MALTA Law and Practice Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates
Judicial Review of Data Protection Authority Orders Under Maltese law, prior to the imposition of a decision by the Commissioner, the parties are heard or asked to make submissions, at the investigation stage. If the respondent disagrees with the decision reached by the Commissioner, they may file an appeal with the Data Protec - tion Appeals Tribunal within 20 days of service of such decision, insofar as it is made on the following substantive grounds (Article 26 of CAP 586): • a material error as to the facts has been made; • there was a material procedural error; • an error of law has been made; or • there was some material illegality, including unreasonableness or lack of proportionality. The appeal procedure before the Data Protec - tion Appeals Tribunal is undertaken in accord - ance with Article 26 of CAP 586, which sets out the various formalities to be observed by the appellant, the tribunal and its registry, such as time limits and the serving/submission of perti - nent legal documents. If the parties (including the IDPC) are aggrieved with an appeal decision by the Data Protection Appeals Tribunal, they may resort to the Court of Appeal, on a question of law, as constituted by Article 41(9) of the Code of Organisation and Civil Procedure, Chapter 12 of the Laws of Mal - ta, as per Article 29 of CAP 586. 1.4 Data Protection Fines in Practice Fines and Penalties Under the GDPR, the maximum penalty for non- compliance is either EUR20 million or 4% of worldwide turnover, whichever is higher (Article 83 of the GDPR). Although the Malta Data Pro -
tection Act does not specify the administrative fines that the IDPC may impose for GDPR viola - tions, the GDPR’s provisions are directly appli - cable. Therefore, the IDPC can enforce the fines outlined in Article 83 of the GDPR. In addition, and without prejudice to the above, the Data Protection Act stipulates that any indi - vidual found guilty of certain offences will face penalties. These offences include knowingly providing false information to the IDPC during an investigation, and failing to comply with any lawful request from the IDPC. Conviction for these offences can result in a fine ranging from EUR1,250 to EUR50,000, imprisonment for up to six months, or both. Furthermore, violations of SL 586.01 (the Pro - cessing of Personal Data (Electronic Commu - nications Sector) Regulations, which implement the ePrivacy Directive) are subject to administra - tive fines. These fines can be up to EUR23,293.73 for each violation and EUR2,329.37 for each day the infringement continues. The IDPC is respon - sible for determining and imposing these fines. 1.5 AI Regulation There is currently no Maltese law that defines “artificial intelligence” but, as Malta is an EU member state, the anticipated and proposed EU AI Act will cover this domain. Malta is set to implement the EU Artificial Intelligence Act (AI Act), which entered into force on 1 August 2024 and represents a significant step into regulating AI. The Act undertakes a risk-based approach and aims to implement transparency and accountability, human oversight and data governance over AI systems. The EU AI Act and the GDPR are designed to work together. While the AI Act focuses on the safe development and use of AI systems, the
307 CHAMBERS.COM
Powered by FlippingBook