Information Technology 2026

PORTUGAL Law and Practice Contributed by: Luís Portela de Carvalho, Pedro Cortés and Cláudia de Azevedo Neves, Lektou

7.4 Information Notification Requirements GDPR Breach Notification Where a personal data breach occurs, the controller must notify CNPD without undue delay and, where feasible, within 72 hours of becoming aware of it, unless the breach is unlikely to create risk for indi - viduals. Processors must notify the controller without undue delay. If the breach is likely to result in a high risk to individuals, the controller may also need to Entities within the scope of Decree-Law No 125/2025 are subject to a separate notification regime for signifi - cant cybersecurity incidents to the competent cyber - security authority (CNCS). The process is phased and may include an initial notification within 24 hours, an update within 72 hours where relevant, a notification of the end of the significant impact and a final report within the applicable statutory deadline, generally 30 business days after notification of the end of the sig - nificant impact. notify the affected data subjects. Cybersecurity Incident Notification Telecoms providers may also have to notify ANACOM of significant network security or integrity incidents under sector-specific rules, with short-phased notifi - cation deadlines. If personal data is affected, CNPD The legal duty to notify usually sits with the data con - troller, the telecoms operator or the essential or impor - tant entity. In contracts, however, customers typically require suppliers to notify them quickly, provide tech - nical information and assist with investigation, mitiga - tion and regulatory reporting. 7.5 Supply Chain Requirements 7.5.1 Risk Assessments and Due Diligence on Suppliers and Extended Supply Chains The GDPR requires controllers to appoint only proces - sors that can provide “sufficient guarantees” of com - pliance. In practice, this means that controllers should carry out due diligence before engaging a processor and maintain an appropriate level of oversight during the relationship. notification may also be required. Customer and Supplier Roles

safeguards (such as standard contractual clauses or binding corporate rules), in the absence of such a decision. In situations where there is no adequacy decision nor appropriate safeguards, Article 49 GDPR allows trans - fers only under specific derogations, such as explicit informed consent of the data subject, necessity for the performance of a contract, important reasons of public interest, legal claims, vital interests or from a public register. Non-Personal Data There is no equivalent general restriction on transfers of non-personal data. However, sectoral confidential - ity rules, trade secrets, export control requirements or contractual restrictions may still be relevant, depend - ing on the type of data and the sector involved. 7.3 Information Security and Cybersecurity Standards Portuguese law generally requires risk-based secu - rity rather than adherence to one mandatory technical standard. Under the GDPR, controllers and processors must implement appropriate technical and organisational measures. For entities covered by Decree-Law No 125/2025, which entered into force on 3 April 2026, the cyberse - curity regime requires risk-based technical, operation - al and organisational measures and takes into account a national cybersecurity reference framework. The implementing Regulation No 756/2026, published on 22 June 2026, should also be checked for operational details before finalising incident reporting and plat - form references. Sectoral regulators may recommend or expect adher - ence to recognised standards (eg, ISO 27001, NIST, or CSA CCM) as evidence of best practice, but these standards are typically not expressly mandated by legislation.

63 CHAMBERS.COM

Powered by