Personal Data Protection Bill, pending before the People's Majlis
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
Proposed: draft date not recorded.
A comprehensive regime rule binding public and private bodies.
As of 19 September 2026.
What it requires
- The Maldives' Personal Data Protection Bill has not been enacted and creates no binding duty as of the date shown; it was submitted to the People's Majlis on 11 May 2026 and had not passed a chamber as of the most recent reporting located.
- If enacted as drafted, a Controller or Processor would need a lawful basis before processing personal data, would have to collect it only for specific, explicit and legitimate purposes declared before collection, and would not be able to process it further in a way incompatible with those purposes.
- If enacted as drafted, personal data would have to be adequate, relevant and necessary to the declared purposes, accurate and kept up to date, and retained in identifiable form no longer than those purposes need.
- If enacted as drafted, a Controller or Processor would have to secure personal data with appropriate technical, physical or organizational measures against unauthorized or unlawful processing and against accidental loss, destruction or damage.
What it reaches
Obligation class
Consent, Security, Retention, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Section 3 would apply the Bill to the processing of all types of personal data by a Controller or Processor in both the public and private sectors within the Maldives, including processing equipment located there and anyone maintaining an Authority, branch or agency there, and to the processing of the personal data of data subjects located in the Maldives.
Chapter 2 would establish a Data Protection Authority, whose functions the Bill proposes be carried out by the existing Information Commissioner.
Section 14 would set the principles: collection for specific, explicit and legitimate purposes declared before collection and no further processing incompatible with them, lawful, impartial and transparent processing, data adequate, relevant and necessary to those purposes, data accurate and kept up to date with inaccurate or outdated data erased or rectified without delay, retention in identifiable form no longer than the purpose needs, and processing that ensures appropriate security against unauthorized or unlawful processing and against accidental loss, destruction or damage using appropriate technical, physical or organizational measures.
Chapter 5 would carry the security duties and chapter 10 the miscellaneous provisions, including technological neutrality and the definitions the rest of the Bill turns on. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbotautomated_outreachgenerates_content
Read the law
draft bill text hosted at mifps.com.mv, not an official government publication
corroborated by a Maldivian news report on the submission event
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.