Law / Maldives

Maldives

privacy

No comprehensive personal-data or biometric-privacy law is currently binding law in the Maldives. Three independent secondary sources describe a "Data Protection Act" dated around 2017, but no Act number, gazette citation, or working government-hosted URL could be located this pass, so it is not authored as an instrument here; its existence is an open question, not a confirmed absence or a confirmed finding.

A separate, government-backed Personal Data Protection Bill, a complete General Data Protection Regulation (GDPR)-shaped draft covering controller/processor obligations, special categories of personal data, a Data Protection Authority, 72-hour breach notification, and cross-border transfer conditions, was submitted to the People's Majlis on 11 May 2026, per a dated Maldivian news report; it had not passed a chamber as of that report and no later reporting confirming passage was located.

This directly corrects a derivation seed candidate that had characterized the bill as already "passed by People's Majlis ~2025."

6 instruments named 1 researched in detail As of 2026-08-29

Instruments

Each one links to its LexLint note, which carries what it requires and what it flags on.

Comprehensive regime

Personal Data Protection Bill, pending before the People's Majlis

cite Personal Data Protection Bill, submitted to the People's Majlis, first reported 11 May 2026 stage PROPOSED draft date not recorded binds public and private bodies source draft bill text hosted at mifps.com.mv, not an official government publication
What it requires

The pending bill would apply to the processing of all types of personal data by a Controller or Processor in both the public and private sectors within the Maldives, enforced by a Data Protection Authority whose functions are proposed to be carried out by the existing Information Commissioner.

Its Special Categories of Personal Data definition lists biometric data for the purpose of uniquely identifying a natural person, alongside racial or ethnic origin, political opinions, philosophical beliefs, trade union membership, genetic data, health data, and sex life or sexual orientation data, materially identical in structure to Sri Lanka's enacted PDPA definition in this same batch.

Section 34 would require dual notification, to the Data Protection Authority and to affected data subjects, within 72 hours of a reasonable belief that a breach involving special-category or fraud-enabling data has occurred. Chapter 8 would condition cross-border transfer on an Authority adequacy determination or appropriate safeguards.

Tiered administrative fines up to MVR 500,000 or 4% of annual revenue are proposed for the most serious violations, and section 55 would give every person a right to compensation for damage caused by a breach of the Act.

The bill's own text carries no Act number and no evidence of Presidential ratification or gazette publication; a dated Maldivian news report confirms it was still at the submission stage as of 11 May 2026, contradicting an earlier, uncorroborated characterization that it had already passed.

This summary covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted above and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.