Skip to the content
Global Data RulesData governance rules, country by country

Malta

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: MediumEnforcement: Active

Malta runs on the European rulebook. Data may go abroad once the right paperwork is in place, and there is no general rule that it must stay on the island. Two things break that. Online gaming companies must keep their core systems inside Europe. And any Maltese company that keeps its books abroad must still keep a copy of its accounts in Malta.

Eight questions about Malta

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Malta's rules apply to my company?

Yes. Malta's Data Protection Act reaches a company with no office in Malta if it offers goods or services to people in Malta, or watches their behaviour in Malta. There is no size or revenue threshold. There is no extra Maltese representative to appoint beyond the one the European rules already require of companies based outside Europe.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Malta?

In general, yes. Malta has no law saying personal data must be stored on the island. It follows the European Union rules: send data outside Europe once you have an approved destination or the right contract. Three areas override that. Online gaming is the big one, and it is Malta's flagship industry.

High confidenceDepends on your industryAllowlist

What do I need in place before data leaves Malta?

Use the European toolkit. Send data to a country the European Commission has approved, or sign the European standard contract, or use approved group-wide rules. Malta adds nothing on top. Malta's own minister has a power to restrict transfers of named categories of data, but has never used it, so the list of Maltese restrictions is empty today.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesGovernment sign-off needed

Who enforces the rules in Malta, and what can they do?

The Information and Data Protection Commissioner. It is real, staffed and issuing decisions: its public register shows around nineteen decisions published in 2026 and thirty-eight in 2025. The fines are small by European standards — most sit between about 2,000 and 20,000 euros (roughly $2,300 to $23,000). The gaming regulator is the harder one, and it cancels licences.

High confidenceActive

How long do I have to keep the data?

There is a floor and a ceiling. The floor: company accounting records for ten years, tax and value-added-tax records for at least six years, and anti-money-laundering records for five years. The ceiling: the European rule that you delete personal data once you no longer need it. Where they clash, the specific Maltese law that orders you to keep something wins, because keeping it is then a legal duty.

High confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count three clocks, and they do not line up. Seventy-two hours to tell the privacy regulator about a personal data breach. Twenty-four hours to send a first warning about a serious cyber incident, then seventy-two hours for the full report and one month for the final one. Phone and internet companies have their own separate duty to report straight away.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsRegister or notify

What trips people up in Malta?

Five things that are not in the summary. A child in Malta is thirteen, not sixteen. Health and biometric research needs the regulator's written permission before you start, not just a risk assessment. Copying someone's identity card is restricted. Leaking a client secret can be a crime, not a fine. And the gaming regulator can keep personal data forever, in a law that says so out loud.

High confidenceGet a parent's consent for childrenAssess high-risk projectsExtra vendor secrecy termsCriminal liabilityChildren's data

What is changing soon in Malta?

Three dated changes. On 1 January 2027 a new law stops insurers, banks and employers asking about a cancer diagnosis once enough time has passed since treatment. On 12 January 2027 European rules make cloud switching and data export fees free. And Malta's artificial intelligence rules started phasing in on 2 August 2026, with the privacy regulator now policing the market.

High confidencePassed, not yet fully in forcePartly in forceMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    2 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    5 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    5 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules2 rules

Regolament (UE) 2016/679 (Regolament Generali dwar il-Protezzjoni tad-Data)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European privacy rulebook applies directly in Malta. It does not require data to stay in Europe. It sets conditions for sending data out: an approved destination, the European standard contract, approved group-wide rules, or a narrow exception.

In force since 25 May 2018

Enforced by Information and Data Protection Commissioner

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Important public interest, Someone's life is at risk

High confidence

Regolament (UE) 2018/1807 dwar qafas għall-moviment liberu ta' data mhux personali fl-Unjoni Ewropea

Directly binding regulation · Regulation (EU) 2018/1807

In forceYes — store it anywhere

Malta is forbidden from ordering non-personal data to be stored inside the country, except on public security grounds. This is why Malta's few storage rules attach to gaming licences, company books and government procurement rather than to data in general.

In force since 28 May 2019

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules5 rules

Att dwar il-Protezzjoni tad-Data (Kap. 586)

Act of parliament · Chapter 586 of the Laws of Malta, Act XX of 2018, as amended by Act XII of 2021 and Legal Notice 212 of 2023

In forceYes — store it anywhere

Malta's national privacy statute. It adds no storage-location rule. It does add a prior-authorisation gate for health, genetic and biometric research, a restriction on processing identity documents, a low fine ceiling for public bodies, and a criminal offence for obstructing the regulator.

In force since 28 May 2018

Enforced by Information and Data Protection Commissioner

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Att dwar il-Kumpaniji (Kap. 386), artikolu 163

Act of parliament · Companies Act, Chapter 386 of the Laws of Malta, article 163

In forceA copy must stay

A quiet mirror rule that applies to every Maltese company regardless of industry. Books may live in a foreign cloud, but a Maltese copy of the accounts and returns must exist and be open to inspection, refreshed at least every six months.

In force since 1 January 1996

Enforced by Malta Business Registry

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order

Government rules · S.L. 460.41, Legal Notice 71 of 2025 (Government Gazette No. 21,418 of 8 April 2025), as amended by Legal Notice 89 of 2026

In forceYes — store it anywhere

Malta's cybersecurity regime, new since 23 January 2026. It replaced the 2018 order and brings a 24-hour early warning, a 72-hour report, a one-month final report, and a duty to self-register with the national critical infrastructure department. No data has to stay in Malta.

In force since 23 January 2026

Enforced by Critical Infrastructure Protection Department and CSIRTMalta

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules5 rules

Gaming Authorisations and Compliance Directive (Directive 3 of 2018)

Regulator directive · Directive 3 of 2018, issued under the Gaming Act (Chapter 583), version 2 of October 2021 · Online gaming

In forceYes, with paperwork

Malta's real data-location wall. A licensed gaming operator's core systems, including its player and financial databases, must be hosted in Malta or elsewhere in the European Economic Area unless the regulator approves another location case by case. A live mirror of essential regulatory data must be kept permanently reachable by the regulator, including physically.

In force since 1 August 2018

Enforced by Malta Gaming Authority

Transfer model: Allowlist · Accepted routes: Government sign-off needed

High confidence

Processing of Personal Data (Electronic Communications Sector) Regulations, Part II — Retention of Data

Directly binding regulation · S.L. 586.01, Part II, added by Legal Notice 198 of 2008; last amended by Legal Notice 429 of 2013 · Telecoms

UnenforceableYes — store it anywhere

Malta still prints a blanket duty on phone and internet companies to keep everyone's call and connection records for six to twelve months. It transposed a European directive that the European Court of Justice annulled in 2014, and it has not been amended since 2013. A naive reading of the statute book reports this as binding. General, indiscriminate retention of this kind cannot lawfully be enforced.

In force since 15 August 2008

Enforced by Information and Data Protection Commissioner

Transfer model: No restriction · Accepted routes: Nothing required

Medium confidence

GMICT Cloud Services Policy

Government policy document · GMICT P 0124, version 1.0 · Government

In forceYes, with paperwork

Not a statute, but it governs every Maltese public body and everyone selling to one. Cloud services should as a rule be inside the European Union or European Economic Area, and classified information must sit on the Government's own cloud rather than a commercial one.

In force since 13 September 2024

Enforced by Malta Information Technology Agency

Transfer model: Allowlist · Accepted routes: Government sign-off needed

Medium confidence

Who you would hear from

  • Kummissarju għall-Informazzjoni u l-Protezzjoni tad-Data

    Privacy, freedom of information, the EU Data Act, and market surveillance for artificial intelligence

    Fully operational. Publishes every binding decision on its own register: roughly 19 published entries dated 2026 and 38 dated 2025 as of 18 August 2026, with fines typically between EUR 2,000 and EUR 20,000 and a published maximum of EUR 250,000. Capacity caveat: the most recent annual report published is for 2024 and was only uploaded in April 2026.

  • Awtorità Maltija dwar il-Logħob

    Remote and land-based gaming, including where licensees may host their systems

    Highly active. Its public enforcement register shows repeated cancellations, revocations and suspensions of authorisations through 2024 and 2025.

  • Cyber incident reporting, essential and important entity supervision under the 2026 cybersecurity order

    The department is the named competent authority under S.L. 460.41, in force since 23 January 2026. It runs the national self-registration mechanism. No public enforcement decisions found yet — the regime is in its first supervisory year.

  • Government ICT policy, the Malta Government Cloud, and the GMICT policy framework

  • Banking, insurance, investment services and payments

    Active supervisor. Imposes no data localisation of its own; material outsourcing must be notified under article 19A of the Banking Act, and the European financial resilience regulation known as DORA governs technology risk.

  • Electronic communications networks and services

  • Company registration, accounting records and annual returns

  • Anti-money-laundering supervision and record-keeping rules

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • That the blanket telecoms data retention rules in Part II of S.L. 586.01 are actually unenforceable in Malta today

    The text is still printed and unamended since Legal Notice 429 of 2013, and the European Court of Justice annulled the directive it transposes in 2014 and has repeatedly held general, indiscriminate retention unlawful. But we could not find a Maltese court judgment disapplying it, nor a statement from the Maltese government or the Commissioner confirming it is not enforced. The status is coded 'disapplied' on the strength of superior European law, at medium confidence.

  • The exact commencement date of the Malta Gaming Authority's Gaming Authorisations and Compliance Directive

    The directive itself is dated 2018 and the current text is marked version 2, October 2021. Internal references point to 1 August 2018 as the start of the current gaming framework, but we did not locate a separate commencement notice on the regulator's site. The date shown is our best reading.

  • The name and appointment date of the current Information and Data Protection Commissioner

    The office's own pages describe its functions but do not name the current holder in the material we could retrieve. We did not want to assert a name from memory.

  • The 'established period' after which a past cancer diagnosis must be ignored under Chapter 657

    The Act defines the term but we did not extract the specific number of years, and the Act is not yet in force. Treat the mechanism as confirmed and the exact period as open until 1 January 2027.

  • Whether any Malta Financial Services Authority rule, banking rule or insurance rule imposes a location requirement not visible in the primary statutes

    The Authority's own publications index returned errors to our fetches. We verified the absence of localisation in the Banking Act itself, but the rulebook was not directly readable, so this is an absence of evidence rather than evidence of absence, checked 18 August 2026.

  • Current staffing, budget and complaint volumes at the Information and Data Protection Commissioner

    The most recent annual report on the office's site is for 2024, and the PDF is served through a viewer we could not open directly. Enforcement is rated 'active' on the decision register alone.

  • Whether Malta has any health-sector or geospatial storage-location rule outside the instruments we read

    We checked the Health Act (Chapter 528), the data protection subsidiary legislation series and the health-for-insurance regulations and found none. No rule found, checked 18 August 2026, confidence medium.

60-day cadence. Two reasons. First, the cybersecurity and critical entities orders only started on 23 January 2026 and are in their first supervisory year, so the enforcement picture can change fast. Second, three switches can flip with no consultation: the ministerial power at article 10 of the Data Protection Act to restrict transfers of named data categories, the Malta Gaming Authority's discretionary approval of hosting outside the European Economic Area, and the unrepealed telecoms retention rules.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.