Skip to content

Evidence request lists

Portugal Law No. 58/2019 - Data Protection Implementation Act

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Accountability Instruments

PORTUGAL-4
DPIA, Privacy by Design, Records of Processing

Per Portugal law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + CNPD (Comissao Nacional de Proteccao de Dados) lists + (b) implement Privacy by Design and by Default per GDPR Article 25 + (c) maintain Records of Processing Activities (RoPA) per GDPR Article 30 + (d) implement Accountability Demonstration including governance + roles + documentation + (e) integrate with broader privacy + risk + IT governance + (f) maintain documented accountability framework.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-4
Where this commonly fails
  • CNPD notification + health data + DPIA partial

Breach and Enforcement

PORTUGAL-8
Breach Notification, CNPD (Comissao Nacional de Proteccao de Dados) Inspections, Enforcement

Per Portugal law + GDPR Articles 33-34 + 77-84: breach notification + enforcement. Requirements include (a) implement Personal Data Breach Notification to CNPD (Comissao Nacional de Proteccao de Dados) within 72 hours of becoming aware unless unlikely to result in risk + notify affected data subjects where high risk per GDPR Article 34 + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) maintain CNPD (Comissao Nacional de Proteccao de Dados) Inspections and Cooperation cooperation including responding to inspection + audit + complaint + (d) maintain Enforcement and Penalties awareness including administrative fines (up to higher of EUR 20m or 4% global annual turnover) + national criminal penalties + civil liability + (e) maintain breach log + incident response + tabletop exercises.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-8
Where this commonly fails
  • CNPD notification + health data + DPIA partial

Cross-Border Transfer

PORTUGAL-6
International Transfers

Per Portugal law + GDPR Chapter V: international transfers. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain inventory of cross-border flows + recipients + safeguards + (d) implement contractual protections with processors involving international transfer + (e) cooperate with CNPD (Comissao Nacional de Proteccao de Dados) on transfer matters.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-6
Where this commonly fails
  • CNPD notification + health data + DPIA partial

Governance and Lifecycle

PORTUGAL-7
DPO Designation, CNPD (Comissao Nacional de Proteccao de Dados) Cooperation, Retention, Marketing, Training

Per Portugal law + GDPR: governance + lifecycle. Requirements include (a) Designation and Notification of Data Protection Officer (DPO) per GDPR Article 37 + national requirements with notification to CNPD (Comissao Nacional de Proteccao de Dados) + (b) cooperate with CNPD (Comissao Nacional de Proteccao de Dados) (CNPD) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + (d) implement Direct Marketing and Cookies safeguards per national + EU ePrivacy + (e) deliver Training and Awareness programmes including role-based content + national specifics + (f) maintain documented governance + accountability framework.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-7
Where this commonly fails
  • CNPD notification + health data + DPIA partial

High-Risk Processing

PORTUGAL-3
Special Categories, Children, Employee Monitoring, Health Data

Per Portugal law + GDPR Article 9 + national supplements: heightened safeguards. Requirements include (a) implement Special Categories and Sensitive Data protections per GDPR Article 9 + Portugal-specific safeguards + (b) implement Children's Data including consent age per national law (13 years per Portuguese law) + (c) implement Employee Monitoring and Workplace Privacy controls per Portugal labour law + GDPR + (d) implement Health Data Processing per national + GDPR requirements + (e) conduct DPIA where required + (f) maintain documented safeguards + risk assessments.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-3
Where this commonly fails
  • CNPD notification + health data + DPIA partial

Individual Rights

PORTUGAL-2
Data Subject Rights Handling and Information Obligation

Per Portugal law + GDPR Articles 12-23: data subject rights. Requirements include (a) implement Data Subject Rights Handling including Access + Rectification + Erasure + Restriction + Object + Data Portability per GDPR + (b) implement Information Obligation in Portuguese including privacy notices in national language per CNPD (Comissao Nacional de Proteccao de Dados) guidance + (c) maintain mechanism for receiving + verifying + responding within statutory timelines (typically 30 days extendable) + (d) maintain records of requests + responses + decisions + (e) integrate with broader privacy programme.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-2
Where this commonly fails
  • CNPD notification + health data + DPIA partial

Scope and Lawful Basis

PORTUGAL-1
GDPR Implementation Scope and Lawful Basis (Portugal)

Per Portugal Lei 58/2019 implementing GDPR: scope + lawful basis + Portugal-specific supplements. Requirements include (a) determine GDPR + national law scope including extraterritorial application + sectoral specifics + (b) establish Lawful Basis per GDPR Article 6 + Article 9 for special categories + national derogations + (c) maintain Lawful Basis Register and Documentation + (d) provide Privacy Notices in Portuguese per national requirement + (e) document applicability + lawful basis + (f) align with CNPD (Comissao Nacional de Proteccao de Dados) guidance + national derogations + supplements.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-1
Where this commonly fails
  • CNPD notification + health data + DPIA partial

Security and Processor

PORTUGAL-5
Security of Processing and Processor Agreements

Per Portugal law + GDPR Articles 32 + 28: security + processor management. Requirements include (a) implement Security of Processing including organisational + technical + appropriate to risk per GDPR Article 32 + CNPD (Comissao Nacional de Proteccao de Dados) security guidance + (b) maintain Processor Agreements per GDPR Article 28 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement supplier + processor + sub-processor due diligence + (d) conduct regular security testing + (e) integrate with broader information security programme.

Artefacts an auditor will ask for
  • Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-5
Where this commonly fails
  • CNPD notification + health data + DPIA partial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.