Back to Home

GDPR Compliance

Last updated: March 1, 2026

LusoPass is fully committed to compliance with the General Data Protection Regulation (EU) 2016/679 ("GDPR") and the Portuguese Data Protection Law (Lei n.º 58/2019). This page outlines our approach to data protection and your rights as a data subject.

Your Rights Under GDPR

Right of Access

Art. 15

You can request a copy of all personal data we hold about you, including the purposes of processing, categories of data, and recipients.

Right to Rectification

Art. 16

You can request correction of inaccurate personal data or completion of incomplete data we hold about you.

Right to Erasure

Art. 17

You can request deletion of your personal data when it is no longer necessary for the purpose it was collected, subject to legal retention obligations.

Right to Restrict Processing

Art. 18

You can request that we limit how we use your data while we verify its accuracy or assess your objection to processing.

Right to Data Portability

Art. 20

You can receive your personal data in a structured, machine-readable format and transfer it to another service provider.

Right to Object

Art. 21

You can object to processing of your personal data based on legitimate interests, including profiling and direct marketing.

Our Data Protection Framework

LusoPass has implemented a comprehensive data protection framework that includes: • A designated Data Protection Officer (DPO) overseeing all data processing activities • Data Protection Impact Assessments (DPIAs) conducted for high-risk processing operations • Privacy by Design and Privacy by Default principles embedded in our development process • Regular staff training on data protection obligations and best practices • Documented data processing records as required by Article 30 GDPR

Lawful Basis for Processing

We process personal data only when we have a valid legal basis under Article 6 GDPR: • Contract Performance (Art. 6(1)(b)): Processing necessary to deliver our platform services, manage immigration cases, and administer investment transactions. • Legal Obligation (Art. 6(1)(c)): Processing required by Portuguese immigration law, AML/KYC regulations (Lei n.º 83/2017), tax reporting obligations, and financial services regulations. • Legitimate Interest (Art. 6(1)(f)): Platform security, fraud prevention, service improvement, and internal analytics. We conduct balancing tests to ensure our interests do not override your fundamental rights. • Consent (Art. 6(1)(a)): Marketing communications and optional analytics tracking, which you may withdraw at any time without affecting the lawfulness of prior processing.

International Data Transfers

When personal data is transferred outside the European Economic Area (EEA), we ensure adequate protection through: • EU Standard Contractual Clauses (SCCs) as approved by the European Commission • Transfer Impact Assessments to evaluate the data protection landscape of the recipient country • Supplementary technical measures including encryption in transit and at rest • Data processing agreements with all sub-processors that meet GDPR requirements We maintain a register of all international data transfers available upon request.

Data Breach Notification

In the event of a personal data breach, LusoPass will: • Notify the Portuguese Data Protection Authority (CNPD) within 72 hours of becoming aware of the breach, as required by Article 33 GDPR • Notify affected data subjects without undue delay when the breach is likely to result in a high risk to their rights and freedoms, as required by Article 34 GDPR • Document all breaches including their effects and remedial actions taken • Implement corrective measures to prevent recurrence

Sub-Processors

We use the following categories of sub-processors to deliver our services: • Cloud Infrastructure: EU-based data centers for hosting and storage • Payment Processing: PCI DSS-compliant payment providers • Email Services: Transactional email delivery • Analytics: Privacy-focused analytics platforms All sub-processors are bound by data processing agreements that meet GDPR requirements. A complete list of sub-processors is available upon request.

Exercising Your Rights

To exercise any of your GDPR rights, you can: • Email our Data Protection Officer at [email protected] • Use the data management tools available in your account settings • Submit a written request to our postal address We will respond to your request within 30 days. If your request is complex, we may extend this period by an additional 60 days, and we will notify you of any such extension. If you are unsatisfied with our response, you have the right to lodge a complaint with the Portuguese Data Protection Authority: Comissão Nacional de Proteção de Dados (CNPD) Rua de São Bento, 148-3° 1200-821 Lisboa, Portugal https://www.cnpd.pt