GDPR Articles 82-83 and IDPC Enforcement in Malta
Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 2 September 2026.
What it requires
- Expect the IDPC to have jurisdiction and fining power over your processing of personal data of a person in Malta, up to the General Data Protection Regulation (GDPR) Article 83 tiers.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Data Protection Act (Cap. 586) Article 22 makes it a criminal offence, separate from the Commissioner's administrative fines, for a person to knowingly provide false information to the Commissioner when required under his Article 58 GDPR investigative powers, or to fail to comply with a lawful request made in the course of a Commissioner investigation. On conviction the penalty is a fine (multa) of not less than EUR 1,250 and not more than EUR 50,000, or imprisonment for up to six months, or both.
Penalty structure
GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, for a private-sector undertaking. The Data Protection Act (Cap. 586) Article 21 sets a lower, Malta-specific ceiling that applies only to a public authority or body: up to EUR 25,000 per violation plus a daily fine of up to EUR 25 for an Article 83(4)-tier infringement, and up to EUR 50,000 per violation plus a daily fine of up to EUR 50 for an Article 83(5) or 83(6)-tier infringement.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Information and Data Protection Commissioner (IDPC), Malta's supervisory authority under the GDPR and the Data Protection Act (Cap. 586).
Enforcement record
Counts the administrative fines the report narrates for calendar year 2024, the latest annual report published: a EUR 15,000 fine (28 June 2024, unsolicited direct marketing, Articles 21(2) and 5(2)) described in section 6.7, and a EUR 2,500 fine (access-request and transparency failures, Articles 13-15) described in section 6.3, for a fines_per_year of EUR 17,500. The report also states other administrative fines were collected in 2024 following final judgments on cases the Commissioner concluded in prior years, without giving their count or amount, so this likely understates total 2024 collections; it gives no summary table of the year's total fines or actions the way some larger DPAs do. Public enforcement actions only; no private civil claim count is published.
- As of
- 2 September 2026
- Trend
- Flat
- Currency
- EUR
- Source link
- https://idpc.org.mt/wp-content/uploads/2025/09/IDPC-Annual-Report-2024-Final.pdf
- Fines per year
- 17,500
- Actions per year
- 2
What it reaches
Obligation class
Governance, Reporting
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The IDPC is the supervisory authority and enforces General Data Protection Regulation (GDPR) fines up to EUR 20 million or 4 percent of global annual turnover for private-sector controllers and processors. Corrected during the #8352 wave 4 review: Cap. 586's own Article 21 (Administrative fines on public authorities or bodies) shows a Malta-specific ceiling does exist for the public sector, distinct from the private-sector maximum.
A public authority or body faces a EUR 25,000 per-violation cap plus a EUR 25 daily fine for infringements of the Article 83(4) tier, and a EUR 50,000 per-violation cap plus a EUR 50 daily fine for infringements of the Article 83(5) or 83(6) tier. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsprocesses_biometricsprocesses_voice
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.