Transparency Report
In force since 18 September 2026 · Period covered: 1 January to 31 August 2026
What this document is for
The transparency report publicly discloses how many requests for access to client data Sooma has received from authorities, of what type, and how many were refused for not meeting the legal requirements.
Sooma states that client data is subject exclusively to Portuguese law. This report shows what that means in practice.
The report is updated annually, and previous reports remain available on this page.
Transparency Report 2026
Sooma operates electronic communications infrastructure in Portugal. In that capacity, it may receive requests from judicial authorities and criminal police bodies concerning client data. We publish annually the number and nature of these requests, as well as their outcome.
1. Figures for the year
1.1. Total requests received
| Indicator | 2025 | 2026 |
|---|---|---|
| Total requests received | 0 | 0 |
| Requests from Portuguese authorities | 0 | 0 |
| Requests from authorities of other EU Member States | 0 | 0 |
| Requests from authorities of third countries | 0 | 0 |
1.2. Origin of requests
| Requesting entity | 2026 |
|---|---|
| Judicial authorities (courts and Public Prosecutor's Office) | 0 |
| Criminal police bodies | 0 |
| Tax and Customs Authority (Autoridade Tributária e Aduaneira) | 0 |
| Intelligence services | 0 |
| Other administrative bodies | 0 |
1.3. Type of request
| Nature of the request | 2026 | Remarks |
|---|---|---|
| Account holder identification data (basic data) | 0 | Name, address, contact details and contractual details |
| Expedited preservation of data | 0 | Temporary preservation of existing data, at the request of a competent authority |
| Seizure of email | 0 | Subject to judicial authorisation |
| Traffic data | 0 | Subject to judicial authorisation |
| Interception of communications | 0 | Subject to judicial authorisation |
1.4. Outcome
| Outcome | 2026 | % |
|---|---|---|
| Requests fulfilled | 0 | — |
| Requests refused for not meeting the legal requirements | 0 | — |
| Requests corrected by the authority and subsequently fulfilled | 0 | — |
| Requests that could not be answered because the data did not exist | 0 | — |
Note on traffic data: Sooma retains technical logs for short periods, strictly as necessary for the security and operation of the Service, and does not keep traffic data for criminal investigation purposes. For this reason, some requests concerning traffic data cannot be fulfilled: the data no longer exists.
1.5. Accounts affected
| Indicator | 2026 |
|---|---|
| Number of client accounts targeted by the requests | 0 |
| Percentage of total accounts managed | — |
2. How we handle requests
- All requests are received through a dedicated channel and recorded internally.
- Each request is analysed individually by the Data Protection Officer and, whenever the nature of the request justifies it, with external legal support.
- In each case, Sooma verifies: the competence of the requesting entity; the existence of a legal basis for the request; the existence of judicial authorisation, where required; proportionality and the delimitation of scope; and the security of the transmission channel.
- Data is only provided when the request is legally valid and formally correct. Where this is not the case, the request is refused, stating the grounds, and the authority may correct and resubmit it.
- No data is provided to authorities of third countries on the basis of direct requests. Such requests must follow the applicable international judicial cooperation mechanisms, with the involvement of the competent Portuguese authorities.
- Sooma has no mechanism whatsoever for permanent, automated or unsupervised access by authorities to its clients' data.
3. What data can be requested
| Category | What it includes | Availability |
|---|---|---|
| Basic data | Holder identification, contact details, contract details | Retained for the duration of the contract and the subsequent legal periods |
| Message content | Messages in the mailbox at the time of the request | Only with judicial authorisation |
| Traffic data | IP addresses and connection logs | Retained for short periods; often already deleted |
| Interception | Monitoring of communications over a set period | Only with judicial authorisation |
4. Methodological notes
- Each request received is counted, not each account or each item of data requested; a single request may cover more than one account.
- Requests resubmitted after correction are counted only once, with the final outcome stated.
- No information is disclosed that would allow specific clients, proceedings or authorities to be identified.
- Where the law imposes secrecy on a specific request, the report indicates it in aggregate form, to the extent legally permissible.
