data subjects’ fundamental rights. Scope The GDPR applies to any natural or legal person, pub - lic authority, agency or other entity acting as a con - troller, processor or recipient of personal data under its provisions. As for Portuguese law, it applies to all personal data processing carried out within national territory, irrespective of whether the controller or pro - cessor is public or private.

258 CHAMBERS.COM

Powered by