Law note · Malta

Data Protection Act, Chapter 586 of the Laws of Malta

cite Data Protection Act, Cap. 586 stage In effect since 2018-05-25 reviewed 2026-08-24

Malta's private-sector regime is the General Data Protection Regulation (GDPR) plus the Data Protection Act, Chapter 586 of the Laws of Malta, in effect since 25 May 2018 alongside the GDPR itself, supplying domestic derogations and procedural rules. Subsidiary Legislation 586.11 sets the digital age of consent at 13, per secondary commentary.

The Information and Data Protection Commissioner (IDPC) is the supervisory authority; a second designation (Legal Notice 227 of 2025) makes it a market-surveillance authority for specific EU AI Act high-risk categories, including biometrics, an ai-topic matter outside this document's scope. Cap. 586's own official PDF could not be extracted through WebFetch this pass, so article-level detail below is commentary sourced.

What it asks of an app

  • Establish a General Data Protection Regulation (GDPR) Article 6 lawful basis before processing personal data of a person in Malta, including data collected by crawling.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach

Primary source: IDPC official PDF (idpc.org.mt), not independently extracted this pass
secondary commentary (Linklaters, Mondaq) for national specifics

← Back to the example  ·  Lint your app →