Law / Malta

Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025)

Legal Notice 227 of 2025, Government Gazette of Malta No. 21,519 (10 October 2025)

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force 11 months, effective 10 October 2025.

An AI risk obligations rule binding government bodies.

As of 6 September 2026.

What it requires

  • Obtain prior authorisation from a Magistrate before deploying a real-time or post-remote biometric identification system in a publicly accessible space in Malta for law enforcement purposes, and notify the Commissioner with the Regulation (EU) 2024/1689 Article 5(6) information excluding sensitive operational data, under Legal Notice 227 of 2025.
  • Where you are a public authority or body, expect an administrative penalty of up to EUR 50,000 per infringement plus a daily penalty of up to EUR 50 per day of continuing infringement for a breach of Regulation (EU) 2024/1689 within the Commissioner's Annex III jurisdiction, under the same Legal Notice.

If you get it wrong

Penalty structure

Ceiling for an administrative penalty the IDPC imposes on a public authority or body for an infringement of Regulation (EU) 2024/1689 within the Commissioner's Annex III market-surveillance jurisdiction under Legal Notice 227 of 2025: EUR 50,000 per infringement plus EUR 50 for each day the infringement persists. The EU AI Act's own Article 99 penalty tiers for a private-sector operator are not restated here.

Rule
Per violation only
As of
6 September 2026
Currency
EUR
Fixed cap
50,000
Per violation unit
Day
Per violation amount
50

Over one month of continuous breach, EUR 1,522.

Who enforces it

Enforcement body

Information and Data Protection Commissioner (IDPC), designated market surveillance authority under Legal Notice 227 of 2025 for the Annex III high-risk AI systems used in law enforcement, migration and border control, and the administration of justice.

What it reaches

How the hook was established

express

What makes it apply

Operator establishment

Obligation class

Biometric, Governance

What it makes you log

Who may demand the log

Regulator

Log retention

Regulation 9 extends Article 18(1)'s ten-year technical-documentation retention period through a provider's or authorised representative's bankruptcy or cessation of operations; it is the same ten-year period, not an independent one.

Unit
Years
As of
22 September 2026
Basis
Fixed
Minimum value
10

Logging duty

The Article 5(6) notification Regulation 6 requires before deploying a real-time or post-remote biometric identification system is a pre-deployment authorisation and disclosure gate, not a duty to keep an operational log or record over the system's use. Regulations 9 and 10 are different: Regulation 9 requires a provider or its authorised representative established in Malta that becomes bankrupt or ceases operating before Article 18(1)'s ten-year retention period ends to keep the Article 18(2) technical documentation at the disposal of the Commissioner for the rest of that period, and Regulation 10 requires an importer, on the Commissioner's reasoned request, to provide all necessary information and documentation, including the Article 23(5) material, to demonstrate a high-risk AI system's conformity. Neither Regulation names a log, a record or an audit trail; each requires documentation to be kept available or produced on request.

Kind
Implicit
As of
22 September 2026
Provision
Regulations 9 and 10
Trigger
high_risk_systems

Who checks it

Audit expectation

on_request

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Legal Notice 227 of 2025 designates the Information and Data Protection Commissioner (IDPC) as a second market surveillance authority under the EU AI Act, for the Annex III high-risk categories of biometric systems used for law enforcement, border management, or justice and democracy purposes; emergency-call evaluation and emergency-response dispatching; law enforcement generally; migration, asylum and border control management; and the administration of justice and democratic processes, each insofar as its use is permitted by law.

Published in Government Gazette of Malta No. 21,519 of 10 October 2025. A real-time or post-remote biometric identification system deployed in a publicly accessible space for law enforcement requires prior authorisation from a Magistrate and notification to the Commissioner with the Article 5(6) information, excluding sensitive operational data.

Where the Commissioner finds an infringement of Regulation (EU) 2024/1689 by a public authority or body within this jurisdiction, an administrative penalty of up to EUR 50,000 per infringement plus a daily penalty of up to EUR 50 for each day the infringement persists may follow.

When LexLint raises it

  • high_risk_decisions
  • processes_biometrics

Read the law

Information and Data Protection Commissioner, official news page
legislation.mt, Government Gazette of Malta No. 21,519

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app