Jurisdictional Intelligence · PT
Portugal
Steady enforcement with landmark health-sector and public-sector sanctions.
Portugal's CNPD is a quiet but consistent enforcer with growing cross-border influence
Total Fines Tracked
€3.4M
EUR equivalent
Average Fine
€342.5K
per enforcement action
Top Sector
health
most-fined industry
Authorities
—
active regulators
Regulators
Authorities
No authority data yet.
Enforcement
Landmark Cases
AMA - Agência para a Modernização Administrativa
technologyCNPD criticized a public digital-services operator for privacy-by-design shortcomings in citizen self-service workflows, engaging GDPR Articles 25 and 32.
€110,000.0
Millennium BCP
technologyCNPD reviewed banking customer-data governance and found shortcomings in retention and internal access controls under GDPR Articles 5, 24 and 32.
€180,000.0
CUF Saúde
technologyCNPD sanctioned CUF Saúde for insufficient controls over employee access to patient information and inadequate audit logging under GDPR Articles 5 and 32.
€275,000.0
Universidade do Porto
technologyCNPD found excessive retention of student and alumni records and incomplete transparency notices, implicating GDPR Articles 5 and 13.
€90,000.0
Vodafone Portugal
technologyCNPD investigated Vodafone Portugal after a security incident affecting customer data and found deficiencies in technical and organizational measures under GDPR Articles 24 and 32.
€450,000.0
EDP Comercial
technologyCNPD sanctioned EDP Comercial over direct-marketing and profiling transparency deficiencies, citing GDPR Articles 12, 13 and 21.
€220,000.0
NOS Comunicações
technologyCNPD reviewed telecom customer-data retention and marketing consent practices at NOS, identifying shortcomings under GDPR Articles 5, 6, 7 and 21.
€300,000.0
Municipality of Lisbon
technologyCNPD fined Lisbon's municipality after personal data of political activists was shared with foreign embassies without lawful basis, implicating GDPR Articles 5, 6 and 32.
€1.3M
Hospital Garcia de Orta
technologyCNPD sanctioned the hospital for inadequate access governance and insufficient segregation of user profiles in clinical systems under GDPR Articles 5 and 32.
€150,000.0
Centro Hospitalar Barreiro Montijo
technologyCNPD fined a Portuguese hospital for allowing excessive numbers of users, including doctors without active functions, to access patient records, violating GDPR Articles 5, 24 and 32.
€400,000.0
Legal Framework
Regulations by Domain
Marketplace