Privacy Policy
Last updated: July 2026
This Privacy Policy describes how MG Law Office processes personal data, in accordance with Regulation (EU) 2016/679 of 27 April (General Data Protection Regulation — "GDPR") and Portuguese Law 58/2019 of 8 August, which implements it in the Portuguese legal system.
It applies to users of this site, to the firm's clients and prospective clients and, to the extent indicated in section 3, to third parties whose data is processed in the course of the professional activity of a solicitador.
1. Data controller
Miguel Ângelo Raposo Graça (MG Law Office)
Solicitador registered with the Portuguese Order of Solicitadores and Enforcement Agents (OSAE), professional licence no. 9145
Tax no. PT259988227
Rua Batalhoz n.º 12, 2.º C, 2070-071 Cartaxo, Portugal
Email: geral@mglaw.pt · Phone: +351 919 995 170
Given the size and nature of the practice, no Data Protection Officer has been appointed (Article 37 GDPR). All questions concerning personal data should be addressed to the controller using the contact details above.
2. Categories of data processed
a) Site users
- Identification and contact details provided through the MGLAW Hub portals — appointment booking, new request and Client Portal — or the Digital Desk (name, email, phone) and the content of the messages sent;
- Technical data strictly necessary for the operation and security of the site (IP address, access logs) and, only with consent, analytics data (cookies — see the Cookie Policy);
- Documents submitted through the document-upload system, associated with the corresponding reference code.
b) Clients and prospective clients
- Identification, contact and tax identification data;
- Data contained in identification documents, where required by law (in particular to comply with the identification and due-diligence duties set out in Law 83/2017 of 18 August);
- Asset, financial, contractual and other data necessary to provide the engaged service;
- Billing and payment data.
c) Third parties related to the matters entrusted to the firm
In the exercise of the solicitador's activity, data of third parties — counterparties, representatives, witnesses, experts, other lawyers and other participants — is inevitably processed, strictly to the extent necessary for representation, legal advice or the requested act.
d) Special categories of data
Certain matters (notably family, employment, health or immigration matters) may involve the processing of special categories of data (Article 9 GDPR). Such processing takes place only where necessary for the establishment, exercise or defence of legal claims (Article 9(2)(f) GDPR) or on another applicable legal basis.
3. Source of the data
Data is, as a rule, collected directly from the data subject. It may also be obtained from the client who entrusts the matter to the firm, from lawyers and other professionals involved, from courts and public bodies, and from registers and databases that are publicly accessible or legally authorised (land, commercial and civil registries, among others).
Where data is not collected from the data subject, the information required by Article 14 GDPR may be dispensed with, in particular where the data must remain confidential under the solicitador's professional secrecy (Article 14(5)(d) GDPR and Articles 127 and 141 of the OSAE Statute, approved by Law 154/2015 of 14 September).
4. Purposes and legal bases
- Responding to contact requests and pre-contractual steps — pre-contractual measures at the data subject's request (Art. 6(1)(b) GDPR);
- Provision of the engaged legal services, including judicial and extrajudicial representation — performance of a contract (Art. 6(1)(b) GDPR);
- Compliance with legal obligations (tax, accounting, anti-money-laundering and counter-terrorist-financing, professional conduct) — legal obligation (Art. 6(1)(c) GDPR);
- Processing of third-party data necessary for representation and the defence of the client's interests; establishment, exercise or defence of the firm's rights — legitimate interest (Art. 6(1)(f) GDPR; Art. 9(2)(f) for special categories);
- Security of the information systems and the site (access logs, abuse prevention) — legitimate interest (Art. 6(1)(f) GDPR);
- Site analytics (Google Analytics) — consent (Art. 6(1)(a) GDPR and Art. 5 of Law 41/2004 of 18 August).
Where consent is the applicable basis, it may be withdrawn at any time, without affecting the lawfulness of the processing carried out until that date.
5. Whether providing data is mandatory
Providing the identification data required by law (in particular Law 83/2017 of 18 August) is a legal requirement: without it, the business relationship cannot be established or continued. Providing the other data necessary for the service is a contractual requirement: without it, the service may be wholly or partly unfeasible. All other data is provided on a voluntary basis.
6. Retention periods
Data is kept only for as long as necessary for the purposes for which it was collected, applying in particular the following periods and criteria:
- Identification and due-diligence duties (AML): 7 years after the client's identification or the end of the business relationship, and 7 years from the execution of the transactions — Article 51 of Law 83/2017 of 18 August;
- Tax and accounting documentation: 10 years — Article 52 of the Portuguese VAT Code and Article 19 of Decree-Law 28/2019 of 15 February;
- Case files and documentation of entrusted matters: for the period necessary for the establishment, exercise or defence of legal claims, by reference to the applicable statutory limitation periods, including those relating to professional civil liability;
- Requests from prospective clients (including the new-request form): identification details and the record of the decision are kept for the period necessary to check for conflicts of interest in future engagements (Article 143 of the OSAE Statute), and remain subject to professional secrecy even where the engagement is not accepted (Article 141(2) of the same Statute);
- Contact messages without follow-up: up to 12 months after the last contact;
- Technical access logs of the site: up to 12 months;
- Data processed on the basis of consent: until consent is withdrawn, without prejudice to other grounds for retention.
Once the applicable periods have elapsed, data is securely deleted or anonymised.
7. Recipients, processors and data disclosure
a) Processors (process data on the firm's behalf, bound by contract under Article 28 GDPR):
- Microsoft (Microsoft 365 and Microsoft Azure) — email, document storage, hosting of the site and of the firm's management system;
- Google (Google Analytics) — site analytics, exclusively with consent.
b) Recipients acting as independent controllers, where necessary for the service or required by law:
- Courts, registries, notary offices, tax offices and other public or administrative bodies;
- Lawyers and other professionals involved in the same matter (including co-counsel arrangements), bound by professional secrecy;
- The firm's certified accountant, for tax and accounting obligations;
- Insurance companies, in the context of professional civil liability insurance, where applicable;
- The Order of Solicitadores and Enforcement Agents and supervisory authorities, in the cases provided for by law.
c) Contact via WhatsApp: contacting the firm through the WhatsApp feature made available on the site entails the processing of data by Meta Platforms Ireland Ltd., under that service's terms and privacy policy, which the user should consult before using it.
d) Interactive map: the site provides a map supplied by the OpenStreetMap Foundation, which is only loaded after the user expressly requests it. At that point, the IP address and technical connection data are disclosed to that entity, under its own privacy policy.
The firm does not sell or transfer personal data for third-party marketing purposes.
8. International transfers
Data is, as a rule, processed within the European Economic Area. The service providers listed in section 7 may, in limited situations (notably technical support), involve transfers to third countries, in particular the United States of America. In such cases, transfers are carried out under the mechanisms provided for in Chapter V of the GDPR: a European Commission adequacy decision (including the EU-U.S. Data Privacy Framework, for certified entities) or standard contractual clauses approved by the European Commission, accompanied, where necessary, by supplementary measures.
9. Data subjects' rights
Under Articles 15 to 22 GDPR, data subjects may exercise the rights of access, rectification, erasure, restriction of processing, objection and portability, and withdraw any consent given, by written request addressed to geral@mglaw.pt or to the firm's address, accompanied by elements allowing the requester's identity to be confirmed.
Requests are answered within one month, extendable under Article 12(3) GDPR.
The exercise of these rights may be limited where legal retention obligations prevail (sections 5 and 6), where the solicitador's professional secrecy applies (Articles 127 and 141 of the OSAE Statute, approved by Law 154/2015 of 14 September) or where the rights and freedoms of third parties so require; in such cases, the grounds for the limitation are communicated to the requester, to the extent that doing so does not defeat the purpose of the restriction.
10. Automated decision-making
The firm does not take decisions based solely on automated processing, including profiling, that produce legal effects or similarly significantly affect data subjects (Article 22 GDPR).
11. Security
Technical and organisational measures appropriate to the risk are adopted under Article 32 GDPR, including access control with strong authentication, encryption in transit, backups, access logging and binding staff to confidentiality duties. In the event of a personal data breach likely to result in a risk to data subjects' rights, the notification duties under Articles 33 and 34 GDPR will be complied with.
12. Professional secrecy
Regardless of the data protection framework, all matters entrusted to the firm are covered by the solicitador's professional secrecy, under Articles 127 and 141 of the OSAE Statute, which extends to all staff. Correspondence relating to the exercise of the profession benefits from the protection provided for in Article 142 of the same Statute.
13. Minors
The site is not directed at persons under 18 and the firm does not knowingly collect minors' data through the site. The processing of minors' data in the context of matters entrusted to the firm (notably family or inheritance matters) is carried out with the applicable legal safeguards.
14. Cookies
The use of cookies and similar technologies is governed by the Cookie Policy, in accordance with Article 5 of Law 41/2004 of 18 August. Non-essential cookies are only used with prior consent.
15. Changes to this Policy
This Policy may be updated to reflect legal, technological or business changes. The version in force, with its update date, is the one published on this page. Significant changes will be appropriately highlighted.
16. Complaints
Without prejudice to any other remedy, data subjects have the right to lodge a complaint with the supervisory authority:
Comissão Nacional de Proteção de Dados (CNPD)
Av. D. Carlos I, 134, 1.º, 1200-651 Lisboa, Portugal
Tel.: (+351) 213 928 400 · geral@cnpd.pt · www.cnpd.pt
This translation is provided for convenience; in the event of any discrepancy, the Portuguese version prevails.
← Back to home