Malta
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Malta — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can store Maltese data abroad. Malta follows the European rules. Once your paperwork is in order, data can leave. No general rule says data must stay on the island. Two things change that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.
Data governance in Malta
The eight things that decide how you handle data about people in Malta. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Malta's Data Protection Act applies to you even if you have no office in Malta. It catches you if you offer goods or services to people in Malta. It also catches you if you watch their behaviour in Malta. There is no size or revenue threshold. If you are based outside Europe you must appoint a representative in Europe. That comes from the European rules. Malta adds no extra Maltese representative of its own.
- What you have to do here:
- Appoint a representative
Article 4(2) of the Data Protection Act (Chapter 586 of the Laws of Malta) covers three cases. First, you use or store personal data through a business you have in Malta, or through a Maltese Embassy or High Commission abroad. That applies wherever the data is actually handled. Second, you are based outside the European Union and you handle data about people who are in Malta, because you offer them goods or services or watch their behaviour in Malta. Third, you are based outside the European Union, in a place where Maltese law applies under international law. The duty to appoint a representative comes from Article 27 of the European privacy rules. Malta adds none of its own.
Sources
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586 of the Laws of Malta, article 4(2)
legislation.mt
“This Act shall apply to: (a) the processing of personal data in the context of the activities of an establishment of a controller or a processor in Malta or in a Maltese Embassy or High Commission abroad, regardless of whether the processing takes place in Malta or not; (b) the processing of personal data of data subjects who are in Malta by a controller or processor not established in the European Union...”
Link checked 18 August 2026
- Official sourcePublications Office of the European UnionGeneral Data Protection Regulation (EU) 2016/679, Articles 3 and 27
eur-lex.europa.eu
Where the data is allowed to live
Yes, in most cases. No Maltese law says personal data must stay on the island. Malta follows the European Union rules. You can send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.
Sector by sector, checked 18 August 2026. ONLINE GAMING - data can leave only if conditions are met This is the tightest storage rule in the country. Article 17 of the Malta Gaming Authority's Gaming Authorisations and Compliance Directive (Directive 3 of 2018, version 2 of October 2021) says the key technical setup must be located in Malta, or in another Member State of the European Union or the European Economic Area. The Authority can allow other locations case by case if it is satisfied the protection is just as good. It can also allow a spread-out setup where geography does not matter. The key technical setup includes the player database, the financial database, the gaming database, the control system, the random number generators and the jackpot parts. You must also keep a live mirror server for essential regulatory data. The Authority must be able to reach it at all times, including in person. COMPANIES OF ANY INDUSTRY - a copy must stay in the country Article 163(3) of the Companies Act lets you keep accounting records anywhere. If you keep them outside Malta, you must send accounts and returns to a place in Malta and keep them there. They must show the financial position at least every six months. GOVERNMENT - data can leave only if conditions are met The Government of Malta Cloud Services Policy (GMICT P 0124, version 1.0, effective 13 September 2024) says cloud services should normally be provided within the European Union or European Economic Area. Anything that stores, uses, sends or shares classified information must use the Government's own cloud through its agent. BANKING - we found no rule that data must stay in Malta. The Banking Act only says a credit institution must tell the regulator before it outsources important services (article 19A). PAYMENTS, INSURANCE, SECURITIES - we found no rule that data must stay in Malta. The European financial resilience rules known as DORA apply. They make you say where data is handled. They do not make it stay anywhere. HEALTH - we found no rule that data must stay in Malta, either in the Health Act (Chapter 528) or in the health data rules. Malta's health-specific data rule (S.L. 586.10) is about insurance, not about where data sits. TELECOMS - we found no rule that data must stay in Malta. The old blanket rules on keeping call records are still printed in the law but cannot be enforced (see the rules list). EDUCATION, MAPPING AND GEOSPATIAL, DEFENCE - we found no rule about where data must be stored.
Sources
- Official sourceMalta Gaming AuthorityGaming Authorisations and Compliance Directive (Directive 3 of 2018), article 17
mga.org.mt
“The key technical setup shall be located in Malta or in another Member State of the European Union or the European Economic Area: Provided that the Authority may, on a case by case basis, allow the placement of the key technical setup in other geographical locations where it is reasonably satisfied that such other location, taking all the relevant circumstances into account, offers equivalent safeguards to those offered by locations in the European Economic Area”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaCompanies Act, Chapter 386 of the Laws of Malta, article 163(3)
legislation.mt
“Provided that if accounting records are kept at a place outside Malta there shall be sent to, and kept at a place in Malta and at all times be open to the inspection of the officers of the company such accounts and returns with respect to the business dealt with in the accounting records so kept as will disclose with reasonable accuracy the financial position of that business at intervals not exceeding six months”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaBanking Act, Chapter 371 of the Laws of Malta, article 19A (outsourcing — notification only, no localisation)
legislation.mt
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Use the European tools. Send data to a country the European Commission has approved. Or sign the European standard contract. Or use approved group-wide rules. Malta adds nothing on top. Malta's minister can restrict transfers of named types of data, but has never used that power. So there are no Maltese restrictions today.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed
You can only send data to approved countries, and that approved list is run at European Union level, not by Malta. Malta's own rules work like this. Article 10 of the Data Protection Act lets the Minister, after consulting the Commissioner, make regulations limiting transfers of specific types of personal data outside Europe or to an international organisation, for important reasons of public interest. We found no such regulations in force on the official statute site on 18 August 2026. The power sits unused. Malta's two older transfer rules are gone. The Third Country (Data Protection Act) Regulations (S.L. 586.03) were repealed by Legal Notice 298 of 2019. The Transfer of Personal Data to Third Countries Order (S.L. 586.05) was repealed by Legal Notice 296 of 2019. What remains is S.L. 586.12 (Legal Notice 204 of 2023). It puts the 2021 European standard contract clauses into Maltese law. It also gives the Commissioner power to enforce the rules on transfers. Online gaming has its own separate route. Hosting outside the European Economic Area needs the Malta Gaming Authority's approval, case by case.
Sources
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586, article 10 (limits to transborder data transfers)
legislation.mt
“In the absence of an adequacy decision pursuant to Article 45(3) of the Regulation, the Minister may, following consultation with the Commissioner, by regulations set limits to the transfer of specific categories of personal data to a third country or an international organisation for important reasons of public interest.”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaEnforcement of Rights of Data Subjects in relation to Transfers of Personal Data to a Third Country or an International Organisation Regulations, S.L. 586.12 (Legal Notice 204 of 2023)
legislation.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaThird Country (Data Protection Act) Regulations, S.L. 586.03 — repealed by Legal Notice 298 of 2019
legislation.mt
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Information and Data Protection Commissioner. It is real, staffed and issuing decisions. Its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards. Most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one. It cancels licences.
The Prime Minister appoints the Commissioner on the advice of Cabinet, after consulting the Leader of the Opposition (Data Protection Act, article 11). The office publishes every binding decision on its own site. The 2026 entries include an order, a reprimand and two fines against an insurance company for ignoring a marketing objection. The largest fine on the published register is 250,000 euros (about $288,000). A well-known earlier case fined a data analytics company 65,000 euros (about $75,000). The office also decides freedom of information complaints. One caveat on capacity. As of 18 August 2026 the most recent annual report published is for 2024, uploaded in April 2026. So the office does not publish current-year statistics. Other regulators that act here: the Malta Gaming Authority, whose public enforcement register shows repeated cancellations and suspensions of licences in 2024 and 2025; the Malta Financial Services Authority for banks, insurers and investment firms; the Critical Infrastructure Protection Department and CSIRTMalta for cyber incidents since 23 January 2026; and the Malta Communications Authority for telecoms.
Sources
- Official sourceOffice of the Information and Data Protection CommissionerDecisions issued by the Information and Data Protection Commissioner — public register
idpc.org.mt
Link checked 18 August 2026
- Official sourceMalta Gaming AuthorityMalta Gaming Authority enforcement register — licence cancellations and suspensions
mga.org.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586, articles 11 to 23 (the Commissioner, fines and offences)
legislation.mt
Link checked 18 August 2026
How long you must keep it — and when to delete it
Some records you must keep. Company accounting records for ten years. Tax and value-added-tax records for at least six years. Anti-money-laundering records for five years. Everything else you must delete once you no longer need it. That is the European rule. Where the two clash, the Maltese law that orders you to keep something wins. Keeping it is then a legal duty.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
WHAT YOU MUST KEEP. Companies Act article 163(5): keep accounting records for ten years. Where they are in bound or unified form, the ten years run from the last entry. Failure is a crime for every officer in default. Value Added Tax Act article 48: keep records and accounts for at least six years from the end of the year. Prevention of Money Laundering and Funding of Terrorism Regulations (S.L. 373.01), regulation 13: five years, and this can be extended. Old telecoms rules requiring six months of internet records and twelve months of telephone records are still printed in S.L. 586.01. They cannot be enforced as a blanket duty (see the rules list). The gaming rulebook adds its own. A licensee must give the holder of a dormant account a final notice. It may not take the remaining money any sooner than five years from that notice. Audit logs of changes to the key technical setup must be kept for at least two years. WHAT YOU MUST DELETE. The European rules say you keep personal data only as long as you need it. The Commissioner enforces that. One Maltese rule runs the other way. Article 55 of the Gaming Act says that despite any other law, including the Data Protection Act, the Malta Gaming Authority may keep any information, including personal information, for as long as it thinks necessary 'or indefinitely as the case may be'. The Authority's own retention rules (S.L. 583.12) set a default of ten years after the data stops being needed.
Sources
- Official sourceGovernment of Malta — Legislation MaltaCompanies Act, Chapter 386, article 163(5) — ten-year accounting record retention
legislation.mt
“Notwithstanding the provisions of article 26 of the Commercial Code, the accounting records of the company shall be kept for a period of ten years”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaValue Added Tax Act, Chapter 406, article 48 — records retained at least six years
legislation.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaPrevention of Money Laundering and Funding of Terrorism Regulations, S.L. 373.01, regulation 13 — five-year record keeping
legislation.mt
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaGaming Act, Chapter 583, article 55 — retention of information notwithstanding the Data Protection Act
legislation.mt
“Notwithstanding any other law, including the Data Protection Act, the Authority may, for the purpose of carrying out its functions under this Act or any other regulatory instrument, retain any information, including personal information, for such period of time as it may in its discretion deem necessary, or indefinitely as the case may be.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
There are three deadlines and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident. Then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents · Register or notify
CLOCK 1 - personal data. The European rule: tell the Information and Data Protection Commissioner within 72 hours of finding out. Tell the affected people without undue delay where the risk to them is high. CLOCK 2 - cyber incidents. Malta's version of the European network security rules has been in force since 23 January 2026. If you are an essential or important organisation, you must give the national computer security team an early warning without undue delay. That must happen within 24 hours of finding out about a significant incident. A fuller report follows within 72 hours. A final report follows within one month. The same organisations must sign themselves up on a national self-registration system run by the Critical Infrastructure Protection Department. CLOCK 3 - telecoms. If you provide public electronic communications services, you must tell the Commissioner about a personal data breach without undue delay. You must also tell the subscriber where the breach is likely to harm them. The European rule that applies directly to this sector sets that at 24 hours. Financial firms have a fourth deadline under the European financial resilience rules known as DORA. Gaming licensees must report certain incidents to the Malta Gaming Authority. Nothing in Maltese law lines these up.
Sources
- Official sourceGovernment of Malta — Legislation MaltaMeasures for a High Common Level of Cybersecurity across the European Union (Malta) Order, S.L. 460.41 (Legal Notice 71 of 2025, as amended by Legal Notice 89 of 2026) — 24 hour, 72 hour and one month reporting
legislation.mt
“an early warning, which, shall be submitted without undue delay and in any event within twenty-four (24) hours of becoming aware of the significant incident”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Personal Data (Electronic Communications Sector) Regulations, S.L. 586.01, regulation 3A — telecoms breach notification
legislation.mt
“In the case of a personal data breach, the provider of publicly available electronic communications services shall, without undue delay, notify the personal data breach to the Commissioner.”
Link checked 18 August 2026
- Official sourceOffice of the Information and Data Protection CommissionerReport a personal data breach — Information and Data Protection Commissioner
idpc.org.mt
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, because a law says so directly.
- What you have to do here:
- Get a parent's consent for children · Assess high-risk projects · Extra vendor secrecy terms
- What it costs if you get it wrong:
- Criminal liability
1. AGE THIRTEEN. Malta picked the lowest age Europe allows. A child can agree to an online service at thirteen (S.L. 586.11, Legal Notice 179 of 2018). If you build to a sixteen-or-parental-consent rule, you are stricter than Malta requires. If you build to a global thirteen rule, you are too loose for most other European countries. Neither default works across Europe. 2. YOU NEED PERMISSION FIRST, NOT JUST A RISK ASSESSMENT. Article 7 of the Data Protection Act says you must ask the Commissioner and get written permission before you start. This covers genetic data, biometric data or health data used for statistics or research in the public interest. It also covers special categories of data used to manage social care services. For research the Commissioner must also consult a research ethics committee. You have to wait for this permission. There is no European equivalent. 3. IDENTITY DOCUMENTS. Article 8 says you may only use an identity document where the purpose and the need for secure identification clearly justify it. You may only use the national identity number with proper safeguards. Routine 'send us a photo of your ID card' sign-up is not automatically legal in Malta. 4. YOU CAN GO TO PRISON, TWO WAYS. First, the Professional Secrecy Act extends the Criminal Code's secrecy offence to a long list of people. That list covers staff and officers of banks and financial institutions, insurers, accountants, auditors, lawyers, notaries, doctors, psychologists, social workers and state employees. So a badly run cloud migration that exposes client information is a criminal matter. It can only be prosecuted with the Attorney General's sanction. Second, article 22 of the Data Protection Act makes it an offence to give the Commissioner false information, or to fail to cooperate with an investigation. The penalty is a fine of 1,250 to 50,000 euros (about $1,400 to $58,000) or six months in prison, or both. 5. PUBLIC BODIES ARE CHEAP TO FINE. Article 21 caps fines on a public authority at 25,000 euros (about $29,000) per breach for the lower tier and 50,000 euros (about $58,000) for the higher tier. There is also a daily payment of 25 or 50 euros. If you deal with a Maltese public authority, the pressure on them to comply is small. 6. THE GAMING RETENTION OVERRIDE. Article 55 of the Gaming Act lets the Malta Gaming Authority keep personal information forever. It expressly overrides the Data Protection Act. Nobody has yet tested whether that survives a challenge under the European rules.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Child's Personal Data in relation to the Offer of Information Society Services Regulations, S.L. 586.11 (Legal Notice 179 of 2018)
legislation.mt
“The processing of personal data of a child in relation to information society services shall be lawful where the child is thirteen years of age.”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586, articles 7, 8, 21 and 22
legislation.mt
“A controller shall consult with, and obtain prior authorisation from, the Commissioner where the controller intends to process in the public interest: (a) genetic data, biometric data or data concerning health for statistical or research purposes”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaProfessional Secrecy Act, Chapter 377, articles 3 and 14
legislation.mt
Link checked 18 August 2026
What's changing next
Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export free of charge. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.
- What you have to do here:
- Make switching cloud provider possible
DATED CHANGES. 1 January 2027 - the Protection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act (Chapter 657, Act X of 2026) comes into force. It stops anyone offering a life insurance contract, a bank loan, an employment contract or a related agreement from asking for or using a person's cancer history. That applies once a set period has passed since treatment ended. It also sets up a Review Board. This is a flat ban on using a type of health data, not a paperwork exercise. 12 January 2027 - the European Data Act makes cloud switching and data export free of charge. Malta gave the Information and Data Protection Commissioner the job of enforcing the Data Act, in S.L. 586.13 (Legal Notice 223 of 2025, in force 10 October 2025). Fines follow the European privacy penalty scale. 2 August 2026 - most of Malta's artificial intelligence rules (S.L. 586.14, Legal Notice 227 of 2025) started. They name the Commissioner as the authority that polices the market. On 27 July 2026 the Commissioner said publicly that European timelines had moved. High-risk standalone systems moved to 2 December 2027 and regulatory sandboxes to 2 August 2027. Transparency labelling stayed at 2 August 2026. Through 2026 - the network security order and the critical entities resilience order both started on 23 January 2026. Both are in their first year of supervision. The duty to self-register is new and we have not yet seen it enforced. POWERS THE GOVERNMENT ALREADY HOLDS, usable with no consultation. 1. Article 10 of the Data Protection Act: the Minister may make regulations limiting transfers of named types of personal data outside Europe, for important reasons of public interest. Never used. This is the only way Malta could impose its own limit on sending data abroad, and it needs no debate in parliament. 2. Article 5 and S.L. 586.09: the Minister may limit people's rights for national security, tax, social security and other listed reasons. 3. The Malta Gaming Authority decides case by case whether to allow hosting outside the European Economic Area. It can refuse or withdraw that permission. 4. The old telecoms retention rules have never been repealed. They could be brought back in a narrower form at any time.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProtection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act, Chapter 657 (Act X of 2026)
legislation.mt
“This Act shall come into force on 1st January 2027.”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaData Protection (Fair Access to and Use of Data) Regulations, S.L. 586.13 (Legal Notice 223 of 2025) — national implementation of the EU Data Act
legislation.mt
Link checked 18 August 2026
- Official sourceOffice of the Information and Data Protection CommissionerIDPC draws attention to revised EU AI Act timelines following Council approval, 27 July 2026
idpc.org.mt
Link checked 18 August 2026
What to do: Diarise 1 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries4 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Online gaming data rules
Official name: Gaming Authorisations and Compliance Directive (Directive 3 of 2018) · Directive 3 of 2018, issued under the Gaming Act (Chapter 583), version 2 of October 2021 · Regulator directive
This is Malta's main rule about where data must sit. A licensed gaming operator's core systems must be hosted in Malta or elsewhere in the European Economic Area. That includes its player and financial databases. Another location needs the regulator's approval, case by case. You must also keep a live mirror of essential regulatory data that the regulator can reach at any time, including in person.
Enforced by Malta Gaming Authority
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryThe key technical setup must sit in Malta or another European Economic Area state. That covers the player database, the financial database, the gaming database, the control system, the random number generators and the jackpot parts. Anywhere else needs the Authority's approval, case by case, on the basis that protection is just as good.
- Keep logs — 2 yearsAudit logs of changes to the key technical setup.
- Independent auditRisk assessment of essential components, filed with the Authority and kept current.
- Written vendor contractYou must tell your hosting provider to allow and help the Authority with any checks it wants to make.
What it costs if you get it wrong
- Loss of your licenceBreach of authorisation conditions; the Authority's public register shows repeated cancellations and suspensions in 2024 and 2025
- Order to stopSuspension of authorisation pending investigation
Sources
- Official sourceMalta Gaming AuthorityGaming Authorisations and Compliance Directive (Directive 3 of 2018), articles 16 to 18
mga.org.mt
“The licensee shall maintain a live or real-time mirror server for essential regulatory data, and which shall be, at all times, made readily accessible to the Authority, including by means of physical access where applicable.”
Link checked 18 August 2026
- Official sourceMalta Gaming AuthorityRegulatory Framework — Malta Gaming Authority (directive list, page updated 15 July 2026)
mga.org.mt
Link checked 18 August 2026
Government data must stay in the country
Official name: GMICT Cloud Services Policy · GMICT P 0124, version 1.0 · Government policy document
This is a policy, not a law. It covers every Maltese public body and everyone selling to one. Cloud services should normally sit inside the European Union or European Economic Area. Classified information must sit on the Government's own cloud, not a commercial one.
Enforced by Malta Information Technology Agency
How this country controls where data goes: Only approved countries · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryAs a rule, cloud services used by the public administration must be provided within the European Union or European Economic Area.
- Prove the data stays under local controlAnything that stores, uses, sends or shares classified information must use the Government's own cloud through its agent.
Sources
- Official sourceMalta Information Technology AgencyGovernment of Malta Cloud Services Policy, GMICT P 0124 version 1.0, effective 13 September 2024
mita.gov.mt
“As a rule, Cloud services utilised shall be those provided within the EU/EEA to minimise regulatory derivative risks.”
Link checked 18 August 2026
- Official sourceMalta Information Technology AgencyGMICT policies — Malta Information Technology Agency
mita.gov.mt
Link checked 18 August 2026
Insurance rules
Official name: Protection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act · Chapter 657 of the Laws of Malta, Act X of 2026 · Act of parliament
From 1 January 2027, insurers, lenders and employers in Malta may not ask about or use a past cancer diagnosis once enough time has passed since treatment ended. It is a ban on using a category of health data, and a Review Board settles disputes.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Delete data after a period — from 1 January 2027If you offer life insurance, a bank loan, a related agreement or a job contract, you may not ask for or use a person's cancer history. This applies once the set period since the end of treatment has passed.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProtection against Adverse Consequences for Persons who recovered from Oncological Diseases (Right to be Forgotten) Act, Chapter 657
legislation.mt
“This Act shall come into force on 1st January 2027.”
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Att dwar is-Segretezza Professjonali (Kap. 377) · Professional Secrecy Act, Chapter 377 of the Laws of Malta, read with article 257 of the Criminal Code (Chapter 9) · Act of parliament
In Malta, breaking confidentiality is a crime for a long list of people. That list covers bank and financial institution staff, insurers, accountants, auditors, lawyers, notaries, doctors, psychologists, social workers and state employees. If you move their files to a new supplier or a foreign cloud, that is a criminal risk, not just a privacy one.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Extra vendor secrecy termsAny legal duty of secrecy or confidentiality counts as at least as strong as professional secrecy. A standard data protection contract is not enough to meet it.
What it costs if you get it wrong
- Criminal liabilityDisclosure of a secret by a person bound by professional secrecy; prosecution requires the Attorney General's sanction
Sources
- Official sourceGovernment of Malta — Legislation MaltaProfessional Secrecy Act, Chapter 377 of the Laws of Malta, articles 3, 13 and 14
legislation.mt
“Any reference in an enactment, whether passed before or after the date of entry into force of this Act, to an obligation to observe secrecy or confidentiality, shall be interpreted as imposing a duty at least as strong as the duty of professional secrecy”
Link checked 18 August 2026
Applies to every company5 rules
These bind you whatever business you are in, once the country's rules reach you.
Health data rules
Official name: Att dwar il-Protezzjoni tad-Data (Kap. 586) · Chapter 586 of the Laws of Malta, Act XX of 2018, as amended by Act XII of 2021 and Legal Notice 212 of 2023 · Act of parliament
Malta's national privacy law. It does not say where data must be stored. It adds four things. You need permission before you use health, genetic or biometric data for research. You are limited in how you can use identity documents. Fines on public bodies are capped low. And obstructing the regulator is a crime.
Enforced by Information and Data Protection Commissioner
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Assess high-risk projectsArticle 7 goes further than a risk assessment. You need written permission from the Commissioner first. That covers genetic, biometric or health data used for statistics or research in the public interest. It also covers special categories of data used to manage social care.
- Allowed because the law requires itArticle 8 limits how you can use identity documents and the national identity number.
- Put a transfer safeguard in place
What it costs if you get it wrong
- Fixed maximum fine: €25,000 per violation plus €25 per day — about $29 thousandPublic authority or body — lower tier infringement
- Fixed maximum fine: €50,000 per violation plus €50 per day — about $58 thousandPublic authority or body — higher tier infringement
- Criminal liability: €1,250 to €50,000 fine and/or 6 months imprisonment — about $58 thousandKnowingly giving the Commissioner false information, or failing to comply with an investigation
Sources
- Official sourceGovernment of Malta — Legislation MaltaData Protection Act, Chapter 586 of the Laws of Malta
legislation.mt
“Provided that such a fine shall not exceed twenty-five thousand euro (€25,000) for each violation and, additionally, the Commissioner may impose a daily fine payment of twenty-five euro (€25) for each day during which such violation persists”
Link checked 18 August 2026
- Official sourceOffice of the Information and Data Protection CommissionerLegislation — Office of the Information and Data Protection Commissioner
idpc.org.mt
Link checked 18 August 2026
Personal data needs a copy kept in the country
Official name: Att dwar il-Kumpaniji (Kap. 386), artikolu 163 · Companies Act, Chapter 386 of the Laws of Malta, article 163 · Act of parliament
This applies to every Maltese company, whatever your industry. Your books can live in a foreign cloud. But a Maltese copy of the accounts and returns must exist and be open to inspection. Update it at least every six months.
Enforced by Malta Business Registry
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryThe records themselves can sit abroad. But you must send accounts and returns to a place in Malta and keep them there. They must show the financial position at least every six months.
- Keep data for a minimum period — 10 yearsTen years; where records are in a bound or unified form the ten years run from the last entry.
What it costs if you get it wrong
- Criminal liability: €11,646 — about $13 thousandEvery officer in default, unless they show they acted diligently and the default was excusable
Sources
- Official sourceGovernment of Malta — Legislation MaltaCompanies Act, Chapter 386 of the Laws of Malta, article 163
legislation.mt
“Provided that if accounting records are kept at a place outside Malta there shall be sent to, and kept at a place in Malta ... such accounts and returns ... as will disclose with reasonable accuracy the financial position of that business at intervals not exceeding six months”
Link checked 18 August 2026
Cyber security rules
Official name: Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order · S.L. 460.41, Legal Notice 71 of 2025 (Government Gazette No. 21,418 of 8 April 2025), as amended by Legal Notice 89 of 2026 · Government rules
Malta's cybersecurity rules, new since 23 January 2026. They replaced the 2018 order. They bring a 24-hour early warning, a 72-hour report, a one-month final report, and a duty to self-register with the national critical infrastructure department. No data has to stay in Malta.
Enforced by Critical Infrastructure Protection Department and CSIRTMalta
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursEarly warning. Then a fuller notification within 72 hours and a final report within one month.
- Register or notifyIf you are an essential or important organisation providing services in Malta, you must sign up. The same goes for domain name registration providers. The Critical Infrastructure Protection Department runs the self-registration system.
- Secure the data
- Independent audit
What it costs if you get it wrong
- Percentage of global turnover: €10,000,000 or 2% of worldwide turnover — about $12 millionEssential entities
- Percentage of global turnover: €7,000,000 or 1.4% of worldwide turnover — about $8 millionImportant entities
- Daily fine until fixed: €100 per day — about $115Continuing default
Sources
- Official sourceGovernment of Malta — Legislation MaltaMeasures for a High Common Level of Cybersecurity across the European Union (Malta) Order, S.L. 460.41
legislation.mt
“Essential and important entities providing services in Malta as well as entities providing domain name registration services in Malta shall register on the national self-registration mechanism established by the CIP Department”
Link checked 18 August 2026
- Official sourceGovernment of Malta — Legislation MaltaResilience of Critical Entities and Infrastructures (Identification, Designation and Protection) Order, S.L. 460.43 (Legal Notice 5 of 2026), in force 23 January 2026
legislation.mt
Link checked 18 August 2026
AI rules
Official name: Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations · S.L. 586.14, Legal Notice 227 of 2025 · Directly binding regulation
Malta named its privacy regulator as the authority that polices artificial intelligence products on the market. Most of the rules started on 2 August 2026. The rest were already in force from 10 October 2025.
Enforced by Information and Data Protection Commissioner
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Check your algorithms — from 2 August 2026
- Keep records of how you use data — from 2 August 2026You must keep technical documentation available for the Commissioner, which polices the market.
What it costs if you get it wrong
- Fixed maximum fine: €50,000 per violation plus €50 per day — about $58 thousandPublic authority or body
Sources
- Official sourceGovernment of Malta — Legislation MaltaArtificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, S.L. 586.14
legislation.mt
“Regulations 5 to 7 and 9 to 12 shall come into force on the 2nd August 2026.”
Link checked 18 August 2026
Children's data rules
Official name: Processing of Child's Personal Data in relation to the Offer of Information Society Services Regulations · S.L. 586.11, Legal Notice 179 of 2018 · Directly binding regulation
In Malta a child can agree to an online service at thirteen. That is the lowest age the European rules allow. Most other European countries set it higher. So one age gate across the whole of Europe will be wrong somewhere.
Enforced by Information and Data Protection Commissioner
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Get a parent's consent for children — applies at: under 13Malta chose the lowest age Europe permits. Below thirteen, a parent must consent.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Child's Personal Data in relation to the Offer of Information Society Services Regulations, S.L. 586.11
legislation.mt
“The processing of personal data of a child in relation to information society services shall be lawful where the child is thirteen years of age.”
Link checked 18 August 2026
Applies across the European Union2 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Regolament (UE) 2016/679 (Regolament Generali dwar il-Protezzjoni tad-Data) · Regulation (EU) 2016/679 · Directly binding regulation
The European privacy rulebook applies directly in Malta. It does not require data to stay in Europe. It sets conditions for sending data out: an approved destination, the European standard contract, approved group-wide rules, or a narrow exception.
Enforced by Information and Data Protection Commissioner
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, To save someone’s life
What you have to do
- Tell people what you do
- Secure the data
- Keep records of how you use data
- Assess high-risk projects
- Appoint a data protection officerWhere Article 37 applies. Malta may add cases by regulations under article 33(f) of the Data Protection Act; none found in force.
- Appoint a representativeFor companies based outside the European Union that decide how data is used, or that handle it for someone else.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Put a transfer safeguard in place
- Written vendor contract
- Let people see their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Delete data after a period
What it costs if you get it wrong
- Percentage of global turnover: €20 million or 4% of worldwide group turnover — about $23 millionBasic principles, individual rights, unlawful transfers, defying a regulator order
- Percentage of global turnover: €10 million or 2% of worldwide group turnover — about $12 millionController and processor duties, security, records, breach notification
- Order to stopOrder to stop processing or suspend transfers outside Europe
- Claims by individualsCompensation claims by individuals
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Government data rules
Official name: Regolament (UE) 2018/1807 dwar qafas għall-moviment liberu ta' data mhux personali fl-Unjoni Ewropea · Regulation (EU) 2018/1807 · Directly binding regulation
Malta is forbidden from ordering non-personal data to be stored inside the country, except on public security grounds. This is why Malta's few storage rules attach to gaming licences, company books and government procurement rather than to data in general.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possible
Sources
- Official sourcePublications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union
eur-lex.europa.eu
On the books, but not enforceable1 rule
These rules are still printed in the law, but a court struck them down or the regulator has said it will not apply them. You do not have to comply today. They are here because text nobody deleted can come back without warning.
Telecoms rules
Official name: Processing of Personal Data (Electronic Communications Sector) Regulations, Part II — Retention of Data · S.L. 586.01, Part II, added by Legal Notice 198 of 2008; last amended by Legal Notice 429 of 2013 · Directly binding regulation
Malta still prints a blanket duty on phone and internet companies to keep everyone's call and connection records for six to twelve months. Malta copied a European directive that the European Court of Justice cancelled in 2014. The Maltese text has not been changed since 2013. If you just read the statute book, this looks binding. Keeping everyone's records like this cannot lawfully be enforced.
Enforced by Information and Data Protection Commissioner
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 6 monthsInternet access and internet e-mail records. Printed in the law, but unenforceable as a blanket duty.
- Keep data for a minimum period — 1 yearFixed, mobile and internet telephony records. Printed in the law, but unenforceable as a blanket duty.
- Keep logsPolice conservation orders can extend retention by six months, up to a total of two years without a court order.
Sources
- Official sourceGovernment of Malta — Legislation MaltaProcessing of Personal Data (Electronic Communications Sector) Regulations, S.L. 586.01, regulations 17 to 24
legislation.mt
“The categories of data specified in regulation 20 shall be retained by the service providers for the following periods: (a) communications data relating to Internet Access and Internet e-mail for a period of six months from the date of communication; (b) communications data concerning fixed network telephony, mobile telephony and Internet telephony for a period of one year from the date of communication.”
Link checked 18 August 2026
- Official sourceCourt of Justice of the European UnionDigital Rights Ireland, Joined Cases C-293/12 and C-594/12 — the Data Retention Directive declared invalid, 8 April 2014
curia.europa.eu
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
That the blanket telecoms data retention rules in Part II of S.L. 586.01 are actually unenforceable in Malta today
The text is still printed and has not been changed since Legal Notice 429 of 2013. The European Court of Justice cancelled the directive it copies in 2014. That court has repeatedly held that keeping everyone's records is unlawful. We could not find a Maltese court judgment setting the Maltese rule aside. We also could not find a statement from the Maltese government or the Commissioner saying it is not enforced. We treat it as not applying, on the strength of superior European law, at medium confidence.
The exact commencement date of the Malta Gaming Authority's Gaming Authorisations and Compliance Directive
The directive itself is dated 2018 and the current text is marked version 2, October 2021. References inside it point to 1 August 2018 as the start of the current gaming rules. We could not find a separate commencement notice on the regulator's site. The date shown is our best reading.
The name and appointment date of the current Information and Data Protection Commissioner
The office's own pages describe what it does but do not name the current post-holder in anything we could retrieve. We did not want to state a name from memory. Check the regulator's site for the current name.
The 'established period' after which a past cancer diagnosis must be ignored under Chapter 657
The Act defines the term but we did not get the exact number of years. The Act is not yet in force. Treat the mechanism as confirmed and the exact period as open until 1 January 2027.
Whether any Malta Financial Services Authority rule, banking rule or insurance rule imposes a location requirement not visible in the primary statutes
We could not open the Authority's publications index. We checked the Banking Act itself and found no rule that data must stay in Malta. We could not read the Authority's rulebook directly, so we could not confirm it there. Checked 18 August 2026. If you run a bank, ask the Authority before you rely on this.
Current staffing, budget and complaint volumes at the Information and Data Protection Commissioner
The most recent annual report on the office's site is for 2024, and we could not open the file. We rate enforcement as active on the decision register alone.
Whether Malta has any health-sector or geospatial storage-location rule outside the instruments we read
We found no health-specific rule about where data must be stored. We checked the Health Act (Chapter 528), the data protection secondary legislation and the health insurance regulations. Checked 18 August 2026, at medium confidence. If you work in health, check with the regulator before you rely on this.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.