Cybersecurity 2026

PORTUGAL Trends and Developments Contributed by: Ricardo Henriques, Diogo Pereira Duarte, José Maria Alves Pereira and Leonor de Sá e Frade, Abreu Advogados

Penalties for breaches are segmented by type of per - son and economic activity of the breaching company. For infractions committed in the course of the activi - ties of credit institutions, investment firms, securities depositories, entities managing regulated markets, multilateral or organised trading facilities, central counterparties, data-reporting service providers or collective investment undertaking management companies, payment institutions, electronic money institutions, insurance and reinsurance companies, account information service providers, crypto-asset service providers, critical benchmark administrators or pension fund management entities: • if the offender is a legal (collective) person (a company or equivalent), the fine shall be between EUR10,000 and EUR5 million; and • if the offender is a natural (single) person (an administrator officer or director), the fine shall be between EUR5,000 and EUR2.5 million. For infractions committed in the context of the activity of insurance intermediaries, reinsurance intermediar - ies and ancillary insurance intermediaries: • if the offender is a legal (collective) person (a company or equivalent), the fine shall be between EUR3,000 and EUR2.5 million; and • if the offender is a natural (single) person (an administrator officer or director), the fine shall be between EUR1,000 and EUR500,000. For infractions committed in the context of the activity of collaborative financing service providers: • if the offender is a legal (collective) person (a company or equivalent), the fine shall be between EUR2,500 and EUR500,000; and • if the offender is a natural (single) person (an administrator officer or director), the fine shall be between EUR400 and EUR500,000. Despite these limits, the maximum applicable fine is increased to the greater of the following amounts: • three times the economic benefit obtained, even if wholly or partly in the form of avoided losses; or

• in the case of administrative offences provided for in the first subparagraph of the previous paragraph and when committed by legal persons, 10% of turnover, according to the latest consolidated or individual accounts approved by the management body. Decree-Law No 125/2025 Decree-Law No 125/2025 is a horizontal framework transposing Directive (EU) 2022/2555 of the European Parliament and of the Council of December 14th on measures for a high common level of cybersecurity across the Union. The Cybersecurity Legal Framework will take effect on 3 April 2026, with the initial obliga - tions becoming applicable from 4 May 2026. Pursuant to Article 8, entities must self-identify as essential or important and, pursuant to Article 35, complete their registration on the National Cybersecu - rity Centre (CNCS) electronic platform within 60 days of the date on which it becomes available. The CNCS will then review this self-identification and determine, in accordance with the criteria established by law, the qualification of the entities, informing them of its deci - sion within 30 days. It is the responsibility of the enti - ties to keep the information on the CNCS electronic platform up to date. These essential or important enti - ties must also, by 4 May 2026, notify the CNCS of the person(s) designated to perform the functions of Cybersecurity Officer and permanent point of contact, providing their contact details and the information provided for in Articles 31 and 32 of the Cybersecu - rity Legal Framework (subject to the relevant CNCS Regulations). From the outset, members of the board and other directors will be subject to an accountability obliga - tion, under which they will be responsible not only for approving measures but also for providing for the production and updating of documentation and records relating to the adoption, implementation and execution of cybersecurity measures appropriate to the entity they manage. Management bodies must also appoint a person responsible for cybersecurity in the entity they man - age. This person may be a member of a management body – who, in addition to their duties, takes on the

276 CHAMBERS.COM

Powered by