2002 concerning the processing of personal data and the protection of privacy in the
electronic communications sector.” (Article 1/1).
The providers of publicly available electronic communications services or of
public communications networks must retain the following categories of data:
(a) Data necessary to trace and identify the source of a communication; (b) Data
necessary to trace and identify the destination of a communication; (c) Data necessary to identify the date, time and duration of a communication; (d) Data necessary to
identify the type of communication; (e) Data necessary to identify users’ communication equipment or what purports to be their equipment; (f) Data necessary to
identify the location of mobile communication equipment (Article 4/1).
The providers referred to in section 1 of Article 4 must retain data provided for
therein for a one-year-period from the date of the communication (Article 6).
The Portuguese Data Protection Act contemplates the following specific crimes:
(i) “Non-compliance with obligations relating to data protection” which consists
of: (a) omitting the notification or the application for authorisation referred to in
Articles 27 and 28; (b) providing false information in the notification or in
applications for authorisation for the processing of personal data or makes
alterations in the latter which are not permitted by the legalisation instrument;
(c) misappropriating or using personal data in a form incompatible with the
purpose of the collection or with the legalisation instrument; (d) promoting or
carrying out an illegal combination of personal data; (e) failing to comply with
the obligations provided for in this Act or in other data protection legislation
when the time limit fixed by the CNPD for complying with them has expired;
(f) continuing to allow access to open data transmission networks to controllers
who fail to comply with the provisions of this Act after notification by the
CNPD not to do so, shall be liable to up to one year’s imprisonment or a fine of
up to 120 days (Article 43);
(ii) “Undue access”, which consists of a person acting without due authorisation in
order to gain access by any means to personal data prohibited to it, such person
being liable to up to one year of imprisonment or a fine of up to 120 days. The
penalty shall be increased to the double of the maxima when access: (a) is
achieved by violating technical security rules; (b) allows the agent or third
parties to obtain knowledge of personal data and (c) provides the agent or third
parties with a benefit or material advantage (Article 44);
(iii) “Invalidation or destruction of personal data”, which consists of acting without
due authorisation, erasing, destroying, damaging, deleting or changing personal
data, making them non usable or affecting their capacity for use, the agent being
liable to up to 2 years of imprisonment or a fine of up to 240 days. The penalty
shall be increased to the double of the maxima if the damage caused is
particularly serious (Article 45);
(iv) “Qualified non-compliance”, which concerns any person who, after being
notified to do so, does not interrupt, cease or block the processing of personal
data, such person being subject to a penalty corresponding to the crime of
qualified non-compliance (Article 46);
282
A. S. Pinheiro
electronic communications sector.” (Article 1/1).
The providers of publicly available electronic communications services or of
public communications networks must retain the following categories of data:
(a) Data necessary to trace and identify the source of a communication; (b) Data
necessary to trace and identify the destination of a communication; (c) Data necessary to identify the date, time and duration of a communication; (d) Data necessary to
identify the type of communication; (e) Data necessary to identify users’ communication equipment or what purports to be their equipment; (f) Data necessary to
identify the location of mobile communication equipment (Article 4/1).
The providers referred to in section 1 of Article 4 must retain data provided for
therein for a one-year-period from the date of the communication (Article 6).
The Portuguese Data Protection Act contemplates the following specific crimes:
(i) “Non-compliance with obligations relating to data protection” which consists
of: (a) omitting the notification or the application for authorisation referred to in
Articles 27 and 28; (b) providing false information in the notification or in
applications for authorisation for the processing of personal data or makes
alterations in the latter which are not permitted by the legalisation instrument;
(c) misappropriating or using personal data in a form incompatible with the
purpose of the collection or with the legalisation instrument; (d) promoting or
carrying out an illegal combination of personal data; (e) failing to comply with
the obligations provided for in this Act or in other data protection legislation
when the time limit fixed by the CNPD for complying with them has expired;
(f) continuing to allow access to open data transmission networks to controllers
who fail to comply with the provisions of this Act after notification by the
CNPD not to do so, shall be liable to up to one year’s imprisonment or a fine of
up to 120 days (Article 43);
(ii) “Undue access”, which consists of a person acting without due authorisation in
order to gain access by any means to personal data prohibited to it, such person
being liable to up to one year of imprisonment or a fine of up to 120 days. The
penalty shall be increased to the double of the maxima when access: (a) is
achieved by violating technical security rules; (b) allows the agent or third
parties to obtain knowledge of personal data and (c) provides the agent or third
parties with a benefit or material advantage (Article 44);
(iii) “Invalidation or destruction of personal data”, which consists of acting without
due authorisation, erasing, destroying, damaging, deleting or changing personal
data, making them non usable or affecting their capacity for use, the agent being
liable to up to 2 years of imprisonment or a fine of up to 240 days. The penalty
shall be increased to the double of the maxima if the damage caused is
particularly serious (Article 45);
(iv) “Qualified non-compliance”, which concerns any person who, after being
notified to do so, does not interrupt, cease or block the processing of personal
data, such person being subject to a penalty corresponding to the crime of
qualified non-compliance (Article 46);
282
A. S. Pinheiro
