Data Protection and Privacy 2025

MALTA Law and Practice Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates

4.2 Personalised Advertising and Other Online Marketing Practices The applicable Maltese subsidiary legislation regarding online marketing (SL.586.01) is in line with the ePrivacy Directive. 4.3 Employment Privacy Law In relation to workplace or employment law con - siderations, Maltese law does not provide any specific regulatory framework further to EU data protection law. In this respect, therefore, from an employment relationship point of view, as there is a disparity in power dynamics between the employer and the employee, consent cannot be relied upon as a lawful basis for processing, so contract perfor - mance is utilised. The employer may also qualify the ground of legitimate interest within a contract of employ - ment, in relation to certain matters. Nevertheless, as an EU member state, Malta is subject to EU jurisprudence and is a contracting party to the ECHR. In this respect, the 2017 judgment of the European Court of Human Rights in Bărbulescu v Romania, which related to the monitoring of an employee’s personal data, established that such monitoring of employees may be carried out in compliance with applicable legislation if it is done in a transparent manner as provided by law. Under Maltese employment law, it may be inferred that the employer has a legitimate rea - son to ascertain whether the agreed “hours of work” are duly undertaken. Accordingly, further to the above judgment, a degree of proportion - ality and due informed notice and explanation must be undertaken, with the adoption of the least intrusive monitoring and adequate safe -

guards and, last but not least, the qualification of legitimacy in justifying such monitoring. Previous provisions addressing certain time/ record-keeping matters in relation to employ - ment-related data have now been repealed. In Malta, the Whistleblower Act, Chapter 527 of the Laws of Malta, was enacted in 2013 with the intention of encouraging employees to flag workplace malpractice or illegality encoun - tered or observed. Data protection wrongdoing is included in such legislation, given the wide scope of “improper practice” defined therein. Therefore, employees may raise the issue of pri - vacy and data protection infringements occur - ring within the organisation discreetly. 4.4 Transfer of Personal Data in Asset Deals Malta does not have specific laws in relation to data protection in due diligence exercises for asset deals, but it is subject to the GDPR, which stipulates indirect obligations in this respect. In corporate and M&A transactions, the acquir - ing entity is typically interested in carrying out a due diligence exercise to understand the entity with which they are planning to do business (ie, whether it is and has been compliant with laws such as data protection) and to understand the inherent risk of the seller’s data assets. Whilst this may be desirable for an acquiring entity before it inherits unlawfully obtained or processed data, Article 28(1) of the GDPR mandates an obliga - tion for controllers to ensure that the processors being engaged provide sufficient guarantees that their processing meets the GDPR standards and requirements, in addition to guaranteeing the protection of data subjects’ rights.

311 CHAMBERS.COM

Powered by