Portugal Law No. 58/2019 — Data Protection Implementation Act
Portugal's Law No. 58/2019 supplements the EU GDPR with national provisions. The Comissão Nacional de Protecção de Dados (CNPD — National Data Protection Commission) oversees enforcement. The law includes provisions for the age of digital consent (13 years), processing by the public sector, employee data, video surveillance, deceased persons' data, and research derogations. Portugal was one of the later EU Member States to adopt its GDPR supplementary legislation.
Framework summaries on this platform are AI-assisted interpretations for educational and compliance planning purposes. They do not reproduce or replace the official standards. Refer to the authoritative source for the definitive text. Framework names and trademarks belong to their respective organisations.
Framework Domains (20)
Awareness
| Code | Title |
|---|---|
| PT-DPA-17 | Training and Awareness |
Chapter I — General Provisions
| Code | Title |
|---|---|
| Art. 1 | Open Finance Implementation |
| Art. 2 | Consent Definition |
| Art. 3 | Objectives of Open Finance |
| Art. 4 | Participating Institutions |
| Art. 5 | Prohibited AI Practices |
| Art.1 | Purpose of the Law |
| Art.2 | Scope |
| Art.3 | Definitions |
| Art.4 | Principles for Data Processing |
| Art.8 | Rights of Data Subjects |
| HUN-1 | Purpose and Scope |
| HUN-2 | Definitions |
| HUN-3 | Fundamental Rules |
| URY-1 | Fundamental Right (Article 1) |
| URY-2 | Scope and Definitions (Article 2–4) |
Chapter II — National Data Protection Commission (CNPD)
| Code | Title |
|---|---|
| Art. 11 | Technical Documentation |
| Art. 5 | Prohibited AI Practices |
| Art. 6 | Writing |
| Art. 7 | Minimum Standards |
| Art. 8 | Compliance with the Requirements |
Chapter III — Rights of Data Subjects
| Code | Title |
|---|---|
| Art. 14 | Human Oversight |
| Art. 16 | Obligations of Providers of High-Risk AI Systems |
| Art. 17 | Quality Management System |
| Art. 18 | Documentation Keeping |
| Art. 19 | Automatically Generated Logs |
| Art. 20 | Corrective Actions and Duty of Information |
| Art. 21 | Cooperation with Competent Authorities |
| Art. 23 | Transitional Provisions |
| Art. 25 | Criminal Penalties |
| URY-7 | Right of Access (Article 13) |
| URY-8 | Right of Rectification (Article 15) |
| URY-9 | Right of Deletion (Article 15) |
Chapter IV — Controller and Processor
| Code | Title |
|---|---|
| Art. 21 | Cooperation with Competent Authorities |
| Art. 22 | Authorised Representatives of Providers of High-Risk AI Systems |
| Art. 23 | Transitional Provisions |
Chapter V — Specific Processing Situations
| Code | Title |
|---|---|
| Art. 24 | Restrictions on Processing Unique Identification Information |
| Art. 26 | Obligations of Deployers of High-Risk AI Systems |
| Art. 27 | Fundamental Rights Impact Assessment for High-Risk AI Systems |
| Art. 28 | Notifying Authorities |
| Art. 29 | Application of a Conformity Assessment Body for Notification |
Chapter VI — Sanctions
| Code | Title |
|---|---|
| Art. 37 | Right to Suspension of Processing |
| Art. 38 | Processing in Employment Context |
| Art. 39 | Compensation for Damages |
| Art. 43 | Mediation of Disputes |
Chapter VII — Final and Transitional Provisions
| Code | Title |
|---|---|
| Art. 59 | Entry into Force |
| Art. 61 | Repeal |
| Art. 62 | Entry into Force |
Data Lifecycle
| Code | Title |
|---|---|
| PT-DPA-12 | Retention Periods and Erasure |
Data Subject Rights
| Code | Title |
|---|---|
| PT-DPA-02 | Portuguese Language Privacy Notices |
| PT-DPA-03 | Consent Framework and Withdrawal |
Data Transfers
| Code | Title |
|---|---|
| PT-DPA-11 | International Transfers |
Employment Privacy
| Code | Title |
|---|---|
| PT-DPA-06 | Employee Data and Workplace Monitoring |
Governance
| Code | Title |
|---|---|
| PT-DPA-01 | Designation of Data Protection Officer and Communication to CNPD |
| PT-DPA-08 | Records of Processing Activities (RoPA) |
| PT-DPA-18 | Accountability Demonstration |
Incident Management
| Code | Title |
|---|---|
| PT-DPA-10 | Breach Notification to CNPD |
Information Security
| Code | Title |
|---|---|
| PT-DPA-09 | Security of Processing |
Marketing
| Code | Title |
|---|---|
| PT-DPA-13 | Direct Marketing and Cookies |
Regulatory Compliance
| Code | Title |
|---|---|
| PT-DPA-16 | CNPD Inspections and Cooperation |
Risk Management
| Code | Title |
|---|---|
| PT-DPA-07 | Data Protection Impact Assessment (DPIA) |
Special Categories
| Code | Title |
|---|---|
| PT-DPA-04 | Rights of Deceased Persons |
| PT-DPA-05 | Children Consent Age |
| PT-DPA-14 | Health Data Processing |
Third Party Management
| Code | Title |
|---|---|
| PT-DPA-15 | Processor Agreements and Sub-Processing |
Your Compliance Coverage
If you comply with Portugal Law No. 58/2019 — Data Protection Implementation Act, you already cover:
EU AI Act
31%
19 controls mapped
Compare →Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data
31%
19 controls mapped
Compare →Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014)
29%
18 controls mapped
Compare →+ 609 more: Uruguay Personal Data Protection Act (Law No. 18.331) (29%), GDPR (29%)
See all 612 mapped frameworks ↓Maps to 612 other frameworks
Frequently Asked Questions
What is Portugal Law No. 58/2019 — Data Protection Implementation Act?
Portugal Law No. 58/2019 — Data Protection Implementation Act is a compliance framework from Portugal with 20 domains and 65 controls. Portugal's Law No. 58/2019 supplements the EU GDPR with national provisions. The Comissão Nacional de Protecção de Dados (CNPD — National Data Protection Commission) oversees enforcement. The law includes provisions for the age of digital consent (13 years), processing by the public sector, employee data, video surveillance, deceased persons' data, and research derogations. Portugal was one of the later EU Member States to adopt its GDPR supplementary legislation. It is used by organisations to establish and maintain compliance with industry standards and regulatory requirements.
How many controls does Portugal Law No. 58/2019 — Data Protection Implementation Act have?
Portugal Law No. 58/2019 — Data Protection Implementation Act has 65 controls organised across 20 domains. The largest domains are Chapter I — General Provisions (15 controls), Chapter III — Rights of Data Subjects (12 controls), Chapter II — National Data Protection Commission (CNPD) (5 controls). Each control defines specific requirements that organisations must implement to achieve compliance.
What frameworks does Portugal Law No. 58/2019 — Data Protection Implementation Act map to?
Portugal Law No. 58/2019 — Data Protection Implementation Act maps to 612 other compliance frameworks. The top mapping partners are EU AI Act (31% coverage), Law 1581 of 2012 - Statutory Framework for the Protection of Personal Data (31% coverage), Albania Law on Protection of Personal Data (Law No. 9887, 2008, amended 2014) (29% coverage). Use our comparison tool to explore control-level mappings between frameworks.
How do I get started with Portugal Law No. 58/2019 — Data Protection Implementation Act compliance?
Start your Portugal Law No. 58/2019 — Data Protection Implementation Act compliance journey by running a self-assessment on our platform to identify your current compliance posture. Our AI advisory can answer specific questions about Portugal Law No. 58/2019 — Data Protection Implementation Act requirements, and cross-framework mapping helps you leverage existing controls from other frameworks you may already comply with. Create a free account to access all 65 controls and track your progress.
Start Your Compliance Journey
Create a free account to run self-assessments, get AI advisory, and track your compliance progress across 718 frameworks.
Get Started Free →Free forever — no credit card required