What Is Data Protection Act, Chapter 586?
Malta’s Data Protection Act, Chapter 586, was enacted through Act XX of 2018 and commenced on 28 May 2018, repealing and replacing Chapter 440. GDPR applies directly, while Chapter 586 and subsidiary legislation supply institutional rules, national choices, restrictions, derogations, and sector-specific provisions. The identified amendments are Act XII of 2021 and Legal Notice 212 of 2023; the latter substituted references to the Attorney General with references to the State Advocate and was not a substantive GDPR-rights amendment. Malta’s Section 9 expression derogation is notably granular. It applies to specified GDPR sub-paragraphs rather than whole articles, including only Articles 13(1)-(3), 14(1)-(4), 15(1)-(3), 17(1)-(2), 18(1)(a), (b), and (d), 20(1)-(2), and 21(1). Articles not listed remain subject to GDPR, and the derogation requires incompatibility with the expression purpose, necessity, proportionality, and substantial public interest. No Malta-specific data-broker complaint, deletion, opt-out, or public-record-specific deletion route was located. The identified routes are ordinary GDPR rights against the relevant controller and the general IDPC complaint process.
At a glance
- Full name
- Data Protection Act, Chapter 586
- Short code
- Chapter 586
- Jurisdiction
- Malta
- Enacted
- 2018
- Last major update
- Act XII of 2021 and Legal Notice 212 of 2023; Legal Notice 212 of 2023 substituted references to the Attorney General with references to the State Advocate and was not a substantive GDPR-rights amendment
- Regulator
- Information and Data Protection Commissioner (IDPC)
- Private right of action
- Limited
- Statutory citation
- Data Protection Act, Chapter 586, Act XX of 2018
Scope, who Chapter 586 covers
Protected data
Data subject rights
Right to transparency and information under GDPR Article 12, subject to specified Article 23 restrictions
Right to information under Articles 13 and 14, with Malta’s Section 9 derogation limited to the listed sub-paragraphs
Right of access under Article 15, with Section 9 limited to paragraphs 15(1)-(3)
Right to rectification under Article 16, subject to research, statistics, and public-interest archiving derogations
Right to erasure under Article 17, subject to GDPR exceptions and Section 9’s limited expression derogation
Right to restriction under Article 18, subject to listed Section 9 sub-paragraphs
Right to data portability under Article 20, subject to Section 9 paragraphs 20(1)-(2)
Right to object under Article 21, with Section 9 listing paragraph 21(1) but not the direct-marketing-specific paragraphs
Right to complain to the Commissioner and challenge decisions before the Information and Data Protection Appeals Tribunal and subsequently the Court of Appeal
Notable features
Malta’s Section 9 expression derogation is unusually precise, operating at the sub-paragraph level and not creating an unrestricted deletion right for journalistic, academic, artistic, or literary material. Malta also has a distinctive territorial rule covering a Maltese embassy or high commission abroad and a public-international-law hook. The penalty framework includes a narrow public-authority-only cap separate from the general GDPR Article 83 structure.
Enforcement & penalties
Regulator: Information and Data Protection Commissioner (IDPC)
Penalties: Chapter 586 Section 20 provides the fine-imposition mechanism, while GDPR Article 83 supplies the general structure: up to €10 million or 2% of worldwide turnover for the lower tier and up to €20 million or 4% for the upper tier. A narrow Malta-specific cap applies only to public authorities or bodies: up to €25,000 per Article 83(4) violation plus possible €25 per day while ongoing, and up to €50,000 per Article 83(5) or (6) violation plus possible €50 per day. These caps do not apply to ordinary controllers or processors. Knowingly providing false information to the Commissioner or failing to comply with a lawful investigation request is a criminal offence punishable by a fine of €1,250-€50,000, imprisonment of up to 6 months, or both.
Private right of action: The GDPR Article 78(2) judicial-remedy trigger after 3 months without progress or outcome information applies, together with appeals before the Information and Data Protection Appeals Tribunal and subsequently the Court of Appeal; no separate Malta-specific general private-action route was identified.
Relevance to data brokers
No Malta-specific data-broker complaint, deletion, opt-out, or public-record-specific deletion route was located. The identified routes are ordinary GDPR rights against the relevant controller and the general IDPC complaint process. The Freedom of Information Act governs public-authority information access but is not a dedicated data-broker deletion mechanism.
Generate requests in under 60 seconds
Generate removal requests for 1,034 US/global profiles, $9
FAQ
Does Malta have a dedicated data-broker deletion route?+
Not located. The identified mechanisms are ordinary GDPR rights against the relevant controller and the general IDPC complaint process.
Does Malta’s expression derogation create an unrestricted deletion right?+
No. Section 9 may derogate from specified GDPR provisions, including parts of Article 17, where compliance would be incompatible with the expression purpose and the processing is necessary, proportionate, and justified by substantial public interest.
Is there a fixed deadline for IDPC to resolve a complaint?+
No fixed statutory deadline located. The 3-month period under GDPR Article 78(2) is an information or judicial-remedy trigger, not a guaranteed final-decision deadline.
Official sources & citations
Other international privacy regimes
Chapter 586 sits in a global ecosystem of data-protection laws. Compare with other jurisdictions that shape cross-border data flows:
