or (2) it affects data holders located in Portugal and such data processing is covered
by Article 3 (2) of GDPR
2 ; or (3) it affects data registered in Portuguese consulates,
the holders of which are Portuguese citizens residing abroad (Article 2).
In the field of electronic communications Law no. 41/2004 is applicable.
According to Article 2, the scope of this law covers the processing of personal
data within the context of public communications networks. The purpose of the law
is to specify the domestic rules on data protection in respect of electronic communications (Article 1/2).
The providers of electronic communications must notify the Portuguese Data
Protection Authority, without further delay, of the occurrence of any events that may
affect the security of personal data (Article 3-A).
Article 35/2 of the Constitution states that an independent administrative entity
must be created to guarantee the protection of personal data.
The Portuguese Data Protection Authority, the Comissão Nacional de Proteção
de Dados—CNPD (National Data Protection Commission), is defined by Law
no. 58/2019 as an independent administrative entity endowed with the power to
supervise and monitor compliance with the laws and regulations in the area of
personal data protection, in order to protect human rights and the fundamental
freedoms and guarantees of individuals in the area of personal data treatment (Article
4/1).
As a consequence thereof, in matters of data protection there is only one supervisory body in Portugal—the CNPD.
Article 6 of Law no. 58/2019 designates the CNPD as the national supervisory
authority for the purposes of article 57 of the GDPR.
The CNPD is further entrusted with the following assignments: (1) to issue
non-binding opinions on legislative and regulatory measures on data protection, as
well as on legal instruments under preparation in European and International institutions on the same matters; (2) to monitor compliance with the GDPR and other
legislative and regulatory provisions on data protection; (3) to make available a list
of processing operations which are subject, pursuant to Article 35 (4) of the GDPR,
to an impact assessment; (4) to draw up and submit to the European Data Protection
Board a draft of requirements for the accreditation of monitoring bodies pursuant to
Articles 41 and 43 of the GDPR; (5) to cooperate with the Portuguese Accreditation
Institute (IPAC). (Article 6 (1) of the Law).
The CNPD also exercises the powers foreseen in Article 38 of the GDPR (Article
6 (2) of the Law).
Article 15 (1) provides that the CNPD shall encourage the drawing up of codes of
conduct concerning specific activities. The Portuguese Association of Direct Marketing approved in 2003 a Code of Conduct applicable in matters of personal data
processing, based on a previous opinion approved by the Portuguese DPA.
3
According to the said code, companies are required to erase personal data collected
2 On which see, in Portuguese, Pinheiro et al. (2018).
3 http://www.amd.pt/codigoconduta.pdf.
272
A. S. Pinheiro
Précédent

- 276/540

Suivant