Personal Data Protection | MEO Institutional

Personal Data Protection

Personal Data Protection

MEO Group Commitment

The MEO Group undertakes to guarantee the protection of the personal data entrusted to it, ensuring rigorous and transparent processing.

To this end, MEO Group companies adopt a transversal approach to compliance with the General Data Protection Regulation ("GDPR") and other applicable legislation on the protection of personal data ("Data Protection Legislation"), and are aligned with the best information security practices.

We recommend that you carefully read this Data Protection Policy (“Policy”), as well as consult the Privacy Policy and Cookies Policy.

1. Responsible for treatment

The entity responsible for collecting and processing your personal data will be the MEO Group company that provides you with the service or product and which, in this context, decides what data to collect, the purposes for which it is used, and the means of processing to be applied.

2. Processing and collection of personal data

The term “personal data” refers to any information, of any nature or medium, related to you and that allows us to identify you, directly or indirectly (such as your name, address, email, or tax identification number).

The personal data we collect about you, as well as how it is collected, may vary depending on the nature of your interactions with MEO Group companies, whether you are acting as a Customer, User, Candidate, or Representative of a third party. In addition, your personal data may be obtained from third parties, provided that they are authorized to share it with the MEO Group.

Processing and collection of personal data

The following personal data may be collected as part of these interactions:

  • Identification and contact data: includes civil and tax identification numbers, billing and/or installation address, telephone contacts and email addresses, date of birth, gender and customer number.
  • Contractual relationship data: this includes information on products and services purchased or subscribed to, payment data, information on debt and credit risk, as well as billing elements.
  • Service Usage Data: includes, but is not limited to, destination and source numbers of communications, date and time of communications, respective duration, IP address, MAC address, among other technical identifiers.
  • Profile and Interests: includes information on your preferences regarding products or services from MEO Group companies, as well as demographic data such as age, gender and area of residence.
  • Location: refers to the geographical reference of the customer or terminal equipment, at a given time or during the use of services.
  • Security data: includes authentication elements in the Digital Channels (user ID, password, answers to password recovery questions), as well as access records (logs).
  • Professional data: referring to the position and function held.

2.1 Personal data collected directly

We collect your personal data directly, particularly in the following situations:

  • When you use our Digital Channels (Websites and Apps);
  • When you subscribe to newsletters, notifications or other commercial or institutional communications;
  • When you request information or contact us through our communication channels, including face-to-face, e-mail, telephone or through a Website/App;
  • When you submit an application for recruitment through the designated channels;
  • When you take part in our satisfaction polls and surveys by answering them;
  • When you take part in events, campaigns, promotions or competitions promoted by us or in partnership with third parties;
  • When you interact with us through our pages or profiles on social networks or external digital platforms;
  • When you visit our premises and video surveillance cameras are installed.

2.2 Personal data collected by third parties

We also collect personal data from third parties and/or external sources, to the extent that we can legally do so and when they are legitimized to share it. These include:

  • MEO Group companies, when they share personal data with each other;
  • Suppliers and service providers;
  • Authorized partner entities;
  • Public authorities and regulatory bodies.

3. Purposes and grounds for processing

For each specific purpose of processing personal data, there must be at least one adequate legal basis. Therefore, MEO Group will process your personal data for the purposes and with the legal grounds indicated in the table in Annex I to this document.

When the lawful basis for processing your personal data is consent, the data subject may withdraw that consent at any time and free of charge, without prejudice to the validity of the processing carried out up to that date. In this situation, the processing will cease immediately for the purpose in question and the data will be deleted, unless its retention proves necessary for compliance with legal or contractual obligations, or if there is another legitimate basis justifying the processing.

In cases where the processing is based on legitimate interest or public interest, or where the data is used for direct marketing purposes, the data subject has the right to object to the processing. In these cases, processing will be interrupted, unless compelling legitimate grounds prevail or the data is indispensable for the purposes of declaring, exercising or defending rights in legal proceedings. When the objection relates to direct marketing activities, processing will cease immediately.

In cases where the processing is based on legitimate interest or public interest, or where the data is used for direct marketing purposes, the data subject has the right to object to the processing. In these cases, processing will be interrupted, unless compelling legitimate grounds prevail or the data is indispensable for the purposes of declaring, exercising or defending rights in legal proceedings. When the objection relates to direct marketing activities, processing will cease immediately.

4. Retention of personal data

Personal data is only kept for the period necessary to fulfill the purposes for which it is processed, when no law, regulation or guideline provides for a specific retention period.

Different criteria are taken into account to determine the retention periods for personal data, such as:

  • the duration of the contractual relationship;
  • where applicable, the time during which the consent given by the data subject is considered valid and/or is not withdrawn;
  • the time it takes to respond to a request or complaint.

Exceptionally, data may be kept for longer periods, in order to comply with different purposes that may persist, such as, for example, compliance with legally established deadlines, the exercise of a right in a judicial process or archiving purposes in the public interest, with the MEO Group applying the appropriate technical and organizational measures.

Therefore, whenever there is no specific legal requirement, the data will only be kept to the extent necessary for the purposes for which they were collected, in accordance with the criteria set out, unless the right to object or erasure is exercised within the legal limits, or if consent is withdrawn.


5. Sharing personal data

In certain circumstances, your personal data may be transmitted to subcontractors who process personal data on behalf of MEO Group companies and in accordance with their instructions.

The data may also be shared with the following third parties (who, in principle, will process the personal data received as autonomous data controllers):

  • MEO Group companies, but only when necessary to provide the Customer with adequate and high quality services;
  • Independent service providers who provide legal advice;
  • Authorized partner entities;
  • Police authorities, government bodies, regulatory authorities, courts or other public authorities, when we are obliged or authorized to do so under national law.

6. Data transfers to third countries

MEO Group may transfer your personal data to a third country outside the European Economic Area ("EEA"), implementing appropriate measures under applicable law to ensure the protection of personal data subject to such transfer.

Thus, your personal data will be transferred when there is an adequacy decision by the European Commission for a given country or when the appropriate safeguards provided for in the GDPR are implemented, namely the conclusion of standard contractual data protection clauses adopted by the European Commission and the adoption of additional measures to ensure that personal data enjoy a level of protection essentially equivalent to that existing in the European Union. Exceptionally, your data may be transferred on the basis of the derogations provided for in Article 49 of the GDPR, such as your explicit consent to the transfer.

To request more information about the safeguards adopted in data transfers, you can use the contacts indicated in section 10. "How you can contact us".

7. Security of personal data

MEO Group is committed to protecting and maintaining the confidentiality of the personal data of its Customers and Users, by implementing the appropriate technical and organizational measures to protect their data against forms of improper or illegitimate processing and against the loss, alteration, dissemination or destruction of this data, such as:

  • teams and systems to guarantee the security of the personal data processed;
  • carrying out data protection impact assessments;
  • creating and updating procedures to prevent unauthorized access, accidental loss and/or destruction of personal data;
  • respect for data protection legislation;
  • processing of data only for the purposes for which it was collected;
  • guarantee that the data is processed with levels of security and confidentiality appropriate to the risk of processing.

Because we recognize the importance of the personal data entrusted to us, we have implemented and communicated personal data protection procedures to all our employees, and have carried out training sessions with them to ensure that they are aware of the obligations imposed on them in this area, namely not to disclose to third parties or use for purposes contrary to the law any personal information to which they have access in the course of their duties.

8. Use of Artificial Intelligence

MEO Group implements Artificial Intelligence ("AI") functionalities in the context of the different services it provides, which are used, in particular, for the purpose of personalizing services, by adapting content, commercial offers and functionalities to the preferences and specific needs of customers; for the optimization of internal processes, namely in the management and monitoring of networks, in the detection of technical anomalies, in the prevention of fraud and in the improvement of operational efficiency; for decision support, enabling advanced data analysis to support strategic planning, the development of new products and customer relationship management; as well as for improving the user experience by providing faster, more personalized and responsive services, including the use of virtual assistants and automated response mechanisms.

When AI functionalities are used, they comply with strict confidentiality and data security protocols. The processing of personal data through these will be carried out in accordance with this Policy and the applicable legislation, particularly with regard to the protection of personal data and artificial intelligence.

In particular, whenever the use of AI functionalities may entail a high risk to the fundamental rights and freedoms of data subjects, MEO Group will carry out a Data Protection Impact Assessment, pursuant to Article 35 of the GDPR. This assessment will take into account, in particular, the risks related to automated profiles, automated individual decisions, the use of predictive algorithms and possible ethical implications.

9. Holders' rights

The data subject may exercise, in accordance with the law, the rights listed below. To do so, please send your request to the email address dpo@meo.pt or to the postal address Av. Fontes Pereira Melo, 38 C 1069-300.

Without prejudice to any other administrative or judicial remedy, the data subject also has the right to lodge a complaint with the National Data Protection Commission or another competent supervisory authority under the terms of the law, if they consider that their data is not being processed legitimately.

Right of access

Obtain confirmation of what personal data is being processed about you, request access to it, obtain information about the processing, and obtain a copy of the personal data being processed. In this case, we reserve the right to apply a reasonable fee taking into account the administrative costs involved.

Right to rectification or updating

Request the rectification or updating of your personal data that is inaccurate or has changed since it was collected, or request that incomplete personal data be completed.

Right to erasure

Obtain the erasure of your personal data, including any links, copies or reproductions of such data, namely if your personal data is no longer necessary for the purpose for which it was collected or processed, or if you object to the processing and there are no overriding legitimate interests justifying it, and provided that there are no valid grounds for retaining it.

Right to restriction of treatment

Request the restriction of the processing of your personal data in certain cases, namely if the processing is unlawful and you oppose the erasure of the data, requesting the suspension of the processing or the restriction of the scope of the processing to certain categories of data or processing purposes.

Right to portability

Receive the data you have provided us in a commonly used and machine-readable digital format, or request the direct transfer of your data to another entity that will become the new data controller, if the processing of your data is carried out by automated means and is based on your consent or the performance of a contract.

Right to object

Object, at any time, and for reasons related to your particular situation, to the processing of your data based on the pursuit of legitimate interests by the controller or on the compatibility of the initial processing with the subsequent processing of such data.

Right to withdraw consent

Withdraw your consent to the processing of data legitimized by this basis. Withdrawal of consent does not invalidate the processing carried out up to that date based on the consent previously given.

10. How to contact us

MEO Group has appointed a Data Protection Officer ("DPO").

If you wish to find out more about the processing of your personal data, as well as ask questions or make suggestions regarding this Data Protection Policy, you can do so through the following contacts:

  • Postal Address: Av. Fontes Pereira Melo, 38 C 1069-300
  • E-mail address: dpo@meo.pt


11. Changes to this Policy

This Policy may be subject to adjustments or changes, which will be duly publicized on the website (for example, through the display of a banner or pop-up) and/or other channels deemed appropriate, whenever justified.

1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016.

Update date: October 1, 2025