2019-01-15

Added

Instruction No. 1/2019: Reporting of Severe Incidents

Payment Service Providers (PSPs) registered and authorized by the Bank of Portugal are required to report severe operational or security incidents to the Bank of Portugal without delay. The instruction establishes criteria for classifying incidents as severe based on impact levels, such as affected operations, users, service interruptions, and economic impact, and mandates the use of a specific English-language report via the BPnet portal. It also outlines the methodology for calculating indicators and the continuous assessment required during an incident.

Banco de Portugal logo

Portugal

Banco de Portugal

Click to view thumbnail

Instruction No. 01/2019 BO No. 1/2019 • 2019/01/15 .................................................................................................................................................................................................. Topics Payment Systems :: Information Elements Mod. 99999940/T – 01/14 Index Text of the Instruction Text of the Instruction Subject: Reporting of severe incidents

Directive (EU) 2015/2366 of the European Parliament and of the Council of 25 November 2015 on payment services in the internal market (PSD2), in its Article 96 (“Notification of incidents”), enshrines the duty to notify by Payment Service Providers (PSPs) in the event of a severe operational or security incident related to the provision of payment services.

Complementarily, paragraph 3 of the aforementioned Article 96 of PSD2 determines that the European Banking Authority (EBA) issues Guidelines regarding the classification of severe operational or security incidents by PSPs and the communication of such incidents to the competent authority of the Member State of origin.

In this context, the EBA issued the “Guidelines on the reporting of major incidents under PSD2” (EBA/GL/2017/10), which establish the criteria for the classification of severe operational or security incidents and the procedures for communication of these incidents by PSPs to competent authorities. The aforementioned Guidelines also define how competent authorities must assess the relevance of incidents reported by PSPs and share this information with the EBA, the European Central Bank (ECB) and other national authorities.

The aforementioned EBA Guidelines entered into force on 13 January 2018 and can be consulted (in English and Portuguese versions) via the following link: https://www.eba.europa.eu/regulation-and-policy/payment-services-and-electronic-money/guidelines-on-major-incidents-reporting-under-psd2.

At the national level, Article 71 of Decree-Law No. 91/2018 of 12 November, which transposed the provision relating to Article 96 of PSD2 into Portuguese law, establishes in paragraph 1 that PSPs with headquarters in Portugal must make the aforementioned communication to the Bank of Portugal without delay. For its part, paragraph 2 of the same article determines that the Bank of Portugal must establish the regulatory norms regarding the classification, by PSPs, of the aforementioned severe incidents and the content, format, models and procedures for communication of such incidents by PSPs.

Instruction No. 01/2019 BO No. 1/2019 • 2019/01/15 Topics Payment Systems Payment Systems :: Information Elements .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 In these terms, the Bank of Portugal, in the exercise of the competence conferred upon it by Article 14 of its Organic Law, approved by Law No. 5/98 of 31 January, and by paragraph 2 of Article 71 of Decree-Law No. 91/2018 of 12 November, determines the following:

I – SCOPE OF APPLICATION AND GENERAL PROVISIONS

  1. Object 1.1. This instruction regulates the duty to report to the Bank of Portugal operational or security incidents of a severe nature, in compliance with the provisions of Article 71 of the Legal Regime for Payment Services and Electronic Money (RJSPME), published in annex to Decree-Law No. 91/2018 of 12 November, which incorporated the provision of Article 96 of PSD2 into Portuguese law. Text amended by Instruction No. 20/2021, published in BO No. 12/2021 of 15 December.

1.2. For the purposes of the preceding paragraph, this instruction implements the “Revised Guidelines on the reporting of major incidents under PSD2” issued by the EBA (EBA/GL/2021/03), which establish the criteria for the classification of severe operational or security incidents and the procedures for communication of these incidents by PSPs to competent authorities. Text amended by Instruction No. 20/2021, published in BO No. 12/2021 of 15 December.

1.3. The object of this instruction is severe incidents that affect the functions performed by the PSPs themselves and the functions subcontracted by PSPs to third parties. Added by Instruction No. 20/2021, published in BO No. 12/2021 of 15 December.

  1. Recipients The recipients of this Instruction are PSPs registered and authorized by the Bank of Portugal, even when operating in other countries through the exercise of the right of establishment or the free provision of services.

  2. Definitions For the purposes of this Instruction, the definitions contained in Article 2 of the RJSPME and those indicated below are applicable: Operational or security incident: A single event or a series of connected events not foreseen by the PSP, which have, or are likely to have, an adverse impact on the integrity, availability, confidentiality and/or authenticity of payment-related services. Integrity: Characteristic that safeguards the accuracy and completeness of assets (including data).

Instruction No. 01/2019 BO No. 1/2019 • 2019/01/15 Topics Payment Systems Payment Systems :: Information Elements .................................................................................................................................................................................................. Mod. 99999940/T – 01/14 Availability: Characteristic that allows payment-related services to be fully accessible and usable by payment service users, according to pre-defined acceptable levels set by the PSP. Confidentiality: Characteristic that inhibits access to or disclosure of information to unauthorized individuals, entities or processes. Authenticity: Characteristic that confirms the veracity of a source. Payment-related services: Any commercial activity within the meaning of point (v) of Article 2 of the RJSPME and all technical support tasks necessary for the correct provision of payment services. Text amended by Instruction No. 20/2021, published in BO No. 12/2021 of 15 December.

II – REPORTING REQUIREMENTS 4. Classification of an incident as severe 4.1. PSPs must classify operational or security incidents as severe if they meet: 4.1.1. one or more “higher impact level” criteria, or 4.1.2. three or more “lower impact level” criteria, as indicated in the following table:

CriteriaLower Impact LevelHigher Impact Level
Operations Affected> 10% of the PSP’s normal level of operations (in terms of number of operations) and incident duration > 1 hour* OR > 500,000 EUR and incident duration > 1 hour*> 25% of the PSP’s normal level of operations (in terms of number of operations) OR > 15,000,000 EUR
Payment Service Users Affected> 5,000 and incident duration > 1 hour* OR > 10% of the PSP’s payment service users and incident duration > 1 hour*> 50,000 OR > 25% of the PSP’s payment service users
Service Disruption> 2 hoursNot applicable
Security Breach in the network or information systemsYesNot applicable
Economic ImpactNot applicableMaximum (0.1% of Level 1 own funds, 200,000 EUR) ** OR > 5,000,000 EUR
Escalation to higher internal bodiesYesYes, and it is likely that crisis mode (or other equivalent) will be activated
Other PSPs or relevant infrastructures potentially affectedYesNot applicable
Reputational ImpactYesNot applicable
  • The limit regarding incident duration exceeding one hour applies only to operational incidents that affect the PSP’s ability to initiate and/or process operations. ** Level 1 own funds, within the meaning of Article 25 of Regulation (EU) No 575/2013 of the European Parliament and of the Council of 26 June on prudential requirements for credit institutions and investment firms and amending Regulation (EU) No 648/2012. Text amended by Instruction No. 20/2021, published in BO No. 12/2021 of 15 December.
  1. Criteria / indicators to consider 5.1. PSPs must evaluate operational or security incidents according to the following criteria and their underlying indicators:

5.1.1. Operations affected: PSPs must determine the total value of affected operations, as well as the number of compromised payments, in percentage terms relative to the normal level of payment operations executed by the affected payment services.

5.1.2. Affected payment service users: PSPs must determine the number of affected payment service users both in absolute terms and in percentage terms, relative to the total number of payment service users.

5.1.3. Security breach in the network or information systems: PSPs must verify whether any malicious action has compromised the security of the network or information systems related to the provision of payment services.

5.1.4. Service disruption: PSPs must determine the period of time during which the service is likely to be unavailable to payment service users or during which the payment order, within the meaning of point (ii) of Article 2 of the RJSPME, cannot be executed by the PSP.

5.1.5. Economic impact: PSPs must determine the total monetary costs of the incident and take into account both absolute values and, where relevant, the relative importance of these costs in relation to the size of the PSP (i.e., the PSP’s Level 1 own funds).

5.1.6. Escalation to higher internal bodies: PSPs must determine whether the incident in question has been, or is likely to be, communicated to the administrative body.

5.1.7. Other PSPs or relevant infrastructures potentially affected: PSPs must determine the likely systemic implications of the incident, namely the risk of contagion to other PSPs, financial market infrastructures and/or payment systems.

5.1.8. Reputational impact: PSPs must determine how the incident may prejudice the confidence of users in the PSP itself and, in general, in the service in question or in the entire market.

5.2. PSPs must calculate the value of the indicators according to the following methodology:

5.2.1. Operations affected: Generally, PSPs must consider as “affected operations” all national and cross-border operations that have been, or are likely to be, directly or indirectly affected by the incident, and in particular, operations that have not been initiated or processed, as well as operations whose payment message content has been altered and those that have been ordered fraudulently (regardless of whether funds have been recovered or not), or operations whose proper execution has been prevented or prejudiced in any other way by the incident.

In the case of operational incidents that affect the ability to initiate and/or process operations, PSPs must report only incidents with a duration exceeding one hour. The duration of the incident must be measured from the moment the incident occurs until the moment when regular activities/operations are recovered to the service level provided before the incident.

Additionally, PSPs must consider the normal level of payment operations to be the annual daily average of national and cross-border payment operations executed by the same payment services that were affected by the incident, considering the previous financial year as the reference period for calculation purposes. In the event that PSPs do not consider this number representative (e.g., due to seasonality), they must use another more representative measure and transmit to the Bank of Portugal the rationale underlying this approach in the corresponding field of the reporting report.

5.2.2. Affected payment service users: PSPs must consider as “affected payment service users” all customers (national or foreign, consumers or companies) who have a contract with the affected PSP granting them access to the said service and who have suffered or are likely to suffer the consequences of the incident. To determine the number of payment service users who may have used the service during the period of occurrence of the incident, PSPs must resort to estimates based on their respective activity histories.

In the case of a group, each PSP must only consider its own payment service users. If it is a PSP that provides operational services to third parties, it must only consider its own payment service users (if it has any) and the PSPs benefiting from these operational services must evaluate the incident in relation to their own payment service users.

In the case of operational incidents that affect the ability to initiate and/or process operations, PSPs must report only incidents that affect payment service users with a duration exceeding one hour. The duration of the incident must be measured from the moment the incident occurs until the moment when regular activities/operations are recovered to the service level provided before the incident.

Furthermore, PSPs must consider the total number of payment service users to be the aggregated number of national and cross-border payment service users contractually bound at the time of the incident (or, alternatively, the most recent value available) and with access to the payment service affected, regardless of their size or whether they are considered active or passive users of the services in question.

5.2.3. Security breach in the network or information systems: PSPs must verify whether any malicious action has compromised the availability, authenticity, integrity or confidentiality of the network or information systems (including data) related to the provision of payment services.

5.2.4. Service disruption: PSPs must consider the period of time during which any task, process or channel associated with the provision of payment services is, or is likely to be, interrupted and that prevents: (i) the initiation and/or execution of a payment service and/or (ii) access to a payment account. PSPs must account for service disruption time from the start of the disruption, considering both the period of time during which the provision of payment services is available to the public, as well as closing hours and maintenance periods, when relevant and applicable. If PSPs cannot determine the moment when the service disruption began, they must exceptionally account for the disruption from the moment of its detection.

5.2.5. Economic impact: PSPs must consider costs directly and indirectly related to the incident. Among other factors, PSPs must take into account funds or assets expropriated, costs of replacing hardware or software, other judicial or dispute resolution costs, fees for breach of contractual obligations, sanctions, external liabilities and loss of revenue.

Regarding indirect costs, PSPs must consider only those that are already known or those that are very likely to materialize.

5.2.6. Escalation to higher internal bodies: PSPs must consider whether, as a result of the impact on payment-related services, the administrative body, as defined in the EBA Guidelines on ICT and security risk management, has been, or is likely to be, informed, in accordance with point (d) of Guideline 60 of the EBA Guidelines on ICT and security risk management, about the incident outside the scope of any periodic notification procedure and on a continuous basis during the period of occurrence of the incident. Furthermore, PSPs must consider whether crisis mode has been, or is likely to be, activated as a result of the impact of the incident on payment-related services.

5.2.7. Other PSPs or relevant infrastructures potentially affected: PSPs must evaluate the impact of the incident on the financial market, including financial market infrastructures and/or the payment systems that support them and the remaining PSPs. In particular, PSPs must evaluate whether the incident has had, or is likely to have, repercussions on other PSPs, whether it has affected, or is likely to affect, the proper functioning of financial market infrastructures and whether it has compromised, or is likely to compromise, the good functioning of the entire financial system. PSPs must be attentive to several factors, namely whether the affected component/software is private or widely accessible, or whether the compromised network is internal or external or whether the PSP has ceased, or is likely to cease, to comply with its obligations towards the financial market infrastructures to which it belongs.

5.2.8. Reputational impact: PSPs must consider the level of visibility that, to the best of their knowledge, the incident has obtained, or is likely to obtain, in the market. PSPs must consider, in particular, the probability that the incident could cause damage to society as an indicator to assess the potential impact of the incident on their reputation. PSPs must take into consideration: (i) whether payment service users and/or other PSPs have complained about the adverse impact of the incident, (ii) whether the incident has affected any visible process related to payment services, and is therefore likely to have received or already has received media coverage (considering not only traditional media, such as newspapers, but also blogs, social networks, etc.), (iii) whether contractual obligations have not been, or are likely not to be, fulfilled, resulting in the disclosure of legal actions against the PSP, (iv) whether regulatory requirements have not been fulfilled, resulting in the imposition of supervisory measures or sanctions that have been, or are likely to be, disclosed to the public, and (v) whether the same type of incident has occurred previously.

5.3. PSPs must resort to estimates when real values are not available to support their assessment on whether a certain limit is, or is likely to be, reached before the resolution of the incident (e.g., this may happen during the initial investigation phase).

5.4. PSPs must carry out this assessment on a continuous basis throughout the period of occurrence of the incident, in order to identify any changes in the status of the incident, whether in the direction of its aggravation (from non-severe to severe) or mitigation (from severe to non-severe). Any reclassification of the incident from severe to non-severe must be communicated to the competent authority, in accordance with the description in point 10.5 of this instruction and without unjustified delay). Text amended by Instruction No. 20/2021, published in BO No. 12/2021 of 15 December.

III – REPORTING PROCESS 6. Reporting channel 6.1. PSPs must report severe incidents to the Bank of Portugal by filling out a report, in English, on the BPnet portal (www.bportugal.net).

Instruction No. 01/2019 BO No. 1/2019 • 2019/01/15 Topics Payment Systems Payment Systems :: Information Elements .................................................................................................................................................................................................. Mod. 99999940/T – 01/14

6.2. For this purpose, those responsible for submitting reports to the Bank of Portugal must subscribe to the "Payment Systems » DSP2 Incident Reporting" service made available on the BPnet portal.

  1. Reporting Model

7.1. PSPs must collect all relevant information, complete the incident report in accordance with the instructions provided in the technical manual available on the BPnet Portal, and use the model also available on the BPnet Portal for this purpose, and submit it to the Bank of Portugal, as the competent authority of the Member State of origin.

7.2. PSPs must complete the initial, interim, and final reports regarding the same incident incrementally, and update, where applicable, the information provided in previous reports.

7.3. Where applicable, PSPs must also send to the Bank of Portugal, via the email sp.psd2@bportugal.pt, a copy of the information provided (or to be provided) to their users, as provided for in point (b) of paragraph 1 of Article 71 of the RJSPME, as soon as this information is available.

7.4. PSPs must, at the request of the Bank of Portugal, provide any additional documents that complement the information presented in the report, in the form of one or more attachments sent to the email sp.psd2@bportugal.pt.

7.5. PSPs must respond to any request for additional information or clarifications regarding the documentation submitted, made by the Bank of Portugal.

7.6. Any additional information contained in the documents provided by PSPs to the Bank of Portugal, whether on the initiative of the PSP or at the request of the Bank of Portugal, in accordance with the previous point of this Instruction, must be reflected by the PSP in its incident report.

7.7. PSPs must permanently ensure the confidentiality and integrity of the information exchanged, as well as its adequate authentication with the Bank of Portugal.

Text amended by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

  1. Initial Report

8.1. PSPs must submit an initial report to the Bank of Portugal whenever an operational or security incident is classified as severe. The Bank of Portugal must acknowledge receipt of the initial report without delay and assign a unique reference code that unequivocally identifies the incident. PSPs must indicate this reference code when submitting an update to the initial, interim, and final reports regarding the same incident, unless the interim and final reports are submitted together with the initial report.

8.2. PSPs must send the initial report to the Bank of Portugal within 4 hours from the moment the operational or security incident was classified as severe, or, in the case where BPnet is not available or operational at that time, as soon as it becomes available/operational again.

8.3. PSPs must classify the incident in accordance with the provisions in point 4 of this Instruction, in a timely manner after the detection of the incident, but no later than 24 hours after its detection, and without unjustified delay after the information necessary for the classification of the incident is available to the PSP. If a longer period is necessary to classify the incident, PSPs must explain, in the initial report submitted to the Bank of Portugal, the reasons for the extension of the deadline.

8.4. PSPs must also submit an initial report to the Bank of Portugal whenever a non-severe incident is reclassified as severe. In this specific case, PSPs must send the initial report to the Bank of Portugal immediately after the detection of the change in status, or, in the case where BPnet is not available or operational at that time, as soon as it becomes available/operational again.

8.5. PSPs must provide, in the initial report, general information (i.e., section A of the report), describing some of the essential characteristics of the incident and its probable consequences, based on the information immediately available after its classification as severe. PSPs must resort to estimates whenever actual values are not available.

Text amended by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

  1. Interim Report

9.1. PSPs must submit the interim report as soon as regular activities are recovered and commercial activity returns to normal, informing the Bank of Portugal of this fact. PSPs must consider that commercial activity has returned to normal when activities/operations are recovered to the same service levels/conditions defined by the PSP, or stipulated by an external entity through a service level agreement (with regard to processing times, capacity, security requirements, among others) and when contingency measures cease to apply. The interim report must contain a more detailed description of the incident and its consequences (section B of the report).

9.2. If regular activities have not yet been recovered, PSPs must submit an interim report to the Bank of Portugal within 3 business days from the submission of the initial report.

9.3. PSPs must update the information already provided in sections A and B of the report whenever they become aware of significant changes after the submission of the previous report (e.g., when the incident worsens or improves, when new causes are identified or new measures are taken to resolve the problem).

This situation includes cases where the incident has not been resolved within 3 business days, which requires PSPs to submit an additional interim report. Notwithstanding, PSPs must submit an additional interim report whenever requested by the Bank of Portugal.

9.4. As defined for the initial report, whenever actual values are not available, PSPs must resort to estimates.

9.5. In the case where commercial activity returns to normal before 4 hours have elapsed since the incident was classified as severe, PSPs should seek to submit the initial and interim reports simultaneously (filling in sections A and B of the report) within this 4-hour period.

Text amended by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

  1. Final Report

10.1. PSPs must submit a final report when the cause of the problem is analyzed (regardless of whether mitigation measures have already been implemented or the ultimate cause of the problem has been identified) and actual values are available to replace any potential estimates.

10.2. PSPs must deliver the final report to the Bank of Portugal within a maximum of 20 business days after the return to normality. PSPs who need an extension of the deadline (e.g., because actual values regarding the impact are not yet available or because the causes of the problem have not been identified) must contact the Bank of Portugal before the deadline expires and provide adequate justification for the delay, as well as a new estimate of the delivery date of the final report.

10.3. In the case where PSPs can provide all the information requested in the final report (section C of the report) within 4 hours after the classification of the incident as severe, they should seek to provide, simultaneously, the information related to the initial, interim, and final reports.

10.4. PSPs must include in the final report all available information, namely: (i) the actual impact values instead of estimates (as well as any other necessary updates in sections A and B of the report) and (ii) in section C of the report, the cause of the problem, if already known, and a summary of the measures adopted or planned to be adopted to resolve the problem and prevent its occurrence in the future.

10.5. PSPs must also send a final report when, as a result of a continuous assessment of the incident, they conclude that a previously reported incident no longer meets the criteria to be considered severe nor is it expected to meet them before the resolution of the incident. In this case, PSPs must send the final report as soon as this situation is detected and, in any case, within the period provided for the submission of the next report. In this particular situation, instead of filling in section C of the report, PSPs must select the option "incident reclassified as non-severe" and provide an explanation of the reasons justifying their reclassification.

Text amended by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

  1. Delegation of Reporting

11.1. Whenever authorized by the Bank of Portugal, PSPs wishing to delegate their obligations to communicate severe incidents under Article 71 of the RJSPME to a third party must inform the Bank of Portugal and ensure the fulfillment of the following conditions:

a) The formal contract or, where applicable, the internal agreements entered into within the scope of a group, underlying the delegation of communication obligations between the PSP and a third party, unequivocally define the responsibilities attributed to each of the parties. In particular, they must clearly state that, regardless of the possible delegation of communication obligations, the affected PSP remains entirely responsible for complying with the requirements defined in Article 71 of the RJSPME, as well as for the content of the information provided to the Bank of Portugal.

b) The delegation of the communication obligation must comply with the requirements for outsourcing important operational functions, as established:

i. in Article 71 of the RJSPME regarding payment institutions and electronic money institutions, applicable, with the necessary adaptations, in accordance with Article 3 of Directive 2009/110/EC of the European Parliament and of the Council, of September 16, 2009, on the taking up, pursuit and prudential supervision of the business of electronic money institutions (Electronic Money Directive); or

ii. in the EBA Guidelines on outsourcing (EBA/GL/2019/02) regarding all PSPs.

c) The information must be submitted to the Bank of Portugal in advance and, in any case, complying with all deadlines and procedures established by the Bank of Portugal.

d) The confidentiality of sensitive data and the quality, consistency, integrity, and reliability of the information to be provided to the Bank of Portugal are adequately guaranteed.

11.2. PSPs must not delegate their communication obligations after having been notified that the outsourcing contract does not meet the requirements established in point (b) of paragraph 11.1.

11.3. PSPs wishing to cancel the delegation of their communication obligations must communicate their decision to the Bank of Portugal within 15 business days before the intended date for cancellation.

11.4. PSPs must inform the Bank of Portugal about any relevant event affecting the designated third party and its capacity to comply with communication obligations.

11.5. PSPs must comply with their communication obligations without any recourse to external support whenever the designated third party fails to inform the Bank of Portugal about an operational or security incident of a severe character, in accordance with the provisions of Article 71 of the RJSPME and this Instruction.

11.6. PSPs must ensure that an incident is not reported twice, individually by the respective PSP and also by the third party.

11.7. PSPs must ensure that, in the case where an incident is caused by a disruption in services provided by a technical service provider (or infrastructure) affecting multiple PSPs, the delegated communication refers to the individual data of the PSP (except in the case of consolidated communication).

Text amended by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

  1. Consolidated Reporting

PSPs wishing to allow a designated third party to fulfill their communication obligations in a consolidated manner (namely through the submission of a single report regarding multiple PSPs affected by the same operational or security incident of a severe character) must inform the Bank of Portugal, providing contact information regarding the "affected PSP" in the report and ensuring that the following conditions are met:

12.1. Include this provision in the contract underlying the delegation of communication obligations;

12.2. Condition consolidated communication on the fact that the incident was caused by a disruption of services provided by a third party;

12.3. Limit consolidated communication to PSPs established in Portugal;

12.4. Provide a list of all PSPs affected by the incident;

12.5. Ensure that the third party assesses the materiality of the incident relative to each affected PSP and only includes in the consolidated report the PSPs for whom the incident is classified as severe; additionally, ensure that, in case of doubt, the PSP is included in the consolidated report, whenever there is no evidence confirming the contrary;

12.6. Ensure that, whenever there are fields in the report where a common response cannot be provided (e.g., sections B2, B4, or C3), the third party proceeds: (i) to individual filling for each affected PSP, specifically identifying each PSP to which the information refers, or; (ii) to the use of cumulative values, as observed or estimated for the PSPs.

12.7. The third party keeps the PSP informed, at all times, of all relevant information regarding the incident and all interactions that it may have with the Bank of Portugal, as well as the content of such interactions, but only to the extent possible, so as to avoid a breach of confidentiality regarding information related to other PSPs.

Text amended by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

  1. Operational and Security Policy

PSPs must ensure that their general operational and security policies clearly define all responsibilities regarding the communication of incidents under Article 71 of the RJSPME and this Instruction.

Added by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

IV – FINAL PROVISIONS

  1. Entry into Force

This Instruction enters into force on the day of its publication.

Renumbered by Instruction No. 20/2021, published in BO No. 12/2021, of December 15.

More like this from BDP

We email you every new BDP publication the day it's published.

Share