MALTA Trends and Developments Contributed by: Antonio Ghio, Paul Gonzi and Rebecca Iversen, Fenech & Fenech Advocates
Recent case law: illegal processing of electoral data and voter preferences The Civil Courts of Malta are currently hearing a collective action (similar in scope to a class action) regarding the illegal processing of per - sonal data (including voter preferences). The case was instituted after a Maltese service pro - vider (C-Planet) that provided technology ser - vices to a number of entities in Malta suffered a massive data breach. The impacted data, released on the internet, included a database containing the details of all Maltese citizens who are eligible to vote as well as their voting prefer - ences, thereby including special category data. When called to testify by the plaintiffs, the Malta Electoral Commission confirmed that part of this database comprised the electoral register. However, the affected database also contained various other data fields, such as telephone numbers, but also voting preferences, which are not typically part of the electoral database. It appears therefore that there had been an amal - gamation of various data sources. Whilst the case is still ongoing, there have been several local reports that this database has been in use extensively by the Labour party (the party currently in government) to award government jobs and to check the political orientation of pro - spective government employees. The case has been instituted by more than 500 Maltese citizens, who are being assisted by the NGOs Daphne Caruana Galizia Foundation and Repubblika. The current civil case is seeking damages against the service provider that suf - fered the data breach and also against the third parties who actually created the database itself. Through its investigations and eventual decision, the IDPC has already found the service provider
the information is necessary to defend an actual legal claim instituted against the controller. The IDPC decided that the controller had failed to provide a legal defence for retaining the person - al data and refuting erasure, and had therefore breached Article 17(1) and was ordered to erase the personal data of the complainant. Unlawful processing In 2024, similar to 2023, the IDPC continued to receive complaints of infringements regarding the unlawful processing of personal data under Article 6(1) of the GDPR, particularly concerning CCTV surveillance systems. Many complaints involved data subjects claiming that CCTV instal - lations, intended to protect tenants’ safety, were not lawful under the GDPR. Defendants often argued that their CCTV processing was exempt under the household exemption of the GDPR, claiming it was for property protection. However, the IDPC frequently determined that this exemp - tion did not apply, especially when the CCTV captured public spaces, referencing the CJEU’s Rynes judgment (Case C-212/13). In cases where the household exemption was deemed inapplicable, the IDPC examined whether the CCTV processing had a lawful basis under Article 6 of the GDPR. The IDPC often found no such lawful basis, thus ruling the processing as contravening the GDPR. The IDPC emphasised that CCTV capturing public spaces could only be lawful in exceptional cas - es where a compelling legitimate interest was proven or where legislative provisions permitted such processing. Even in cases of prior vandal - ism or serious incidents, the IDPC often found the evidence insufficient to justify limiting data protection rights. The IDPC’s corrective meas - ures typically included reprimands and orders to recalibrate CCTV systems to limit their scope and protect public areas.
318 CHAMBERS.COM
Powered by FlippingBook