EU Artificial Intelligence Act (AI Act)

🇵🇹EU Artificial Intelligence Act in Portugal

A comprehensive guide to EU Artificial Intelligence Act compliance for organisations operating in Portugal. Understand local enforcement, the national data protection authority, key focus areas, and notable enforcement actions.

About EU Artificial Intelligence Act

The world's first comprehensive AI regulation, establishing a risk-based framework for the development, deployment, and use of artificial intelligence systems within the EU.

Effective: 1 August 2024Max penalty: €35,000,000 or 7% of total annual worldwide turnover
Full EU Artificial Intelligence Act overview

EU Artificial Intelligence Act Enforcement in Portugal

Portugal's CNPD was one of the first data protection authorities in Europe, established in 1994. The Portuguese GDPR implementation law (Lei 58/2019) includes specific provisions on employee consent (generally not considered valid in employment relationships), processing for public interest, and research exemptions. The CNPD has been particularly notable for its independent stance on certain GDPR interpretations, including its 2022 decision ordering the Portuguese National Institute of Statistics to stop transferring census data to the US in the wake of Schrems II. The CNPD has also scrutinised government digital services and health data processing. Portugal sets the age of digital consent at 13, the lowest in the EU.

Data Protection Authority

Comissão Nacional de Proteção de Dados (CNPD)

Key Enforcement Focus Areas in Portugal

  • International data transfers (post-Schrems II enforcement)
  • Government digital services and census data
  • Employee data protection and consent validity
  • Health data processing
  • Statistical and research data processing

Notable Enforcement Actions in Portugal

Instituto Nacional de Estatística (INE)

€4,300,000(2022)

Census 2021 data transfer to Cloudflare in the US without adequate safeguards under Schrems II

Centro Hospitalar Barreiro Montijo

€400,000(2018)

Allowing non-medical staff access to patient records — 985 active doctor profiles but only 296 actual doctors

Câmara Municipal de Lisboa

€1,250,000(2022)

Disclosing personal data of protest organisers and activists to foreign embassies without legal basis

TAP Air Portugal

€1,200,000(2023)

Failure to implement adequate security measures preventing a data breach affecting 1.5 million customers

Check Your Compliance Status

Take our free assessment to evaluate your organisation's compliance posture. Get a personalised report with actionable recommendations in minutes — no sign-up required.

Start Free Assessment

Disclaimer: The information on this page is for educational purposes and does not constitute legal advice. For specific compliance guidance, consult a qualified legal professional in your jurisdiction.

Other Regulations Affecting Portugal