Piracy and fraud access data of thousands of Portuguese citizens
A surge in data theft and fraudulent activities is compromising the personal information of thousands of Portuguese citizens, highlighting growing concerns over digital security.

Latest news and stories about data privacy in technology in Portugal for expats and residents.
A surge in data theft and fraudulent activities is compromising the personal information of thousands of Portuguese citizens, highlighting growing concerns over digital security.

Cybersecurity incidents surged from 2,000 in 2023 to over 61,000 last year, with 48,000 passwords compromised, largely due to enhanced automated detection systems.

The National Ethics Council warns of the risks of devices and applications that can cross-reference data to create profiles on emotions, behaviours, and mental states.

The country explained that it initiated this “investigation into Google Ireland Limited (‘Google’)” in February 2020, following complaints filed by several European consumer protection organisations.

The tech giant infringed the EU's General Data Protection Regulation.

When someone entrusts a secret to an artificial intelligence, are they merely using a tool or are they, legally speaking, telling it to a third party? Opinion by Francisco Teixeira da Mota

BMW has strengthened its European programme for collecting image data in real traffic, using customer vehicles to feed and refine future driver assistance systems and partially autonomous driving functions. The initiative focuses on the German manufacturer's new technological wave, leveraging the processing capabilities and sensors installed in vehicles with the Neue Klasse architecture. Unlike continuous monitoring, the system operates in a closed loop and reacts only to specific pre-programmed events. According to the manufacturer, the collection of images from exterior cameras and driving parameters (such as speed, steering angle, and trajectory) is only triggered when the vehicle registers evasive manoeuvres, hard braking, activations of autonomous emergency braking, or automatic swerving to avoid collisions on the motorway. In these situations, the car can store up to a maximum of 120 seconds of footage of the incident. The Munich-based brand justifies the methodology with the limitations of laboratory testing: simulations and internal development fleets cannot replicate the total unpredictability of daily traffic, turning the open-road experience into a living laboratory for training machine learning models. Participation in the programme depends on explicit authorisation from the owner and covers models such as the new iX3 and i3, as well as the latest generation of the X5 and the refreshed 7 Series. To meet European privacy protection requirements, the Bavarian brand has integrated 'privacy by design' safeguards: the vehicle identification number (VIN) is deleted as soon as the information is downloaded to BMW's servers, preventing the car from being traced. Additionally, faces of pedestrians and third-party licence plates captured by the cameras are hidden or blurred before any analysis by technical development teams, BMW guarantees. With this strategy, the manufacturer aims to ensure that the technological evolution of cars does not stagnate once they leave the assembly line, allowing the experience accumulated by real drivers to return to the entire fleet through over-the-air updates.

12,000 affected users will receive compensation of approximately 2,500 euros.

Following a fine in the US, the company may have to pay up to 6% of its sales volume in Europe for the same reasons.

Imposing the burden on platforms to store copies of identification documents, even with good intentions, is creating hundreds of 'mini-Discords' waiting to happen

Cette entreprise américaine spécialisée dans le traitement des données est profondément impliquée dans les processus européens les plus sensibles, qu'il s'agisse des forces de l'ordre, des services de renseignement ou du secteur de la santé. Il ne sera pas facile de lui trouver des alternatives.

Ethiack found a vulnerability, which it considers critical, in Ruby on Rails, an omnipresent open-source web framework.

Between the convenience of digital services and privacy protection, many consumers continue to accept data collection without fully understanding what they are authorizing. In this episode of Minuto Consumidor, we explain what cookies are, what they are used for, and what precautions you should take before clicking 'accept all'.

Mobile phone numbers, personal emails, and other data belonging to hundreds of thousands of Portuguese citizens are available online through monthly subscription services sold by various platforms, as demonstrated to Expresso by Andrea Mavilla, an Italian cybersecurity expert. This data includes information on members of the government, security forces, intelligence services, the judiciary, and other bodies.

Anthropic, the creator of the artificial intelligence (AI) platform Claude, revealed it discovered that its models invaded three organisations during cybersecurity testing. The models were supposedly operating in an isolated environment, but due to a 'misunderstanding' between the company and an external provider, this was not the case, it claims.

In November 2025, the European Commission introduced the Digital Omnibus, a legislative package aimed at simplifying Europe's digital regulatory ecosystem. By 2026, the package reached a decisive implementation phase, with the AI component approved and the general regulation progressing through the European Parliament. The initiative seeks to reduce friction caused by overlapping concepts and reporting requirements across existing frameworks like GDPR, NIS2, and the AI Act, without lowering protection standards. Key changes include raising the threshold for data breach notifications, harmonizing scientific research definitions, and introducing machine-readable consent for cookies. While the simplification is necessary, it also redefines the scope of personal data and expands grounds for AI development, shifting risks between stakeholders. For Portuguese SMEs, this presents a balance between reduced administrative burdens and the potential for increased reliance on external compliance expertise.

The University of Aveiro (UA) was the target of a cyberattack, with some email accounts being breached, the institution indicated today.
The University of Aveiro (UA) was the target of a cyberattack, with some email accounts compromised, the institution indicated this Wednesday. In a note published on its website, the UA states that it detected unauthorised access to its information systems, which resulted in the exposure of personal and institutional data.

Home News European Digital Identity Wallet set to launch in 2027 European Digital Identity Wallet set to launch in 2027 New voluntary system will allow EU citizens to store official documents digitally while giving users greater control over the personal information they share.

Data protection fails when it focuses on formalities and technical bureaucracy that only serve to delay those who defend us, while criminals operate outside of any rules.

An analysis of European Union policies regarding data privacy standards for international trade versus internal surveillance practices.
The preliminary findings recently published by the European Commission, as part of the proceedings regarding Alphabet Inc.'s compliance with the Digital Markets Act, propose measures that could force Google to share search data with competing search engines. These measures raise a central question regarding personal data protection: is there a risk...

The General Secretariat guarantees that it has not entered into any agreements with the American artificial intelligence solutions company, which has sparked controversy and has a strong presence in Europe.

The Human Consent Register, in its original designation, is accessible at rslmedia.org.

Following the controversy over the Christian-exclusive nature of an Anthropic summit, the company engaged with diverse religious leaders to discuss AI ethics. However, the article argues that while these diplomatic efforts are underway, millions of users are already treating AI chatbots as therapists, sharing deeply personal vulnerabilities. Unlike traditional confessionals or professional consultations, these digital interactions are not legally private; they are subject to subpoenas, data harvesting, and corporate exploitation. The author contends that no private company should hold the power to define the values of systems that interact with such intimacy, warning that good intentions cannot compensate for an architecture that inherently enables the abuse of human privacy.

The sessions address practical examples, such as identifying suspicious links and preventing the improper sharing of personal data.
Digital sovereignty is not a technical problem. It is a problem of power. Portugal, small and peripheral, will have to decide whether it wants to own its cloud or continue living under the cloud of others.

Data does not exist in a legal vacuum. It is subject to multiple jurisdictions, and the choice of a cloud service or electronic communications provider is simultaneously a choice regarding the legal regime to which the data is exposed.

Meta is implementing a new method to detect users under 13 on Instagram and Facebook by using artificial intelligence to analyse bone structure. Aiming to strengthen safety measures for minors, the company led by Mark Zuckerberg has expanded its AI system to the European Union to identify profiles of children who claim to be adults. The system evaluates profile context, such as birthday celebrations or school reports, and now incorporates visual analysis of photos and videos to estimate age based on physical traits like height and bone structure. Meta clarified that this is not a facial recognition system, as it does not identify specific individuals, but rather assesses physical development to determine if a user is underage. Brussels has threatened to fine Meta for failing to prevent children under 13 from using its platforms.
