Cybersecurity 2026

PORTUGAL Law and Practice Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

However, it is mandatory that it has in place adequate mechanisms for detecting personal data breaches. When the controller becomes aware of such a breach, it must consider the obligation to notify the supervi - sory authority without undue delay where there is a foreseeable risk to the rights and freedoms of natural persons. If the controller or the supervisory authority subsequently conclude that there is a high risk to the rights of data subjects, it is obliged to communicate the personal data breach to the data subjects without undue delay. Law No 58/2019 does not provide any further speci - fications regarding the security of processing. Never - theless, it is worth noting that the CNPD has issued guidelines (Diretriz/2023/1, CNPD, available only in Portuguese here ) proposing indicative security meas - ures to be implemented by data controllers. In terms of organisational measures, the CNPD suggests that controllers and processors consider implementing analysis procedures for monitoring network flows and carrying out periodic IT security audits and vulnerabil - ity assessments. With regard to technical measures, the CNPD suggests, inter alia, increasing the robust - ness of servers. Given the synergies between cybersecurity and the protection of personal data, the CNCS acts in col - laboration with the CNPD whenever a cybersecurity incident involves a breach of personal data. 6.2 Cybersecurity and AI AI is elevating cybersecurity threats by enabling the easy generation of malware, deepfakes and other cyber-threats. On the other side of the coin, AI sys - tems are particularly vulnerable to cyber-attacks and cybersecurity incidents. These incidents can impact not only the AI system’s performance but also its end users. For instance, a cybersecurity breach affecting the algorithm or training data of a credit-scoring AI system could affect decisions on a user’s access to credit. Therefore, the AI Act (Regulation (EU) 2024/1689) emphasises the necessity for high-risk AI systems to maintain a high level of accuracy, robustness and cybersecurity (see Article 15). AI systems with a high risk to fundamental rights and freedoms must be

resistant to unauthorised access and equipped with adequate measures for detecting, preventing and responding to cybersecurity incidents. For this purpose, providers of high-risk AI systems can seek cybersecurity certification under Regula - tion (EU) 2019/881. In such a case, Article 43 of the AI Act established a presumption of compliance with the cybersecurity requirements outlined in Article 15. Additionally, the cybersecurity measures implement - ed by the provider must be included in the technical documentation accompanying the system. When the AI Act was approved, there was not yet a final agreement from European legislative bodies on the CRA. Nonetheless, the AI Act’s recitals mention the co-ordination between the two laws. Recitals 77 and following of the AI Act are mirrored in Recital 51 and Article 12 of the CRA, which presumes compli - ance with Article 15 of the AI Act when the high-risk AI system meets the essential cybersecurity require - ments in Annex I of the CRA. Furthermore, the procedure for assessing compli - ance with the essential cybersecurity requirements for a product with digital elements that is simultane - ously classified as a high-risk AI system will follow the provisions of Article 43 of the AI Act. However, in the event that the application of this provision would lead to a reduction in the level of security required for critical or important products with digital elements, the conformity assessment procedure provided for in the CRA with regard to the essential cybersecurity requirements should apply by way of derogation from this rule. 6.3 Cybersecurity in the Healthcare Sector Entities operating in the healthcare sector will, in prin - ciple, be qualified as essential under the new Cyber - security Legal Framework, provided they meet the formal and territorial criteria laid down in such Decree- Law. Additionally, healthcare providers may also be classified as critical entities under the CER framework, thereby becoming subject to comprehensive require - ments relating to cybersecurity, cyber-resilience and physical security.

271 CHAMBERS.COM

Powered by