MALTA Law and Practice Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates
spaces or third-party properties, whereby the authority ordered the controller to stop process - ing operations and remove the camera. The only administrative fine issued in 2024 by the IDPC was a EUR15,000 fine in relation to a data pro - tection complaint against two direct unsolicited marketing phone calls (two years apart) after several complaints to stop the processing of personal data by the data subject towards the controller. In such a case, the authority found that the controller infringed Articles 21 (2) and 5 (2) of the GDPR. The IDPC noted that the length and repeated nature of infringement increased the gravity of the breach and further warranted an administrative fine be applied (Article 82). The authority also noted that the way in which the infringement occurred revealed a certain amount of negligence on the controller’s part since the controller’s system failed to erase the com - plainant’s telephone number from its systems after several complaints to erase the complain - ant’s personal data and following reassurance that such measures had been taken, and thus infringed Article 21(2) of the GDPR. Another interesting decision taken in 2024 by the IDPC involved a balancing test between one’s right to privacy and the right to freedom of expression, particularly journalistic expression. In this decision, the alleged breach regarded the publishing of 200 pages of WhatsApp chat conversations between the complainant and a third party, which was consequently published through a blog post found on a blogger’s web - site. The IDPC needed to take into consideration the right to one’s private life and reconcile an eventual court ban on the publication of such chats with the right to freedom of expression and the right of public interest in relation to persons and information that are deemed to be in the public eye and published in virtue of maintain - ing a democratic society. In its final decision, the
IDPC decided that, although the right to jour - nalistic expression is a fundamental right, the controller of such information should have con - ducted a fundamental assessment and carefully removed parts containing intimate personal data (for example, sexual relations of the complain - ant). It decided that the controller had failed to demonstrate proportionate, necessary and justi - fied reasons for substantial public interest as the reason for publishing, and thus deemed the pro - cessing unlawful. As a consequence, the IDPC ordered the controller to erase the blog post. 2.3 Collective Redress Mechanisms Class actions do exist in Malta, under the Collec - tive Proceedings Act (Chapter 520 of the Laws of Malta, as it stood before the 2023 amend - ments), but this legislation has faced challenges in its application before the Maltese courts since data protection claims, for example, do not fall under such statute. However, a collective claim is possible in respect of data protection matters in light of Maltese Civil Procedure, which has been termed by court jurisprudence as azzjoni kollettiva or a “cumulative action”. This was in fact the basis for the collective claim of C-Planet in 2022; the case concerned the data leak of sensitive personal data pertaining to citizens’ political leanings and association, which, in the jurisdiction in question, is an immensely delicate issue. Nevertheless, the Representative Actions Act (Directive (EU) 2020/1828 of 25 November 2020) is designed to provide a more robust legal framework, and is expected to enhance the effectiveness of collective actions by quali - fied entities in court. Essentially, the Representa - tive Actions Directive requires member states to implement a harmonised procedural framework to permit consumer class actions where a party
309 CHAMBERS.COM
Powered by FlippingBook