Data Protection and Privacy 2025

MALTA Law and Practice Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates

sioner may also delegate powers, including investigative powers, to the seconding supervi - sory authority during joint operations with super - visory authorities from other EU member states, provided these powers are exercised under the IDPC’s guidance and presence. The GDPR mandates the IDPC to co-operate on cases with a cross-border component to ensure consistent application of the GDPR, known as the one-stop shop mechanism. In the context of processing personal data in the electronic communications sector, the IDPC is authorised to seek advice from and, where appropriate, consult with the MCA while per - forming its functions. Article 7 of CAP 586 requires the IDPC to consult an ethics committee or an institution recognised by the IDPC when genetic data, biometric data or health data need to be processed for research purposes. Regarding the scope of investigations and audits by the key local regulator, local implementation legislation does not provide significantly more than what is outlined under the GDPR (complaint basis, Article 57, and ex officio, Article 58), simi - lar to other EEA jurisdictions. Scope of Data Protection Authority Investigations and Audits CAP 586 mandates that the Commissioner, as the national supervisory authority, performs the duties assigned under the GDPR (Article 15 of the GDPR). From a domestic law perspective, the Commissioner’s role includes handling com - plaints from third parties with locus standi and exercising the power and duty to investigate ex officio and implement corrective measures. This scope does not extend significantly beyond the

provisions of Articles 57 and 58 of the GDPR (Article 15(2) of the GDPR). Artificial Intelligence (AI) The pertinent regulator for AI matters would be the Malta Digital Innovation Authority (MDIA), established by the Malta Digital Innovation Authority Act, Chapter 591 of the Laws of Malta (MDIAA). The MDIAA stipulates that the MDIA shall endeavour to assist the competent data protection authorities as required by law (Article 4 (2) (h)). 1.3 Enforcement Proceedings and Fines Domestic Administrative and Enforcement Process Aside from the relevant GDPR articles, Maltese law does not provide extensive detail on the administrative procedures the IDPC must follow or the legal standards and criteria for evaluat - ing the merits of an investigation; these aspects are largely left to the Commissioner’s discre - tion. Consequently, the primary reference is the “duties assigned to him” under Article 15 of CAP 586. Moreover, when making decisions, the Commis - sioner “...may seek the advice of, and may con - sult with, any other competent authority in the exercise of his functions under this Act and the Regulation” (Article 15.3 of CAP 586). Regarding the legal standards and criteria that empower the Commissioner to take action, Arti - cle 15(2) of CAP 586 specifies that the “Commis - sioner shall have the power to institute civil judi - cial proceedings in cases where the provisions of this Act or the Regulation have been or are about to be violated”. The applicable law estab - lishes an objective statutory standard rather than a subjective interpretation, focusing on the Com - missioner’s discretion or the level of likelihood.

306 CHAMBERS.COM

Powered by