MALTA Trends and Developments Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates
Data Protection and Privacy in Malta: an Overview Data protection authority decisions in Malta Over the past few years, there has been an increase in the number of enforcements and decisions passed by the Information and Data Protection Commissioner (IDPC or “Commis - sioner”) in connection with infringements of data protection law. The IDPC issued more decisions in 2024 than in 2023, reflecting the exponen - tial trajectory for enforcement measures by the IDPC. 2024 also saw the first decision that was instituted ex officio rather than by virtue of a public complaint – ie, by the IDPC’s own voli - tion and within its regulatory scope. The majority of the decisions published by the IDPC relate mainly to an infringement of the data subjects’ rights to their personal data in terms of Article 15 (and Article 17) of the EU General Data Protection Regulation (GDPR), and to the unlawful processing of personal data pursuant to Article 6 of the GDPR. Right of access Over recent months, several claims and com - plaints have been lodged with the IDPC con - cerning the infringement of data subject access right requests. The vast majority of these have been centred around the right of access to per - sonal data, as per Article 15 of the GDPR. How - ever, interestingly, several claims made in 2024 pertained to right to access requests that were denied by the controller, based on the belief that the request for data was predominantly aimed at facilitating litigation as found under regula - tion 4(e) of the Restriction of the Data Protection (Obligation and Rights) Regulations, Subsidiary Legislation 586.09. In its examination of such cases, the Commis - sioner noted that the controller cannot apply
such derogation based on an “assumption” that the complainant may be requesting such infor - mation in order to institute a legal action. In fact, in its decisions the Commissioner emphasised that said derogation and the right of data sub - jects can only be restricted “for… defence of a legal claim and for legal proceedings” (Article 4(e) of SL 586.09). Therefore, the restriction shall only apply if it is necessary for the controller to defend an actual legal claim and legal proceed - ings that may subsequently be instituted under any law. In such cases, the Commissioner noted that the controllers failed to provide evidence during the IDPC’s investigation to effectively demon - strate that the complainant brought a legal claim against it, and therefore the derogation was applicable. Thus, the Commissioner ordered the controller to comply with the request and provide the complainant with the information requested as underpinned in Article 15 of the GDPR. The IDPC has already issued its first decision for 2025, regarding a data subject’s right to access their personal data from a bank acting as the data controller. Once again, the fundamental right of the data subject, as underpinned in Arti - cle 15(1)(a) to (h) of the GDPR and, where appli - cable, Article 15(2), and access to copy of the personal data undergoing processing in accord - ance with Article 15(3) of the GDPR, formed the legal basis for the request. However, after the complainant was informed that he had received “all” data in relation to himself, the complain - ant further requested that he also be provided with any internal correspondence at the bank that included his personal data. The controller denied this request on the basis of Article 15(4) of the GDPR. The Commissioner noted that the bank continued to provide contradictory state -
316 CHAMBERS.COM
Powered by FlippingBook