Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (L.N. 227 of 2025)
Legal Notice 227 of 2025, Government Gazette of Malta No. 21,519 (10 October 2025)
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force 11 months, effective 10 October 2025.
An AI risk obligations rule binding government bodies.
As of 6 September 2026.
What it requires
- Obtain prior authorisation from a Magistrate before deploying a real-time or post-remote biometric identification system in a publicly accessible space in Malta for law enforcement purposes, and notify the Commissioner with the Regulation (EU) 2024/1689 Article 5(6) information excluding sensitive operational data, under Legal Notice 227 of 2025.
- Where you are a public authority or body, expect an administrative penalty of up to EUR 50,000 per infringement plus a daily penalty of up to EUR 50 per day of continuing infringement for a breach of Regulation (EU) 2024/1689 within the Commissioner's Annex III jurisdiction, under the same Legal Notice.
If you get it wrong
Penalty structure
Ceiling for an administrative penalty the IDPC imposes on a public authority or body for an infringement of Regulation (EU) 2024/1689 within the Commissioner's Annex III market-surveillance jurisdiction under Legal Notice 227 of 2025: EUR 50,000 per infringement plus EUR 50 for each day the infringement persists. The EU AI Act's own Article 99 penalty tiers for a private-sector operator are not restated here.
- Rule
- Per violation only
- As of
- 6 September 2026
- Currency
- EUR
- Fixed cap
- 50,000
- Per violation unit
- Day
- Per violation amount
- 50
Over one month of continuous breach, EUR 1,522.
Who enforces it
Enforcement body
Information and Data Protection Commissioner (IDPC), designated market surveillance authority under Legal Notice 227 of 2025 for the Annex III high-risk AI systems used in law enforcement, migration and border control, and the administration of justice.
What it reaches
How the hook was established
express
What makes it apply
Operator establishment
Obligation class
Biometric, Governance
What it makes you log
Who may demand the log
Regulator
Log retention
Regulation 9 extends Article 18(1)'s ten-year technical-documentation retention period through a provider's or authorised representative's bankruptcy or cessation of operations; it is the same ten-year period, not an independent one.
- Unit
- Years
- As of
- 22 September 2026
- Basis
- Fixed
- Minimum value
- 10
Logging duty
The Article 5(6) notification Regulation 6 requires before deploying a real-time or post-remote biometric identification system is a pre-deployment authorisation and disclosure gate, not a duty to keep an operational log or record over the system's use. Regulations 9 and 10 are different: Regulation 9 requires a provider or its authorised representative established in Malta that becomes bankrupt or ceases operating before Article 18(1)'s ten-year retention period ends to keep the Article 18(2) technical documentation at the disposal of the Commissioner for the rest of that period, and Regulation 10 requires an importer, on the Commissioner's reasoned request, to provide all necessary information and documentation, including the Article 23(5) material, to demonstrate a high-risk AI system's conformity. Neither Regulation names a log, a record or an audit trail; each requires documentation to be kept available or produced on request.
- Kind
- Implicit
- As of
- 22 September 2026
- Provision
- Regulations 9 and 10
- Trigger
- high_risk_systems
Who checks it
Audit expectation
on_request
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Legal Notice 227 of 2025 designates the Information and Data Protection Commissioner (IDPC) as a second market surveillance authority under the EU AI Act, for the Annex III high-risk categories of biometric systems used for law enforcement, border management, or justice and democracy purposes; emergency-call evaluation and emergency-response dispatching; law enforcement generally; migration, asylum and border control management; and the administration of justice and democratic processes, each insofar as its use is permitted by law.
Published in Government Gazette of Malta No. 21,519 of 10 October 2025. A real-time or post-remote biometric identification system deployed in a publicly accessible space for law enforcement requires prior authorisation from a Magistrate and notification to the Commissioner with the Article 5(6) information, excluding sensitive operational data.
Where the Commissioner finds an infringement of Regulation (EU) 2024/1689 by a public authority or body within this jurisdiction, an administrative penalty of up to EUR 50,000 per infringement plus a daily penalty of up to EUR 50 for each day the infringement persists may follow.
When LexLint raises it
high_risk_decisionsprocesses_biometrics
Read the law
Information and Data Protection Commissioner, official news page
legislation.mt, Government Gazette of Malta No. 21,519
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.