Portugal Law No. 58/2019 - Data Protection Implementation Act
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Accountability Instruments
Per Portugal law + GDPR Articles 25 + 30 + 35: accountability instruments. Requirements include (a) conduct Data Protection Impact Assessment (DPIA) for high-risk processing per GDPR Article 35 + CNPD (Comissao Nacional de Proteccao de Dados) lists + (b) implement Privacy by Design and by Default per GDPR Article 25 + (c) maintain Records of Processing Activities (RoPA) per GDPR Article 30 + (d) implement Accountability Demonstration including governance + roles + documentation + (e) integrate with broader privacy + risk + IT governance + (f) maintain documented accountability framework.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-4
- CNPD notification + health data + DPIA partial
Breach and Enforcement
Per Portugal law + GDPR Articles 33-34 + 77-84: breach notification + enforcement. Requirements include (a) implement Personal Data Breach Notification to CNPD (Comissao Nacional de Proteccao de Dados) within 72 hours of becoming aware unless unlikely to result in risk + notify affected data subjects where high risk per GDPR Article 34 + (b) operate Security Incident Response Procedures including detection + triage + containment + recovery + lessons learned + (c) maintain CNPD (Comissao Nacional de Proteccao de Dados) Inspections and Cooperation cooperation including responding to inspection + audit + complaint + (d) maintain Enforcement and Penalties awareness including administrative fines (up to higher of EUR 20m or 4% global annual turnover) + national criminal penalties + civil liability + (e) maintain breach log + incident response + tabletop exercises.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-8
- CNPD notification + health data + DPIA partial
Cross-Border Transfer
Per Portugal law + GDPR Chapter V: international transfers. Requirements include (a) implement International Transfers restrictions per GDPR including adequacy + appropriate safeguards (SCCs + BCRs + certification) + derogations + (b) maintain Cross-Border Transfer Safeguards documentation + Transfer Impact Assessment (TIA) per Schrems II + (c) maintain inventory of cross-border flows + recipients + safeguards + (d) implement contractual protections with processors involving international transfer + (e) cooperate with CNPD (Comissao Nacional de Proteccao de Dados) on transfer matters.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-6
- CNPD notification + health data + DPIA partial
Governance and Lifecycle
Per Portugal law + GDPR: governance + lifecycle. Requirements include (a) Designation and Notification of Data Protection Officer (DPO) per GDPR Article 37 + national requirements with notification to CNPD (Comissao Nacional de Proteccao de Dados) + (b) cooperate with CNPD (Comissao Nacional de Proteccao de Dados) (CNPD) including responding to inquiries + facilitating audits + (c) implement Retention and Erasure including retention schedules + secure deletion + (d) implement Direct Marketing and Cookies safeguards per national + EU ePrivacy + (e) deliver Training and Awareness programmes including role-based content + national specifics + (f) maintain documented governance + accountability framework.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-7
- CNPD notification + health data + DPIA partial
High-Risk Processing
Per Portugal law + GDPR Article 9 + national supplements: heightened safeguards. Requirements include (a) implement Special Categories and Sensitive Data protections per GDPR Article 9 + Portugal-specific safeguards + (b) implement Children's Data including consent age per national law (13 years per Portuguese law) + (c) implement Employee Monitoring and Workplace Privacy controls per Portugal labour law + GDPR + (d) implement Health Data Processing per national + GDPR requirements + (e) conduct DPIA where required + (f) maintain documented safeguards + risk assessments.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-3
- CNPD notification + health data + DPIA partial
Individual Rights
Per Portugal law + GDPR Articles 12-23: data subject rights. Requirements include (a) implement Data Subject Rights Handling including Access + Rectification + Erasure + Restriction + Object + Data Portability per GDPR + (b) implement Information Obligation in Portuguese including privacy notices in national language per CNPD (Comissao Nacional de Proteccao de Dados) guidance + (c) maintain mechanism for receiving + verifying + responding within statutory timelines (typically 30 days extendable) + (d) maintain records of requests + responses + decisions + (e) integrate with broader privacy programme.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-2
- CNPD notification + health data + DPIA partial
Scope and Lawful Basis
Per Portugal Lei 58/2019 implementing GDPR: scope + lawful basis + Portugal-specific supplements. Requirements include (a) determine GDPR + national law scope including extraterritorial application + sectoral specifics + (b) establish Lawful Basis per GDPR Article 6 + Article 9 for special categories + national derogations + (c) maintain Lawful Basis Register and Documentation + (d) provide Privacy Notices in Portuguese per national requirement + (e) document applicability + lawful basis + (f) align with CNPD (Comissao Nacional de Proteccao de Dados) guidance + national derogations + supplements.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-1
- CNPD notification + health data + DPIA partial
Security and Processor
Per Portugal law + GDPR Articles 32 + 28: security + processor management. Requirements include (a) implement Security of Processing including organisational + technical + appropriate to risk per GDPR Article 32 + CNPD (Comissao Nacional de Proteccao de Dados) security guidance + (b) maintain Processor Agreements per GDPR Article 28 ensuring processors process only on documented instructions + maintain security + assist with rights + breach notification + (c) implement supplier + processor + sub-processor due diligence + (d) conduct regular security testing + (e) integrate with broader information security programme.
- Portugal Lei 58/2019 + GDPR evidence for PORTUGAL-5
- CNPD notification + health data + DPIA partial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.