MALTA Law and Practice Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates
Typical issues encountered include the absence of written policies governing data protection and non-reported data breaches. Parties may opt to enter into an indemnification agreement whereby the vendor would need to reimburse any fine(s) suffered by the purchaser for data protection non-compliance following acquisition. However, this does not account for an increase in insurance premiums in cases where the data protection due diligence results in existing insufficiencies and a high risk of fines. 5. International Considerations 5.1 Restrictions on International Data Transfers Further to EU data protection law, personal data that is attributable to a person within the EU or that is processed within the EU may be trans - ferred freely within the EU territory. This may also occur in respect to third countries and interna - tional organisations if the processing to occur within such countries or organisation is able to comply with the GDPR’s requirements, ensuring adequate safeguards in terms of Chapter 5 of the GDPR. Furthermore, the “appropriate safeguards” requirement may be met by virtue of a num - ber of legitimising instruments, as delineated in the GDPR – notably, a Commission adequacy, standard contractual clauses (SCCs), binding corporate rules (BCRs) or other legally binding instruments (Article 46 of the GDPR). Mechanisms or Derogations That Apply to International Data Transfers Multilateral agreements in place by virtue of the EU may be applicable for the benefit of Malta and therefore may facilitate cross-border trans -
fers of data to third countries in satisfying the GDPR’s appropriate safeguards element. In this respect, the EU-US adequacy decision issued in July 2023 effectively acts to fill in the gap for the EU-US Privacy Shield that was invali - dated by the CJEU in 2016, and hence facilitates the unhindered flow of data across the Atlantic. 5.2 Government Notifications and Approvals In the EU data protection law sphere, notifica - tions to one’s authority are not currently required in terms of third-country transfers. Appropriate safeguards in terms of the GDPR must be in place vis-à-vis the recipient third country where no adequacy decision for such exists. 5.3 Data Localisation Requirements In terms of Maltese company law, certain pre - scribed company-related records must be kept at the company’s registered office in Malta. How - ever, this pertains to the originals in question, so such data may be transferred overseas insofar as such transfer complies with the application legislation, such as being done in accordance with the appropriate safeguards legitimising the regime of third countries or if the transfer does not breach any other law or legal agreement, such as client privilege or a non-disclosure, confidentiality agreement, with the original copy remaining at the registered office. 5.4 Blocking Statutes As a member state of the EU, Malta is subject to Council Regulation 2271/96 of 22 November 1996, which protects against the effects of the potential extraterritorial application of legislation adopted by a third country, and actions based thereon or resulting therefrom. This consequent - ly protects EU operators from the reach of a third country’s extraterritoriality jurisdiction, which
312 CHAMBERS.COM
Powered by FlippingBook