Users with the Manage Portal Profile permission can create a portal and invite customers.
Note: Subform permission needs to be maintained separately. Permissions set in the parent module's Portal Module Configuration will not be applicable for subforms. 
Field permissions are specific to each module. They are not specific to layouts.When a portal user logs in for the first time after org-wide MFA is mandated, they are prompted — after entering the TOTP from their authenticator app — to choose whether or not to trust the browser.
Note: Portal users cannot disable MFA or delete their authenticator app when org-wide MFA is mandated.
When MFA is not mandated org-wide, portal users can enable it individually from their account settings.
They can also manage or delete their MFA configuration at any time, giving them the flexibility to add a layer of security even when it is not required.
Note: When MFA is enabled, the user is required to enter an OTP from their authenticator app during each subsequent login.
Portal users can manage their passwords directly from their account. A Change Password option is available under the More option in the portal user account, giving users a straightforward way to update their password without having to use the Forgot Password option at login.





You must consider the below points when setting data privacy for the portal users:
They can also add requests in the portal on behalf of the contacts or leads that they add to the portal. See Also Data Subject Rights