Skip to the content
Global Data RulesData governance rules, country by country

Malta

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Malta — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: MediumEnforcement: Active

You can store Maltese data abroad. Malta follows the European rules. Once your paperwork is in order, data can leave. No general rule says data must stay on the island. Two things change that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.

Data governance in Malta

The eight things that decide how you handle data about people in Malta. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Malta's Data Protection Act applies to you even if you have no office in Malta. It catches you if you offer goods or services to people in Malta. It also catches you if you watch their behaviour in Malta. There is no size or revenue threshold. If you are based outside Europe you must appoint a representative in Europe. That comes from the European rules. Malta adds no extra Maltese representative of its own.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, in most cases. No Maltese law says personal data must stay on the island. Malta follows the European Union rules. You can send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Use the European tools. Send data to a country the European Commission has approved. Or sign the European standard contract. Or use approved group-wide rules. Malta adds nothing on top. Malta's minister can restrict transfers of named types of data, but has never used that power. So there are no Maltese restrictions today.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Information and Data Protection Commissioner. It is real, staffed and issuing decisions. Its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards. Most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one. It cancels licences.

How long you must keep it — and when to delete it

Some records you must keep. Company accounting records for ten years. Tax and value-added-tax records for at least six years. Anti-money-laundering records for five years. Everything else you must delete once you no longer need it. That is the European rule. Where the two clash, the Maltese law that orders you to keep something wins. Keeping it is then a legal duty.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

There are three deadlines and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident. Then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents · Register or notify

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, because a law says so directly.

What you have to do here:
Get a parent's consent for children · Assess high-risk projects · Extra vendor secrecy terms
What it costs if you get it wrong:
Criminal liability

What's changing next

Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export free of charge. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 1 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries4 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Online gaming

Online gaming data rules

Official name: Gaming Authorisations and Compliance Directive (Directive 3 of 2018) · Directive 3 of 2018, issued under the Gaming Act (Chapter 583), version 2 of October 2021 · Regulator directive

In forceYes, with paperwork

This is Malta's main rule about where data must sit. A licensed gaming operator's core systems must be hosted in Malta or elsewhere in the European Economic Area. That includes its player and financial databases. Another location needs the regulator's approval, case by case. You must also keep a live mirror of essential regulatory data that the regulator can reach at any time, including in person.

In force since 1 August 2018

Enforced by Malta Gaming Authority

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Government

Government data must stay in the country

Official name: GMICT Cloud Services Policy · GMICT P 0124, version 1.0 · Government policy document

In forceYes, with paperwork

This is a policy, not a law. It covers every Maltese public body and everyone selling to one. Cloud services should normally sit inside the European Union or European Economic Area. Classified information must sit on the Government's own cloud, not a commercial one.

In force since 13 September 2024

Enforced by Malta Information Technology Agency

How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Insurance

Insurance rules

Official name: Protection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act · Chapter 657 of the Laws of Malta, Act X of 2026 · Act of parliament

Passed, not yet fully in forceYes — store it anywhere

From 1 January 2027, insurers, lenders and employers in Malta may not ask about or use a past cancer diagnosis once enough time has passed since treatment ended. It is a ban on using a category of health data, and a Review Board settles disputes.

In force since 1 January 2027

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Applies to every company5 rules

These bind you whatever business you are in, once the country's rules reach you.

Health data rules

Official name: Att dwar il-Protezzjoni tad-Data (Kap. 586) · Chapter 586 of the Laws of Malta, Act XX of 2018, as amended by Act XII of 2021 and Legal Notice 212 of 2023 · Act of parliament

In forceYes — store it anywhere

Malta's national privacy law. It does not say where data must be stored. It adds four things. You need permission before you use health, genetic or biometric data for research. You are limited in how you can use identity documents. Fines on public bodies are capped low. And obstructing the regulator is a crime.

In force since 28 May 2018

Enforced by Information and Data Protection Commissioner

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Personal data needs a copy kept in the country

Official name: Att dwar il-Kumpaniji (Kap. 386), artikolu 163 · Companies Act, Chapter 386 of the Laws of Malta, article 163 · Act of parliament

In forceA copy must stay

This applies to every Maltese company, whatever your industry. Your books can live in a foreign cloud. But a Maltese copy of the accounts and returns must exist and be open to inspection. Update it at least every six months.

In force since 1 January 1996

Enforced by Malta Business Registry

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cyber security rules

Official name: Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order · S.L. 460.41, Legal Notice 71 of 2025 (Government Gazette No. 21,418 of 8 April 2025), as amended by Legal Notice 89 of 2026 · Government rules

In forceYes — store it anywhere

Malta's cybersecurity rules, new since 23 January 2026. They replaced the 2018 order. They bring a 24-hour early warning, a 72-hour report, a one-month final report, and a duty to self-register with the national critical infrastructure department. No data has to stay in Malta.

In force since 23 January 2026

Enforced by Critical Infrastructure Protection Department and CSIRTMalta

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union2 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Regolament (UE) 2016/679 (Regolament Generali dwar il-Protezzjoni tad-Data) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European privacy rulebook applies directly in Malta. It does not require data to stay in Europe. It sets conditions for sending data out: an approved destination, the European standard contract, approved group-wide rules, or a narrow exception.

In force since 25 May 2018

Enforced by Information and Data Protection Commissioner

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life

Government data rules

Official name: Regolament (UE) 2018/1807 dwar qafas għall-moviment liberu ta' data mhux personali fl-Unjoni Ewropea · Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes — store it anywhere

Malta is forbidden from ordering non-personal data to be stored inside the country, except on public security grounds. This is why Malta's few storage rules attach to gaming licences, company books and government procurement rather than to data in general.

In force since 28 May 2019

How this country controls where data goes: No restriction · Accepted routes: Nothing required

On the books, but not enforceable1 rule

These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.

Telecoms

Telecoms rules

Official name: Processing of Personal Data (Electronic Communications Sector) Regulations, Part II — Retention of Data · S.L. 586.01, Part II, added by Legal Notice 198 of 2008; last amended by Legal Notice 429 of 2013 · Directly binding regulation

UnenforceableYes — store it anywhere

Malta still prints a blanket duty on phone and internet companies to keep everyone's call and connection records for six to twelve months. Malta copied a European directive that the European Court of Justice cancelled in 2014. The Maltese text has not been changed since 2013. If you just read the statute book, this looks binding. Keeping everyone's records like this cannot lawfully be enforced.

In force since 15 August 2008

Enforced by Information and Data Protection Commissioner

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Not fully verified — see “What we're not sure about” below.

Who you would hear from

  • Kummissarju għall-Informazzjoni u l-Protezzjoni tad-Data

    Privacy, freedom of information, the EU Data Act, and market surveillance for artificial intelligence

    Fully operational. It publishes every binding decision on its own register. As of 18 August 2026 that register held roughly 19 entries dated 2026 and 38 dated 2025. Fines are typically between EUR 2,000 and EUR 20,000, with a published maximum of EUR 250,000. One caveat on capacity: the most recent annual report published is for 2024, and it was only uploaded in April 2026.

  • Awtorità Maltija dwar il-Logħob

    Remote and land-based gaming, including where licensees may host their systems

    Highly active. Its public enforcement register shows repeated cancellations, revocations and suspensions of authorisations through 2024 and 2025.

  • Cyber incident reporting, essential and important entity supervision under the 2026 cybersecurity order

    The department is the named authority under S.L. 460.41, in force since 23 January 2026. It runs the national self-registration system. We found no public enforcement decisions yet. These rules are in their first year of supervision.

  • Government ICT policy, the Malta Government Cloud, and the GMICT policy framework

  • Banking, insurance, investment services and payments

    Active supervisor. It does not require data to stay in Malta. You must tell it before you outsource important services, under article 19A of the Banking Act. The European financial resilience rules known as DORA cover technology risk.

  • Electronic communications networks and services

  • Company registration, accounting records and annual returns

  • Anti-money-laundering supervision and record-keeping rules

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • That the blanket telecoms data retention rules in Part II of S.L. 586.01 are actually unenforceable in Malta today

    The text is still printed and has not been changed since Legal Notice 429 of 2013. The European Court of Justice cancelled the directive it copies in 2014. That court has repeatedly held that keeping everyone's records is unlawful. We could not find a Maltese court judgment setting the Maltese rule aside. We also could not find a statement from the Maltese government or the Commissioner saying it is not enforced. We treat it as not applying, on the strength of superior European law, at medium confidence.

  • The exact commencement date of the Malta Gaming Authority's Gaming Authorisations and Compliance Directive

    The directive itself is dated 2018 and the current text is marked version 2, October 2021. References inside it point to 1 August 2018 as the start of the current gaming rules. We could not find a separate commencement notice on the regulator's site. The date shown is our best reading.

  • The name and appointment date of the current Information and Data Protection Commissioner

    The office's own pages describe what it does but do not name the current post-holder in anything we could retrieve. We did not want to state a name from memory. Check the regulator's site for the current name.

  • The 'established period' after which a past cancer diagnosis must be ignored under Chapter 657

    The Act defines the term but we did not get the exact number of years. The Act is not yet in force. Treat the mechanism as confirmed and the exact period as open until 1 January 2027.

  • Whether any Malta Financial Services Authority rule, banking rule or insurance rule imposes a location requirement not visible in the primary statutes

    We could not open the Authority's publications index. We checked the Banking Act itself and found no rule that data must stay in Malta. We could not read the Authority's rulebook directly, so we could not confirm it there. Checked 18 August 2026. If you run a bank, ask the Authority before you rely on this.

  • Current staffing, budget and complaint volumes at the Information and Data Protection Commissioner

    The most recent annual report on the office's site is for 2024, and we could not open the file. We rate enforcement as active on the decision register alone.

  • Whether Malta has any health-sector or geospatial storage-location rule outside the instruments we read

    We found no health-specific rule about where data must be stored. We checked the Health Act (Chapter 528), the data protection secondary legislation and the health insurance regulations. Checked 18 August 2026, at medium confidence. If you work in health, check with the regulator before you rely on this.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.