Law No. 133/V/2001 on the Protection of Personal Data, enforcement and supervision
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force.
An enforcement supervision rule binding public and private bodies.
As of 19 September 2026.
What it requires
- Expect the CNPD, an independent administrative authority operating within the National Assembly, to follow up, evaluate and control compliance with this law, safeguarding the fundamental rights, freedoms and guarantees of citizens.
- Submit a code of conduct to the CNPD before relying on it, and expect the CNPD to declare whether it complies with the data protection laws and regulations in force.
- Expect any individual to be able to seek legal recourse for a violation of their rights under this law, in addition to filing a complaint with the CNPD.
- Expect to be held liable to compensate a data subject for damage caused by an unlawful processing operation or another act incompatible with this law, unless you can show you are not responsible for the fact that caused the damage.
- Expect an administrative fine of CVE 50,000 to 500,000 for a single individual or CVE 300,000 to 3,000,000 for a group or unincorporated entity for omitting or falsifying the article 23 or 24 notification or authorisation, doubled to the maximum for data subject to article 24 prior authorisation, or a fine of CVE 100,000 to 1,000,000, doubled for violating articles 7 to 10, 19 or 20, for another listed omission.
- Expect criminal liability of up to one year's imprisonment or a fine of up to 120 days, doubled for article 8 or 9 sensitive data, for intentionally omitting a required CNPD notification or authorisation, giving false information in one, misappropriating data, or carrying out an illegal data combination.
- Do not access personal data barred to you without due authorisation, on pain of up to one year's imprisonment or a fine of up to 120 days, doubled where achieved by defeating security rules or for a benefit.
- Do not erase, destroy, damage or alter personal data without authorisation, on pain of up to two years' imprisonment or a fine of up to 240 days, doubled for particularly serious damage.
- Interrupt, cease or block processing once notified to do so, cooperate with a CNPD request, and destroy personal data once its retention period under article 6 has elapsed, on pain of the penalty for qualified non-compliance.
- Keep personal data confidential once bound by professional secrecy, on pain of imprisonment from six months to three years or a fine of eighty to two hundred days, increased by half for a civil servant, a financial gain motive, or harm to the data subject's reputation, honour or privacy.
- Expect a court to add, alongside a fine or penalty, a temporary or permanent processing ban, an order to block, erase or destroy data, or publication of the conviction at your expense in a widely circulated periodical.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Intentional non-compliance with the notification or authorisation duties draws up to one year's imprisonment or a fine of up to 120 days, doubled to the maximum where the data is Article 8 or 9 sensitive data (Article 40); undue access to prohibited personal data draws the same range, doubled for a security rule violation or an obtained benefit (Article 41); invalidation or destruction of personal data draws up to two years' imprisonment or a fine of up to 240 days, doubled for particularly serious damage (Article 42); qualified non-compliance, including failing to cooperate with the CNPD or to erase or destroy personal data after notice or after its retention period has elapsed, draws the corresponding penalty (Article 43); and violation of professional secrecy over personal data draws imprisonment from six months to three years or a fine of 80 to 200 days, increased by half for a civil servant or a material advantage motive (Article 44). These are day fine terms; the statute does not itself state the escudo value of a day fine unit.
Penalty structure
Administrative offences: omitting the Article 23/24 notification or authorisation, or giving false information in it, draws a fine of CVE 50,000 to 500,000 for a single individual or CVE 300,000 to 3,000,000 for a group or unincorporated entity, doubled to the maximum for data subject to Article 24 prior authorisation (Article 33); other listed omissions draw a fine of CVE 100,000 to 1,000,000 (Article 34). Separately, Articles 40 to 44 create day fine and imprisonment crimes for the same and related conduct; see criminal_exposure_note.
- Rule
- Fixed only
- As of
- 19 September 2026
- Minimum
- 50,000
- Currency
- CVE
- Fixed cap
- 3,000,000
Who enforces it
Enforcement body
Comissão Nacional de Protecção de Dados (CNPD)
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 21 has the CNPD follow up, evaluate and control the activities of legally competent organs or services processing personal data, safeguarding the Constitution, this Law, and the fundamental rights, freedoms and guarantees of citizens, and Article 22 establishes the CNPD as an independent administrative authority operating within the National Assembly.
Article 29 has the CNPD help draft codes of conduct and declare whether a submitted draft complies with the data protection laws and regulations in force.
Article 30 lets any individual seek legal recourse for a violation of their rights under this law, in addition to a complaint to the CNPD, and Article 31 entitles a person who suffers damage from an unlawful processing operation or another act incompatible with this law to compensation from the controller, who may be exempted in whole or in part on proving they are not responsible for the damage.
Article 33 fines an entity that negligently omits, falsifies, or otherwise fails the article 23 or 24 notification or authorisation duty from CVE 50,000 to CVE 500,000 for a single individual or CVE 300,000 to CVE 3,000,000 for a group or unincorporated entity, doubled to the maximum for data subject to article 24 prior authorisation, and Article 34 fines another listed omission, including failing to designate a representative or to observe the article 6, 11, 12, 13, 14, 16 or 17 obligations, from CVE 100,000 to CVE 1,000,000, doubled for a failure touching articles 7, 8, 9, 10, 19 or 20.
Article 40 makes it a crime, punishable by up to one year's imprisonment or a fine of up to 120 days and doubled for article 8 or 9 sensitive data, to intentionally omit a required CNPD notification or authorisation, give false information in one, misappropriate personal data, or carry out an illegal combination of personal data.
Article 41 makes undue access to prohibited personal data a crime punishable the same way, doubled where achieved by violating a technical security rule or for a benefit, and prosecutable only on complaint. Article 42 makes invalidating or destroying personal data without authorisation a crime punishable by up to two years' imprisonment or a fine of up to 240 days, doubled for particularly serious damage.
Article 43 makes failing to interrupt, cease or block processing after notice, refusing to cooperate with the CNPD, or failing to erase or destroy personal data once its retention period under article 6 has elapsed, punishable as qualified non-compliance.
Article 44 makes violating the duty of professional secrecy over personal data a crime punishable by imprisonment from six months to three years or a fine of eighty to two hundred days, increased by half for a civil servant, a material advantage motive, or harm to the data subject's reputation, honour or privacy.
Article 46 lets a court order, in addition to a fine or penalty, a temporary or permanent prohibition of processing, blocking, erasure or destruction of data, or publication of the judgement at the convicted party's expense.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsis_listed_company
Read the law
Official English translation of Law No. 133/V/2001 of 22 January
on the Protection of Individuals with Regard to the Processing of Personal Data, published by the Comissão Nacional de Protecção de Dados (CNPD)
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.