Portugal's Data Watchdog and Its Bar Association Both Back a New Digital Identity Theft Crime, Then Ask Parliament to Rewrite Almost Every Line of It
Two opinions on Chega's Projeto de Lei 697/XVII/1 reached the Constitutional Affairs Committee this week. The lawyers cite 61,798 cyber incidents in 2025, 78 percent of them account takeovers. The CNPD found paragraphs that repeat themselves and a numbering scheme with holes in it.
Two legal opinions landed at the same parliamentary committee this week, and they agree on something unusual: Portugal probably should have a specific crime of digital identity theft, and the bill currently written to create one should not be voted in the form it is in.
The bill is Projeto de Lei 697/XVII/1, filed by Chega at the end of June. It adds a definition of "identidade digital" (digital identity) to the Lei do Cibercrime (Cybercrime Law), Lei n.º 109/2009, and inserts a new article 7.º-A creating the offence of usurping it. The Comissão de Assuntos Constitucionais, Direitos, Liberdades e Garantias (Committee on Constitutional Affairs, Rights, Freedoms and Guarantees), where the text is now being examined line by line, asked both the data protection regulator and the bar association what they made of it.
The Ordem dos Advogados (Bar Association) answered on Monday, in an opinion signed by its bastonário, João Massano. The Comissão Nacional de Proteção de Dados (National Data Protection Commission) answered with Parecer 56/2026, approved at its meeting of Tuesday 1 September and signed by its president, Paula Meira Lourenço. Both are favourable to the idea. Neither is favourable to the drafting.
What the bill would actually make illegal
The proposed definition is wide by design. "Digital identity" would mean the set of digital elements identifying or representing a natural or legal person, "including, for example, the name, the image, the voice, personal data, the email address, the account, the profile, the page, the username, access credentials and the digital identifier or any other element capable of allowing identification, representation or association before third parties".
The new article 7.º-A would then punish anyone who, without the holder's consent and intending to act in their name and under their identity, uses, assumes, controls, keeps or makes available an account, profile, page, email address, username, access credentials or any other element of another person's digital identity. The base penalty is up to one year in prison or a fine of up to 120 days.
Two aggravated tiers follow. Using someone's digital identity elements by any computerised means, intending to cause harm or obtain an illegitimate advantage, carries up to two years or 240 days. A five-band clause raises the range to one to five years where, among other things, the conduct involves disclosing or threatening to disclose sensitive personal data, intimate images, private communications or information about the victim's family, professional, financial or clinical life; where it is carried out through an organised criminal network or hits several accounts or identities at once; or where a public official does it in or through their functions.
Attempt would be punishable. Prosecution would normally require a complaint from the victim, except in the aggravated cases or where the victim is a minor or especially vulnerable. And there is an express carve-out: use that is manifestly satirical, parodic, artistic, academic, journalistic or a matter of political or social criticism is not punishable, provided it is not capable of misleading anyone about whose identity it is and is not done to cause harm, gain an illegitimate advantage or facilitate a crime.
The lawyers: a real gap, and a text that would create case-law chaos
The Ordem dos Advogados opinion opens with a number that explains why the subject is on the agenda at all. In 2025, it says, 61,798 cybersecurity incidents were recorded in Portuguese cyberspace, and account compromise was the single most numerous subtype at 47,953 records, about 78 percent of the total. That is one national cyber incident in every four being, in substance, somebody taking over somebody else's account.
On that basis the bar association says the initiative answers a genuine gap, because none of the existing offences (computer forgery, computer fraud, illegitimate access, or usurpation of civil status) covers the full spectrum of digital identity theft conduct adequately and completely. It calls an autonomous offence coherent with the constitutional protection of personal identity and digital privacy, and says it would align Portugal with European best practice.
Then it says that approving the text in its current configuration would generate legal uncertainty and divergent case law that would undermine the initiative's own objectives. Its conclusion is formally favourable, with reservations.
The head of the Polícia Judiciária (Judicial Police), Carlos Cabreiro, told deputies in May that he wanted this crime created, describing a steady stream of people arriving at the PJ to complain about the takeover of a Facebook or LinkedIn account.
The regulator: thirteen pages of objections
The CNPD opinion is longer and harder. Its central complaint is that "digital identity" has no settled legal meaning and that the bill's definition collapses several different things into one.
The regulator distinguishes a person's identity, the attributes or data that allow them to be identified, the means by which that identity is represented to others, and the technical mechanisms that authenticate a person or grant access to a system. Access credentials, it notes, are simultaneously an identifying element and a security mechanism, and their primary function is not the same as that of a name or a face. Bundling all of it together, and then adding an open clause covering "any other element capable of" identifying someone, makes the object of the offence itself uncertain. For a criminal provision, which has to satisfy the principle of determinability, the CNPD calls the result closer to an open and heterogeneous list of digital items than to a legal concept.
Its second objection is overlap. The opinion walks through computer forgery (article 3 of the Cybercrime Law, punishable by up to five years or a fine of 120 to 600 days), computer fraud, illegitimate access, invasion of privacy, non-consensual disclosure of intimate content, and the criminal offences in Lei n.º 58/2019 for unlawful processing of personal data. Portuguese courts, it points out, have been folding exactly this kind of case, the creation and use of fake profiles and accounts, into computer forgery already, sometimes in combination with other offences. A residual zone of conduct that falls outside all of them may well exist, but the bill does not identify it, and the CNPD's position is that the burden of doing so lies with whoever proposes a new crime.
The third objection is that the text does not hold together internally. The regulator points out that paragraph 2 and subparagraph a) of paragraph 3 describe the same conduct in the same words while attaching different penalties, with nothing to explain the difference; and that the numbering has holes in it, with no subparagraph b) in paragraph 3 and no paragraph 6 at all.
Two more technical points close the list. The aggravating clause uses the phrase "sensitive personal data", which is not the terminology of the General Data Protection Regulation; the GDPR speaks of "special categories of personal data" in its article 9, and the bill's own list reaches wider than those categories, so it is not possible to say with confidence what the aggravation covers. And because the offence also protects the digital identity of legal persons, while data protection law under the GDPR and Directive (EU) 2016/680 applies only to natural persons, the CNPD says the justification for the diploma cannot rest on data protection arguments for a substantial part of what it proposes.
The commission also records, in one dry paragraph, that the request for its opinion arrived without the data protection impact study that article 18(4) of Lei n.º 43/2004 requires parliament to send with it.
Its six recommendations follow from all of that: delimit the elements covered by "digital identity" and in particular the generic reference to "personal data"; give the concept enough content to satisfy criminal law's determinability requirement; replace or bound the phrase "sensitive personal data"; identify precisely which legal interest the new offence protects and how it relates to data protection; identify the concrete situations not already covered by existing offences and show that a separate criminal response to those is necessary, proportionate and a last resort; and clarify whether the new crime is meant to be special, subsidiary or cumulative in relation to the offences already on the books.
What this changes for you today
Nothing, yet. The bill is in committee, no date has been set for a final vote, and its own article 4 gives it thirty days from publication before it would take effect.
What the CNPD opinion does usefully establish, for anyone whose account has been taken over, is that the absence of a crime called "digital identity theft" does not mean there is no crime. Fake profiles built to deceive have been prosecuted as computer forgery. Money taken through a hijacked account is computer fraud. Getting into an account you have no right to is illegitimate access. Publishing someone's private material is invasion of privacy, and misusing their personal data can be an offence under the national data protection law. A complaint to the Polícia Judiciária does not need to wait for parliament.
The practical case for a new offence, and the reason the bar association supports one despite everything it says about the drafting, is narrower than the headline suggests: it is about the cases where somebody impersonates you convincingly and nothing measurable has yet been stolen. That is a real category, and it is the category the CNPD says the bill has not bothered to define.
The wider context is that Portugal has spent this year adding machinery against exactly this kind of fraud. The Bank of Portugal stood up a digital fraud monitoring platform with SIBS, the telecoms operators and the PJ in May, and the cabinet handed ANACOM a mandate to block caller-ID spoofing at the end of the same month. The regulators have also spent the year telling people what the scams look like: the CMVM said this week that investment scammers now arrive with AI-generated video and that it never contacts anyone on WhatsApp, and the tax authority added telephone calls to its own fraud warning in August. Impersonation is the common thread through all of it.
If you want to know what you can already demand from anyone holding your data, and how to complain when they will not give it to you, our guide to your data rights in Portugal sets out the one-month reply deadline and the CNPD's complaint routes. And if the impersonation involves manipulated images of a minor, the Penal Code already treats that as child pornography, as the wave of fake AI nudes in Portuguese schools has shown.
One footnote on the document itself, for anyone who goes looking. The CNPD's opinion carries "PAR/2026/55" in its running header on all thirteen pages while calling itself PARECER/2026/56 in the body and appearing as Parecer 56/2026 in the commission's own published list. It is a copy-paste slip, and there is a certain symmetry in a document that spends four pages on drafting errors carrying one of its own.