logo

Portugal Revises Cybercrime Law to Protect Security Researchers

ID: 43f9a1c8-f4a5-5340-8b6a-1492cb526353

STIX ID: report--43f9a1c8-f4a5-5340-8b6a-1492cb526353

Feed Name: Infosecurity Magazine (News)

Date Published: 2025-12-08

Date Updated: 2026-04-22

...
...

Portugal has amended its cybercrime law to exempt security researchers and ethical hackers from prosecution when their actions are aimed at identifying vulnerabilities or otherwise contribute to cybersecurity, provided they meet strict conditions (no economic motive; no violation of personal data; no DoS, social engineering, phishing, data theft or alteration; proportionate and limited actions; no disruption or harmful effects). Researchers must report findings to the system owner/designated manager and the data protection regulator, keep the data confidential, and delete it within 10 days after a vulnerability is fixed. The report also notes comparable moves in Germany and the US and a proposed statutory defense for researchers under consideration in the UK.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.