# Portugal

> Portugal (CMVM · Banco de Portugal · CNPD): A data regulator stopping biometrics bought with tokens. Region: Europe. Confidential with disclosure: Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.

Part of the Soda Labs Privacy Hub regulation map, which reads the instruments
themselves rather than summarising the summaries: https://www.sodalabs.xyz/privacy-hub/regulation

## Key facts

- Entry type: Jurisdiction
- Region: Europe
- Subject: A data regulator stopping biometrics bought with tokens
- Authority: CMVM · Banco de Portugal · CNPD
- Stance on on-chain confidentiality: Confidential with disclosure. Confidentiality is workable so long as the regulated firm can identify the parties and disclose on demand. Encrypted amounts are not the thing being restricted.
- Tags: biometrics for tokens, CNPD suspension, minors, data protection first
- Canonical page: https://www.sodalabs.xyz/privacy-hub/regulation/jur-portugal

## What it actually says

Portugal's distinctive contribution came from its data protection authority rather than its financial regulators, and it addresses a question the financial rules do not reach. When an identity system offered crypto tokens in exchange for iris scans, the authority suspended collection of biometric data across Portuguese territory as an urgent measure, citing collection from minors without parental authorisation, inadequate information, and no way to delete data or withdraw consent. The detail that matters here is the absence of any age check while people joined specifically to receive tokens. It is a regulator treating payment for biometric data as the problem, which is the mirror image of most debates in this section, where the worry is that transactions reveal too much rather than that identity is being bought.

## The instruments that matter

- **CNPD suspension of Worldcoin, 26 March 2024**: suspended collection of iris, eye and face biometric data in Portuguese territory to safeguard the fundamental right to personal data protection, especially for minors
- **An urgent provisional measure**: imposed for 90 days to allow the authority to conclude its investigation and issue a final decision, and maintained on review in July 2024
- **What prompted it**: numerous complaints reporting collection from minors without parental authorisation, deficient information to data subjects, and inability to delete data or withdraw consent
- **The crypto link is the point**: the authority noted there was no age verification mechanism despite a significant influx of people, including minors, joining to receive tokens

## Sources

- [CNPD suspends biometric data collection](https://www.cnpd.pt/comunicacao-publica/noticias/cnpd-suspende-recolha-de-dados-biometricos/)
- [CNPD press release, 26 March 2024](https://www.cnpd.pt/media/bzwb5k5j/comunicado-de-imprensa_cnpd-suspende-recolha-de-ddos-da-worldcoin_26-mar%C3%A7o-2024.pdf)

## Related entries

- [Austria](https://www.sodalabs.xyz/privacy-hub/regulation/jur-austria): EU baseline, with an early transition close
- [Belgium](https://www.sodalabs.xyz/privacy-hub/regulation/jur-belgium): EU baseline, with no national layer on confidentiality
- [Czechia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-czechia): EU baseline, supervised by the central bank
- [Denmark](https://www.sodalabs.xyz/privacy-hub/regulation/jur-denmark): EU baseline, with tax as the historic pressure point
- [Estonia](https://www.sodalabs.xyz/privacy-hub/regulation/jur-estonia): The licence cull that reshaped the European market
- [France](https://www.sodalabs.xyz/privacy-hub/regulation/jur-france): Hardest against anonymity, most literate about privacy tech
