PORTUGAL Law and Practice Contributed by: Luís Portela de Carvalho, Pedro Cortés and Cláudia de Azevedo Neves, Lektou
Decree-Law No 125/2025, which entered into force on 3 April 2026, adds a more explicit supply-chain dimension for entities within scope. Essential and important entities must consider supplier and ser - vice-provider security as part of their cybersecurity risk management. The implementing Regulation No 756/2026 should be verified for operational require - ments, including supplier classification and assess - ment processes. Portuguese organisations are there - fore increasingly using structured vendor assessment processes, including questionnaires, certification checks, contractual security schedules and targeted audits for higher-risk suppliers. 7.5.2 Data Protection or Information/Cybersecurity Terms in Supply Agreements Data Protection Terms Where a supplier acts as processor, the GDPR requires a binding contract or equivalent legal act. The agree - ment must describe the processing and include the mandatory Article 28 terms, including instructions, confidentiality, sub-processing, assistance with data subject rights, deletion or return of data and audit rights. Cybersecurity Terms For entities subject to Decree-Law No 125/2025, cybersecurity requirements should also be reflected in relevant supply contracts. These clauses typi - cally address minimum security measures, incident reporting, co-operation, audit, business continuity and remediation. In practice, larger customers often use a layered struc - ture: a master services agreement, a data-processing agreement and a security schedule. Higher-risk sup - pliers may also be subject to more detailed onboard - ing and ongoing monitoring obligations. 7.5.3 The Application of Laws Relevant to Supply Chains Supply-chain obligations may apply to both the cus - tomer and the supplier. They do not sit solely with the customer. Their application depends on each party’s legal role, the sector in which it operates and whether it independently falls within the scope of the relevant regime.
For example, under the GDPR, the customer will often be the controller and must assess whether its pro - cessors provide sufficient guarantees of compliance. The supplier may, in turn, have direct obligations as a processor. Under Decree-Law No 125/2025, a cloud, managed service or managed security service pro - vider may also have direct cybersecurity obligations if it qualifies as an essential or important entity under the Portuguese cybersecurity regime. Conversely, the customer may itself be directly regulated if it operates in a covered sector, such as financial services, health - care, energy, transport, telecoms or public adminis - tration. In practice, contracts increasingly include mutual obli - gations, co-operation mechanisms and flow-down requirements so that both parties can meet their own regulatory duties. Portuguese AI regulation is likely to develop mainly through implementation of the AI Act rather than through a separate national AI code. The immediate focus should be institutional: designating competent authorities, creating supervisory capacity and, where appropriate, developing regulatory sandboxes and sector-specific guidance. Further changes are also expected in adjacent areas. Product safety, prod - uct liability, consumer protection, data protection and employment rules may all need to be applied or adapted to AI-related risks, particularly in credit scor - ing, healthcare, recruitment, workplace monitoring and critical infrastructure. At EU level, the proposed AI Liability Directive has been withdrawn. The principal EU-level liability devel - opment is now the revised Product Liability Directive – Directive (EU) 2024/2853 – which modernises the product-liability regime by expressly bringing soft - ware, including AI systems, and digital manufacturing files within scope. Portugal will need to transpose the Directive by 9 December 2026. 8. Legislative and Regulatory Adaptation and Advancement 8.1 AI-Related Legal Adaptation
64 CHAMBERS.COM
Powered by FlippingBook