Malta
Malta Data Privacy Laws: Cap. 586 and GDPR Guide (2026)
Independently fact-checked against primary sources (last audited September 10, 2026). · Reviewed by the RecordingLaw editorial team. · Law checked current as of September 10, 2026. · 17 primary sources cited on this page. How we verify our legal content

Malta data privacy is governed by the EU General Data Protection Regulation, which has applied directly since 25 May 2018, alongside the Data Protection Act (Chapter 586 of the Laws of Malta), in force since 28 May 2018. The Information and Data Protection Commissioner (IDPC) enforces both instruments and handles violations under Cap. 586 and the GDPR.
Quick Answer: What Governs Data Privacy in Malta?
Malta applies the EU General Data Protection Regulation (GDPR) directly, supplemented by the Data Protection Act (Chapter 586 of the Laws of Malta, in force 28 May 2018) and 14 items of subsidiary legislation. The Information and Data Protection Commissioner (IDPC) enforces compliance and, since 2024, also serves as a fundamental rights authority under the EU AI Act, insofar as the protection of personal data is concerned.

Constitutional and Legal Basis
Malta's data protection framework draws its legitimacy from multiple layers of constitutional and international law.
The Constitution of Malta (1964) touches privacy in three provisions. Article 32(c) declares that every person in Malta is entitled to respect for his private and family life, subject to the limitations set out in the rest of Chapter IV. Article 38, headed Protection for privacy of home or other property, provides that no person shall be subjected to the search of his person or his property or the entry by others on his premises, except with consent, by way of parental discipline, or under a law reasonably required for one of the listed public interests.
Article 41 is the freedom of expression article. Freedom from interference with correspondence is one limb of article 41(1), alongside the freedom to hold opinions and to receive and communicate ideas and information. Its limitation clause in article 41(2) applies a test of what is reasonably required in the interests of defence, public safety, public order, public morality or decency, or public health, not the ECHR formula of necessity in a democratic society.
The European Convention Act, Chapter 319 of the Laws of Malta, gives the European Convention on Human Rights direct effect in Maltese domestic law. Article 8 ECHR, which protects the right to respect for private and family life, home, and correspondence, is therefore directly enforceable in Maltese courts without the need to rely on constitutional provisions alone.
Malta ratified the Council of Europe Convention for the Protection of Individuals with regard to Automatic Processing of Personal Data (Convention 108) in February 2003, predating EU GDPR harmonisation by 15 years. This ratification formed part of the legal scaffolding that supported Malta's successive data protection legislation.
At the EU level, the GDPR (Regulation (EU) 2016/679) applies as directly applicable EU law in Malta. Unlike a directive, the GDPR does not require transposition: it takes effect in its entirety without national implementing legislation. Chapter 586 supplements the GDPR in areas where the Regulation expressly permits or requires national rules.

The Data Protection Act (Chapter 586)
Structure and Scope
The Data Protection Act, Chapter 586 of the Laws of Malta (Act XX of 2018), came into force on 28 May 2018, three days after the GDPR became applicable on 25 May 2018. It replaced the Data Protection Act 2001 (Cap. 440) and aligns with the structure of the GDPR.
Cap. 586 has eight Parts: Preliminary (articles 1 to 3); Applicability (article 4); Restrictions, Consultation and Prior Authorisation (articles 5 to 9, covering GDPR Article 23 restrictions, the research and archiving derogations, prior authorisation, processing of identity documents and the national identity number, and the freedom of expression exemption); Transborder Data Transfers (article 10); the Information and Data Protection Commissioner (articles 11 to 19); Administrative Fines and Penalties (articles 20 to 23); Appeals to the Information and Data Protection Appeals Tribunal (articles 24 to 31); and General Provisions (articles 32 to 34).
The Act applies to processing of personal data by automated means and to processing that forms part of a filing system, in both the private and public sectors. Article 4(1)(d) expressly excludes processing by competent authorities for the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties. The EU Law Enforcement Directive (Directive (EU) 2016/680) is transposed separately, by S.L. 586.08, made under the delegated power in the second proviso to article 4(1). Cap. 586 contains no provisions on intelligence or security services.
The age of digital consent is not set in the Act either. Article 33(g) is a power for the Minister to prescribe an age lower than sixteen but not below thirteen, and that power was exercised by S.L. 586.11.
Subsidiary Legislation
Malta has enacted 14 items of subsidiary legislation under Cap. 586. The full inventory as of September 2026:
| S.L. Number | Title | Scope |
|---|---|---|
| S.L. 586.01 | Processing of Personal Data (Electronic Communications Sector) Regulations | ePrivacy sector |
| S.L. 586.02 | Notification and Fees (Data Protection Act) Regulations | Registration/fees |
| S.L. 586.03 | Third Country (Data Protection Act) Regulations | Third-country transfers |
| S.L. 586.04 | Processing of Personal Data (Protection of Minors) Regulations | Children's data |
| S.L. 586.05 | Transfer of Personal Data to Third Countries Order | Transfer orders |
| S.L. 586.06 | Processing of Personal Data (Election/Local Government) Regulations | Electoral processing |
| S.L. 586.07 | Processing of Personal Data (Education Sector) Regulations | Education sector |
| S.L. 586.08 | Data Protection (Law Enforcement Processing) Regulations | LED transposition |
| S.L. 586.09 | Restriction of the Data Protection (Obligations and Rights) Regulations | Derogations |
| S.L. 586.10 | Processing of Data concerning Health for Insurance Purposes Regulations | Insurance/health |
| S.L. 586.11 | Processing of Child's Personal Data (Information Society Services) Regulations | Children's digital consent |
| S.L. 586.12 | Enforcement of Rights of Data Subjects on International Transfers Regulations | Cross-border enforcement |
| S.L. 586.13 | Data Protection (Fair Access to and Use of Data) Regulations (2025) | EU Data Act |
| S.L. 586.14 | Artificial Intelligence (IDPC Designation) Regulations (2025) | EU AI Act oversight |
Legal Bases for Processing
Malta follows the six legal bases for processing established by Article 6 of the GDPR: consent of the data subject; performance of a contract to which the data subject is party; compliance with a legal obligation; protection of vital interests; performance of a task carried out in the public interest or in the exercise of official authority; and legitimate interests pursued by the controller or a third party, subject to a balancing test against the data subject's fundamental rights.
For special categories of data (health data, biometric data, data revealing racial or ethnic origin, genetic data, religious beliefs, and trade union membership, among others), processing is only permitted under the conditions of Article 9 of the GDPR. Cap. 586 adds national provisions specifying how those conditions apply in Malta, particularly in employment, social security, and public health contexts.
Children's Data
Subsidiary Legislation 586.11 sets the age of digital consent in Malta at 13. Under GDPR Article 8, Member States may set the threshold between 13 and 16; Malta adopted the minimum permissible age. This means that organizations offering information society services to children aged 13 and above may rely on that child's own consent for data processing. For children below 13, the consent or authorisation of the person holding parental responsibility is required, and controllers must make reasonable efforts to verify it.
A separate consideration applies to contract formation: under Maltese civil law, the age of contractual capacity is 18. Organizations processing data of users aged 13 to 17 under S.L. 586.11 consent rules should take legal advice on whether the underlying service agreement is enforceable given this gap.

The Information and Data Protection Commissioner (IDPC)
Role and Independence
The IDPC is Malta's independent supervisory authority for data protection under Cap. 586. The Commissioner holds a distinct legal personality and operates with full independence. Article 12(1) of Cap. 586 explicitly prohibits the IDPC from seeking or accepting instructions from any person or entity, including government ministries.
The Commissioner is appointed by the Prime Minister acting on the advice of the Cabinet of Ministers, after consulting the Leader of the Opposition, under Cap. 586 article 11(1) as amended by Act XII of 2021. The term is five years and is renewable (article 14(1)). Dr Reno Borg has held the office since 22 April 2026, when he took the oath of office for a five-year term following the expiry of his predecessor's term.
The two-thirds majority in the House of Representatives is a removal safeguard, not a step in the appointment. Under article 14(2) the Commissioner may only be removed by the Prime Minister on an address of the House supported by the votes of not less than two-thirds of all its members, and only on the ground of proved inability to perform the duties of the office or proved misbehaviour.
Powers and Functions
The IDPC exercises the full range of investigative, corrective, and advisory powers conferred by GDPR Articles 57 and 58. Investigative powers include the right to obtain access to premises, processing systems, and any personal data being processed. Corrective powers include ordering controllers and processors to comply with data subject requests, imposing temporary or permanent bans on processing, ordering rectification, restriction, or erasure of data, and imposing administrative fines. The Commissioner may also institute civil judicial proceedings for violations or imminent violations of Cap. 586 or the GDPR.
Enforcement Record: 2020-2026
Malta's IDPC has taken an active and increasingly assertive approach to enforcement. Key enforcement data:
Administrative fines issued:
- EUR 250,000 (2022): a personal data breach decision on the IDPC register, for infringements of Articles 32(1) and 32(2) after a controller failed to implement appropriate technical and organisational measures. This is the largest administrative fine on the published register.
- EUR 65,000: C-Planet IT Solutions Limited (2022): a personal data breach recorded on the register as infringing Articles 5(1)(f), 6(1), 9(1), 9(2), 14, 32(1), 33(1) and 34(1), involving personal and special category data. It is the second largest fine on the register.
- EUR 20,000 (three violations totalling EUR 20,000: EUR 12,500, EUR 5,000, EUR 2,500): Decision ref 0476_001 (2025): breaches of Articles 5(1)(a) (lawfulness), 6(1) (legal basis), 14 (transparency), 16 (rectification), and 37(1)(c) (DPO appointment failure).
- EUR 15,000: Decision ref 4794_001 (2024): two unsolicited direct marketing calls placed after the controller had erased the personal data of the complainant and barred her numbers, infringing Articles 21(2) and 5(2).
- EUR 5,000 (2020): a personal data breach involving the unauthorised disclosure of a complainant's confidential data to an external client, infringing Articles 5(1)(f) and 32(1)(b). The IDPC register does not name controllers, so no controller is attributed here.
2024 enforcement highlights:
- The IDPC received 883 total complaints in 2024, up from prior years.
- Article 6(1) (lawfulness of processing) was the most frequently infringed GDPR provision.
- 112 CCTV-related cases were investigated, resulting in orders to remove cameras capturing public spaces or third-party properties.
- Multiple access request decisions found that controllers cannot deny requests on the assumption they are litigation-motivated, absent specific statutory grounds for restriction.
Coordinated Enforcement (CEF 2024): The IDPC participated in the EDPB-coordinated 2024 Coordinated Enforcement Action on the Right of Access. The IDPC surveyed 100 private-sector organisations across health, insurance, finance, retail, telecommunications, and manufacturing. The overall finding was positive: six years post-GDPR, controllers demonstrated high compliance with access requests, though occasional improper denials and resource constraints were noted.
Data Subject Rights Under Maltese Law
Individuals in Malta hold the data subject rights in GDPR Articles 15 to 22, which apply directly without national transposition. National law can and does restrict them in defined situations, so a Maltese controller may lawfully refuse a request on one of the grounds below. Check whether one applies before assuming a refusal is unlawful.
Research, statistics and archiving. Cap. 586 article 6(1) lets controllers and processors derogate from Articles 15, 16, 18 and 21 for scientific or historical research and official statistics, and article 6(2) adds Articles 19 and 20 for archiving in the public interest. Both require that exercising the right would render the purpose impossible or seriously impair it, and both are subject to safeguards under article 6(4), including pseudonymisation.
Journalism and expression. Cap. 586 article 9 exempts processing for journalistic purposes and for academic, artistic or literary expression from a wide list of provisions under GDPR Article 85(2), including Articles 13, 14, 15(1) to (3), 17(1) and (2), 18(1)(a), (b) and (d), 20(1) and (2), and 21(1).
Article 23 restrictions. Cap. 586 article 5 lets the Minister restrict controller and processor obligations under GDPR Article 23. That power was exercised by S.L. 586.09, which lists grounds including national security, public security, the investigation and prosecution of criminal offences, and the administration of tax.
Right of access (Article 15): Data subjects may obtain confirmation of processing, access to their data, and information about the purpose, categories, recipients, retention period, and origin of data. Access request compliance has been the most-litigated right before the IDPC.
Right to rectification and erasure (Articles 16-17): Data subjects may request correction of inaccurate data and deletion of data that is no longer necessary, where consent is withdrawn, where processing lacked a legal basis, or where a legal obligation requires erasure.
Right to restriction of processing (Article 18): Data subjects may request that a controller restrict processing while accuracy is contested, while an objection is pending, or where processing is unlawful but the data subject requests restriction rather than erasure.
Right to data portability (Article 20): Where processing is based on consent or a contract and carried out by automated means, data subjects may receive their data in a structured, commonly used, machine-readable format and transmit it to another controller.
Right to object (Article 21): Data subjects may object at any time to processing for direct marketing. They may also object to processing based on legitimate interest or public interest grounds, in which case the controller must demonstrate compelling legitimate grounds to override the objection.
Right not to be subject to automated decision-making (Article 22): Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects. Exceptions apply where the decision is necessary for a contract, authorised by law, or based on explicit consent.
Cross-Border Data Transfers
General Framework
As an EU Member State, Malta follows Chapter V of the GDPR for international data transfers. Personal data may only be transferred outside the EEA where one of the following applies: an adequacy decision adopted by the European Commission (Article 45); appropriate safeguards such as standard contractual clauses (SCCs), binding corporate rules (BCRs), or an approved code of conduct (Article 46); or a specific derogation for situations such as consent, contract performance, or compelling legitimate interests (Article 49).
The European Commission's 2023 adequacy decision for the EU-US Data Privacy Framework opened a new transfer mechanism for data flows to certified US organisations. Malta's controllers and processors may rely on this decision as they would any other adequacy determination.
Malta's Unique Subsidiary Legislation
S.L. 586.12, the Enforcement of the Rights of Data Subjects in Relation to Transfers of Personal Data to a Third Country or an International Organisation Regulations, provides data subjects with directly enforceable rights in Maltese courts when their personal data is transferred internationally. This legislation addresses a gap that exists in some other EU jurisdictions where the enforceability of transfer safeguards by individual third-party beneficiaries (as distinct from the contracting parties) may be legally uncertain under national contract law.
Cap. 586 article 10 gives the Minister a separate power. In the absence of an adequacy decision pursuant to GDPR Article 45(3), he may, following consultation with the Commissioner, set limits by regulations on the transfer of specific categories of personal data to a third country or an international organisation for important reasons of public interest. S.L. 586.12 itself confers no such power.
Penalties and Sanctions
Administrative Fines
The GDPR's two-tier fine structure applies in Malta for private-sector controllers and processors:
- Tier 1 (less serious): Up to EUR 10 million or 2% of annual worldwide turnover, whichever is higher. Applies to infringements such as failure to maintain records of processing activities (Article 30), failure to notify a data breach to the supervisory authority (Article 33), and failure to appoint a DPO when required (Article 37).
- Tier 2 (more serious): Up to EUR 20 million or 4% of annual worldwide turnover, whichever is higher. Applies to infringements of the basic principles for processing (Article 5), conditions for consent (Article 7), data subjects' rights (Articles 15-22), and international transfer rules (Articles 44-49).
Public body caps under Cap. 586: For controllers that are public authorities or public bodies, Cap. 586 sets separate national fine maxima:
- Up to EUR 25,000 per Article 83(4) violation, plus EUR 25 per day for continuing breaches.
- Up to EUR 50,000 for each infringement of GDPR Article 83(5) or 83(6), plus EUR 50 per day for continuing breaches.
Both figures are absolute maxima under Cap. 586 article 21. The Act contains no provision allowing either cap to be doubled, and the EUR 50,000 tier is itself the more serious tier.
Criminal Offenses
Article 22 is the only offence provision in Cap. 586, and it creates two offences: knowingly providing false information to the Commissioner when requested under his investigative powers pursuant to GDPR Article 58, and failing to comply with any lawful request made pursuant to an investigation by the Commissioner.
Either offence carries a fine (multa) of not less than EUR 1,250 and not more than EUR 50,000, or imprisonment for six months, or both. Proceedings may only be instituted after the Commissioner provides information to an officer of the Executive Police.
Cap. 586 contains no separate offence of unauthorised disclosure of personal data. That was a feature of the repealed Cap. 440.
Special Processing Situations
Employment Context
Malta enacted specific provisions governing processing of employee personal data. Employers must have a lawful basis for processing employee data and must inform employees about the nature and extent of any monitoring. The IDPC has issued guidance on CCTV in the workplace, email monitoring, and GPS tracking of company vehicles, applying the necessity and proportionality tests required by GDPR Article 5(1)(c).
Health Data
Health data is a special category under GDPR Article 9, subject to heightened protection. S.L. 586.10 specifically governs the processing of health data for insurance purposes. Healthcare providers must implement appropriate safeguards and may process health data only when necessary for medical treatment, public health purposes, or other grounds specified in Article 9.
Journalism and Academic Expression
Cap. 586 includes exemptions for processing personal data for journalistic purposes and for academic, artistic, or literary expression, as required by GDPR Article 85. These exemptions balance the right to data protection against freedom of expression and information.
Malta as an iGaming and Financial Services Hub
The iGaming Sector
Malta is the EU's leading iGaming jurisdiction, home to hundreds of online gaming operators licensed by the Malta Gaming Authority (MGA). This concentration has made the IDPC one of the busiest Lead Supervisory Authorities in the EU for cross-border data protection complaints involving gaming companies.
The caseload has more than doubled in a year. In 2024 the IDPC received 256 One Stop Shop (OSS) cross-border cases, of which 244 (95%) involved gaming operators with their main establishments in Malta, and it acted as Lead Supervisory Authority in 252 of them. In 2025 it handled 535 OSS cases and was Lead Supervisory Authority in 517, with 450 of the OSS cases concerning the right of access. The 2025 annual report does not publish a sector breakdown of the OSS caseload.
Common complaint patterns in the gaming sector include: failure to comply with subject access requests under Article 15; excessive retention of player data beyond the period necessary for the gaming relationship; and insufficient transparency about data sharing with advertising and analytics third parties.
In May 2018 the MGA published a guidance document on GDPR compliance for its licensees, produced after a consultation process with the IDPC. It is MGA guidance rather than a joint IDPC instrument, the MGA describes it as a living document, and it is expressed to be without prejudice to any decision the Commissioner may take. The guidance addresses lawful bases for processing player data, retention periods aligned with MGA licensing conditions, age-verification data handling, and responsible gambling data.
Financial Services
Malta's financial services sector, regulated by the Malta Financial Services Authority (MFSA), processes significant volumes of personal and transaction data. The intersection of GDPR with sector-specific retention obligations (including those under MiFID II and Anti-Money Laundering directives) requires financial institutions to carefully calibrate their retention schedules.
The NIS2 Directive, transposed by Subsidiary Legislation 460.41 (L.N. 71 of 2025, in force 23 January 2026 and already amended by L.N. 89 of 2026), adds cybersecurity obligations for essential and important entities in the financial services sector. Obligations include risk management measures, incident reporting to competent authorities, and supply chain security assessments. GDPR breach notification (72 hours to IDPC) and NIS2 incident reporting obligations may both be triggered by the same cybersecurity incident, requiring coordinated response procedures.
AI Regulation and the Expanding Role of the IDPC
The EU AI Act in Malta
The EU AI Act (Regulation (EU) 2024/1689), which entered into force on 1 August 2024, applies directly in Malta. Malta implemented national designations through two complementary legal notices in 2025:
Legal Notice 226 of 2025 designates the Malta Digital Innovation Authority (MDIA) as Malta's primary Market Surveillance Authority (MSA) for AI systems, as well as the Notifying Authority for conformity assessment bodies and the operator of Malta's AI regulatory sandbox. The MDIA acts as the default MSA for all AI system categories not specifically allocated to another authority.
Legal Notice 227 of 2025, enacted as Subsidiary Legislation 586.14, designates the IDPC as MSA for the specific high-risk AI categories under Annex III of the EU AI Act that relate to data-sensitive and fundamental-rights-intensive uses:
- High-risk biometric systems used for law enforcement, border management, and justice and democracy: remote biometric identification (excluding one-to-one verification that a person is who he claims to be), biometric categorisation by sensitive or protected attributes, and emotion recognition
- Systems that evaluate and classify emergency calls, or dispatch and prioritise emergency first response services, including emergency healthcare patient triage
- Law enforcement systems: victimisation risk assessment, polygraphs and similar tools, evaluation of the reliability of evidence, reoffending risk assessment, and profiling in the course of detection, investigation or prosecution
- Migration, asylum and border control systems: polygraphs, risk assessment of persons entering Malta, assistance with asylum, visa and residence applications, and detection or identification of natural persons other than the verification of travel documents
- Administration of justice and democratic processes: systems assisting a judicial authority in researching and interpreting facts and law, and systems intended to influence the outcome of an election or referendum or voting behaviour
Regulation 4 of S.L. 586.14 is a separate list. It gives the IDPC the AI Act tasks and powers over four prohibited practices, which are not high-risk designations: criminal risk assessment based solely on profiling or personality traits, untargeted scraping of facial images to create or expand facial recognition databases, biometric categorisation to infer race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, and real-time remote biometric identification in publicly accessible spaces for law enforcement outside three narrow objectives. Under regulation 6, any permitted real-time use needs prior authorisation from a Magistrate, with a 24-hour window to seek it in a justified urgency.
When the obligations actually bite
The national machinery arrived in two stages, and the designations came first. Regulations 3 and 4 of S.L. 586.14, which make the Commissioner the market surveillance authority for the Annex III categories listed above and give him tasks and powers over the prohibited practices, have been in force since 10 October 2025. So have regulations 3 and 7 of L.N. 226 of 2025, which designate the MDIA as market surveillance authority, single point of contact and Notifying Authority.
The remaining provisions commenced on 2 August 2026: regulations 5 to 7 and 9 to 12 of S.L. 586.14, and regulations 4, 5, 6, 8, 9 and 10 of L.N. 226. That is also the general application date of the EU AI Act under Article 113.
The substantive high-risk duties are on a later timetable. Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and rewrote Article 113 of the AI Act. Chapter III Sections 1, 2 and 3, which carry the Article 8 to 15 requirements and the Article 16 to 27 provider and deployer obligations, including the Article 27 fundamental rights impact assessment, now apply from 2 December 2027 for the Annex III high-risk systems the IDPC supervises, and from 2 August 2028 for Annex I product-embedded high-risk systems.
The Article 50 transparency rules were not postponed. They apply from 2 August 2026, as do Chapter III Section 5 on standards, conformity assessment and registration, and Article 101.
IDPC as Fundamental Rights Authority
On 3 November 2024 the Government identified the IDPC as a fundamental rights authority for the purposes of AI Act Article 77, insofar as the protection of personal data is concerned. That designation was put on a statutory footing by S.L. 586.14 regulation 5, which came into force on 2 August 2026 and expressly preserves the separate market surveillance role in regulations 3 and 4.
Article 77 is an oversight power, not a helpdesk. It lets a designated authority request and access information or documentation created or maintained under the AI Act from the relevant market surveillance authority, and, where that documentation is insufficient, make a reasoned request for the market surveillance authority to organise testing of the system. A deployer preparing a fundamental rights impact assessment notifies the market surveillance authority of the results under Article 27(3), not the fundamental rights authority.
EU Data Act
S.L. 586.13 (L.N. 223 of 2025, in force 10 October 2025) implements the EU Data Act (Regulation (EU) 2023/2854) in Malta. Regulation 3 designates the IDPC as a competent authority under Data Act Article 37(3) only insofar as the protection of personal data is concerned, and confines his tasks and powers to the processing of personal data. Regulation 5 lets him impose GDPR Article 83 fines, up to the Article 83(5) ceiling, for infringements of Chapters II, III and V of the Data Act. It does not make him Malta's national data coordinator.
The Data Act governs fair access to and use of data generated by connected devices and related services. It has applied since 12 September 2025. Its Article 3(1) access-by-design obligation applies only to connected products, and the services related to them, placed on the market after 12 September 2026. Chapter IV on unfair contractual terms reaches contracts concluded on or before 12 September 2025 from 12 September 2027, where those contracts are of indefinite duration or due to expire at least ten years from 11 January 2024.
Compliance Requirements for Organizations
Data Protection Officer
Organizations that are public authorities, that carry out large-scale systematic monitoring of individuals, or that process special categories of data on a large scale must appoint a DPO. As GDPR Article 37(7) requires in every Member State, the details of an appointed DPO must be published and communicated to the supervisory authority. In Malta that means emailing the IDPC with the name of the data controller, the name of the DPO, a mailing address, an email address, a contact number, the nature of the business, and the date of appointment. The IDPC registers those contact details for the purposes of Article 37(7) and neither approves nor endorses the designation. A voluntary appointment should be notified the same way.
Records of Processing Activities
Controllers and processors must maintain records of processing activities under GDPR Article 30 and make them available to the IDPC on request. The pre-GDPR notification regime under Cap. 440 was abolished; there is no obligation to notify the IDPC of processing activities prior to commencing them, except where a DPIA consultation is required.
Data Protection Impact Assessments
Where processing is likely to result in high risk to the rights and freedoms of individuals, controllers must carry out a Data Protection Impact Assessment (DPIA) before commencing processing. The IDPC publishes a list of processing operations for which a DPIA is mandatory in Malta. Where a DPIA reveals a residual high risk that cannot be mitigated, the controller must consult the IDPC prior to processing under GDPR Article 36.
Breach Notification
Controllers must notify the IDPC of a personal data breach within 72 hours of becoming aware of it, unless the breach is unlikely to result in risk to individuals' rights and freedoms. Where a breach is likely to result in high risk, the controller must also notify the affected data subjects without undue delay. The IDPC received 114 personal data breach reports in 2025, with the financial sector most affected and cyber-attacks the leading cause, up from 105 reports in 2024, of which 61 were cyber-attacks such as phishing and ransomware.
Recent IDPC Developments (2024-2026)
2025 Annual Report Highlights
The IDPC published its Annual Report and Financial Statements 2025 on 19 August 2026, under Commissioner Dr Reno Borg. It recorded:
- 701 complaints received.
- 182 admissible complaints, of which 75% ended in a finding of infringement.
- 535 One Stop Shop cases handled, including 517 in which the IDPC acted as Lead Supervisory Authority.
- 450 One Stop Shop cases concerning the right of access.
- 114 personal data breaches reported, with the financial sector most affected and cyber-attacks the leading cause.
- 667 Freedom of Information requests received by public authorities, plus 52 applications handled directly by the IDPC.
2024 Annual Report Highlights (prior year)
The 2024 Annual Report, published in 2025, recorded the following activity:
- 883 complaints received in total.
- 7 ex-officio investigations initiated.
- 256 One Stop Shop cases processed, of which 244 involved gaming operators.
- 105 data breaches reported, including 61 cyber-attacks.
- Article 6(1) (lawfulness of processing) was the most frequently infringed provision.
- 112 CCTV cases investigated; the IDPC emphasised necessity and proportionality when cameras capture public spaces.
Recent Enforcement Decisions
In 2025 the IDPC imposed three administrative fines in a single decision, 0476_001, against a healthcare provider: EUR 12,500 for breaches of Articles 5(1)(a), 6(1) and 14, EUR 5,000 for Article 16, and EUR 2,500 for the failure to designate a DPO under Article 37(1)(c). The decision also carried a reprimand and orders to rectify the data and appoint a DPO.
Decision 4794_001, issued in 2024, imposed a EUR 15,000 fine for two unsolicited direct marketing calls, in breach of Articles 21(2) and 5(2).
In 2026 the IDPC fined an insurance company EUR 1,000 across two administrative fines (decision 0583_001) for allowing a third party to keep marketing to a complainant in breach of an earlier IDPC decision, alongside a reprimand and corrective orders.
Most 2024-2026 decisions resulted in reprimands and corrective orders rather than fines, consistent with the IDPC's practice of reserving financial penalties for aggravated cases involving repeat violations, special category data, or wilful non-compliance.
AI Act Designations (2024-2025)
The IDPC was designated as a Fundamental Rights Authority under the EU AI Act effective 3 November 2024, and as a Market Surveillance Authority for specific Annex III high-risk AI categories under S.L. 586.14. That designation sits in regulations 3 and 4, which have been in force since 10 October 2025; regulations 5 to 7 and 9 to 12 of the same instrument came into force on 2 August 2026. The substantive Annex III high-risk obligations those powers will be used to supervise apply from 2 December 2027, following Regulation (EU) 2026/1744.
EU Data Act and NIS2
S.L. 586.13 (Data Act) came into force on 10 October 2025 and S.L. 460.41 (NIS2) on 23 January 2026, expanding the IDPC portfolio and creating intersecting obligations for organisations in financial services, health, and critical infrastructure.
Business Compliance: Practical Considerations
Organizations processing personal data in Malta benefit from the IDPC's accessible guidance library, which includes template breach notification forms, DPIA decision trees, and sector-specific guidance for gaming and employment.
For organizations new to Malta, the following are the highest-priority compliance steps:
- Map data flows and identify whether the GDPR's extra-territorial scope (Article 3) applies to your processing of Malta residents' data.
- Audit legal bases for each processing activity, particularly for direct marketing, employee monitoring, and sharing data with MGA licensing bodies.
- Register your DPO with the IDPC if appointment is mandatory.
- Review children's data handling with the correct age threshold of 13 under S.L. 586.11.
- Implement cross-border transfer mechanisms for any data sent outside the EEA; consider S.L. 586.12 when assessing enforceability of transfer safeguards.
- Prepare for the EU AI Act if deploying or using high-risk AI systems, with particular attention to the IDPC's MSA role for biometric and law enforcement AI.
- Coordinate NIS2 and GDPR breach response procedures for organisations in financial services, health, or critical infrastructure.
For gaming operators specifically: the IDPC's role as Lead Supervisory Authority for your EU-wide player data obligations means that engagement with the IDPC is effectively engagement with your primary EU data protection regulator. The volume and pattern of the caseload (244 gaming OSS cases in 2024, and 450 of the 535 OSS cases in 2025 concerning the right of access) signals that player access request handling and data retention practices are primary enforcement targets.
This article presents general legal information about Malta's data protection framework as of September 2026. It does not constitute legal advice. Data protection law is subject to ongoing change, including through EDPB guidance, IDPC enforcement decisions, and EU legislative development. Organizations should consult a lawyer licensed in Malta or a qualified data protection professional for advice on their specific situation.
Frequently Asked Questions
Does Malta have its own data protection law separate from the GDPR?
Yes. Malta enacted the Data Protection Act (Cap. 586) on 28 May 2018 to supplement the EU GDPR, which applies directly as EU law. Cap. 586 covers areas where national implementation is required or permitted: establishing the IDPC as supervisory authority, setting the children's digital consent age at 13 under S.L. 586.11, creating criminal offenses, providing exemptions for journalism and academic expression, and enacting sector-specific subsidiary legislation. Cap. 586 does not re-enact GDPR provisions but fills the gaps the GDPR leaves to national law.
What age can children in Malta give consent for their personal data to be processed?
Malta has set the age of digital consent at 13 under Subsidiary Legislation 586.11. Children aged 13 and above may consent to data processing for information society services in their own right. For children below 13, the consent or authorisation of the person holding parental responsibility is required, and controllers must make reasonable efforts to verify this. Note that Maltese civil law sets contractual capacity at 18, creating a gap for service terms that organizations should review with legal counsel.
What is the maximum fine the IDPC can impose for a data protection violation?
For private-sector controllers and processors, the GDPR's standard maxima apply: up to EUR 20 million or 4% of annual worldwide turnover for serious violations (whichever is higher). For public authorities and bodies, Cap. 586 sets separate national caps: up to EUR 25,000 for each infringement of Article 83(4) (plus EUR 25/day) and up to EUR 50,000 for each infringement of Article 83(5) or 83(6) (plus EUR 50/day). In practice, the largest administrative fine on the IDPC published decisions register is EUR 250,000, imposed in 2022 for infringements of Articles 32(1) and 32(2) after a personal data breach. The widely reported EUR 65,000 fine against C-Planet IT Solutions Limited, also from 2022, is the second largest.
Can personal data be transferred from Malta to countries outside the EU?
Yes, subject to GDPR Chapter V requirements. Transfers require an adequacy decision from the European Commission (including the 2023 EU-US Data Privacy Framework for certified US recipients), appropriate safeguards such as standard contractual clauses or binding corporate rules, or a specific derogation under Article 49. Malta's S.L. 586.12 gives data subjects directly enforceable rights in Maltese courts in connection with such transfers, addressing an enforceability gap in Maltese contract law that affects data subjects as third-party beneficiaries.
How does Malta regulate artificial intelligence under the EU AI Act?
Malta designated two national authorities under the EU AI Act. Legal Notice 226 of 2025 designates the Malta Digital Innovation Authority (MDIA) as the primary Market Surveillance Authority for most AI systems. Legal Notice 227 of 2025 (S.L. 586.14) separately designates the IDPC as MSA for high-risk AI systems under Annex III that involve biometrics, criminal risk assessment, law enforcement, migration, border control, and democratic processes. The IDPC was also identified as a fundamental rights authority effective 3 November 2024, insofar as the protection of personal data is concerned. The designation provisions of both legal notices have been in force since 10 October 2025, and their remaining provisions commenced on 2 August 2026, the AI Act's general application date, but Regulation (EU) 2026/1744, the Digital Omnibus on AI, moved the substantive Annex III high-risk obligations to 2 December 2027 and Annex I high-risk obligations to 2 August 2028.
Why is Malta particularly important for EU data protection compliance in the iGaming sector?
Malta is the EU's primary iGaming licensing jurisdiction through the Malta Gaming Authority (MGA). Because GDPR assigns responsibility to the supervisory authority of the Member State where a company has its main EU establishment, the IDPC serves as Lead Supervisory Authority for the vast majority of EU-wide GDPR complaints against online gaming operators. In 2025 the IDPC handled 535 One Stop Shop cross-border cases and acted as Lead Supervisory Authority in 517 of them, up from 256 OSS cases in 2024, of which 244 involved gaming operators. Common enforcement targets include player subject access request compliance, data retention practices, and transparency obligations.
What is the constitutional basis for data protection in Malta?
Data protection rights in Malta derive from three constitutional and international sources. Article 32(c) of the Constitution of Malta (1964) declares the entitlement to respect for private and family life, article 38 protects the privacy of the home and other property against search and entry, and article 41, the freedom of expression article, includes freedom from interference with correspondence. The European Convention Act (Chapter 319) gives ECHR Article 8 (right to private life) direct effect in Maltese courts. Malta also ratified Council of Europe Convention 108 on automatic processing of personal data in February 2003. These foundations underpin Cap. 586 and Malta's application of the GDPR.
What is S.L. 586.12 and why does it matter?
Subsidiary Legislation 586.12, the Enforcement of the Rights of Data Subjects in Relation to Transfers of Personal Data to a Third Country or an International Organisation Regulations, gives data subjects directly enforceable rights in Maltese courts when their personal data is transferred internationally. Other EU Member States rely on general contract law for third-party beneficiary enforcement of transfer safeguards (such as standard contractual clauses), but this can create enforceability uncertainty. S.L. 586.12 resolves that uncertainty in Malta by creating a specific statutory right of action.
Does Malta require DPOs to register with the IDPC?
Details must be communicated to the IDPC, but that is a GDPR requirement rather than a Maltese addition. Article 37(7) obliges every controller or processor to publish the DPO contact details and communicate them to the supervisory authority. The IDPC asks for the name of the data controller, the name of the DPO, a mailing address, an email address, a contact number, the nature of the business, and the date of appointment, sent to its DPO mailbox. It registers the details for the purposes of Article 37(7) without approving or endorsing the designation, and it encourages voluntary appointments to be notified too. The underlying duty to appoint a DPO comes from GDPR Article 37(1) and covers public authorities, large-scale systematic monitoring operations, and large-scale special category processing.
Updates
Corrected the Commissioner's start date (Dr Reno Borg took the oath of office on 22 April 2026, not in 2025), split the two EU AI Act commencement dates so the page no longer says the national designations began on 2 August 2026 when the IDPC's and the MDIA's designation provisions have been in force since 10 October 2025, restored Article 83(6) to the public-body fine cap in the FAQ, corrected the enforcement-record date range, and updated the currency stamps to September 2026.
Independently fact-checked against the cited primary sources; governing law re-checked for recent changes
Expanded from 2,450 to ~5,200 words. Corrected children's digital consent age from 16 to 13 (per S.L. 586.11). Rewrote AI regulation section to reflect dual MDIA/IDPC authority split under L.N. 226 and L.N. 227 of 2025. Added constitutional basis section, recent 2024-2026 enforcement developments, iGaming hub section with 2024 cross-border complaint statistics, and full subsidiary legislation table. Updated meta description.
Reviewed and approved by an editor
Sources and References
- Data Protection Act (Cap. 586) - Laws of Malta(legislation.mt).gov
- IDPC Legislation Page (subsidiary legislation list)(idpc.org.mt).gov
- IDPC Decisions(idpc.org.mt).gov
- IDPC 2024 Annual Report (published 2025)(idpc.org.mt).gov
- IDPC CEF 2024 Report on Right of Access(idpc.org.mt).gov
- General Data Protection Regulation - Government of Malta(les.gov.mt).gov
- Malta Data Protection Overview - DLA Piper(dlapiperdataprotection.com)
- Artificial Intelligence Regulations, 2025 (L.N. 226 of 2025, Malta Digital Innovation Authority Act, Cap. 591) - Laws of Malta(legislation.mt).gov
- MGA Industry Guidelines on the GDPR - Malta Gaming Authority(mga.org.mt).gov
- Malta IT Law, Data Protection and AI: 2025 Legal Review - INPLP(inplp.com)
- Malta Data Transfers Guidance Note (June 2025) - GTG Legal(gtg.com.mt)
- GDPR Guide to National Implementation: Malta - White and Case LLP(whitecase.com)
- Malta IDPC Fines C-Planet EUR 65,000 for Data Breach - DataGuidance(dataguidance.com)
- Regulation (EU) 2026/1744 of 8 July 2026 (Digital Omnibus on AI), amending Regulation (EU) 2024/1689 - EUR-Lex, OJ L, 2026/1744, 24.7.2026(eur-lex.europa.eu).gov
- S.L. 586.14 - Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations (L.N. 227 of 2025)(legislation.mt).gov
- S.L. 586.13 - Data Protection (Fair Access to and Use of Data) Regulations (L.N. 223 of 2025, in force 10 October 2025)(legislation.mt).gov
- IDPC Publishes 2025 Annual Report (19 August 2026) - Information and Data Protection Commissioner(idpc.org.mt).gov
- Data Protection Officers - IDPC (details to be communicated under GDPR Article 37(7))(idpc.org.mt).gov
- Regulation (EU) 2023/2854 (Data Act), Article 50 - application dates - EUR-Lex(eur-lex.europa.eu).gov
- S.L. 460.41 - Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (L.N. 71 of 2025, in force 23 January 2026, as amended by L.N. 89 of 2026)(legislation.mt).gov
- Constitution of Malta, articles 32, 38 and 41 - Laws of Malta(legislation.mt).gov
- IDPC news: New Information and Data Protection Commissioner takes oath of office (22 April 2026)(idpc.org.mt).gov