Law / Malta

GDPR Articles 82-83 and IDPC Enforcement in Malta

Regulation (EU) 2016/679, Arts. 82-83

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 2 September 2026.

What it requires

  • Expect the IDPC to have jurisdiction and fining power over your processing of personal data of a person in Malta, up to the General Data Protection Regulation (GDPR) Article 83 tiers.
  • Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Data Protection Act (Cap. 586) Article 22 makes it a criminal offence, separate from the Commissioner's administrative fines, for a person to knowingly provide false information to the Commissioner when required under his Article 58 GDPR investigative powers, or to fail to comply with a lawful request made in the course of a Commissioner investigation. On conviction the penalty is a fine (multa) of not less than EUR 1,250 and not more than EUR 50,000, or imprisonment for up to six months, or both.

Penalty structure

GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, for a private-sector undertaking. The Data Protection Act (Cap. 586) Article 21 sets a lower, Malta-specific ceiling that applies only to a public authority or body: up to EUR 25,000 per violation plus a daily fine of up to EUR 25 for an Article 83(4)-tier infringement, and up to EUR 50,000 per violation plus a daily fine of up to EUR 50 for an Article 83(5) or 83(6)-tier infringement.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Information and Data Protection Commissioner (IDPC), Malta's supervisory authority under the GDPR and the Data Protection Act (Cap. 586).

Enforcement record

Counts the administrative fines the report narrates for calendar year 2024, the latest annual report published: a EUR 15,000 fine (28 June 2024, unsolicited direct marketing, Articles 21(2) and 5(2)) described in section 6.7, and a EUR 2,500 fine (access-request and transparency failures, Articles 13-15) described in section 6.3, for a fines_per_year of EUR 17,500. The report also states other administrative fines were collected in 2024 following final judgments on cases the Commissioner concluded in prior years, without giving their count or amount, so this likely understates total 2024 collections; it gives no summary table of the year's total fines or actions the way some larger DPAs do. Public enforcement actions only; no private civil claim count is published.

As of
2 September 2026
Trend
Flat
Currency
EUR
Source link
https://idpc.org.mt/wp-content/uploads/2025/09/IDPC-Annual-Report-2024-Final.pdf
Fines per year
17,500
Actions per year
2

What it reaches

Obligation class

Governance, Reporting

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

The IDPC is the supervisory authority and enforces General Data Protection Regulation (GDPR) fines up to EUR 20 million or 4 percent of global annual turnover for private-sector controllers and processors. Corrected during the #8352 wave 4 review: Cap. 586's own Article 21 (Administrative fines on public authorities or bodies) shows a Malta-specific ceiling does exist for the public sector, distinct from the private-sector maximum.

A public authority or body faces a EUR 25,000 per-violation cap plus a EUR 25 daily fine for infringements of the Article 83(4) tier, and a EUR 50,000 per-violation cap plus a EUR 50 daily fine for infringements of the Article 83(5) or 83(6) tier. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions
  • processes_biometrics
  • processes_voice

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app