Priority sector
Central, regional and local government, public institutes and public companies combine general EU obligations with duties specific to the public sector.
Key obligations
Every public authority or body must designate a Data Protection Officer under Article 37 of the GDPR.
NIS2 covers public administration entities of central government and, depending on national risk assessments, of regional level, and Member States may extend it to local level.
Public-sector entities must establish internal reporting channels, subject to exemptions that Member States may grant to small municipalities and entities.
Public bodies that deploy high-risk AI systems must carry out a fundamental rights impact assessment before use.
Public bodies answer to citizens and to supervisors at the same time. Data protection, cybersecurity, transparency, integrity and whistleblowing obligations overlap, and in Portugal the Regime Geral de Prevenção da Corrupção applies to public entities with 50 or more workers. Budgets are tight and specialised staff are scarce, which makes shared and external arrangements especially valuable.
Data Protection Officer: individual or shared among several bodies, as Article 37(3) of the GDPR allows;
information security: support for public administration entities within the scope of NIS2 and national cybersecurity rules;
integrity programmes: whistleblowing channels, codes of conduct and corruption risk plans;
public procurement: services that can be contracted under the procurement rules of each body.
A free Compliance Assessment identifies which obligations apply and which gaps matter most.
Related domains: Data Protection · Cybersecurity (NIS2) · Whistleblower Protection · Anti-Corruption · Artificial Intelligence
Regulated functions: Data Protection Officer · Information Security Officer · Whistleblowing Officer · All sectors
General information as at October 2026; it does not constitute legal advice.
Request a free assessment designed for public administration.