Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

incidents and cyber-threats and establishes manda - tory reporting obligations. These requirements must be read together with: • Commission Delegated Regulation (EU) 2024/1772, which defines incident-classification criteria, mate - riality thresholds and reporting content for major incidents; • Commission Delegated Regulation (EU) 2025/301, which specifies the content and deadlines for initial, intermediate and final reports on major ICT incidents, as well as voluntary notifications of sig - nificant cyber-threats; and • Commission Implementing Regulation (EU) 2025/302, which provides the standard forms, templates and procedures for reporting major ICT incidents and notifying significant cyber-threats. 3.4 Operational Resilience Enforcement Under DORA’s institutional framework, the Lead Overseer is granted extensive supervisory powers over critical ICT third-party service providers. These include the ability to: • request all relevant information and documentation pursuant to Article 37; • conduct investigations and on-site inspections under Articles 38 and 39; and • require post-oversight reports detailing the actions or remedial measures implemented in response to issued recommendations. Article 50 further empowers competent authorities to: • access any documents or data, in any form, deemed necessary for the performance of their duties and obtain copies thereof; • carry out on-site inspections and investigations; and • require corrective or remedial measures in cases of non-compliance with the Regulation. At national level, Law No 73/2025 identifies several administrative offences, including: • the provision of information to the competent authority or to customers that is not complete, true,

current, clear, objective and lawful, or the omission of such provision; • failure to co-operate with the competent authorities in crisis and contingency management exercises involving cyber-attack scenarios; and • the violation of a set of duties, without prejudice to others established in the DORA Regulation, listed illustratively in Law No 73/2025. Under this law, the competent authorities referred to in 1.3 Cybersecurity Regulators may investigate administrative offences and impose fines and ancillary sanctions. Fines range from: • EUR2,500 to EUR5 million for legal entities; and • EUR400 to EUR2.5 million for individuals. The maximum fine may be increased to: • three times the economic benefit obtained (includ - ing avoided losses); or • 10% of annual turnover for certain legal entities. 3.5 International Data Transfers DORA requires financial institutions to ensure that third-party ICT service providers meet spe cific requirements in their contractual relation ships. These include incorporating certain con tractual provisions (Article 30) and assessing whether conditions for supervisory oversight – such as those related to subcontracting – are satisfied (Article 28 (4) (b)). In particular, financial entities must ensure that out - sourcing and ICT service contracts specify the loca - tions where functions are performed and where data is stored or processed, and must be notified in advance of any intended changes. When outsourcing involves personal data processed outside the EEA, GDPR transfer rules apply. Transfers to third countries must rely on a lawful transfer mechanism such as adequacy decision, standard contractual clauses or binding cor - porate rules. In practice, regulators typically expect that financial entities assess third-country risks as part of their operational-resilience and outsourcing due-diligence obligations. This includes evaluating the legal and

267 CHAMBERS.COM

Powered by