Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Biometric privacy
cite Regulation (EU) 2016/679, Art. 9; Data Protection Act, Cap. 586
stage In effect
since 2018-05-25
source Two independent secondary sources (Linklaters, Mondaq), not independently confirmed against Cap. 586's own text this pass
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category.
Two independent secondary sources (Linklaters, Mondaq) converge on the same finding: a controller must consult with, and obtain prior authorization from, the IDPC before processing genetic, biometric, or health data for statistical or research purposes in the public interest, and the IDPC must in turn consult an ethics committee or an IDPC-recognised institution for the same category of processing.
This duty is scoped to statistical, research, and public-interest processing; a commercial product capturing voiceprints or faceprints for authentication or identification outside a research context is governed by GDPR Article 9 alone, with no Malta-specific addition identified for that use case. The provision's exact article number was not independently confirmed against Cap. 586's own text this pass.
What it asks of an app →
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the IDPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Malta, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Cap. 586 derogation from this timeline was identified in this pass.
What it asks of an app →
Comprehensive regime
cite Data Protection Act, Cap. 586
stage In effect
since 2018-05-25
source IDPC official PDF (idpc.org.mt), not independently extracted this pass
Malta's private-sector regime is the General Data Protection Regulation (GDPR) plus the Data Protection Act, Chapter 586 of the Laws of Malta, in effect since 25 May 2018 alongside the GDPR itself, supplying domestic derogations and procedural rules. Subsidiary Legislation 586.11 sets the digital age of consent at 13, per secondary commentary.
The Information and Data Protection Commissioner (IDPC) is the supervisory authority; a second designation (Legal Notice 227 of 2025) makes it a market-surveillance authority for specific EU AI Act high-risk categories, including biometrics, an ai-topic matter outside this document's scope. Cap. 586's own official PDF could not be extracted through WebFetch this pass, so article-level detail below is commentary sourced.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Malta outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Cap. 586 derogation broadening or narrowing this was identified in this pass.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Art. 22; Data Protection Act, Cap. 586
stage In effect
since 2018-05-25
source Secondary commentary (Linklaters, Mondaq), not independently confirmed against Cap. 586's own text this pass
General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Cap. 586 without narrowing per secondary commentary. Subsidiary Legislation 586.11 sets the digital age of consent at 13, a national exercise of the GDPR Article 8 discretion, which permits a range from 13 to 16.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
The IDPC is the supervisory authority and enforces General Data Protection Regulation (GDPR) fines up to EUR 20 million or 4 percent of global annual turnover, per secondary commentary. No Malta-specific fine ceiling distinct from the GDPR Article 83 maximum was identified in this pass. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app →