Policy 2018 Online

Data Protection Act



Data Governance

Definitions of Data:

data is not defined

Main Focus of Document:

To ensure the protection of personal data by public and private bodies and for other incidental connected purposes.

Target Beneficiaries or Sectors:


Key Elements:

Makes provision for general data protection and includes specifics with respect to identity documents. When a person provides his/her identity documents the receiver of the information has an obligation to safeguard the identity information and processing of identity documents must be justified.

Key sections include: 4. (1)Subject to the provisions of sub-article (2), the provisions of this Act shall apply to the processing of personal data, wholly or partly, by automated means and to such processing other than by automated means where such personal data forms part of a filing system or is intended to form part of a filing system.

(2) This Act shall apply to: (a) the processing of personal data in the context of the activities of an establishment of a controller or a processor in Malta or in a Maltese Embassy or High Commission abroad, regardless of whether the processing takes place in Malta or not; (b) the processing of personal data of data subjects who are in Malta by a controller or processor not established in the European Union, where the processing activities are related to: (i) the offering of goods or services, irrespective of whether a payment of the data subject is required, to such data subjects in Malta; or (ii) the monitoring of their behaviour in so far as their behaviour takes place within Malta; (c) the processing of personal data by a controller not established in the Union but in a place where the laws of Malta apply by virtue of public international law. 8.An identity document shall only be processed when such processing is clearly justified having regard to the purpose of the processing and: (a) the importance of a secure identification; or (b) any other valid reason as may be provided by law: Provided that the national identity number or any other identifier of general application shall be used only under appropriate safeguards for the rights and freedoms of the data subject pursuant to the Regulation.

Data Data processing Data protection Data subject Personal data

Policy/regulation mirrored:

Data Protection Acts