Gaming Authorisations and Compliance Directive, Notification of Information Security Breaches
In force since .
A vulnerability and incident reporting rule binding private bodies.
- Enforcement body
- Malta Gaming Authority
- Obligation class
- Reporting, Security
As of .
What it requires
- This binds a licensee of the Malta Gaming Authority: a business-to-consumer licensee providing a gaming service, or a business-to-business licensee providing a critical gaming supply such as a back-end service. Read it by hand if you supply or operate a gaming product licensed in Malta.
- Notify the Authority forthwith, and in any case no later than three working days after the breach, of any breach of your information security that adversely affects the confidentiality of information relating to players (article 37(2)(c)).
- Notify the Authority on the same clock of any breach of your information security that precludes players from accessing their accounts for a period exceeding twelve hours (article 37(2)(d)).
- Submit the notice as an incident report through the Licensee Portal of the Malta Gaming Authority.
What this law does
Article 37(2) of the Gaming Authorisations and Compliance Directive requires a licensee to notify the Malta Gaming Authority of any breach of its information security that adversely affects the confidentiality of information relating to players, and of any such breach that precludes players from accessing their accounts for a period exceeding twelve hours. The notice is due forthwith and in any case no later than three working days after the breach.
A licensee is a business-to-consumer licensee providing a gaming service or a business-to-business licensee providing a critical gaming supply. The Authority takes the notice as an incident report submitted through its Licensee Portal.