PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados
(Extra)territorial reach The GDPR may apply to processing outside the Euro - pean Economic Area (EEA) where Article 3 conditions are met (eg, the offering of goods or services, irre - spective of whether a payment of the data subject is required, to such data subjects in the Union). Regulation (EU) 2019/881 of 17 April 2019 on ENISA and on Information and Communications Technology Cybersecurity Certification (the “Cybersecurity Act”) This was implemented by Commission Implementing Regulation (EU) 2024/482 of 31 January 2024. Subject matter The Cybersecurity Act lays down the objectives, tasks and organisational matters relating to ENISA and a framework for the establishment of European cyber - security certification schemes. Scope The Cybersecurity Act applies to all natural or legal persons involved in the development, provision or use of ICT products, services or processes that may fall under a European cybersecurity certification scheme. (Extra)territorial reach The Cybersecurity Act may apply extraterritorially when ICT products, services or processes are placed on the EU market or used within the EU. Regulation (EU) 2022/2554 of 14 December 2022 (DORA) and Directive (EU) 2022/2556 of 14 December 2022 Regarding Digital Operational Resilience for the Financial Sector The DORA framework was implemented by Law No 73/2025 of December 23rd. Subject matter The DORA framework places the onus on financial entities to exercise comprehensive oversight over ICT risks. It requires institutions to establish robust capabilities for effective ICT risk management, and to implement mechanisms and policies for addressing all ICT-related incidents.
Scope The DORA Framework and Law No 73/2025 apply to the following entities: • insurance and reinsurance companies with head - quarters in Portugal; • pension fund management entities authorised in Portugal; and • other financial institutions falling within the scope of the DORA Regulation. Note that savings banks existing as of 1 January 1985 are excluded, except those operating as corporations. (Extra)territorial reach On an EU level, DORA applies to all the above-men - tioned entities that provide services in the EU and are located therein. Its territorial scope is broad and extends to organisations based outside the EU, where, for example, they offer certain financial services in the EU market or contract with financial entities that are in-scope of DORA. Directive (EU) 2022/2555 of 14 December 2022 (the “NIS2 Directive”) This was transposed by Decree-Law No 125/2025 of The NIS2 Directive is the cornerstone of cybersecurity in the EU, establishing a framework that ensures a high, common level of cybersecurity across the EU. Scope The Directive applies to both essential and important entities that verify a set of: • formal requirements (ie, size of the undertaking or the nature of the public entity); • material requirements typically associated with the criticality of the sector in which the entity operates; and • the territorial scope of application of the Directive. (Extra)territorial reach Decree-Law No 125/2025 applies to entities that have an establishment in Portugal or, where they are provid - ers of public electronic communications networks or December 4th. Subject matter
259 CHAMBERS.COM
Powered by FlippingBook