Data Privacy & Cybersecurity
Keep it safe, keep it private.
If you are interested in:
- GDPR compliance and RGPD obligations in Portugal
- Data Protection Officer as a service
- Privacy and data protection impact assessments
- Cookies, consent and online advertising
- International data transfers
- Data breach response and CNPD notification
- CNPD investigations, fines and appeals
- NIS2 and the Cybersecurity Legal Regime
- Cyber Resilience Act product obligations
- Employee monitoring and workplace privacy
- Law enforcement and court orders for user data
- Designated representative services for non-EU businesses
Overview
For much of the last decade, data protection constituted the compliance programme and cybersecurity constituted a line in the technology budget.
The Portuguese Cybersecurity Legal Regime, in force since 3 April 2026, brought that separation to an end. Security is now a legal obligation carrying registration duties, notification deadlines, fines reaching €10 million and responsibility that attaches personally to management.
GFDL Advogados conducts both sides of the file. In practice sometimes they are a single file: an organisation experiencing one incident does not experience two separate problems.
The firm has provided data protection compliance services since the GDPR entered into application, including DPO as a service, impact assessments and the design of compliance frameworks for organisations at every stage of maturity.
That work now sits alongside the cybersecurity and product security obligations introduced by the more recent European instruments.
This practice forms part of the firm’s wider technology offering, alongside Tech & Media, Artificial Intelligence and Intellectual Property.
Data Privacy
Compliance programmes
A GDPR programme is a set of documents kept accurate by working habits. We build both. The documents comprise records of processing activities, privacy notices people can actually read, data protection impact assessments, legitimate interest assessments, retention schedules and processor agreements. The habits comprise the internal procedures that handle subject requests within the statutory period and route changes in processing back to the documents that describe them.
Where a programme already exists, we run a gap review against the standard the CNPD applies in practice, not a generic checklist. Employee monitoring and biometric systems, children’s data, internal whistleblowing channels and health data get particular attention, since the CNPD treats them more strictly than most foreign parent companies expect.
International transfers
Personal data leaving the European Economic Area needs a documented, defensible basis. We map the transfers, apply the right mechanism to each, and prepare the transfer impact assessments that make standard contractual clauses hold up rather than sit on file unused. Where a US parent company, an offshore support function or a cloud region outside the Area is involved, this is usually the part of the file that decides whether a transaction proceeds.
Cookies, consent and online advertising
Most enforcement starts in the gap between what a consent management platform is configured to do and what the law actually requires. We audit cookie banners and consent flows against the ePrivacy rules and CNPD practice, and advise on analytics, profiling, retargeting and the rules governing electronic marketing and the national opt-out list.
The Digital Services Act bars advertising built on profiling that uses special category data, and profiling-based advertising aimed at minors. Where the advertising creative itself is generated by artificial intelligence, the disclosure duties of the AI Act reach the campaign as well. Advertising and media work more generally sits with Tech & Media.
One development is worth watching rather than acting on. The proposed Data Omnibus would move the cookie rules into the GDPR and change how consent works mechanically. It remains before the Council and could change substantially, so we do not recommend rebuilding a consent architecture around a draft.
Data Protection Officer as a service
Many organisations must appoint a Data Protection Officer and cannot justify a full-time hire. We have provided this service for a number of years: a named lawyer, registered with the CNPD, who learns the client’s processing operations, answers questions from staff, corresponds with the regulator and joins incident calls. The result is a functioning role, not a monitored mailbox.
For organisations below the threshold that requires a formal appointment, the same team provides privacy support on retainer, ordinarily the more proportionate arrangement for a smaller company.
Regulatory proceedings
We act in CNPD investigations, audits, orders and penalty proceedings, and in the appeals that follow: responding to requests for information, preparing submissions, negotiating where negotiation is available and litigating where it is not. Options are widest at the outset, so the right moment to take advice is on receipt of the first letter, not after the first reply has already gone out. Contentious matters run jointly with Litigation.
Cybersecurity
The Portuguese regime
Portugal transposed the NIS2 Directive and rebuilt Portuguese cybersecurity law. New rules entered into force on 3 April 2026 and cover a far larger population of entities than the previous regime, reaching energy, transport, health, digital infrastructure, manufacturing, digital service providers and much of public administration, split between essential and important entities with obligations scaled to each.
The immediate duties are concrete: registration through the CNCS MyCiber platform, a permanent point of contact available at all times, and a named person responsible for cybersecurity.
Risk management measures follow, set out in the CNCS regulation published in June 2026. Management approves those measures, supervises their implementation and answers for their failure. Fines reach €10 million, or a share of worldwide turnover.
We handle the legal side of the file: scoping opinions on whether and how an entity is covered, registration and the required appointments, governance documentation a board can rely on, supply chain security provisions, and the notification procedures the regime requires.
The technical build stays with the client’s own security function or provider. Our role is to make sure what is built matches what the law requires.
Product security
Manufacturers of hardware or software sold in the European Union answer to the Cyber Resilience Act for the product itself.
Actively exploited vulnerabilities and severe incidents must be reported to ENISA and the national CSIRT: an early warning within 24 hours, a fuller notification within 72 hours and a final report once the issue is fixed. The duty reaches products already on the market, which frequently catches manufacturers by surprise.
The full regime, covering secure development, software bills of materials and mandatory support periods, applies from December 2027.
We identify which products are covered, prepare the reporting procedures, review supplier agreements so that component vulnerabilities reach the manufacturer in time to meet its own deadline, and align the product security file with the NIS2 file, so that a single incident does not produce two inconsistent notifications.
Incident response
When a breach happens, the legal questions arrive in a settled order: what occurred, expressed in legal terms; whether it must be notified to the CNPD within 72 hours, to the CNCS on the cybersecurity timetable, to the individuals affected, to insurers, and to counterparties whose contracts require it; what the early internal correspondence should and should not record, since it may later be disclosable; and whether law enforcement should be involved, including how a ransom demand sits against sanctions law.
We run that sequence alongside the client’s technical and communications teams, and prepare the incident response plans and exercises that make a first real incident less costly than it would otherwise be.
Requests from public authorities
Service providers receive orders from police, prosecutors and courts, and both over-compliance and under-compliance carry consequences. We advise on preservation and production orders and on the powers in the Cybercrime Law, and on the conflicts that arise where a foreign authority seeks data that European law does not permit to be transferred without more.
From August 2026, the e-Evidence Regulation lets judicial authorities anywhere in the Union address orders directly to providers established here, with ten days to comply and eight hours in an emergency. Where a service stores user data, a request-handling protocol is best prepared before the first order tests it.
