Sources checked
Does a startup in Portugal legally need to appoint a Data Protection Officer?
Under GDPR Article 37(1), you need a Data Protection Officer only if you are a public authority or body, or your core activities are large-scale, regular and systematic monitoring of people, or large-scale processing of special category or criminal-record data. Portugal's Lei n.º 58/2019 repeats this exact test for private companies, adding no extra trigger. Most early-stage startups process data as a support function, not a core activity, far below these thresholds, so most do not need one.
The three GDPR Article 37(1) triggers
- You are a public authority or body. Any processing carried out by a public authority or body, except courts acting in their judicial capacity (GDPR Art. 37(1)(a)). Lei n.º 58/2019, Article 12, makes this mandatory for an exhaustive list of Portuguese public bodies: the State, the autonomous regions, municipalities and parishes, independent administrative entities and Banco de Portugal, public institutes, public higher-education institutions, and state-owned enterprises.
- Large-scale, regular and systematic monitoring is a core activity. Your core activities — not a side function — require regular and systematic monitoring of people at large scale (GDPR Art. 37(1)(b)). EDPB/WP29 guidance gives continuous behavioural or location tracking as an example; standard website analytics on a small customer base is not this.
- Large-scale special-category or criminal-record processing is a core activity. Your core activities involve large-scale processing of special category data (health, biometric, genetic, ethnicity, and similar under GDPR Art. 9) or criminal-conviction data (GDPR Art. 10) (GDPR Art. 37(1)(c)). A platform built around processing patient health records at scale meets this; a company that merely holds ordinary employee HR files does not.
Sources
Related questions
- What counts as a 'core activity' versus a support function?
- The EDPB-endorsed WP29 guidelines (wp243rev.01) define core activities as the key operations needed to reach your organisation's main objective, including any processing that is an inseparable part of that objective — like a hospital processing patient health data to deliver care. Standard support functions, such as running payroll or basic IT administration, are ancillary, not core, even though they involve personal data.
- What does 'large scale' actually mean?
- GDPR does not set a number. WP29/EDPB guidance points to four factors to weigh together: how many people are affected (an absolute figure or a share of the population), how much data and how many different data items you process, how long the processing runs, and its geographic reach. A startup with a few hundred B2B contacts is not large scale; an app continuously tracking millions of users' location is.
- Does Portuguese law add any DPO trigger that GDPR doesn't already have?
- Not for private companies. Lei n.º 58/2019, Article 13, restates the same two GDPR private-sector tests almost word for word. What Portuguese law adds is narrower: Article 12 turns the 'public authority' trigger into an exhaustive list of which bodies count, and Article 11 gives whoever holds the DPO role extra duties beyond GDPR Articles 37-39 — running periodic and ad hoc audits, raising staff awareness of security incidents, and handling data-subject relations.
- If we're below the threshold, does anything about data protection officers still apply to us?
- Yes, two things. GDPR Article 37(4) lets you appoint a DPO voluntarily even when not required, and once you do, the independence and task duties in Articles 38 and 39 apply the same way as if it were mandatory. Separately, Article 9(1) of Lei n.º 58/2019 confirms no professional certification is needed to act as a DPO in Portugal, which matters if you're weighing an in-house appointment against hiring externally.
- Who decides whether our company crosses the threshold?
- You do. The CNPD states on its own guidance page that it is up to the controller or processor to assess, case by case, whether its processing meets the Article 37 test, and that the CNPD does not rule on individual cases in advance.
What this answer does not cover
- This page covers only the GDPR Article 37(1) appointment test. It does not cover how to select, train, contract, or manage a DPO once one is required — that is GDPR Articles 38 and 39.
- It does not cover the separate procedural step of notifying the CNPD of a DPO's contact details once one is appointed.
- It does not set a numeric definition of 'large scale' — none exists in the law. A startup close to the line (fast user growth, continuous tracking, health or biometric data) needs a specific assessment, not this general guidance.
- It does not address sector-specific rules that can independently require a DPO regardless of company size, such as health-data registries or telecoms metadata processing.