[codicts-css-switcher id=”346″]

Global Law Experts Logo
corporate governance portugal

Portugal Corporate Governance 2026: Rules Boards and Directors Must Follow (gaming, Media & Tech)

By Global Law Experts
– posted 2 hours ago

Corporate governance portugal has moved to the top of the boardroom agenda for 2026, as regulators sharpen enforcement priorities and sector-specific compliance expectations tighten across gaming, media and technology. Boards operating in or with Portugal now face a denser web of obligations, from the director duties codified in the Código das Sociedades Comerciais to the licensing, anti-money-laundering and content rules that apply to regulated activities. This guide sets out what board chairs, general counsel and compliance officers need to know: the statutory framework, director liabilities, sector-specific requirements and a practical, board-ready action plan. Every legal claim is grounded in Portuguese primary sources so that boards can act with confidence rather than assumption.

TL;DR: what boards must know about corporate governance in Portugal in 2026

For time-pressed directors, the essentials are straightforward. Portuguese company law imposes personal duties of care and loyalty on directors, enforceable through civil, administrative and, in defined circumstances, criminal routes. Regulated sectors layer additional obligations on top of the baseline company-law regime. In 2026, the practical challenge is not learning a single new rule but coordinating overlapping regulatory expectations across multiple supervisors, particularly for companies with cross-border operations.

The top actions for boards this year are: confirm director duties are understood and documented; establish or refresh audit, risk and compliance committees; maintain a live conflicts-of-interest register; embed AML and data-protection controls where applicable; verify sector licences and change-of-control provisions; ensure board minutes evidence informed decision-making; secure adequate directors’ and officers’ (D&O) cover; and adopt a 90-day compliance action plan with named owners.

Key 2026 changes shaping corporate governance portugal

  • Heightened enforcement coordination. Supervisors including the CMVM (cmvm.pt), the SRIJ (srij.turismodeportugal.pt) and the CNPD (cnpd.pt) are placing greater weight on demonstrable board-level oversight, meaning documentation of governance decisions matters as much as the decisions themselves.
  • Sector-specific scrutiny. Gaming operators, media companies and digital platforms face intensified attention on AML, responsible-conduct controls, advertising standards and content responsibilities, reflecting EU-driven digital and consumer-protection frameworks (commission.europa.eu).
  • Data governance as a board issue. Data protection is no longer delegated purely to IT or DPO functions; boards are expected to oversee breach-response readiness and processing accountability under CNPD guidance.

2026 regulatory landscape: statutes, regulators and recent updates

Understanding corporate governance portugal begins with mapping where the rules come from. Portugal operates a civil-law system in which the primary governance obligations are set by statute and supplemented by regulator guidance, codes and, increasingly, EU instruments with direct effect. For regulated sectors, the statutory baseline is only the starting point.

Primary statutory framework, the Companies Code

The core instrument is the Código das Sociedades Comerciais (Companies Code), the consolidated text of which is published through the Diário da República Electrónico (dre.pt). The Companies Code governs the structure of Portuguese companies, the composition and powers of management and supervisory bodies, the standard of conduct expected of directors, and the civil liability that attaches when those standards are breached. It applies to both privately held companies (sociedades por quotas) and public limited companies (sociedades anónimas), with additional requirements applying to the latter and to listed entities.

Portuguese law permits companies to adopt different governance models, including a single-tier board with a fiscal supervisory body, and two-tier structures with an executive board and a general and supervisory board. Boards should confirm which model their statutes adopt, because that choice determines reporting lines, the remit of supervisory organs, and how oversight responsibilities are allocated.

Regulators with board-level remit

Several supervisors shape governance expectations depending on a company’s activity:

  • CMVM (Comissão do Mercado de Valores Mobiliários). The securities market regulator supervises listed companies and publishes corporate governance guidance and enforcement decisions (cmvm.pt). Listed issuers face disclosure, remuneration-reporting and board-independence expectations beyond the Companies Code baseline.
  • Banco de Portugal. Where a company undertakes financial or payment-related activities, the central bank sets governance and AML/CTF expectations for supervised entities (bportugal.pt).
  • CNPD (Comissão Nacional de Proteção de Dados). The data protection authority enforces the GDPR framework in Portugal, issuing guidance on breach notification, processing accountability and sanctions (cnpd.pt).
  • SRIJ (Serviço de Regulação e Inspeção de Jogos). Housed within Turismo de Portugal, the SRIJ licenses and supervises online and land-based gaming, setting AML, advertising, player-protection and reporting obligations (srij.turismodeportugal.pt).
  • Autoridade da Concorrência. The competition authority is relevant to merger control, market-conduct and, for media businesses, plurality concerns that can carry board-level consequences.
  • ERC (Entidade Reguladora para a Comunicação Social). The media regulator supervises media outlets, content and ownership-concentration matters relevant to media businesses.

2026 updates to monitor

Boards should track evolving CMVM enforcement priorities for listed companies, CNPD guidance on breach handling, and SRIJ requirements for gaming operators, all published through the respective regulator sites. EU instruments, including digital-services and data-transfer frameworks, continue to filter into Portuguese practice and should be monitored via official EU resources (commission.europa.eu). Industry observers expect the practical effect of 2026 to be a rising evidentiary burden: regulators increasingly ask boards not only what they decided, but how they informed themselves and documented that oversight.

Director duties and liabilities under Portuguese law

The heart of corporate governance portugal is the personal responsibility of directors. Portuguese company law does not treat board membership as a passive honorific: directors owe defined duties, and breaches expose them to personal financial and, in some cases, criminal consequences. General counsel should ensure every director understands the scope of these obligations before, not after, a problem arises.

Legal duties: loyalty, diligence and avoiding conflicts

Under the Companies Code, directors must act with the diligence of a careful and orderly manager and in the interests of the company, weighing the long-term interests of shareholders and the interests of other stakeholders such as employees and creditors. Two duties dominate:

  • Duty of care (diligence). Directors must inform themselves adequately before taking decisions, exercise sound business judgement and supervise the company’s affairs. Passivity or wilful blindness is not a defence.
  • Duty of loyalty. Directors must act in the company’s interest, not their own, and must avoid or properly manage conflicts of interest. This includes disclosing personal interests in transactions and abstaining from decisions where a conflict exists.

These duties are cumulative. A director who follows a fair process but pursues a personal interest breaches loyalty; a director who is well-intentioned but uninformed breaches diligence. Boards should treat both as continuous obligations, evidenced in minutes and registers.

Statutory liability and enforcement routes

Portuguese law provides several avenues through which director conduct is tested:

  • Civil liability. The Companies Code allows the company itself, and in defined circumstances shareholders and creditors, to bring claims against directors for damage caused by breach of their duties. Liability can be joint and several among board members.
  • Administrative sanctions. Sector regulators, the CMVM for market matters, the CNPD for data protection and the SRIJ for gaming, can impose administrative fines and other measures on companies and, where the framework allows, on individuals holding management responsibility.
  • Criminal liability. In defined circumstances, such as certain fraud, insolvency-related or market-abuse offences, directors may face criminal exposure. This is the exception rather than the norm, but it is precisely the scenario where personal freedom, not just money, is at stake.

Because enforcement routes overlap, a single set of facts can generate a regulatory investigation, a civil claim and, at the extreme, criminal proceedings simultaneously. Boards should plan their governance on the assumption that decisions may be scrutinised through more than one lens.

Case law and consequences for boards

Portuguese courts, including the higher courts whose decisions are published through official case-law repositories, provide the interpretive backdrop against which director duties are applied. A consistent theme in Portuguese governance practice is that process and documentation carry significant evidential weight: where directors can demonstrate they informed themselves, sought advice and recorded their reasoning, they are far better placed to defend a good-faith business decision than where the record is silent. The practical lesson for boards is that governance failures are frequently proven not by the underlying decision but by the absence of evidence that the decision was properly considered.

Best-practice protections for directors

Directors can and should build protections into their governance framework:

  • D&O insurance. Confirm the scope of directors’ and officers’ cover, including defence costs, regulatory investigations and cross-border exposure, and check exclusions carefully.
  • Contractual indemnities. Where permitted, align indemnity provisions with the company’s articles and applicable law.
  • Internal approvals and delegations. Use clear delegation matrices so that authority, and accountability, is documented.
  • Board minutes. Record not just outcomes but the information considered, advice taken and dissent expressed. Minutes are the single most valuable defensive asset a director has.
  • Conflicts register. Maintain a live register and require directors to declare interests as they arise, not annually.

Sector-specific governance for gaming companies portugal, media and tech

The distinguishing feature of corporate governance portugal for regulated sectors is that the Companies Code baseline is supplemented by activity-specific obligations. A board that is fully compliant with general company law can still fall short of the licensing, AML, advertising and content requirements that apply to its sector. This section sets out what boards in gaming, media and technology must implement in addition to their general duties.

Gaming: SRIJ oversight, AML and responsible-conduct governance

Gaming is one of the most heavily regulated activities in Portugal. Online gaming and betting operators require licences from the SRIJ, which supervises operators throughout the licence lifecycle (srij.turismodeportugal.pt). Board-level obligations for gaming companies include:

  • Licensing and fit-and-proper standards. Boards must ensure the company holds valid authorisations and that suitability requirements applying to management and significant holders are met and maintained.
  • AML/CTF controls. Gaming operators are subject to anti-money-laundering obligations, requiring customer due diligence, transaction monitoring, suspicious-activity reporting and board-level oversight of the AML programme. Where financial activity intersects, Banco de Portugal AML/CTF guidance is also relevant (bportugal.pt).
  • Player protection and responsible gambling. Boards should oversee age-verification controls, self-exclusion mechanisms and responsible-gambling policies as governance matters, not merely operational ones.
  • Advertising and marketing rules. Gaming advertising is subject to restrictions; the board should ensure marketing governance prevents non-compliant promotion.
  • Reporting obligations. Operators must meet SRIJ reporting requirements, and the board should confirm reporting lines are robust and evidenced.

Media: content, advertising, plurality and IP governance

Media businesses face governance obligations rooted in content regulation, advertising standards, ownership and plurality rules, and intellectual-property management. Boards should ensure:

  • Content compliance. Editorial and content-moderation processes align with applicable content-regulation standards and protect against unlawful or harmful material.
  • Advertising and sponsorship transparency. Disclosure of sponsored content and adherence to advertising rules is governed and monitored.
  • Ownership and plurality. Ownership structures and change-of-control transactions are assessed against media-plurality concerns, which can engage the ERC and the competition authority.
  • IP governance. Rights clearance, licensing and protection of the company’s own IP portfolio are managed with clear board oversight.

Tech: platform responsibility, data flows and AI oversight

Technology companies, particularly platforms and digital-service providers, face a fast-evolving governance landscape driven substantially by EU law (commission.europa.eu). Board priorities include:

  • Platform and intermediary responsibilities. Where the company operates a platform, governance must address content responsibilities, transparency and user-protection obligations under applicable digital-services rules.
  • E-commerce and consumer protection. Online sales and services must comply with consumer-protection and e-commerce requirements.
  • Cross-border data flows. International data transfers must be governed under recognised transfer mechanisms, with CNPD guidance in view (cnpd.pt).
  • AI oversight. Where the company deploys AI systems, boards should establish oversight of risk, accountability and emerging regulatory obligations. Early indications suggest AI governance will become a standing board item for Portuguese tech companies as EU rules mature.

Cross-sector comparison table

Issue Gaming Media Tech
Licensing requirement SRIJ licence required for online/land-based operations Registration/authorisation for certain media activities Generally no sector licence; activity-specific authorisations may apply
Primary regulator SRIJ (Turismo de Portugal) ERC; Autoridade da Concorrência for plurality CNPD for data; EU digital-services framework
AML obligations Extensive, CDD, monitoring, SAR reporting Limited, activity-dependent Limited, unless financial/payment activity involved
Advertising / content rules Restricted gambling advertising; responsible-gambling messaging Content standards, sponsorship transparency Platform transparency, consumer-protection disclosures
Board-level required policies AML, responsible gambling, player protection, licensing suitability Editorial/content, advertising, IP, ownership Data protection, transfer governance, AI oversight
Typical enforcement risk Fines, licence conditions or revocation Sanctions, plurality/competition intervention Data-protection fines, platform-compliance measures

Board obligations: governance frameworks, committees and compliance programmes

Effective corporate governance portugal depends on architecture, not intention. Regulators increasingly assess whether a board has built structures capable of identifying and managing risk. This section sets out the practical framework boards in regulated sectors should implement.

Recommended board structure for regulated firms

Boards should confirm their governance model under the Companies Code and align composition to their risk profile. For regulated firms, this typically means a balance of executive and non-executive members, appropriate independence at supervisory level, and a meeting cadence frequent enough to provide genuine oversight, quarterly as a minimum, with additional sessions when material issues arise. Roles should be clearly allocated: chair, executive management, and the supervisory or fiscal body, each with a defined mandate.

Audit and risk committees

Audit and risk committees provide the board with independent assurance. For regulated companies, their remit should cover financial reporting integrity, internal controls, external audit oversight, and the identification and monitoring of principal risks, including AML, data protection and sector-specific exposures. Reporting lines should run directly to the board, and committee minutes should evidence challenge, not mere ratification. Listed companies should align committee arrangements with CMVM governance expectations (cmvm.pt).

Compliance programme essentials

A credible compliance programme is the practical expression of good governance. Its essentials are:

  • Policies. Documented, current policies covering AML, conflicts, data protection, advertising and sector-specific requirements.
  • Training. Role-appropriate, recorded training for directors, senior managers and relevant staff.
  • Monitoring. Ongoing testing and monitoring of controls, with findings reported to the board.
  • Whistleblowing. A confidential reporting channel with protections for reporters and a defined escalation path, consistent with Portugal’s whistleblower-protection framework transposing the EU Whistleblowing Directive.
  • Record-keeping. Systematic retention of decisions, approvals and registers that can be produced to regulators on request.

Cross-border operations, group governance and M&A considerations

Many gaming, media and tech companies operate across borders, which multiplies governance complexity. Corporate governance portugal for such groups requires reconciling group-wide policy with local Portuguese obligations, particularly around licences, data transfers and change-of-control approvals.

Pre-M&A board diligence checklist

Before any acquisition or change-of-control event, the board should confirm:

  1. Whether regulatory permissions, including SRIJ, CMVM or sector authorisations, permit the transaction or require prior consent.
  2. Whether licences contain change-of-control clauses that could be triggered.
  3. The target’s compliance history, including any open regulatory investigations or sanctions.
  4. Data-protection posture, transfer mechanisms and outstanding CNPD exposure.
  5. Competition and, for media, plurality considerations engaging the Autoridade da Concorrência and the ERC.

Harmonising group policies with local compliance

Group governance should set minimum standards centrally while empowering local compliance teams to apply Portuguese-specific requirements. The board must resist a purely centralised model that overlooks local licensing and reporting obligations, and equally avoid fragmentation where local entities operate without group oversight. The practical answer is a clear escalation framework and a documented allocation of responsibility between group and local levels.

Enforcement landscape: investigations, sanctions and director accountability

Enforcement is where governance is tested. Investigations in Portugal can be triggered by breach reports, whistleblower disclosures, market events, data incidents or routine supervision. Sanctions range from administrative fines and licence conditions to, in serious gaming cases, licence revocation, alongside potential civil claims and, exceptionally, criminal proceedings against individuals.

Immediate steps for boards when notified

When a regulator opens an investigation, boards should act promptly and with discipline: convene independent legal counsel; preserve all relevant documents and suspend routine deletion; pause any activity implicated in the inquiry; appoint a board-level liaison to manage communications; and record every step taken. A measured, well-documented response both protects the company and evidences the governance standards regulators expect. The Ordem dos Advogados provides professional-conduct guidance relevant to counsel supporting boards through such processes (portal.oa.pt).

Practical board checklist and 90-day action plan for corporate governance portugal

To convert principle into practice, boards should adopt a structured 10-point checklist and a 90-day action plan with named owners.

  1. Confirm the company’s governance model and board composition under the Companies Code.
  2. Verify all sector licences and authorisations are current and change-of-control clauses are understood.
  3. Establish or refresh audit, risk and compliance committees with direct board reporting.
  4. Adopt and circulate a live conflicts-of-interest register.
  5. Confirm AML/CTF controls where applicable, with board-level oversight of the programme.
  6. Review data-protection governance and breach-response readiness against CNPD guidance.
  7. Ensure advertising, content and consumer-protection policies are current for the relevant sector.
  8. Verify D&O insurance scope and indemnity arrangements.
  9. Standardise board-minute practice to evidence informed decision-making.
  10. Adopt a monitoring and training cycle with recorded completion.

The 90-day plan should assign each item an owner, a deadline and a reporting milestone, with progress reviewed at the next board meeting. Supporting templates, a board-minute template, a conflicts-register starter and a compliance-training plan, accelerate adoption.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Luis Portela De Carvalho at LEKTOU, a member of the Global Law Experts network.

Further reading and primary sources

The following official sources underpin the guidance above and support deeper research into corporate governance portugal. Boards should treat regulator guidance and consolidated statutory texts as the definitive references and seek tailored legal advice for specific circumstances. This article provides general guidance only and is not a substitute for advice on a particular matter.

Sources

  1. Diário da República Electrónico (DRE)
  2. Comissão do Mercado de Valores Mobiliários (CMVM)
  3. Comissão Nacional de Proteção de Dados (CNPD)
  4. Banco de Portugal
  5. Serviço de Regulação e Inspeção de Jogos (SRIJ)
  6. Entidade Reguladora para a Comunicação Social (ERC)
  7. Ordem dos Advogados
  8. Tribunal Constitucional
  9. European Commission

FAQs

What are the main corporate governance requirements for companies in Portugal?
The baseline requirements derive from the Companies Code (Código das Sociedades Comerciais), which sets out board structure, director duties of care and loyalty, and the civil liability that follows breaches. Listed companies face additional CMVM governance and disclosure expectations, and regulated sectors add licensing, AML, data-protection and content obligations. Effective corporate governance portugal therefore combines the statutory baseline with sector-specific and regulator-driven requirements.
Directors owe a duty of care, informing themselves and managing diligently, and a duty of loyalty to act in the company’s interest and manage conflicts. Breaches can expose directors to civil claims (potentially joint and several), administrative sanctions from regulators such as the CMVM, CNPD and SRIJ, and, in defined circumstances, criminal liability. Documentation, D&O cover and robust internal approvals are the principal mitigations.
Yes. Gaming operators require SRIJ licences and must maintain AML, responsible-gambling and advertising controls. Media companies face content, advertising, ownership-plurality and IP obligations, with oversight from the ERC. Technology companies face platform-responsibility, consumer-protection, cross-border data-transfer and emerging AI-oversight requirements, substantially shaped by EU law. Each layer sits on top of the general Companies Code duties.
Boards should implement a documented compliance programme, refresh committee oversight, update sector policies, maintain live registers, and adopt a 90-day action plan with named owners. The recurring theme in corporate governance portugal for 2026 is evidence: regulators increasingly expect boards to show how they informed themselves and recorded oversight, not merely what they decided.
Convene independent legal counsel, preserve all relevant documents and suspend routine deletion, pause any implicated activity, appoint a board-level liaison, and record every step. A disciplined, well-documented response protects the company and demonstrates the governance standards regulators expect.
Reporting triggers depend on the breach. Personal-data breaches may require notification to the CNPD within the timelines set out in the GDPR and its guidance; gaming and AML matters may require reporting to the SRIJ and relevant authorities; and market-related matters may engage CMVM obligations. Boards should map applicable reporting triggers in advance so that time-sensitive obligations are met.
cross-border grants swiss foundation
By Global Law Experts

posted 1 hour ago

By Olufunke Olumide

posted 2 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Portugal Corporate Governance 2026: Rules Boards and Directors Must Follow (gaming, Media & Tech)

Send welcome message

Custom Message