All news
Enforcement December 12, 2022 7 min

Portugal: the largest fine ever teaches one thing. Vetting a processor is a substantive duty, not a form to sign

EUR 4.3 million against the national statistics institute for the 2021 census. Of the five findings, the one every DPO should re-read concerns Article 28(3)

TL;DR for the DPO

The CNPD writes that verifying the Article 28(3) requirements must be SUBSTANTIVE and not formal, and cannot be reduced to picking some standard set of clauses. That sentence is worth the fine: signing the supplier's DPA without reading it is not compliance, it is documentary proof of the opposite.

The five findings

  • Unlawful processing of health and religious data: the questionnaire did not make clear that those answers were optional, so people could not form an informed will.
  • Breach of the information duties towards those answering the questionnaire.
  • Breach of the duty of diligence in selecting the processor.
  • Breach of the rules on international transfers, Articles 44 and 46(2).
  • Failure to carry out a data protection impact assessment for the census operation as a whole.

The Article 28 point

INE entrusted the infrastructure to a supplier that had an office in Lisbon. The contract, however, was concluded with the company established in the United States, and provided that the court competent for disputes was the California court. The same contract allowed personal data to transit through any of the company's two hundred servers, expressly anticipating that data could be processed outside the European Economic Area.

The clauses were there. They were not enough.

The contract included the standard contractual clauses approved by the Commission for transfers to the United States. The CNPD still found a breach of Articles 44 and 46(2), because no supplementary measure was provided to prevent access to the data by government bodies of the third country, as Schrems II requires. It is precisely the logical leap you see everywhere: attach the clauses and consider the matter closed, without assessing the legal context of the destination.

What had happened before

During the census, after receiving several complaints, the CNPD opened an inquiry and ordered the immediate suspension of transfers of census data to the United States and other third countries lacking an adequate level of protection. The case closed only with the final decision, which imposed a single cumulative fine for the five infringements.

What to do now, across your clients

1) For every supplier in the processor register, check which legal entity signed the contract, not which office answers the phone. A European office is not enough if the contracting counterparty is outside the EU. 2) Read the jurisdiction clause: if it points to a non-EU court, ask yourself how you intend to enforce the Article 28 obligations on the day you need to. 3) If the contract allows data to transit unspecified infrastructure, that is a transfer and must be assessed, not ignored. 4) Standard contractual clauses are the starting point of the assessment, never the end of it: without documented supplementary measures, Article 46 is not satisfied. 5) Document the Article 28(3) verification with evidence and a date: it is the only way to show it was substantive.

Official source:CNPD - CNPD fines INE for five administrative offences (12 December 2022)Official source:CNPD - Deliberacao/2022/1072

Looking for a workspace for your DPO work?

DPO Workspace is built by a certified DPO. 30-day free trial.

Start free

Related articles

Enforcement
26complaints, and no fine

You declare contract, then you reject the objections: Norway shows how the two mistakes travel together

SATS asked members for a photo kept in the membership system and used at the desk to check the identity of people coming in. Datatilsynet found the notice stated the wrong legal basis, failed to explain the right to object, and that objections were rejected without demonstrating compelling legitimate grounds. The deadline to fix it is 11 September 2026.

Aug 26, 2026New 6 min
Enforcement
825 mln €the second-largest fine ever

Eight hundred and twenty-five million for an algorithm that deactivated accounts with nobody looking

It is the second-largest fine ever imposed under the GDPR, behind only Meta's 1.2 billion. It is not about a data transfer or a security breach: it is about Article 22, the rule on automated decisions that almost nobody documents because it looks like a big-platform problem. It is in fact about anyone who lets software decide something that weighs on a person's life.

Aug 24, 2026New 5 min
Enforcement
64 mln złagainst 14 the year before

Poland quadrupled its fines in a year, and the three highest ever all date from 2025

For years Poland was treated as a low-enforcement market. That assumption no longer holds: in twelve months the total went from fourteen to over sixty-four million zloty, and the three largest fines in the country's history all carry the same year. If you look after a client with a branch, a supplier or a service centre in Poland, the risk calculation has changed.

Aug 24, 2026New 4 min