Doing Business In..._2026

GIBRALTAR Law and Practice Contributed by: Emma Lejeune, Stuart Dalmedo, Adrian Pilcher, Nicholas Isola, Danielle Victor, James Castle, Louise Anne Turnock and Danielle Curtis, ISOLAS LLP

the Communications (Personal Data and Privacy) Regulations 2006 (CPDP Regulations), made under the Communications Act 2006; and • the Data Protection (Search and Seizure) Regula - tions 2006 (DPSS Regulations). The Communications Act 2006, together with the CPDP Regulations, transpose the E-Privacy Direc - tive (Directive 2002/58/EC), imposing obligations on publicly available electronic communications services providers and users when they process personal data. The DPSS Regulations, among other things, authorise justices of the peace to issue warrants to the supervi - sory authority (see 8.3 Role and Authority of the Data Protection Agency ) in certain circumstances, allowing them to enter premises, inspect and seize as required. 8.2 Geographical Scope Both the EU GDPR and Gibraltar GDPR have what is referred to as “extraterritorial effect”, in that, respec - tively, the EU GDPR can apply outside the EU, and the Gibraltar GDPR can apply outside Gibraltar. This is achieved in a similar manner in both pieces of leg - islation. Focusing on Gibraltar, the territorial scope of the Gibraltar GDPR can extend to any of the following situations. • Where a controller/processor has an “establish - ment” in Gibraltar and processing occurs “in the context of the activities” of that establishment. This applies regardless of whether the processing occurs in Gibraltar or not. • Where goods or services are offered to data sub - jects in Gibraltar, irrespective of whether payment is required by a non-Gibraltar controller/proces - sor. There should be an element of targeting and other evidence will be considered, such as whether consumers are able to pay in their local currency, or whether a marketing campaign has taken place. This test is also not limited by citizenship or resi - dency of the data subjects. • Where the monitoring of behaviour of data subjects in Gibraltar is carried out by a non-Gibraltar con - troller/processor. Examples of monitoring would be predicting trends, or use of geo-location.

• Where a controller is not established in Gibraltar, but in a place where Gibraltar law applies by virtue of public international law. Under Article 27 of the Gibraltar GDPR, controllers and processors established outside of Gibraltar would need to consider the appointment of a local repre - sentative in Gibraltar, if they are offering goods or ser - vices or monitoring the behaviour of data subjects in Gibraltar. Controllers and processors based in Gibraltar offering goods or services or monitoring the behaviour of data subjects in the EU are subject to the EU GDPR, and will need to consider their obligations in that context. In particular, until the issue of adequacy is decided by the European Commission in respect of Gibraltar, appropriate safeguards (eg, such as standard con - tractual clauses) would need to be considered prior to a data transfer from Gibraltar to the EU or vice versa, given that, at the time of writing, Gibraltar is consid - ered as a “third country” for the purposes of Chapter V of the EU GDPR. 8.3 Role and Authority of the Data Protection Agency The DPA 2004 designates the Gibraltar Regulatory Authority (GRA) as the Information Commissioner. The GRA is an independent statutory body responsi - ble for the enforcement of the DPA 2004, as read with the Gibraltar GDPR, and its primary role as Informa - tion Commissioner is to uphold the privacy rights of individuals. Under changes made to the DPA 2004, the GRA now has increased regulatory powers under that Act, as well as those granted under Article 58 of the Gibraltar GDPR. These powers are classed as “investigative”, “corrective” and “authorisation and advisory”, allow - ing the Information Commissioner to, among other things: • bring or defend legal actions in Gibraltar or other courts; • co-operate with and render assistance to supervi - sory authorities in other states of territories; • conduct data protection compliance audits;

404 CHAMBERS.COM

Powered by