Tech & Media

Law for Code and Content ventures.

If you are interested in:

  • Software, SaaS and technology contracts
  • Digital Services Act and platform regulation
  • Advertising, media and content
  • Data protection, GDPR and CNPD matters
  • Cybersecurity, NIS2 and incident response
  • Artificial intelligence and the EU AI Act
  • Software copyright, trade marks and trade secrets
  • Crypto-assets, MiCA and virtual asset service providers
  • Founding, financing and exiting a technology company
  • Product compliance and the Cyber Resilience Act
  • Technology M&A and due diligence
  • European market access

Overview

The European Union has assembled the most comprehensive body of digital law in existence. Compliance is now a condition of access to the European market rather than a matter of good practice, and the obligations bind companies established in Europe alongside those that serve European customers from elsewhere.

GFDL Advogados advises the businesses operating within that framework.

Our clients include founders whose first enterprise contract arrives with an extensive security and data protection annex; general counsel responsible for compliance programmes they did not design; product and engineering teams requiring a defensible position ahead of a fixed release date; investors pricing regulatory exposure into a term sheet; and non-European groups whose products attract European obligations irrespective of whether they maintain an entity here.

A significant part of the value we provide concerns what has not yet occurred. Describing a rule already in force is straightforward. The more demanding and more useful exercise is establishing which of the coming obligations will reach a particular client, which will not, and which remain proposals that may never be adopted, so that a product roadmap can be built on a settled view rather than on the news cycle.

This practice forms part of the firm’s wider technology offering, alongside Artificial Intelligence, Data Privacy & Cybersecurity, Intellectual Property and Fintech & Blockchain, and draws on the corporate, tax, employment and dispute resolution teams as each matter requires.

 

Tech & Media teams work frequently in disruptive sectors.

Click here to know more about our practice in supporting Traiblazer Businesses.

Our assistance

Product development and market entry

Before a product reaches the market, a series of unglamorous questions requires resolution. Who owns code written by a freelance developer in 2023. Whether the open source licences within the dependency tree permit commercial distribution. Whether the registration flow collects something the CNPD would recognise as consent. Whether the product falls within the Cyber Resilience Act, and if so what a software bill of materials and a committed support period imply for the development roadmap. Whether accessibility requirements apply, and what they demand of the interface rather than of the documentation.

We address these matters at specification stage wherever possible. A substantial proportion of European obligations bind the design of a product rather than its documentation, including data protection by design, accessibility, security by design, age assurance, and the constraints applicable to consent interfaces. Each is inexpensive to satisfy while a feature remains a wireframe and considerably more costly once it has shipped. A legal design review is materially less expensive than a rebuild.

Technology contracts and transactions

We draft and negotiate the commercial documentation of a technology business, including SaaS and subscription terms, software licences, development and integration agreements, cloud and hosting arrangements, source code escrow, service levels, support and maintenance, reseller, OEM and white label agreements, marketplace terms and data licensing.

We are equally often engaged to review the counterparty’s documentation, which is where the greater part of the risk within a technology stack resides. Recurring examples include liability caps drafted so as to exclude the very loss with which the client is concerned, uptime commitments measured monthly so that a two-day outage is absorbed into the average, subprocessor lists amended by unannounced revision to a website, and termination provisions that leave client data resident on a third party’s infrastructure. Cloud and connected-product contracts must additionally be read against the switching and unfair terms provisions of the Data Act, which have shifted the balance in these negotiations further than most suppliers have acknowledged.

We also advise on technology mergers and acquisitions, intellectual property intensive due diligence, licensing into new markets, and outsourcing arrangements together with their termination.

Data protection and privacy

The whole of a business’s treatment of personal data, from the record of processing activities to correspondence with the supervisory authority. This includes GDPR compliance programmes, international transfers, outsourced data protection officer services, cookie and consent audits, breach response and CNPD proceedings.

Know more Data Privacy & Cybersecurity

Platform regulation

Where a service hosts third-party content or connects buyers with sellers, the Digital Services Act now governs its daily operation. Classification is the threshold question, since a hosting service, an online platform and a marketplace carry materially different obligations, and a programme constructed for the wrong category is an expensive route to continued non-compliance.

The subsequent work is concrete, comprising notice and action mechanisms, statements of reasons capable of withstanding challenge, internal complaint handling, trader traceability for marketplaces, transparency reporting, the rules governing advertising and recommender systems, and engagement with ANACOM.

We also act for businesses on the other side of the relationship, being those dependent upon a large platform for distribution or discovery, where the Platform-to-Business Regulation and the Digital Markets Act confer greater leverage than is commonly appreciated.

Media, content and advertising

Advertising law under Portuguese domestic rules, comparative and superlative claims, prize draws and promotions, and the sector-specific rules governing health, financial services, alcohol and advertising directed at children. We advise on influencer campaigns, where disclosure obligations fall upon the brand and the creator alike and where the agreement must allocate reputational risk as well as remuneration.

We further advise on content licensing and distribution, image and personality rights, user-generated content and moderation policy, takedown and right of reply, and reputation matters where damaging material has attached to a client’s name and search results.

Advertising technology falls across this practice and the data practice, comprising programmatic buying, real-time bidding, measurement and attribution, retargeting, and the consent architecture underlying each of them. The Digital Services Act introduced restrictions that merit consideration before a campaign is booked, including the prohibition upon advertising based on profiling that uses special category data and upon profiling-based advertising directed at minors. Where the creative is itself generated by artificial intelligence, the disclosure obligations of the AI Act extend to the campaign.

Cybersecurity, incidents and the authorities

Portuguese cybersecurity law was restructured in April 2026, and a considerably wider population of companies now falls within its scope. We determine whether a client constitutes an essential or an important entity, attend to registration and the required appointments, and translate the technical measures into obligations capable of board supervision, which is material because responsibility under the new regime attaches personally to management.

Where an incident occurs we conduct the legal element of the response, establishing what must be notified, to whom, in what order and against which deadline. A single event may give rise to parallel duties to the CNPD, to the CNCS and, for product manufacturers, to ENISA, each with its own timetable and its own threshold. We also address the aftermath, which is ordinarily longer and more expensive than the incident itself.

Where the authorities approach the client rather than the attacker, we advise on preservation and production orders and on the search, seizure and interception powers under the Cybercrime Law and the Code of Criminal Procedure. From 18 August 2026 the e-Evidence Regulation introduces direct cross-border orders subject to very short deadlines. A request-handling protocol is properly established before the first order is received.

Artificial intelligence

Classification under the AI Act, the disclosure obligations presently in force, internal artificial intelligence policies, contractual provisions in supplier agreements, and the data protection and copyright questions underlying every deployment.

Know about Artificial Intelligence

Intellectual property and ownership

Ownership is rarely as settled as a capitalisation table implies. We repair chains of assignment from founders, employees and contractors, advise upon works created in the course of employment and upon employee inventions, and conduct open source reviews in advance of a financing or an exit rather than during one.

We further advise on trade mark strategy and filings before INPI and EUIPO, oppositions and coexistence agreements, registered designs, database rights, domain name recovery, and the protection of trade secrets, which for most software companies is of greater value than any registered right they hold. Where rights require enforcement we act before the Intellectual Property Court, including on urgent injunctive relief. Because the tax practice sits within the same firm, we also advise upon where intellectual property should be held and how research, development and intellectual property incentives apply to it.

Know more about Intellectual Property

Company formation, financing and exit

Incorporation and founder arrangements, vesting, shareholders’ agreements, convertible instruments and priced rounds. Certification under the Portuguese startup framework and the share option regime attaching to it. Employment agreements for engineering personnel, contractor classification, confidentiality and invention provisions, and residence permits for international hires. Upon exit, due diligence, code and open source review, and the intellectual property and privacy warranties that acquirers now negotiate closely.

Know more about Startups & Scaleups

Know more about Corporate & Commercial

Disputes and regulatory defence

CNPD investigations and appeals, ANACOM and CNCS enforcement, intellectual property litigation and injunctive relief, trade secret claims, disputes arising from failed implementations and vendor performance whether before the courts or in arbitration, and claims following data breaches. Matters are conducted by the same lawyers who provide the underlying advice, so that no understanding is lost in translating a compliance file into a pleading.

Know more about Litigation

Tax Law Practice

Corporate Law

Intellectual Property

Talk to Us