What Is GDPR + Lei n.º 58/2019, de 8 de agosto?
Lei n.º 58/2019, de 8 de agosto, ensures execution of the GDPR in Portuguese law and entered into force 9 August 2019 (the day after publication in Diário da República No. 151/2019, Série I). No later amending act has been located, and no Constitutional Court judgment has struck down any of its provisions. However, CNPD Deliberação n.º 494/2019 states the CNPD will disapply several Law 58/2019 provisions — including Article 2(1)-(2) (territorial scope), Article 20(1) (a statutory-secrecy access bar), and several penalty-related provisions — applying GDPR directly instead, on EU-law-primacy grounds. This is a CNPD disapplication position, not a Constitutional Court annulment or legislative amendment, but it means "unamended and fully applicable exactly as enacted" is not a supportable description of the current law; "in force as enacted, subject to GDPR primacy and CNPD-declared disapplication of specified provisions" is the accurate framing.
At a glance
- Full name
- GDPR + Lei n.º 58/2019, de 8 de agosto
- Short code
- Portugal GDPR + Lei 58/2019
- Jurisdiction
- Portugal
- Enacted
- 2019
- Last major update
- No later amending act located; CNPD Deliberação n.º 494/2019 declares several Law 58/2019 provisions disapplied in favor of direct GDPR application on EU-law-primacy grounds
- Regulator
- Comissão Nacional de Proteção de Dados (CNPD)
- Private right of action
- Yes
- Statutory citation
- Lei n.º 58/2019, de 8 de agosto
Scope, who Portugal GDPR + Lei 58/2019 covers
Protected data
Data subject rights
Access (GDPR Art. 15), with Law 58/2019 Art. 20(1)'s statutory-secrecy access bar declared disapplied by CNPD
Rectification (GDPR Art. 16)
Erasure (GDPR Art. 17), postponed by Law 58/2019 Art. 21(5) where another statute requires retention until that period ends
Restriction (GDPR Art. 18)
Objection (GDPR Art. 21), with an unconditional direct-marketing objection
Portability (GDPR Art. 20), limited by Law 58/2019 Art. 18 to subject-supplied data with a preference for open formats
Complaint to the CNPD
Notable features
Portugal sets the information-society-service consent threshold at 13 (Law 58/2019 Art. 16) — below that age, a child's own consent is not valid and a legal representative must consent, applying specifically to information-society-service consent rather than all processing generally. Article 17 provides special post-mortem rules: a person designated by the deceased, or absent that, heirs, may exercise access, rectification, and erasure for certain sensitive, private-life, image, and communications data. Article 25 provides that personal data published in Portuguese official journals generally cannot be altered, obscured, or deleted; exceptional GDPR Article 17 erasure is instead implemented via search-engine de-indexing while preserving the official publication's evidentiary effect.
Enforcement & penalties
Regulator: Comissão Nacional de Proteção de Dados (CNPD)
Penalties: GDPR Article 83 sets the baseline: up to €10M or 2% of worldwide turnover (whichever higher) for specified obligations, up to €20M or 4% for core principles, rights, transfers, and national-law obligations. Law 58/2019 Articles 37-38 print a separate Portuguese schedule (up to €20M or 4% for very serious offences by large companies, scaled down for SMEs and natural persons) — but CNPD's Deliberação n.º 494/2019 declares it will not apply the Portuguese fine amounts in Articles 37(2) and 38(2), the additional Portuguese aggravating criteria (Art. 39(1)), or the prior-warning rule (Art. 39(3)) where they conflict with GDPR Article 83. Only GDPR Article 83's structure is safely presentable as the operative fine ceiling for GDPR-covered offences without this qualification.
Private right of action: GDPR Article 82 grants a right to compensation for material or non-material damage. CNPD provides a general complaint form plus three subject-specific forms (unsolicited marketing, video surveillance, biometric data); submissions require no special formalities. No official fixed deadline requiring CNPD to complete or decide an ordinary complaint has been located — CNPD's published "30 days" language concerns the controller's response to a rights request, not a CNPD complaint-processing deadline, and GDPR Article 78(2)'s three-month figure only triggers a judicial-remedy right if CNPD has not acted or informed the complainant by then.
Relevance to data brokers
No broker-specific CNPD complaint form, statutory deletion route, or Portugal-specific data-broker procedure has been located; the only official route is the general CNPD participation form. Individuals would ordinarily exercise GDPR rights against the relevant controller directly and, if necessary, use the general CNPD complaint route rather than a dedicated broker-specific mechanism.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Is Lei n.º 58/2019 fully applicable exactly as written?+
Not entirely. While no later amending act or Constitutional Court invalidation has been located, the CNPD has formally declared, in Deliberação n.º 494/2019, that it will disapply several provisions — including the territorial-scope Article 2(1)-(2) and parts of the penalty schedule — applying GDPR directly instead on EU-law-primacy grounds.
How do I file a complaint with the CNPD?+
Use the CNPD's general complaint form, or one of its three subject-specific forms (unsolicited marketing, video surveillance, biometric data), providing a concise factual account and supporting evidence. No official fixed deadline for CNPD to decide an ordinary complaint has been located.
Can I get my data removed from a Portuguese official journal (Diário da República)?+
Generally, no — personal data published in official journals cannot be altered, obscured, or deleted to preserve the publication's evidentiary effect. Exceptional erasure requests are instead handled through search-engine de-indexing rather than removing the underlying official record.
Official sources & citations
Other international privacy regimes
Portugal GDPR + Lei 58/2019 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
