The provider of a public network of communications must ensure a level of
security that is appropriate to the risks posed by the processing and the nature of the
data to be protected (section 2).
The Autoridade Nacional de Comunicações (ANACOM) has as its mission
regulating the communications sector, including electronic communications and,
within this context, it has the duty to approve recommendations on the best policies
to be adopted in the areas of security of personal data and data breaches (section 3).
Having regard to the state-of-the-art measures and the cost of their implementation,
such recommendations must be based on a level of security appropriate to the risks
represented by the processing and the nature of the data to be protected.
The recommendations of ANACOM must take into consideration the opinions
issued by the Portuguese DPA (section 8).
Article 3-A of Law no. 41/2004 provides that companies responsible for making
the electronic communications services accessible to the public shall notify the
Portuguese DPA of a personal data breaches without delay (section 1). The notification of the Portuguese DPA shall include the consequences of data breaches, and
the measures adopted to remedy them (section 8).
This notification must be sent to subscribers or users whenever it may affect them
negatively (section 2).
A negative effect on personal data exists whenever the breach may result, in
particular, in the theft of identity, fraud, physical harm, significant humiliation or
damage to reputation (section 3).
Irrespective of the above, if a person/entity is affected by a breach of Law
no. 67/98, it is entitled to file a claim to the Portuguese DPA and/or file a civil
lawsuit in order to seek compensation for damages (section 6).
Th said notification must include a reference to the nature of the breach of
personal data, information on where further information may be obtained and the
recommendation issued by ANACOM (section 7).
Companies that make available networks and electronic communications services
shall guarantee the inviolability of communications and traffic data involved therein
(Article 4/1).
The use of tapping and storing devices, and other means of monitoring and
intercepting electronic communications and traffic data involved may only be used
with the prior consent of the data subject or when mandatory by law (Article 4/2).
It is however allowed, with prior consent of the data subject, to record and to store
electronic communications and traffic data in the context of lawful contract practices
in order to prove if/or how a contract was concluded (Article 4/3).
It is also allowed to record electronic communications made to public bodies in
the context of emergency situations (Article 4/4).
Article 32 of the Portuguese Data Protection Act provides that the Portuguese
DPA shall encourage the drawing up of codes of conduct intended to contribute to
the proper implementation of the provisions of this Act, taking account of the
specific features of the various sectors (section 1).
Data Protection in the Internet: The Portuguese Case
277
security that is appropriate to the risks posed by the processing and the nature of the
data to be protected (section 2).
The Autoridade Nacional de Comunicações (ANACOM) has as its mission
regulating the communications sector, including electronic communications and,
within this context, it has the duty to approve recommendations on the best policies
to be adopted in the areas of security of personal data and data breaches (section 3).
Having regard to the state-of-the-art measures and the cost of their implementation,
such recommendations must be based on a level of security appropriate to the risks
represented by the processing and the nature of the data to be protected.
The recommendations of ANACOM must take into consideration the opinions
issued by the Portuguese DPA (section 8).
Article 3-A of Law no. 41/2004 provides that companies responsible for making
the electronic communications services accessible to the public shall notify the
Portuguese DPA of a personal data breaches without delay (section 1). The notification of the Portuguese DPA shall include the consequences of data breaches, and
the measures adopted to remedy them (section 8).
This notification must be sent to subscribers or users whenever it may affect them
negatively (section 2).
A negative effect on personal data exists whenever the breach may result, in
particular, in the theft of identity, fraud, physical harm, significant humiliation or
damage to reputation (section 3).
Irrespective of the above, if a person/entity is affected by a breach of Law
no. 67/98, it is entitled to file a claim to the Portuguese DPA and/or file a civil
lawsuit in order to seek compensation for damages (section 6).
Th said notification must include a reference to the nature of the breach of
personal data, information on where further information may be obtained and the
recommendation issued by ANACOM (section 7).
Companies that make available networks and electronic communications services
shall guarantee the inviolability of communications and traffic data involved therein
(Article 4/1).
The use of tapping and storing devices, and other means of monitoring and
intercepting electronic communications and traffic data involved may only be used
with the prior consent of the data subject or when mandatory by law (Article 4/2).
It is however allowed, with prior consent of the data subject, to record and to store
electronic communications and traffic data in the context of lawful contract practices
in order to prove if/or how a contract was concluded (Article 4/3).
It is also allowed to record electronic communications made to public bodies in
the context of emergency situations (Article 4/4).
Article 32 of the Portuguese Data Protection Act provides that the Portuguese
DPA shall encourage the drawing up of codes of conduct intended to contribute to
the proper implementation of the provisions of this Act, taking account of the
specific features of the various sectors (section 1).
Data Protection in the Internet: The Portuguese Case
277
