Regulated Incident Management Ecosystem Versão portuguesa

Security Officer

Regulation

The map of applicable requirements.

Regulatory map

Applicable instruments

InstrumentSubjectRelevant provisions
GDPRPersonal data protectionArticles 5(2), 24, 28, 32 and 39
Law 58/2019National implementation of the GDPRDuties of the data protection officer and penalties
Decree-Law 125/2025Portuguese Cybersecurity ActApplicable to covered entities; see cybersecurityofficer.pt
ISO/IEC 27001 and 27002Management system and controlsCertification framework
ISO 22301Business continuityImpact analysis and testing

Informative summary. Always check the official text in force.

Security that is not measured is not managed

Start with a maturity assessment or ask for a proposal to structure the role.