CNPD
Comissão Nacional de Proteção de Dados
Portuguese authority with notable hospital and municipal sanctions.
15months
Healthcare, Public sector, Telecom
Enforcement Cases (10)
AMA - Agência para a Modernização Administrativa
technologyCNPD criticized a public digital-services operator for privacy-by-design shortcomings in citizen self-service workflows, engaging GDPR Articles 25 and 32.
€110,000.0
Millennium BCP
technologyCNPD reviewed banking customer-data governance and found shortcomings in retention and internal access controls under GDPR Articles 5, 24 and 32.
€180,000.0
CUF Saúde
technologyCNPD sanctioned CUF Saúde for insufficient controls over employee access to patient information and inadequate audit logging under GDPR Articles 5 and 32.
€275,000.0
Universidade do Porto
technologyCNPD found excessive retention of student and alumni records and incomplete transparency notices, implicating GDPR Articles 5 and 13.
€90,000.0
Vodafone Portugal
technologyCNPD investigated Vodafone Portugal after a security incident affecting customer data and found deficiencies in technical and organizational measures under GDPR Articles 24 and 32.
€450,000.0
EDP Comercial
technologyCNPD sanctioned EDP Comercial over direct-marketing and profiling transparency deficiencies, citing GDPR Articles 12, 13 and 21.
€220,000.0
NOS Comunicações
technologyCNPD reviewed telecom customer-data retention and marketing consent practices at NOS, identifying shortcomings under GDPR Articles 5, 6, 7 and 21.
€300,000.0
Municipality of Lisbon
technologyCNPD fined Lisbon's municipality after personal data of political activists was shared with foreign embassies without lawful basis, implicating GDPR Articles 5, 6 and 32.
€1.3M
Hospital Garcia de Orta
technologyCNPD sanctioned the hospital for inadequate access governance and insufficient segregation of user profiles in clinical systems under GDPR Articles 5 and 32.
€150,000.0
Centro Hospitalar Barreiro Montijo
technologyCNPD fined a Portuguese hospital for allowing excessive numbers of users, including doctors without active functions, to access patient records, violating GDPR Articles 5, 24 and 32.
€400,000.0