Malta flag

Malta

Malta Data Privacy Laws: Cap. 586 and GDPR Guide (2026)

Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 17 primary sources cited on this page. How we verify our legal content

Malta Data Privacy Laws: Cap. 586 and GDPR Guide (2026)

Frequently Asked Questions

Does Malta have its own data protection law separate from the GDPR?

Yes. Malta enacted the Data Protection Act (Cap. 586) on 28 May 2018 to supplement the EU GDPR, which applies directly as EU law. Cap. 586 covers areas where national implementation is required or permitted: establishing the IDPC as supervisory authority, setting the children's digital consent age at 13 under S.L. 586.11, creating criminal offenses, providing exemptions for journalism and academic expression, and enacting sector-specific subsidiary legislation. Cap. 586 does not re-enact GDPR provisions but fills the gaps the GDPR leaves to national law.

What age can children in Malta give consent for their personal data to be processed?

Malta has set the age of digital consent at 13 under Subsidiary Legislation 586.11. Children aged 13 and above may consent to data processing for information society services in their own right. For children below 13, the consent or authorisation of the person holding parental responsibility is required, and controllers must make reasonable efforts to verify this. Note that Maltese civil law sets contractual capacity at 18, creating a gap for service terms that organizations should review with legal counsel.

What is the maximum fine the IDPC can impose for a data protection violation?

For private-sector controllers and processors, the GDPR's standard maxima apply: up to EUR 20 million or 4% of annual worldwide turnover for serious violations (whichever is higher). For public authorities and bodies, Cap. 586 sets separate national caps: up to EUR 25,000 for each infringement of Article 83(4) (plus EUR 25/day) and up to EUR 50,000 for each infringement of Article 83(5) or 83(6) (plus EUR 50/day). In practice, the largest administrative fine on the IDPC published decisions register is EUR 250,000, imposed in 2022 for infringements of Articles 32(1) and 32(2) after a personal data breach. The widely reported EUR 65,000 fine against C-Planet IT Solutions Limited, also from 2022, is the second largest.

Can personal data be transferred from Malta to countries outside the EU?

Yes, subject to GDPR Chapter V requirements. Transfers require an adequacy decision from the European Commission (including the 2023 EU-US Data Privacy Framework for certified US recipients), appropriate safeguards such as standard contractual clauses or binding corporate rules, or a specific derogation under Article 49. Malta's S.L. 586.12 gives data subjects directly enforceable rights in Maltese courts in connection with such transfers, addressing an enforceability gap in Maltese contract law that affects data subjects as third-party beneficiaries.

How does Malta regulate artificial intelligence under the EU AI Act?

Malta designated two national authorities under the EU AI Act. Legal Notice 226 of 2025 designates the Malta Digital Innovation Authority (MDIA) as the primary Market Surveillance Authority for most AI systems. Legal Notice 227 of 2025 (S.L. 586.14) separately designates the IDPC as MSA for high-risk AI systems under Annex III that involve biometrics, criminal risk assessment, law enforcement, migration, border control, and democratic processes. The IDPC was also identified as a fundamental rights authority effective 3 November 2024, insofar as the protection of personal data is concerned. The designation provisions of both legal notices have been in force since 10 October 2025, and their remaining provisions commenced on 2 August 2026, the AI Act's general application date, but Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the substantive Annex III high-risk obligations to 2 December 2027 and Annex I high-risk obligations to 2 August 2028.

Why is Malta particularly important for EU data protection compliance in the iGaming sector?

Malta is the EU's primary iGaming licensing jurisdiction through the Malta Gaming Authority (MGA). Because GDPR assigns responsibility to the supervisory authority of the Member State where a company has its main EU establishment, the IDPC serves as Lead Supervisory Authority for the vast majority of EU-wide GDPR complaints against online gaming operators. In 2025 the IDPC handled 535 One Stop Shop cross-border cases and acted as Lead Supervisory Authority in 517 of them, up from 256 OSS cases in 2024, of which 244 involved gaming operators. Common enforcement targets include player subject access request compliance, data retention practices, and transparency obligations.

What is the constitutional basis for data protection in Malta?

Data protection rights in Malta derive from three constitutional and international sources. Article 32(c) of the Constitution of Malta (1964) declares the entitlement to respect for private and family life, article 38 protects the privacy of the home and other property against search and entry, and article 41, the freedom of expression article, includes freedom from interference with correspondence. The European Convention Act (Chapter 319) gives ECHR Article 8 (right to private life) direct effect in Maltese courts. Malta also ratified Council of Europe Convention 108 on automatic processing of personal data in February 2003. These foundations underpin Cap. 586 and Malta's application of the GDPR.

What is S.L. 586.12 and why does it matter?

Subsidiary Legislation 586.12, the Enforcement of the Rights of Data Subjects in Relation to Transfers of Personal Data to a Third Country or an International Organisation Regulations, gives data subjects directly enforceable rights in Maltese courts when their personal data is transferred internationally. Other EU Member States rely on general contract law for third-party beneficiary enforcement of transfer safeguards (such as standard contractual clauses), but this can create enforceability uncertainty. S.L. 586.12 resolves that uncertainty in Malta by creating a specific statutory right of action.

Does Malta require DPOs to register with the IDPC?

Details must be communicated to the IDPC, but that is a GDPR requirement rather than a Maltese addition. Article 37(7) obliges every controller or processor to publish the DPO contact details and communicate them to the supervisory authority. The IDPC asks for the name of the data controller, the name of the DPO, a mailing address, an email address, a contact number, the nature of the business, and the date of appointment, sent to its DPO mailbox. It registers the details for the purposes of Article 37(7) without approving or endorsing the designation, and it encourages voluntary appointments to be notified too. The underlying duty to appoint a DPO comes from GDPR Article 37(1) and covers public authorities, large-scale systematic monitoring operations, and large-scale special category processing.

Updates

Corrected the Commissioner's start date (Dr Reno Borg took the oath of office on 22 April 2026, not in 2025), split the two EU AI Act commencement dates so the page no longer says the national designations began on 2 August 2026 when the IDPC's and the MDIA's designation provisions have been in force since 10 October 2025, restored Article 83(6) to the public-body fine cap in the FAQ, corrected the enforcement-record date range, and updated the currency stamps to September 2026.

Independently fact-checked against the cited primary sources; governing law re-checked for recent changes

Expanded from 2,450 to ~5,200 words. Corrected children's digital consent age from 16 to 13 (per S.L. 586.11). Rewrote AI regulation section to reflect dual MDIA/IDPC authority split under L.N. 226 and L.N. 227 of 2025. Added constitutional basis section, recent 2024-2026 enforcement developments, iGaming hub section with 2024 cross-border complaint statistics, and full subsidiary legislation table. Updated meta description.

Reviewed and approved by an editor

Sources and References

  1. Data Protection Act (Cap. 586) - Laws of Malta(legislation.mt).gov
  2. IDPC Legislation Page (subsidiary legislation list)(idpc.org.mt).gov
  3. IDPC Decisions(idpc.org.mt).gov
  4. IDPC 2024 Annual Report (published 2025)(idpc.org.mt).gov
  5. IDPC CEF 2024 Report on Right of Access(idpc.org.mt).gov
  6. General Data Protection Regulation - Government of Malta(les.gov.mt).gov
  7. Malta Data Protection Overview - DLA Piper(dlapiperdataprotection.com)
  8. Artificial Intelligence Regulations, 2025 (L.N. 226 of 2025, Malta Digital Innovation Authority Act, Cap. 591) - Laws of Malta(legislation.mt).gov
  9. MGA Industry Guidelines on the GDPR - Malta Gaming Authority(mga.org.mt).gov
  10. Malta IT Law, Data Protection and AI: 2025 Legal Review - INPLP(inplp.com)
  11. Malta Data Transfers Guidance Note (June 2025) - GTG Legal(gtg.com.mt)
  12. GDPR Guide to National Implementation: Malta - White and Case LLP(whitecase.com)
  13. Malta IDPC Fines C-Planet EUR 65,000 for Data Breach - DataGuidance(dataguidance.com)
  14. Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689 - EUR-Lex, OJ L, 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
  15. S.L. 586.14 - Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations (L.N. 227 of 2025)(legislation.mt).gov
  16. S.L. 586.13 - Data Protection (Fair Access to and Use of Data) Regulations (L.N. 223 of 2025, in force 10 October 2025)(legislation.mt).gov
  17. IDPC Publishes 2025 Annual Report (19 August 2026) - Information and Data Protection Commissioner(idpc.org.mt).gov
  18. Data Protection Officers - IDPC (details to be communicated under GDPR Article 37(7))(idpc.org.mt).gov
  19. Regulation (EU) 2023/2854 (Data Act), Article 50 - application dates - EUR-Lex(eur-lex.europa.eu).gov
  20. S.L. 460.41 - Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (L.N. 71 of 2025, in force 23 January 2026, as amended by L.N. 89 of 2026)(legislation.mt).gov
  21. Constitution of Malta, articles 32, 38 and 41 - Laws of Malta(legislation.mt).gov
  22. IDPC news: New Information and Data Protection Commissioner takes oath of office (22 April 2026)(idpc.org.mt).gov
Share: