Maldives Personal Data Protection Bill, cross-border transfers
Personal Data Protection Bill, chapters 7-8 (personal data transfers and cross-border transfers)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
A cross border transfer rule binding public and private bodies.
As of 19 September 2026.
What it requires
- The Maldives' Personal Data Protection Bill has not been enacted and creates no binding duty as of the date shown; it was submitted to the People's Majlis on 11 May 2026 and had not passed a chamber as of the most recent reporting located.
- If enacted as drafted, a Controller or Processor would not be able to transfer personal data outside the Maldives without appropriate safeguards, and only where enforceable data subject rights and effective legal remedies are available in the destination.
- If enacted as drafted, an agreement with a cross-border recipient would have to carry a data protection process the Data Protection Authority endorses, or the transfer would have to rest on binding corporate rules the Authority has approved.
What it reaches
Obligation class
Transfer
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 43 would require a cross-border data transfer by a Controller to be carried out on the conditions the Act specifies.
Section 44 would let a Controller or Processor transfer personal data to a jurisdiction outside the Maldives only where it has provided appropriate safeguards, and only on condition that enforceable data subject rights and effective legal remedies are available there; the safeguards would be the corporate process the Bill describes and an agreement with the receiving entity carrying a data protection process the Data Protection Authority endorses, with the Authority formulating the process by regulation.
Section 45 would let the Authority approve binding corporate rules and fixes what they must specify, including the structure and contact details of the group, the transfers and categories of data concerned, and their legally binding nature. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotprocesses_biometrics
Read the law
draft bill text hosted at mifps.com.mv, not an official government publication
corroborated by a Maldivian news report on the submission event
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.