🇵🇹 Daily Portugal news for expats & investors — FREE Subscribe

Your Data Rights in Portugal in 2026: A Practical Guide to the One-Month Reply Deadline, the CNPD's Three Complaint Forms, the Nine Provisions of the National Law the Regulator Refuses to Apply, and What a Camera May Not Film

What you can demand from any company or public body holding your data in Portugal, the one-month reply deadline, where a camera may not point, the CNPD's three complaint forms, and the nine provisions of the national law the regulator disapplies.

Your Data Rights in Portugal in 2026: A Practical Guide to the One-Month Reply Deadline, the CNPD's Three Complaint Forms, the Nine Provisions of the National Law the Regulator Refuses to Apply, and What a Camera May Not Film

Almost every foreign resident in Portugal hands over more personal data in their first year than a Portuguese citizen does in five. A NIF application, a bank onboarding, a landlord's file, an AIMA appointment, a health centre registration, a utility contract, an employer's HR system: each one creates a controller holding data about you, and each one owes you a set of rights you can enforce for free.

Most people never use them, partly because the rules are split across a European regulation and a Portuguese law, and partly because the Portuguese regulator has publicly refused to apply nine provisions of that national law. This guide sets out what you can actually demand, how long they have to answer, where cameras may and may not point, and what happens when you complain.

The three laws that govern this

Data protection in Portugal is governed by layers, and knowing which layer applies decides which rules you get.

  • The RGPD (Regulamento Geral de Proteção de Dados), the Portuguese name for the EU General Data Protection Regulation, Regulation (EU) 2016/679. This is directly applicable and is the source of the rights themselves.
  • Lei n.º 58/2019, de 8 de agosto, which secures the execution of the RGPD in the Portuguese legal order. It adds national specifics: video surveillance limits, employment rules, retention periods, the age of a child's consent, penalties.
  • Lei n.º 59/2019, de 8 de agosto, which covers processing by authorities for preventing, detecting, investigating or prosecuting criminal offences and executing criminal penalties. Your rights exist here too but are more restricted, and access to data in a criminal case, a court decision or the criminal record runs through criminal procedure law instead. This is the layer that governs, for example, the route by which Portuguese authorities made 4,012 user data requests to Google, Meta and six other platforms in a year.

The regulator is the CNPD (Comissão Nacional de Proteção de Dados, the National Data Protection Commission), an independent administrative body with legal personality that operates alongside the Assembleia da República. Since April 2026 it has also been designated, under Lei n.º 12-A/2026, as the authority responsible for the data protection aspects of the EU Digital Services Regulation in Portugal.

The six rights, and what each one actually gets you

The CNPD's guidance is explicit that these are separate rights to be exercised separately, not a single bundle. Asking for the wrong one gets you the wrong answer.

  • Access (RGPD Article 15). The broadest and most useful. You are entitled to know whether your data is being processed and, if so, to receive it along with the purposes of the processing, the categories of data, the source if it was not collected from you, who processes on the controller's behalf, third parties the data is disclosed to, the retention period or the criteria used to set it, whether there is automated decision-making or profiling (and if so the logic and consequences), and what safeguards apply to any transfer outside the European Economic Area.
  • Rectification (Article 16). Correcting data that is wrong or incomplete. Underused, and often the fastest route to fixing a downstream problem such as a mis-recorded address or a wrong tax status.
  • Erasure (Article 17). The right to be forgotten. It is not absolute in Portugal: where a retention period is imposed by law, Article 21(5) of Lei 58/2019 says erasure can only be exercised once that period has run.
  • Restriction of processing (Article 18). Freezing the use of data while a dispute over its accuracy or lawfulness is resolved. The practical middle option when erasure is refused.
  • Portability (Article 20). Getting data you provided in a structured, machine-readable format, or having it sent directly to another controller.
  • Objection (Article 21). Objecting to processing, including direct marketing, where the objection to marketing is absolute.

How to exercise them, and the deadline that follows

The mechanics are set out by the CNPD and are simpler than people assume.

  • It is free. Exercising your rights costs nothing.
  • You go to the controller, not the regulator. Rights are exercised against the company or public body holding the data, preferably through the specific channel it names in its privacy policy or equivalent notice.
  • Identify yourself properly, but no further. You must be able to prove who you are. You do not have to supply more personal data than the controller already processes about you. For requests to public bodies, an authenticated login using the Chave Móvel Digital settles the identity question in one step.
  • One month. You are entitled to a reply within one month of the request being received. The CNPD's own guidance on the right of access phrases this as a legal period of 30 days.
  • Extendable by two more. Where necessary, the period can be extended by a further two months. If it is, the controller must tell you inside the original month and justify the delay.
  • Electronic in, electronic out. If you made the request electronically, the reply should be electronic where possible.
  • They can refuse, in narrow circumstances. A controller may decline to act on a manifestly unfounded or excessive request, particularly a repetitive one, and in those cases may charge a reasonable fee covering administrative costs. Charging outside those circumstances, or charging more than the necessary cost, is itself an infringement.
  • Keep proof. The CNPD says this twice, and it is the single most important practical step: keep dated evidence that you made the request, plus all correspondence. Without it a complaint is much harder to run.

The nine provisions the CNPD refuses to apply

This is the part almost no general guide covers, and it changes the answers.

On 3 September 2019, less than a month after Lei 58/2019 came into force, the CNPD adopted Deliberação 2019/494. It concluded that several provisions of the national law contradicted the RGPD, breached the primacy of European Union law and undermined the regulation's direct applicability, and it resolved to disapply them in the cases it assesses. The nine are:

  • Article 2(1) and (2) on territorial scope.
  • Article 20(1), which barred the rights of information and access where the law imposes a duty of secrecy on the controller that is enforceable against the data subject.
  • Article 23, on processing by public bodies for purposes other than those of collection.
  • Article 28(3)(a), on consent as a basis for processing employee data where the processing brings the worker a legal or economic advantage.
  • Article 37(1)(a), (h) and (k), and Article 37(2), part of the very serious administrative offences and their fine ranges.
  • Article 38(1)(b) and Article 38(2), part of the serious administrative offences and their fine ranges.
  • Article 39(1) and (3), on setting the level of the fine, including the requirement to issue a warning before proceeding against a negligent first infringement.
  • Article 61(2), on the renewal of consent.
  • Article 62(2), on pre-existing data protection regimes.

The CNPD spelled out the consequence: where it disapplies one of these, the RGPD provision that the national rule was restricting or contradicting applies directly instead. In practice that means the fine ranges the regulator works to are the RGPD's own Article 83 ceilings, up to 20 million euros or 4 percent of worldwide annual turnover for the most serious infringements and up to 10 million euros or 2 percent for the rest, rather than the floors and caps written into Articles 37 and 38 of the Portuguese law.

One important caveat. A deliberation by the regulator binds the regulator. It does not repeal the law and it does not bind a court. A Portuguese court hearing a challenge to a CNPD decision, or a civil claim between private parties, can take its own view on whether these provisions apply. Treat the deliberation as a reliable guide to how the CNPD will behave, not as a statement that the provisions no longer exist. The CNPD itself delivered a draft law to the President of the Assembleia da República in September 2025 proposing a new administrative offence regime for data protection, which would settle much of this properly.

Cameras: what may not be filmed

Article 19 of Lei 58/2019 is not among the disapplied provisions, and it is the most concretely useful part of the national law. Where video surveillance is used to protect people and property, the cameras may not cover:

  • Public roads, neighbouring properties or any other place not under the exclusive control of the person responsible, except to the extent strictly necessary to cover the access points to the building.
  • The keypad area of ATMs or other payment terminals.
  • Areas reserved for customers or users where privacy must be respected, specifically toilets, waiting areas and changing rooms.
  • Areas reserved for workers, specifically eating areas, changing rooms, gyms, toilets and spaces used exclusively for rest.

In schools, cameras may only cover external perimeters and access points, plus spaces whose contents require special protection such as laboratories or computer rooms. Where video surveillance is permitted at all, capturing sound is prohibited, except while the premises are closed or with prior authorisation from the CNPD.

For anyone renting in Portugal, the neighbouring-property rule is the one that comes up most: a landlord's or neighbour's camera pointed across your terrace, your entrance or your windows is outside what Article 19 allows, and the CNPD has a dedicated complaint form for exactly this. Camera disputes between neighbours and in workplaces are, on the regulator's own account, among the most frequently reported matters it receives. Municipal systems in public space follow a separate authorisation route, which is why an Algarve municipality approving a CCTV network is a different legal question from a landlord installing one.

Cameras and data at work

Article 28 governs the employment relationship, and it is stricter than most employers behave as though it is.

  • Recorded images and other personal data captured by video or other remote surveillance technology may only be used in criminal proceedings. They may additionally be used to establish disciplinary liability, but only to the extent that they are being used within those criminal proceedings. An employer cannot lawfully review surveillance footage purely to build a disciplinary case.
  • Biometric data of workers is only legitimate for two purposes: attendance control and controlling access to the employer's premises. Only representations of the biometric data may be used, and the collection process must not permit those representations to be reversed.
  • Consent is not the basis for most employment processing. Article 28(3)(b) makes clear that a worker's consent is not a requirement of legitimacy where the processing is necessary to perform the contract. Point (a) of the same paragraph is one of the provisions the CNPD disapplies.
  • The employer's accountant or payroll processor is covered too, where they act under a services contract and are bound by equivalent confidentiality.

Special situations

  • Children. Under Article 16 of Lei 58/2019, a child can consent to the direct offer of information society services from the age of 13. Below 13, only a legal representative can consent, preferably using secure authentication. Rights over a child's data are exercised by the legal representatives, though children may exercise them directly depending on age and maturity.
  • Deceased persons. Article 17 protects the data of the dead where it falls into the RGPD's special categories or relates to private life, image or communications. Access, rectification and erasure are then exercised by whoever the deceased designated or, failing that, by the heirs. A person can also leave instructions making it impossible for anyone to exercise those rights after their death.
  • Joint controllers. Where more than one entity is responsible, you can exercise your rights against any of them, regardless of what they have agreed between themselves.
  • Retention. Article 21 sets the retention period as the one fixed by law or regulation, or failing that whatever is necessary for the purpose. When the purpose ends, the controller must destroy or anonymise the data. Contribution declarations for retirement purposes may be kept without any time limit, to help reconstruct contribution careers.
  • Secrecy duties. Where a controller invokes a legal duty of secrecy against you, Article 20(2) lets you ask the CNPD for an opinion on whether that duty is genuinely enforceable against you. Note that Article 20(1), the provision creating the bar, is one the CNPD disapplies.

Complaining to the CNPD

The CNPD asks you to go to the controller first. Its own guidance says you should turn to the regulator when you get no reply within the legal period, when your request is ignored or unjustifiably refused, or when you consider your rights were not properly guaranteed.

There are three specific complaint forms rather than one, and picking the right one speeds up the preliminary analysis:

  • Unsolicited electronic marketing (spam). Its own form, which routes you according to whether you are a customer, whether you are a natural or legal person, and whether you consented or objected.
  • Video surveillance and biometric data. Its own form.
  • Everything else. The general form. The CNPD asks for a concise account: describe the facts and let the regulator do the analysis. Indicate on the form that you hold relevant documentation or evidence rather than attaching everything; the CNPD will ask for it if it needs it.

A separate channel exists for questions rather than complaints. If you want to know whether a practice is lawful, or need clarification, that is a Pedido de Informação (information request), not a complaint, and using the wrong one delays both.

The regulator's address is Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, with a general contact of [email protected] and a telephone line on +351 213 928 400.

What the CNPD cannot do for you

The CNPD investigates, orders and fines. It does not award you compensation. That distinction sends a fair number of complaints to the wrong place.

  • Civil liability (Article 33). Anyone who suffers damage from unlawful processing, or any other act breaching the RGPD or Portuguese data protection law, has the right to reparation from the controller or processor. They escape liability only by proving the event causing the damage is not attributable to them. Claims against the State and other public legal persons run under the State liability regime in Lei n.º 67/2007.
  • Suing the controller (Article 34(3) and (4)). You can bring an action against the controller or processor, including for damages. Portuguese courts have jurisdiction if the controller or processor has an establishment in Portugal, or if you habitually reside here. That second limb matters: as a resident, you can generally sue in Portugal even where the company is established elsewhere.
  • Suing the CNPD (Article 34(1) and (2)). Actions against the CNPD's decisions and omissions, including in administrative offence matters, go to the administrative courts.
  • Being represented (Article 35). You can mandate a non-profit body, organisation or association constituted under national law, with public interest statutory aims covering data protection, to exercise your Articles 77, 78, 79 and 82 rights on your behalf.
  • Administrative remedies (Article 32). Separately from a CNPD complaint, ordinary administrative remedies under the Código do Procedimento Administrativo remain available against public bodies.

For low-value private disputes, the Julgados de Paz are the cheapest civil route, and a straightforward consumer-facing failure may also be worth logging in the Livro de Reclamações in parallel.

How busy the regulator is

Volume shapes how long you wait, and the CNPD's 2025 activity report is candid about it. In 2025 the regulator opened 3,201 proceedings, a 12 percent rise on 2024, of which 2,037 were investigation proceedings. It opened 234 rights-guarantee proceedings, up about 127 percent on the previous year. It received 9,299 information requests and complaints in total, a 19.2 percent increase, mostly from citizens through the channels on its website.

The matters most reported were unsolicited electronic communications, video surveillance in the workplace and between neighbours, and securing rights against controllers. Spam alone accounted for 1,254 complaints through the dedicated form. The CNPD also took part in a coordinated action with 31 other European data protection authorities examining how controllers implement the right to erasure, inspecting 15 Portuguese entities across health, insurance, marketing and advertising, debt collection and business information.

What This Means for You

  • If you are renting: check where the cameras point. A camera covering a shared entrance is usually defensible; one covering your terrace, your door or the public street beyond the access point generally is not. Photograph the camera and its field of view, ask the landlord or condominium in writing who the controller is, and use the dedicated video surveillance form if that goes nowhere.
  • If you are employed: your employer cannot lawfully use surveillance footage to build a disciplinary case outside criminal proceedings, and cannot take your biometrics for anything beyond attendance and building access. If a fingerprint or face scan is being collected for productivity monitoring, that is outside Article 28.
  • If you are self-employed or running a company: you are a controller. The obligations that generate most complaints are the mundane ones: replying inside the month, not charging for access, having a real privacy notice with a working rights channel, and keeping a record of processing activities. The fine exposure the CNPD works to is the RGPD's, not the softer national floor.
  • If you are a pensioner or benefits claimant: the access right is the practical tool for finding out what a public body actually holds about you and where it came from, which matters when an automated data match produces a decision you disagree with.
  • If you are new to Portugal: start with a single access request to whichever organisation you suspect has the messiest file on you. It costs nothing, it forces a written answer within a month, and the reply tells you who else your data has been shared with, which is usually the genuinely surprising part.

None of this requires a lawyer to begin. A dated email to a controller citing Article 15 of the RGPD, kept with its proof of sending, starts a clock that the controller has to answer. If the month passes in silence, you have exactly the record the CNPD asks for. The rights are only worth what you do with them, and the entry cost is one email.

This guide is general information about Portuguese and European data protection law, current as at 31 August 2026. It is not legal advice. For a specific dispute, particularly one involving damages, take advice from a Portuguese lawyer.