The GDPR (General Data Protection Regulation), known in Portugal as RGPD, is the European regulation that establishes uniform rules for the protection of personal data across the EU, in force since May 2018. It defines the rights of data subjects (access, rectification, erasure, portability), the obligations of data controllers (legal basis, minimisation, security, breach notification within 72 hours) and heavy fines for non-compliance (up to 4% of global annual turnover).
In Portuguese corporate practice, GDPR affects almost every process: recruitment (how long are candidates kept?), CRM (what marketing consents?), HR (access to employee data), security (MFA, encryption, backups), documents (retention, anonymisation). GDPR is not just 'installing a cookie banner' — it is a cross-cutting discipline.
INFOS designs all its solutions with privacy by design. pplPortal stores HR data with auditable logs and granular permissions; the MULTI ERP implements personal-data minimisation in invoicing; Document Management offers encryption at rest and in transit. The European AI Act, recent, adds to GDPR when it comes to AI models that process personal data — the AI layer of pplPortal is designed to meet both.