Malta
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
Eight questions about Malta
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Malta's rules apply to my company?
Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.
Article 4(2) of the Data Protection Act (Chapter 586 of the Laws of Malta) applies the Act to (a) processing in the context of an establishment of a controller or processor in Malta, or in a Maltese Embassy or High Commission abroad, regardless of where the processing happens; (b) processing of people who are in Malta by a controller or processor not established in the European Union, where the activity is offering goods or services to them or monitoring their behaviour in Malta; and (c) processing by a controller not established in the Union but in a place where Maltese law applies by public international law. Article 27 GDPR (bloc layer) supplies the representative duty; Malta adds none of its own.
Sources
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586 of the Laws of Malta, article 4(2)
legislation.mt
“This Act shall apply to: (a) the processing of personal data in the context of the activities of an establishment of a controller or a processor in Malta or in a Maltese Embassy or High Commission abroad, regardless of whether the processing takes place in Malta or not; (b) the processing of personal data of data subjects who are in Malta by a controller or processor not established in the European Union...”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation (EU) 2016/679, Articles 3 and 27
eur-lex.europa.eu
Can I store my users' data outside Malta?
In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.
Sector by sector, checked 18 August 2026. ONLINE GAMING — data can leave with the right paperwork, and the tightest wall in the country. Under article 17 of the Malta Gaming Authority's Gaming Authorisations and Compliance Directive (Directive 3 of 2018, version 2 of October 2021), 'the key technical setup shall be located in Malta or in another Member State of the European Union or the European Economic Area'. The Authority may allow other locations case by case where it is satisfied they offer equivalent safeguards, and may allow a decentralised setup where geography is irrelevant. Key technical setup expressly includes the player database, the financial database, the gaming database, the control system, the random number generators and the jackpot components. A live or real-time mirror server for essential regulatory data must be kept readily accessible to the Authority at all times, including physically. COMPANIES OF ANY INDUSTRY — a copy must stay in the country. Article 163(3) of the Companies Act allows accounting records to be kept anywhere, but if they are kept outside Malta, accounts and returns disclosing the financial position at intervals of no more than six months must be sent to, and kept at, a place in Malta. GOVERNMENT — data can leave with the right paperwork. The Government of Malta Cloud Services Policy (GMICT P 0124, version 1.0, effective 13 September 2024) says cloud services used shall as a rule be those provided within the European Union or European Economic Area, and that anything storing, processing, transmitting or sharing classified information must use the Government's own cloud through its agent. BANKING — no localisation found. The Banking Act only requires a credit institution to inform the regulator before outsourcing material services (article 19A). PAYMENTS, INSURANCE, SECURITIES — no localisation found; the European financial resilience regulation known as DORA governs, and it requires disclosure of where data is processed but does not require it to stay anywhere. HEALTH — no localisation found in the Health Act (Chapter 528) or in the health-sector data regulations. Malta's health-specific data rule (S.L. 586.10) concerns insurance, not storage location. TELECOMS — no localisation found. The old blanket call-record retention rules are still printed in the law but are unenforceable (see the rules list). EDUCATION, MAPPING AND GEOSPATIAL, DEFENCE — no storage-location rule found.
Sources
- Official sourceMalta Gaming AuthorityGaming Authorisations and Compliance Directive (Directive 3 of 2018), article 17
mga.org.mt
“The key technical setup shall be located in Malta or in another Member State of the European Union or the European Economic Area: Provided that the Authority may, on a case by case basis, allow the placement of the key technical setup in other geographical locations where it is reasonably satisfied that such other location, taking all the relevant circumstances into account, offers equivalent safeguards to those offered by locations in the European Economic Area”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaCompanies Act, Chapter 386 of the Laws of Malta, article 163(3)
legislation.mt
“Provided that if accounting records are kept at a place outside Malta there shall be sent to, and kept at a place in Malta and at all times be open to the inspection of the officers of the company such accounts and returns with respect to the business dealt with in the accounting records so kept as will disclose with reasonable accuracy the financial position of that business at intervals not exceeding six months”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaBanking Act, Chapter 371 of the Laws of Malta, article 19A (outsourcing — notification only, no localisation)
legislation.mt
Link checked 18 August 2026
What do I need in place before data leaves Malta?
Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.
The model is an allowlist run at European Union level, not a Maltese one. Malta's own instruments: article 10 of the Data Protection Act lets the Minister, after consulting the Commissioner, set limits by regulations on transferring specific categories of personal data to a third country or an international organisation for important reasons of public interest. No such regulations were found in force on the official statute site on 18 August 2026 — this is a dormant switch. Malta's two pre-2018 transfer instruments are gone: the Third Country (Data Protection Act) Regulations (S.L. 586.03) were repealed by Legal Notice 298 of 2019, and the Transfer of Personal Data to Third Countries Order (S.L. 586.05) by Legal Notice 296 of 2019. What remains is S.L. 586.12 (Legal Notice 204 of 2023), which implements the 2021 European standard contractual clauses and gives the Commissioner enforcement powers over transfers. Online gaming has its own, separate permission route: hosting outside the European Economic Area needs the Malta Gaming Authority's case-by-case approval.
Sources
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586, article 10 (limits to transborder data transfers)
legislation.mt
“In the absence of an adequacy decision pursuant to Article 45(3) of the Regulation, the Minister may, following consultation with the Commissioner, by regulations set limits to the transfer of specific categories of personal data to a third country or an international organisation for important reasons of public interest.”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaEnforcement of Rights of Data Subjects in relation to Transfers of Personal Data to a Third Country or an International Organisation Regulations, S.L. 586.12 (Legal Notice 204 of 2023)
legislation.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaThird Country (Data Protection Act) Regulations, S.L. 586.03 — repealed by Legal Notice 298 of 2019
legislation.mt
Link checked 18 August 2026
Who enforces the rules in Malta, and what can they do?
The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.
The Commissioner is appointed by the Prime Minister on the advice of Cabinet after consulting the Leader of the Opposition (Data Protection Act, article 11). Observable evidence of activity: the office publishes every binding decision on its own site, with 2026 entries including an order, a reprimand and two fines against an insurance company for ignoring a marketing objection. The largest fine on the published register is 250,000 euros (about $288,000); a well-known earlier case fined a data analytics company 65,000 euros (about $75,000). The office also decides freedom of information complaints. One caveat on capacity: as of 18 August 2026 the most recent annual report published is for 2024, uploaded in April 2026, so current-year statistics are not available from the office itself. Other regulators that actually bite: the Malta Gaming Authority, whose public enforcement register shows repeated cancellations and suspensions of licences in 2024 and 2025; the Malta Financial Services Authority for banks, insurers and investment firms; the Critical Infrastructure Protection Department and CSIRTMalta for cyber incidents since 23 January 2026; and the Malta Communications Authority for telecoms.
Sources
- Official sourceOffice of the Information and Data Protection CommissionerDecisions issued by the Information and Data Protection Commissioner — public register
idpc.org.mt
Link checked 18 August 2026
- Official sourceMalta Gaming AuthorityMalta Gaming Authority enforcement register — licence cancellations and suspensions
mga.org.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586, articles 11 to 23 (the Commissioner, fines and offences)
legislation.mt
Link checked 18 August 2026
How long do I have to keep the data?
There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.
FLOOR. Companies Act article 163(5): accounting records kept for ten years, and where they are in bound or unified form the ten years run from the last entry; failure is a criminal offence for every officer in default. Value Added Tax Act article 48: records and accounts retained for at least six years from the end of the year. Prevention of Money Laundering and Funding of Terrorism Regulations (S.L. 373.01), regulation 13: five years, extendable. Old telecoms retention of six months for internet records and twelve months for telephone records is still printed in S.L. 586.01 but is unenforceable as a blanket duty (see the rules list). The gaming rulebook adds its own: a licensee must give a dormant-account holder final notice and may not appropriate remaining funds sooner than five years from that notice, and audit logs of changes to the key technical setup must be kept for at least two years. CEILING. The storage limitation principle in the European rules, enforced by the Commissioner. One striking Maltese exception runs the other way: article 55 of the Gaming Act says that notwithstanding any other law, including the Data Protection Act, the Malta Gaming Authority may retain any information, including personal information, for as long as it thinks necessary 'or indefinitely as the case may be'. The Authority's own retention regulations (S.L. 583.12) set a default of ten years after the data stops being necessary.
Sources
- Official sourceGovernment of Malta — Legislation MaltaCompanies Act, Chapter 386, article 163(5) — ten-year accounting record retention
legislation.mt
“Notwithstanding the provisions of article 26 of the Commercial Code, the accounting records of the company shall be kept for a period of ten years”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaValue Added Tax Act, Chapter 406, article 48 — records retained at least six years
legislation.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaPrevention of Money Laundering and Funding of Terrorism Regulations, S.L. 373.01, regulation 13 — five-year record keeping
legislation.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaGaming Act, Chapter 583, article 55 — retention of information notwithstanding the Data Protection Act
legislation.mt
“Notwithstanding any other law, including the Data Protection Act, the Authority may, for the purpose of carrying out its functions under this Act or any other regulatory instrument, retain any information, including personal information, for such period of time as it may in its discretion deem necessary, or indefinitely as the case may be.”
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.
CLOCK 1 — personal data. The European rule: notify the Information and Data Protection Commissioner within 72 hours of becoming aware, and tell affected people without undue delay where the risk to them is high. CLOCK 2 — cyber incidents. Malta's version of the European network security rules, in force since 23 January 2026, requires an essential or important entity to give the national computer security team an early warning without undue delay and in any event within 24 hours of becoming aware of a significant incident, a fuller notification within 72 hours, and a final report within one month. The same entities must sign themselves up on a national self-registration mechanism run by the Critical Infrastructure Protection Department. CLOCK 3 — telecoms. A provider of publicly available electronic communications services must notify the Commissioner of a personal data breach without undue delay, and the subscriber too where the breach is likely to affect them adversely. The directly applicable European rule for this sector sets that at 24 hours. Financial firms have a fourth clock under the European financial resilience regulation known as DORA, and gaming licensees must report certain incidents to the Malta Gaming Authority. Nothing in Maltese law harmonises these.
Sources
- Official sourceGovernment of Malta — Legislation MaltaMeasures for a High Common Level of Cybersecurity across the European Union (Malta) Order, S.L. 460.41 (Legal Notice 71 of 2025, as amended by Legal Notice 89 of 2026) — 24 hour, 72 hour and one month reporting
legislation.mt
“an early warning, which, shall be submitted without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Personal Data (Electronic Communications Sector) Regulations, S.L. 586.01, regulation 3A — telecoms breach notification
legislation.mt
“In the case of a personal data breach, the provider of publicly available electronic communications services shall, without undue delay, notify the personal data breach to the Commissioner.”
Link checked 18 August 2026
- Official sourceOffice of the Information and Data Protection CommissionerReport a personal data breach — Information and Data Protection Commissioner
idpc.org.mt
What trips people up in Malta?
Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.
1. AGE THIRTEEN. Malta used the lowest option Europe allows. A child can consent to an online service at thirteen (S.L. 586.11, Legal Notice 179 of 2018). A product built to a sixteen-or-parental-consent rule is over-restrictive in Malta; a product built to a global thirteen rule is under-restrictive in most other European countries. Neither default is right across Europe. 2. PRIOR PERMISSION, NOT JUST A RISK ASSESSMENT. Article 7 of the Data Protection Act says a controller must consult and obtain prior authorisation from the Commissioner before processing, in the public interest, genetic data, biometric data or health data for statistical or research purposes, or special categories of data for managing social care services. For research the Commissioner must also consult a research ethics committee. This is a permission you wait for, and it has no European equivalent. 3. IDENTITY DOCUMENTS. Article 8 says an identity document may only be processed where clearly justified by the purpose and the importance of secure identification, and the national identity number may only be used with appropriate safeguards. Routine 'send us a photo of your ID card' onboarding is not automatically lawful in Malta. 4. CRIMINAL LIABILITY, TWO WAYS. First, the Professional Secrecy Act extends the Criminal Code's secrecy offence to a long list of people including employees and officers of banks and financial institutions, insurers, accountants, auditors, lawyers, notaries, doctors, psychologists, social workers and state employees — so a badly controlled cloud migration that exposes client information is a criminal matter, prosecutable only with the Attorney General's sanction. Second, article 22 of the Data Protection Act makes it an offence to give the Commissioner false information or to fail to comply with an investigation: a fine of 1,250 to 50,000 euros (about $1,400 to $58,000) or six months in prison, or both. 5. PUBLIC BODIES ARE CHEAP TO FINE. Article 21 caps administrative fines on a public authority at 25,000 euros (about $29,000) per violation for the lower tier and 50,000 euros (about $58,000) for the higher tier, plus a daily payment of 25 or 50 euros. If your counterparty is a Maltese public authority, the deterrent on them is small. 6. THE GAMING RETENTION OVERRIDE. Article 55 of the Gaming Act lets the Malta Gaming Authority keep personal information indefinitely, expressly overriding the Data Protection Act. Whether that survives a challenge under the European rules has not been tested.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Child's Personal Data in relation to the Offer of Information Society Services Regulations, S.L. 586.11 (Legal Notice 179 of 2018)
legislation.mt
“The processing of personal data of a child in relation to information society services shall be lawful where the child is thirteen years of age.”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586, articles 7, 8, 21 and 22
legislation.mt
“A controller shall consult with, and obtain prior authorisation from, the Commissioner where the controller intends to process in the public interest: (a) genetic data, biometric data or data concerning health for statistical or research purposes”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaProfessional Secrecy Act, Chapter 377, articles 3 and 14
legislation.mt
Link checked 18 August 2026
What is changing soon in Malta?
Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.
DATED CHANGES. 1 January 2027 — the Protection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act (Chapter 657, Act X of 2026) comes into force. It bars a party offering a life insurance contract, bank loan, employment contract or ancillary agreement from requiring or using a person's oncological medical history once an established period has passed since the end of treatment, and sets up a Review Board. This is a hard prohibition on using a category of health data, not a paperwork exercise. 12 January 2027 — the European Data Act's zero cloud-switching and egress charges bite. Malta gave the Information and Data Protection Commissioner the national enforcement role for the Data Act in S.L. 586.13 (Legal Notice 223 of 2025, in force 10 October 2025), with fines under the European privacy penalty scale. 2 August 2026 — most of Malta's artificial intelligence regulations (S.L. 586.14, Legal Notice 227 of 2025) commenced, designating the Commissioner as market surveillance authority. On 27 July 2026 the Commissioner publicly flagged that European timelines had moved: high-risk standalone systems pushed to 2 December 2027 and regulatory sandboxes to 2 August 2027, while transparency labelling stayed at 2 August 2026. Through 2026 — the network security order (in force 23 January 2026) and the critical entities resilience order (also 23 January 2026) are both in their first supervisory year; the self-registration duty is new and enforcement has not yet been observed. DORMANT SWITCHES — powers already held, usable with no consultation. 1. Article 10 of the Data Protection Act: the Minister may by regulations set limits on transferring specific categories of personal data to a third country for important reasons of public interest. Never used. This is the only route by which Malta could impose its own data-export restriction, and it needs no parliamentary debate. 2. Article 5 and S.L. 586.09: the Minister may restrict individuals' rights for national security, tax, social security and other listed grounds. 3. Malta Gaming Authority approval of non-European hosting is discretionary and case by case; it can be refused or withdrawn. 4. The unrepealed blanket telecoms retention rules could be revived by re-enactment in a targeted form at any time.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProtection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act, Chapter 657 (Act X of 2026)
legislation.mt
“This Act shall come into force on 1st January 2027.”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaData Protection (Fair Access to and Use of Data) Regulations, S.L. 586.13 (Legal Notice 223 of 2025) — national implementation of the EU Data Act
legislation.mt
Link checked 18 August 2026
- Official sourceOffice of the Information and Data Protection CommissionerIDPC draws attention to revised EU AI Act timelines following Council approval, 27 July 2026
idpc.org.mt
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
2 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
5 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
5 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules2 rules
Regolament (UE) 2016/679 (Regolament Generali dwar il-Protezzjoni tad-Data)
Directly binding regulation · Regulation (EU) 2016/679
The European privacy rulebook applies directly in Malta. It does not require data to stay in Europe. It sets conditions for sending data out: an approved destination, the European standard contract, approved group-wide rules, or a narrow exception.
Enforced by Information and Data Protection Commissioner
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk
What it makes you do
- Tell people what you do
- Secure the data
- Keep records of processing
- Assess high-risk projects
- Appoint a data protection officerWhere Article 37 applies. Malta may add cases by regulations under article 33(f) of the Data Protection Act; none found in force.
- Appoint a local representativeFor controllers and processors not established in the European Union.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Put a transfer safeguard in place
- Written vendor contract
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover — about $23 millionBasic principles, individual rights, unlawful transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover — about $12 millionController and processor duties, security, records, breach notification
- Order to stopOrder to stop processing or suspend transfers outside Europe
- Claims by individualsCompensation claims by individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Regolament (UE) 2018/1807 dwar qafas għall-moviment liberu ta' data mhux personali fl-Unjoni Ewropea
Directly binding regulation · Regulation (EU) 2018/1807
Malta is forbidden from ordering non-personal data to be stored inside the country, except on public security grounds. This is why Malta's few storage rules attach to gaming licences, company books and government procurement rather than to data in general.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Make switching cloud provider possible
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
eur-lex.europa.eu
National rules5 rules
Att dwar il-Protezzjoni tad-Data (Kap. 586)
Act of parliament · Chapter 586 of the Laws of Malta, Act XX of 2018, as amended by Act XII of 2021 and Legal Notice 212 of 2023
Malta's national privacy statute. It adds no storage-location rule. It does add a prior-authorisation gate for health, genetic and biometric research, a restriction on processing identity documents, a low fine ceiling for public bodies, and a criminal offence for obstructing the regulator.
Enforced by Information and Data Protection Commissioner
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Assess high-risk projectsArticle 7 goes further than a risk assessment: written prior authorisation from the Commissioner is needed to process genetic, biometric or health data for statistics or research in the public interest, and for special categories in social care management.
- Allowed because the law requires itArticle 8 restricts processing of identity documents and the national identity number.
- Put a transfer safeguard in place
What it costs if you get it wrong
- Fixed maximum fine: €25,000 per violation plus €25 per day — about $29 thousandPublic authority or body — lower tier infringement
- Fixed maximum fine: €50,000 per violation plus €50 per day — about $58 thousandPublic authority or body — higher tier infringement
- Criminal liability: €1,250 to €50,000 fine and/or 6 months imprisonment — about $58 thousandKnowingly giving the Commissioner false information, or failing to comply with an investigation
Sources
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586 of the Laws of Malta
legislation.mt
“Provided that such a fine shall not exceed twenty-five thousand euro (€25,000) for each violation and, additionally, the Commissioner may impose a daily fine payment of twenty-five euro (€25) for each day during which such violation persists”
Link checked 18 August 2026
- Official sourceOffice of the Information and Data Protection CommissionerLegislation — Office of the Information and Data Protection Commissioner
idpc.org.mt
Link checked 18 August 2026
Att dwar il-Kumpaniji (Kap. 386), artikolu 163
Act of parliament · Companies Act, Chapter 386 of the Laws of Malta, article 163
A quiet mirror rule that applies to every Maltese company regardless of industry. Books may live in a foreign cloud, but a Maltese copy of the accounts and returns must exist and be open to inspection, refreshed at least every six months.
Enforced by Malta Business Registry
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryRecords themselves may sit abroad, but accounts and returns disclosing the financial position at intervals of no more than six months must be sent to and kept at a place in Malta.
- Keep data for a minimum period — 10 yearsTen years; where records are in a bound or unified form the ten years run from the last entry.
What it costs if you get it wrong
- Criminal liability: €11,646 — about $13 thousandEvery officer in default, unless they show they acted diligently and the default was excusable
Sources
- Official sourceGovernment of Malta — Legislation MaltaCompanies Act, Chapter 386 of the Laws of Malta, article 163
legislation.mt
“Provided that if accounting records are kept at a place outside Malta there shall be sent to, and kept at a place in Malta ... such accounts and returns ... as will disclose with reasonable accuracy the financial position of that business at intervals not exceeding six months”
Link checked 18 August 2026
Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order
Government rules · S.L. 460.41, Legal Notice 71 of 2025 (Government Gazette No. 21,418 of 8 April 2025), as amended by Legal Notice 89 of 2026
Malta's cybersecurity regime, new since 23 January 2026. It replaced the 2018 order and brings a 24-hour early warning, a 72-hour report, a one-month final report, and a duty to self-register with the national critical infrastructure department. No data has to stay in Malta.
Enforced by Critical Infrastructure Protection Department and CSIRTMalta
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursEarly warning. Then a fuller notification within 72 hours and a final report within one month.
- Register or notifyEssential and important entities providing services in Malta, and domain name registration service providers, must sign up on the national self-registration mechanism run by the Critical Infrastructure Protection Department.
- Secure the data
- Independent audit
What it costs if you get it wrong
- Percentage of global turnover: €10,000,000 or 2% of worldwide turnover — about $12 millionEssential entities
- Percentage of global turnover: €7,000,000 or 1.4% of worldwide turnover — about $8 millionImportant entities
- Daily fine until fixed: €100 per day — about $115Continuing default
Sources
- Official sourceGovernment of Malta — Legislation MaltaMeasures for a High Common Level of Cybersecurity across the European Union (Malta) Order, S.L. 460.41
legislation.mt
“Essential and important entities providing services in Malta as well as entities providing domain name registration services in Malta shall register on the national self-registration mechanism established by the CIP Department”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaResilience of Critical Entities and Infrastructures (Identification, Designation and Protection) Order, S.L. 460.43 (Legal Notice 5 of 2026), in force 23 January 2026
legislation.mt
Link checked 18 August 2026
Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations
Directly binding regulation · S.L. 586.14, Legal Notice 227 of 2025 · Artificial intelligence
Malta named its privacy regulator as the authority that polices artificial intelligence products on the market. Most of the regulations commenced on 2 August 2026; the rest were already in force from 10 October 2025.
Enforced by Information and Data Protection Commissioner
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Check your algorithms — from 2 August 2026
- Keep records of processing — from 2 August 2026Technical documentation must be kept at the disposal of the Commissioner as market surveillance authority.
What it costs if you get it wrong
- Fixed maximum fine: €50,000 per violation plus €50 per day — about $58 thousandPublic authority or body
Sources
- Official sourceGovernment of Malta — Legislation MaltaArtificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, S.L. 586.14
legislation.mt
“Regulations 5 to 7 and 9 to 12 shall come into force on the 2nd August 2026.”
Link checked 18 August 2026
Processing of Child's Personal Data in relation to the Offer of Information Society Services Regulations
Directly binding regulation · S.L. 586.11, Legal Notice 179 of 2018
In Malta a child can consent to an online service at thirteen. That is the lowest age the European rules allow and it differs from most other member states, so a single European-wide age gate will be wrong somewhere.
Enforced by Information and Data Protection Commissioner
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Get a parent's consent for children — applies at: under 13Malta chose the lowest age Europe permits. Below thirteen, a parent must consent.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Child's Personal Data in relation to the Offer of Information Society Services Regulations, S.L. 586.11
legislation.mt
“The processing of personal data of a child in relation to information society services shall be lawful where the child is thirteen years of age.”
Link checked 18 August 2026
Industry rules5 rules
Gaming Authorisations and Compliance Directive (Directive 3 of 2018)
Regulator directive · Directive 3 of 2018, issued under the Gaming Act (Chapter 583), version 2 of October 2021 · Online gaming
Malta's real data-location wall. A licensed gaming operator's core systems, including its player and financial databases, must be hosted in Malta or elsewhere in the European Economic Area unless the regulator approves another location case by case. A live mirror of essential regulatory data must be kept permanently reachable by the regulator, including physically.
Enforced by Malta Gaming Authority
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryThe key technical setup — player database, financial database, gaming database, control system, random number generators and jackpot components — must sit in Malta or another European Economic Area state. Anywhere else needs the Authority's case-by-case approval on equivalent-safeguards grounds.
- Keep logs — 2 yearsAudit logs of changes to the key technical setup.
- Independent auditRisk assessment of essential components, filed with the Authority and kept current.
- Written vendor contractHosting providers must be instructed to permit and assist the Authority in any checks it wishes to conduct.
What it costs if you get it wrong
- Loss of your licenceBreach of authorisation conditions; the Authority's public register shows repeated cancellations and suspensions in 2024 and 2025
- Order to stopSuspension of authorisation pending investigation
Sources
- Official sourceMalta Gaming AuthorityGaming Authorisations and Compliance Directive (Directive 3 of 2018), articles 16 to 18
mga.org.mt
“The licensee shall maintain a live or real-time mirror server for essential regulatory data, and which shall be, at all times, made readily accessible to the Authority, including by means of physical access where applicable.”
Link checked 18 August 2026
- Official sourceMalta Gaming AuthorityRegulatory Framework — Malta Gaming Authority (directive list, page updated 15 July 2026)
mga.org.mt
Link checked 18 August 2026
Processing of Personal Data (Electronic Communications Sector) Regulations, Part II — Retention of Data
Directly binding regulation · S.L. 586.01, Part II, added by Legal Notice 198 of 2008; last amended by Legal Notice 429 of 2013 · Telecoms
Malta still prints a blanket duty on phone and internet companies to keep everyone's call and connection records for six to twelve months. It transposed a European directive that the European Court of Justice annulled in 2014, and it has not been amended since 2013. A naive reading of the statute book reports this as binding. General, indiscriminate retention of this kind cannot lawfully be enforced.
Enforced by Information and Data Protection Commissioner
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 6 monthsInternet access and internet e-mail records. Printed in the law, but unenforceable as a blanket duty.
- Keep data for a minimum period — 1 yearFixed, mobile and internet telephony records. Printed in the law, but unenforceable as a blanket duty.
- Keep logsPolice conservation orders can extend retention by six months, up to a total of two years without a court order.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Personal Data (Electronic Communications Sector) Regulations, S.L. 586.01, regulations 17 to 24
legislation.mt
“The categories of data specified in regulation 20 shall be retained by the service providers for the following periods: (a) communications data relating to Internet Access and Internet e-mail for a period of six months from the date of communication; (b) communications data concerning fixed network telephony, mobile telephony and Internet telephony for a period of one year from the date of communication.”
Link checked 18 August 2026
- Official sourceCourt of Justice of the European UnionDigital Rights Ireland, Joined Cases C-293/12 and C-594/12 — the Data Retention Directive declared invalid, 8 April 2014
curia.europa.eu
GMICT Cloud Services Policy
Government policy document · GMICT P 0124, version 1.0 · Government
Not a statute, but it governs every Maltese public body and everyone selling to one. Cloud services should as a rule be inside the European Union or European Economic Area, and classified information must sit on the Government's own cloud rather than a commercial one.
Enforced by Malta Information Technology Agency
Transfer model: Allowlist · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryAs a rule, cloud services used by the public administration must be provided within the European Union or European Economic Area.
- Prove the data stays under local controlAnything storing, processing, transmitting or sharing classified information must use the Government's own cloud through its agent.
Sources
- Official sourceMalta Information Technology AgencyGovernment of Malta Cloud Services Policy, GMICT P 0124 version 1.0, effective 13 September 2024
mita.gov.mt
“As a rule, Cloud services utilised shall be those provided within the EU/EEA to minimise regulatory derivative risks.”
Link checked 18 August 2026
- Official sourceMalta Information Technology AgencyGMICT policies — Malta Information Technology Agency
mita.gov.mt
Link checked 18 August 2026
Protection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act
Act of parliament · Chapter 657 of the Laws of Malta, Act X of 2026 · Insurance
From 1 January 2027, insurers, lenders and employers in Malta may not ask about or use a past cancer diagnosis once enough time has passed since treatment ended. It is a ban on using a category of health data, and a Review Board settles disputes.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Delete data after a period — from 1 January 2027A party offering life insurance, a bank loan, an ancillary agreement or a contract of employment may not require or use a person's oncological medical history once the established period since the end of treatment has passed.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProtection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act, Chapter 657
legislation.mt
“This Act shall come into force on 1st January 2027.”
Link checked 18 August 2026
Att dwar is-Segretezza Professjonali (Kap. 377)
Act of parliament · Professional Secrecy Act, Chapter 377 of the Laws of Malta, read with article 257 of the Criminal Code (Chapter 9) · Professional secrecy trades
Malta turns confidentiality into a criminal matter for a wide list of people — bank and financial institution staff, insurers, accountants, auditors, lawyers, notaries, doctors, psychologists, social workers and state employees. Moving their files to a new supplier or a foreign cloud is a criminal-risk question, not only a privacy one.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Extra vendor secrecy termsAny statutory reference to a duty of secrecy or confidentiality is read as imposing a duty at least as strong as professional secrecy. A standard data processing agreement does not discharge it.
What it costs if you get it wrong
- Criminal liabilityDisclosure of a secret by a person bound by professional secrecy; prosecution requires the Attorney General's sanction
Sources
- Official sourceGovernment of Malta — Legislation MaltaProfessional Secrecy Act, Chapter 377 of the Laws of Malta, articles 3, 13 and 14
legislation.mt
“Any reference in an enactment, whether passed before or after the date of entry into force of this Act, to an obligation to observe secrecy or confidentiality, shall be interpreted as imposing a duty at least as strong as the duty of professional secrecy”
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
That the blanket telecoms data retention rules in Part II of S.L. 586.01 are actually unenforceable in Malta today
The text is still printed and unamended since Legal Notice 429 of 2013, and the European Court of Justice annulled the directive it transposes in 2014 and has repeatedly held general, indiscriminate retention unlawful. But we could not find a Maltese court judgment disapplying it, nor a statement from the Maltese government or the Commissioner confirming it is not enforced. The status is coded 'disapplied' on the strength of superior European law, at medium confidence.
The exact commencement date of the Malta Gaming Authority's Gaming Authorisations and Compliance Directive
The directive itself is dated 2018 and the current text is marked version 2, October 2021. Internal references point to 1 August 2018 as the start of the current gaming framework, but we did not locate a separate commencement notice on the regulator's site. The date shown is our best reading.
The name and appointment date of the current Information and Data Protection Commissioner
The office's own pages describe its functions but do not name the current holder in the material we could retrieve. We did not want to assert a name from memory.
The 'established period' after which a past cancer diagnosis must be ignored under Chapter 657
The Act defines the term but we did not extract the specific number of years, and the Act is not yet in force. Treat the mechanism as confirmed and the exact period as open until 1 January 2027.
Whether any Malta Financial Services Authority rule, banking rule or insurance rule imposes a location requirement not visible in the primary statutes
The Authority's own publications index returned errors to our fetches. We verified the absence of localisation in the Banking Act itself, but the rulebook was not directly readable, so this is an absence of evidence rather than evidence of absence, checked 18 August 2026.
Current staffing, budget and complaint volumes at the Information and Data Protection Commissioner
The most recent annual report on the office's site is for 2024, and the PDF is served through a viewer we could not open directly. Enforcement is rated 'active' on the decision register alone.
Whether Malta has any health-sector or geospatial storage-location rule outside the instruments we read
We checked the Health Act (Chapter 528), the data protection subsidiary legislation series and the health-for-insurance regulations and found none. No rule found, checked 18 August 2026, confidence medium.
60-day cadence. Two reasons. First, the cybersecurity and critical entities orders only started on 23 January 2026 and are in their first supervisory year, so the enforcement picture can change fast. Second, three switches can flip with no consultation: the ministerial power at article 10 of the Data Protection Act to restrict transfers of named data categories, the Malta Gaming Authority's discretionary approval of hosting outside the European Economic Area, and the unrepealed telecoms retention rules.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Malta versus Argentina
- Malta versus Armenia
- Malta versus Australia
- Malta versus Austria
- Malta versus Azerbaijan
- Malta versus Brazil
- Malta versus Bulgaria
- Malta versus Cambodia
- Malta versus Canada
- Malta versus China
- Malta versus Croatia
- Malta versus Cyprus
- Malta versus Estonia
- Malta versus France
- Malta versus Georgia
- Malta versus Germany
- Malta versus Greece
- Malta versus Hong Kong SAR
- Malta versus Hungary
- Malta versus Iceland
- Malta versus India
- Malta versus Indonesia
- Malta versus Ireland
- Malta versus Israel
- Malta versus Italy
- Malta versus Japan
- Malta versus Latvia
- Malta versus Lithuania
- Malta versus Luxembourg
- Malta versus Mexico
- Malta versus Mongolia
- Malta versus Nepal
- Malta versus Netherlands
- Malta versus Poland
- Malta versus Russia
- Malta versus Saudi Arabia
- Malta versus Serbia
- Malta versus Singapore
- Malta versus Slovakia
- Malta versus Slovenia
- Malta versus South Korea
- Malta versus Spain
- Malta versus Sri Lanka
- Malta versus Sweden
- Malta versus Switzerland
- Malta versus Taiwan
- Malta versus Thailand
- Malta versus Turkey
- Malta versus Ukraine
- Malta versus United Arab Emirates
- Malta versus United Kingdom
- Malta versus United States
- Malta versus Uzbekistan