Skip to content

Evidence request lists

Malta Data Protection Act (Cap. 586, 2018)

Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.

Bilingual Notices and Subsidiary Legislation - Malta DPA

MT-DPA-Bilingual-Maltese-English-Privacy-Notices-Subsidiary-Legislation-586-01-to-586-09-Marketing-Direct
Malta DPA Bilingual + Maltese and English Privacy Notices + Subsidiary Legislation 586.01-09 + Direct Marketing

Provide privacy notices in Maltese and English (both constitutional official languages under Constitution Article 5) + comply with Subsidiary Legislation suite governing sector-specific processing. Subsidiary Legislation 586.01 Processing in Education Sector (school records + e-skola platform) + 586.02 Police Sector + 586.03 Data Protection in Police Sector + 586.04 Competent Authorities for Criminal Matters (LED transposition) + 586.05 Restriction of the Data Protection Act + 586.06 Journalistic Artistic and Literary Purposes (Article 85 GDPR derogation) + 586.07 Processing Children Data in Information Society Services (Article 8 GDPR + Malta age 13) + 586.08 Restriction of Application + 586.09 Secondary Processing. Direct marketing under IDPC Cookie Guidelines + Electronic Communications (Regulation) Act + Communications Authority coordination. Cookie consent + behavioural advertising

Artefacts an auditor will ask for
  • Maltese and English privacy notices (both constitutional languages under Constitution Article 5)
  • S.L. 586.01-09 sector applicability assessment + compliance records
  • IDPC Cookie Guidelines compliance + cookie consent management
  • Direct marketing opt-out infrastructure under Electronic Communications (Regulation) Act
  • MGA Player Protection Directive cross-walk for iGaming communications
Where this commonly fails
  • English-only notices breach Constitution Article 5 + IDPC guidance
  • S.L. 586.06 journalism derogation invoked without basis
  • Cookie consent not granular per IDPC 2024 guidance

Children and Sensitive Categories - Malta DPA

MT-DPA-Children-Age-13-Sensitive-Categories-Article-9-iGaming-Player-Protection-Health-MFSA
Malta DPA Children Age 13 + Sensitive + iGaming Player Protection + Health + MFSA Financial

Process children data and sensitive personal data under Maltese-specific provisions. Article 7 Cap. 586 sets digital consent age at 13 (LOWER than GDPR default 16 - among lowest in EU alongside Belgium + Estonia + Finland + Portugal + Sweden + Cyprus) + parental responsibility under Article 8 GDPR for under 13 + S.L. 586.07 Processing Children Data in Information Society Services. iGaming-specific child protection under MGA Player Protection Directive + Responsible Gaming Code + age verification with documentary proof + self-exclusion register. Sensitive categories under GDPR Article 9 (health + religion + political + sexual orientation + biometric + genetic + trade union + ethnic) require explicit consent or narrow exceptions. Maltese employment law derogations under Employment and Industrial Relations Act. Health processing under Department of Health + Medical Council. Financial sensit

Artefacts an auditor will ask for
  • Children processing inventory + age 13 verification + parental consent for under-13 + S.L. 586.07 compliance
  • Sensitive categories inventory + explicit consent records or Article 9 lawful basis documentation
  • MGA Player Protection Directive + Responsible Gaming Code compliance evidence (for iGaming operators)
  • MFSA Conduct of Business Rules compliance (financial)
  • Self-exclusion register integration
Where this commonly fails
  • Age 16 default used despite Malta age 13 (compliance burden inverted)
  • iGaming KYC sensitive categories not Article 9 grounded
  • Self-exclusion register data not protected with appropriate security

Cross-Border Transfer - Malta DPA

MT-DPA-Cross-Border-Transfer-EEA-Schrems-2021-SCC-iGaming-MFSA-Maritime-Cross-Establishment
Malta DPA Cross-Border + EEA + Schrems + 2021 SCC + iGaming + MFSA + Maritime Cross-Establishment

Govern cross-border data transfers under GDPR Chapter V particularly critical due to Malta as EU cross-establishment jurisdiction for iGaming + financial services + maritime registry. Free transfers within EEA + adequacy decisions (UK + Switzerland + Japan + Korea + Canada commercial + Israel + Argentina + Uruguay + New Zealand + Andorra + Faroe Islands + Guernsey + Isle of Man + Jersey + EU-US Data Privacy Framework 2023). 2021 EU Standard Contractual Clauses (Module 1-4) post-Schrems II Transfer Impact Assessment requirement particularly for US transfers post Schrems II 2020. Binding Corporate Rules under Article 47 GDPR with IDPC as lead reviewer for Malta-headquartered groups. Derogations under Article 49 GDPR for specific situations. iGaming-specific cross-border data flows due to MGA-licensed operators serving EU+UK+third-country players - MGA Player Account information + KYC + AML

Artefacts an auditor will ask for
  • Cross-border transfer register + 2021 EU SCC + adequacy decision basis
  • Transfer Impact Assessment for US transfers post Schrems II
  • BCR documentation with IDPC as lead reviewer
  • iGaming-specific cross-border player data flow documentation (MGA-licensed serving EU+UK+third-country players)
  • MFSA financial services passporting cross-walk
  • EDPB cooperation under Article 60 documentation
Where this commonly fails
  • No Transfer Impact Assessment post-Schrems II for US transfers
  • iGaming MGA-licensee cross-border flows not 2021-SCC-papered
  • MFSA passporting cross-border not assessed
  • IDPC not engaged as BCR lead reviewer

Data Subject Rights - Malta DPA

MT-DPA-Data-Subject-Rights-IDPC-Complaints-Article-12-Restrictions-Article-Subsidiary-Legislation-586-05-586-08
Malta DPA Subject Rights + IDPC Complaints + Restrictions + Subsidiary Legislation 586.05 + 586.08

Provide channels for data subjects to exercise GDPR Chapter III rights + IDPC complaint mechanism under Article 12 + Maltese-specific restrictions under S.L. 586.05 and 586.08. Free of charge IDPC complaints procedure with 6-month response target + Tribunal Administrattiv (Information and Data Protection Appeals Tribunal) appeal mechanism under Article 19 + Court of Appeal (Inferior Jurisdiction) final appeal. National derogations under S.L. 586.05 restricting subject rights for national security + defence + public security + criminal investigation + prevention of breaches of professional ethics + economic interests + protection of judicial independence + financial supervision (MFSA). S.L. 586.08 restrictions for Anti-Money Laundering Act + Companies Act + Customs Ordinance + Taxation. Maltese language right to receive responses in Maltese or English at subject choice. Right of access re

Artefacts an auditor will ask for
  • Subject rights request register with 1-month SLA evidence
  • IDPC complaint workflow + Tribunal Administrattiv appeal preparedness (Article 19)
  • S.L. 586.05 + 586.08 restriction invocation register with justification
  • Maltese-language response capability evidence
  • Court of Appeal (Inferior Jurisdiction) escalation plan
Where this commonly fails
  • No Maltese-language response capability
  • Tribunal Administrattiv appeal not anticipated
  • S.L. 586.05 restrictions invoked beyond statutory grounds

Enforcement and Remedies - Malta DPA

MT-DPA-Enforcement-IDPC-Administrative-Fines-Tribunal-Administrattiv-Article-14-19-Court-Appeal
Malta DPA Enforcement + IDPC Administrative Fines + Tribunal Administrattiv + Article 14 + 19 + Court of Appeal

Manage IDPC enforcement engagement + administrative fines + Tribunal appeal + Court of Appeal under Articles 14 + 19 Cap. 586. IDPC powers under Article 14 include investigation + information notices + enforcement notices + variation orders + ban orders + administrative fines aligned with GDPR Article 83 (up to EUR 20M or 4% global annual turnover whichever higher). National penalty discretion under S.L. 586.05 for public authorities (capped). Tribunal Administrattiv (Information and Data Protection Appeals Tribunal) appeal under Article 19 Cap. 586 + within 30 days of IDPC decision + three-member panel (Chairperson Judge + 2 members) + de novo review. Court of Appeal (Inferior Jurisdiction) final appeal on points of law within 20 days. Civil remedies under Article 82 GDPR for material and non-material damage. Criminal sanctions for IDPC obstruction + false statements under Article 18 Ca

Artefacts an auditor will ask for
  • IDPC enforcement notice tracking and remediation evidence
  • Administrative fine exposure assessment (up to EUR 20M or 4% turnover under Article 14 Cap. 586 + GDPR Article 83)
  • Tribunal Administrattiv (Article 19) appeal preparedness within 30 days
  • Court of Appeal (Inferior Jurisdiction) escalation plan
  • Article 18 Cap. 586 obstruction criminal exposure assessment
  • Article 82 GDPR civil claim preparedness
  • Public censure response plan
  • EDPB Article 60 cooperation documentation
Where this commonly fails
  • EUR 20M / 4% turnover exposure not refreshed annually
  • Tribunal Administrattiv 30-day appeal SLA not in incident-response plan
  • Article 18 obstruction criminal risk not flagged to legal
  • EDPB lead/concerned authority status for iGaming + MFSA cross-establishment not mapped

Governance DPO ROPA DPIA - Malta DPA

MT-DPA-Governance-DPO-Article-8-ROPA-DPIA-Codes-Article-15-IDPC-Registration-MFSA-Coordination
Malta DPA Governance + DPO Article 8 + ROPA + DPIA + Codes Article 15 + IDPC Registration

Operate Malta DPA governance structure including DPO designation + ROPA + DPIA + IDPC-registered Codes of Conduct + MFSA coordination. Article 8 Cap. 586 requires DPO designation for public authorities + large-scale processing + sensitive at scale + systematic monitoring. DPO independent + reports to highest management + contact published + IDPC notification. ROPA under GDPR Article 30 in English or Maltese with full controller and processor obligations. DPIA mandatory under GDPR Article 35 for high-risk processing + IDPC consultation under Article 36 for unmitigated high residual risk + IDPC DPIA List published 2018 amended 2024. Codes of Conduct under Article 15 Cap. 586 registered with IDPC for sectors (banking + insurance + iGaming + healthcare + private investigators + direct marketing + educational + journalism). Certification mechanisms under Article 42 GDPR + ILNAS accreditation

Artefacts an auditor will ask for
  • DPO designation letter + reporting line + IDPC notification + Article 8 Cap. 586 compliance
  • ROPA in English or Maltese + Article 30 GDPR completeness
  • DPIA register + IDPC consultation Article 36 records for high-risk
  • Registered Code of Conduct adherence (banking + insurance + iGaming + healthcare + journalism)
  • Certification under Article 42 GDPR via ILNAS-accredited certification body
  • Joint Council of Public Authority DPOs participation
Where this commonly fails
  • No DPO designated despite Article 8 Cap. 586 triggers
  • ROPA English-only and incomplete
  • IDPC DPIA List 2018 amended 2024 not consulted
  • Code of Conduct membership claimed but not registered

Scope and Authority - Malta DPA

MT-DPA-Scope-Cap-586-Kamra-Tad-Deputati-2018-Act-XX-2018-IDPC-Floriana-GDPR-Implementation-Constitutional
Malta DPA Scope + Cap. 586 + Kamra tad-Deputati 2018 + Act XX of 2018 + IDPC Floriana + GDPR Implementation

Establish the legal foundation of Malta Data Protection Act 2018 (Chapter 586 of the Laws of Malta) enacted by Kamra tad-Deputati 28 May 2018 + assent 4 June 2018 + Act XX of 2018 + effective 28 May 2018 alongside GDPR application. Foundational Maltese data protection statute implementing EU GDPR Regulation 2016/679 + LED Directive 2016/680 + replaces Data Protection Act 2001 (Cap. 440). Constitution of Malta Article 38 protection from arbitrary search and entry + Article 41 freedom of expression anchors. Maltese Civil Code Article 26 personality rights. Information and Data Protection Commissioner (IDPC) independent supervisory authority + Floriana headquarters (relocated from Hamrun) + Commissioner appointed by Prime Minister for 5-year term + EDPB member + Convention 108+ Committee. Sectoral coordination with Malta Financial Services Authority (MFSA) + Malta Gaming Authority (MGA) + C

Artefacts an auditor will ask for
  • Cap. 586 applicability assessment
  • Constitution Article 38 + 41 anchor documentation
  • IDPC correspondence records
  • Sectoral coordination memoranda (MFSA + MGA + Communications Authority + MITA + CIRT Malta)
  • Cross-establishment jurisdiction documentation for iGaming + MFSA + maritime
Where this commonly fails
  • No cross-establishment analysis for MGA-licensed or MFSA-passported activities
  • Confusion between Cap. 586 and Cap. 440 (repealed 2001 Act)
  • Missing IDPC notification of major changes

Security and Breach Notification - Malta DPA

MT-DPA-Security-Breach-Notification-IDPC-72-Hour-CIRT-Malta-MITA-NIS2-Cyber-Security-Act-2023
Malta DPA Security + Breach Notification + IDPC 72 Hour + CIRT Malta + MITA + NIS2 + Cyber Security Act 2023

Implement technical and organisational security measures + breach notification process aligned with GDPR Articles 32-34 + national CIRT coordination + NIS2 Cyber Security Act 2023. Security measures appropriate to risk including encryption + access controls + activity logging + secure development + supplier security + business continuity + workforce training. IDPC Security Standards Notice 2018 amended 2024 prescribes baseline measures. Breach notification within 72 hours to IDPC + concurrent affected data subject notification without undue delay where high risk + breach register maintenance + breach response plan + post-incident review. CIRT Malta coordination for cyber incidents under MITA umbrella + Cyber Security Malta national-CSIRT role + NIS2 transposition Cyber Security Act 2023 + critical infrastructure operators (banking + financial markets + healthcare + drinking water + digit

Artefacts an auditor will ask for
  • IDPC Security Standards Notice 2018 amended 2024 compliance evidence
  • 72-hour breach notification procedure + IDPC notification template
  • Affected data subject notification template + high-risk threshold determination
  • CIRT Malta coordination protocol + dual notification process for NIS2-covered operators
  • MFSA Cybersecurity Standards 2020 amended 2024 (financial)
  • MGA Information Security Policy (iGaming)
  • Tabletop exercise records
Where this commonly fails
  • No 72-hour notification capability
  • NIS2 dual notification (IDPC + Cyber Security Malta) not mapped
  • Cross-border critical infrastructure notification not coordinated via EU CSIRT Network
  • Encryption at rest not enforced for iGaming KYC + MFSA financial
Assembled from the framework's own control set. Every line traces to a control in the graph, so this pack is regenerated rather than written, and stays current as the graph does.

Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.