Malta Data Protection Act (Cap. 586, 2018)
Evidence request list. 8 controls, 8 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 12 September 2026. Published by The Art of Service.
Bilingual Notices and Subsidiary Legislation - Malta DPA
Provide privacy notices in Maltese and English (both constitutional official languages under Constitution Article 5) + comply with Subsidiary Legislation suite governing sector-specific processing. Subsidiary Legislation 586.01 Processing in Education Sector (school records + e-skola platform) + 586.02 Police Sector + 586.03 Data Protection in Police Sector + 586.04 Competent Authorities for Criminal Matters (LED transposition) + 586.05 Restriction of the Data Protection Act + 586.06 Journalistic Artistic and Literary Purposes (Article 85 GDPR derogation) + 586.07 Processing Children Data in Information Society Services (Article 8 GDPR + Malta age 13) + 586.08 Restriction of Application + 586.09 Secondary Processing. Direct marketing under IDPC Cookie Guidelines + Electronic Communications (Regulation) Act + Communications Authority coordination. Cookie consent + behavioural advertising
- Maltese and English privacy notices (both constitutional languages under Constitution Article 5)
- S.L. 586.01-09 sector applicability assessment + compliance records
- IDPC Cookie Guidelines compliance + cookie consent management
- Direct marketing opt-out infrastructure under Electronic Communications (Regulation) Act
- MGA Player Protection Directive cross-walk for iGaming communications
- English-only notices breach Constitution Article 5 + IDPC guidance
- S.L. 586.06 journalism derogation invoked without basis
- Cookie consent not granular per IDPC 2024 guidance
Children and Sensitive Categories - Malta DPA
Process children data and sensitive personal data under Maltese-specific provisions. Article 7 Cap. 586 sets digital consent age at 13 (LOWER than GDPR default 16 - among lowest in EU alongside Belgium + Estonia + Finland + Portugal + Sweden + Cyprus) + parental responsibility under Article 8 GDPR for under 13 + S.L. 586.07 Processing Children Data in Information Society Services. iGaming-specific child protection under MGA Player Protection Directive + Responsible Gaming Code + age verification with documentary proof + self-exclusion register. Sensitive categories under GDPR Article 9 (health + religion + political + sexual orientation + biometric + genetic + trade union + ethnic) require explicit consent or narrow exceptions. Maltese employment law derogations under Employment and Industrial Relations Act. Health processing under Department of Health + Medical Council. Financial sensit
- Children processing inventory + age 13 verification + parental consent for under-13 + S.L. 586.07 compliance
- Sensitive categories inventory + explicit consent records or Article 9 lawful basis documentation
- MGA Player Protection Directive + Responsible Gaming Code compliance evidence (for iGaming operators)
- MFSA Conduct of Business Rules compliance (financial)
- Self-exclusion register integration
- Age 16 default used despite Malta age 13 (compliance burden inverted)
- iGaming KYC sensitive categories not Article 9 grounded
- Self-exclusion register data not protected with appropriate security
Cross-Border Transfer - Malta DPA
Govern cross-border data transfers under GDPR Chapter V particularly critical due to Malta as EU cross-establishment jurisdiction for iGaming + financial services + maritime registry. Free transfers within EEA + adequacy decisions (UK + Switzerland + Japan + Korea + Canada commercial + Israel + Argentina + Uruguay + New Zealand + Andorra + Faroe Islands + Guernsey + Isle of Man + Jersey + EU-US Data Privacy Framework 2023). 2021 EU Standard Contractual Clauses (Module 1-4) post-Schrems II Transfer Impact Assessment requirement particularly for US transfers post Schrems II 2020. Binding Corporate Rules under Article 47 GDPR with IDPC as lead reviewer for Malta-headquartered groups. Derogations under Article 49 GDPR for specific situations. iGaming-specific cross-border data flows due to MGA-licensed operators serving EU+UK+third-country players - MGA Player Account information + KYC + AML
- Cross-border transfer register + 2021 EU SCC + adequacy decision basis
- Transfer Impact Assessment for US transfers post Schrems II
- BCR documentation with IDPC as lead reviewer
- iGaming-specific cross-border player data flow documentation (MGA-licensed serving EU+UK+third-country players)
- MFSA financial services passporting cross-walk
- EDPB cooperation under Article 60 documentation
- No Transfer Impact Assessment post-Schrems II for US transfers
- iGaming MGA-licensee cross-border flows not 2021-SCC-papered
- MFSA passporting cross-border not assessed
- IDPC not engaged as BCR lead reviewer
Data Subject Rights - Malta DPA
Provide channels for data subjects to exercise GDPR Chapter III rights + IDPC complaint mechanism under Article 12 + Maltese-specific restrictions under S.L. 586.05 and 586.08. Free of charge IDPC complaints procedure with 6-month response target + Tribunal Administrattiv (Information and Data Protection Appeals Tribunal) appeal mechanism under Article 19 + Court of Appeal (Inferior Jurisdiction) final appeal. National derogations under S.L. 586.05 restricting subject rights for national security + defence + public security + criminal investigation + prevention of breaches of professional ethics + economic interests + protection of judicial independence + financial supervision (MFSA). S.L. 586.08 restrictions for Anti-Money Laundering Act + Companies Act + Customs Ordinance + Taxation. Maltese language right to receive responses in Maltese or English at subject choice. Right of access re
- Subject rights request register with 1-month SLA evidence
- IDPC complaint workflow + Tribunal Administrattiv appeal preparedness (Article 19)
- S.L. 586.05 + 586.08 restriction invocation register with justification
- Maltese-language response capability evidence
- Court of Appeal (Inferior Jurisdiction) escalation plan
- No Maltese-language response capability
- Tribunal Administrattiv appeal not anticipated
- S.L. 586.05 restrictions invoked beyond statutory grounds
Enforcement and Remedies - Malta DPA
Manage IDPC enforcement engagement + administrative fines + Tribunal appeal + Court of Appeal under Articles 14 + 19 Cap. 586. IDPC powers under Article 14 include investigation + information notices + enforcement notices + variation orders + ban orders + administrative fines aligned with GDPR Article 83 (up to EUR 20M or 4% global annual turnover whichever higher). National penalty discretion under S.L. 586.05 for public authorities (capped). Tribunal Administrattiv (Information and Data Protection Appeals Tribunal) appeal under Article 19 Cap. 586 + within 30 days of IDPC decision + three-member panel (Chairperson Judge + 2 members) + de novo review. Court of Appeal (Inferior Jurisdiction) final appeal on points of law within 20 days. Civil remedies under Article 82 GDPR for material and non-material damage. Criminal sanctions for IDPC obstruction + false statements under Article 18 Ca
- IDPC enforcement notice tracking and remediation evidence
- Administrative fine exposure assessment (up to EUR 20M or 4% turnover under Article 14 Cap. 586 + GDPR Article 83)
- Tribunal Administrattiv (Article 19) appeal preparedness within 30 days
- Court of Appeal (Inferior Jurisdiction) escalation plan
- Article 18 Cap. 586 obstruction criminal exposure assessment
- Article 82 GDPR civil claim preparedness
- Public censure response plan
- EDPB Article 60 cooperation documentation
- EUR 20M / 4% turnover exposure not refreshed annually
- Tribunal Administrattiv 30-day appeal SLA not in incident-response plan
- Article 18 obstruction criminal risk not flagged to legal
- EDPB lead/concerned authority status for iGaming + MFSA cross-establishment not mapped
Governance DPO ROPA DPIA - Malta DPA
Operate Malta DPA governance structure including DPO designation + ROPA + DPIA + IDPC-registered Codes of Conduct + MFSA coordination. Article 8 Cap. 586 requires DPO designation for public authorities + large-scale processing + sensitive at scale + systematic monitoring. DPO independent + reports to highest management + contact published + IDPC notification. ROPA under GDPR Article 30 in English or Maltese with full controller and processor obligations. DPIA mandatory under GDPR Article 35 for high-risk processing + IDPC consultation under Article 36 for unmitigated high residual risk + IDPC DPIA List published 2018 amended 2024. Codes of Conduct under Article 15 Cap. 586 registered with IDPC for sectors (banking + insurance + iGaming + healthcare + private investigators + direct marketing + educational + journalism). Certification mechanisms under Article 42 GDPR + ILNAS accreditation
- DPO designation letter + reporting line + IDPC notification + Article 8 Cap. 586 compliance
- ROPA in English or Maltese + Article 30 GDPR completeness
- DPIA register + IDPC consultation Article 36 records for high-risk
- Registered Code of Conduct adherence (banking + insurance + iGaming + healthcare + journalism)
- Certification under Article 42 GDPR via ILNAS-accredited certification body
- Joint Council of Public Authority DPOs participation
- No DPO designated despite Article 8 Cap. 586 triggers
- ROPA English-only and incomplete
- IDPC DPIA List 2018 amended 2024 not consulted
- Code of Conduct membership claimed but not registered
Scope and Authority - Malta DPA
Establish the legal foundation of Malta Data Protection Act 2018 (Chapter 586 of the Laws of Malta) enacted by Kamra tad-Deputati 28 May 2018 + assent 4 June 2018 + Act XX of 2018 + effective 28 May 2018 alongside GDPR application. Foundational Maltese data protection statute implementing EU GDPR Regulation 2016/679 + LED Directive 2016/680 + replaces Data Protection Act 2001 (Cap. 440). Constitution of Malta Article 38 protection from arbitrary search and entry + Article 41 freedom of expression anchors. Maltese Civil Code Article 26 personality rights. Information and Data Protection Commissioner (IDPC) independent supervisory authority + Floriana headquarters (relocated from Hamrun) + Commissioner appointed by Prime Minister for 5-year term + EDPB member + Convention 108+ Committee. Sectoral coordination with Malta Financial Services Authority (MFSA) + Malta Gaming Authority (MGA) + C
- Cap. 586 applicability assessment
- Constitution Article 38 + 41 anchor documentation
- IDPC correspondence records
- Sectoral coordination memoranda (MFSA + MGA + Communications Authority + MITA + CIRT Malta)
- Cross-establishment jurisdiction documentation for iGaming + MFSA + maritime
- No cross-establishment analysis for MGA-licensed or MFSA-passported activities
- Confusion between Cap. 586 and Cap. 440 (repealed 2001 Act)
- Missing IDPC notification of major changes
Security and Breach Notification - Malta DPA
Implement technical and organisational security measures + breach notification process aligned with GDPR Articles 32-34 + national CIRT coordination + NIS2 Cyber Security Act 2023. Security measures appropriate to risk including encryption + access controls + activity logging + secure development + supplier security + business continuity + workforce training. IDPC Security Standards Notice 2018 amended 2024 prescribes baseline measures. Breach notification within 72 hours to IDPC + concurrent affected data subject notification without undue delay where high risk + breach register maintenance + breach response plan + post-incident review. CIRT Malta coordination for cyber incidents under MITA umbrella + Cyber Security Malta national-CSIRT role + NIS2 transposition Cyber Security Act 2023 + critical infrastructure operators (banking + financial markets + healthcare + drinking water + digit
- IDPC Security Standards Notice 2018 amended 2024 compliance evidence
- 72-hour breach notification procedure + IDPC notification template
- Affected data subject notification template + high-risk threshold determination
- CIRT Malta coordination protocol + dual notification process for NIS2-covered operators
- MFSA Cybersecurity Standards 2020 amended 2024 (financial)
- MGA Information Security Policy (iGaming)
- Tabletop exercise records
- No 72-hour notification capability
- NIS2 dual notification (IDPC + Cyber Security Malta) not mapped
- Cross-border critical infrastructure notification not coordinated via EU CSIRT Network
- Encryption at rest not enforced for iGaming KYC + MFSA financial
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does.