Law / Malta

Malta

European Union law applies in Malta Malta is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Malta, described on this page below, applies here too.

13 of 14 named instruments researched to a stage, across all six areas of law we track: 13 in force. As of 18 September 2026.

When they take effect9 of 13 carry a date, 4 do not.
2018: 6 instruments (6 in force) ’18 2019: 0 instruments 2020: 0 instruments ’20 2021: 0 instruments 2022: 0 instruments 2023: 0 instruments 2024: 0 instruments 2025: 2 instruments (2 in force) 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law 1
  5. Age gating law 1
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (196 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Malta and is not restated here as national law. Malta designated its national competent authorities by Legal Notices 226 and 227 of 2025, both published in Government Gazette of Malta No. 21,519 of 10 October 2025. Legal Notice 226 designates the Malta Digital Innovation Authority (MDIA) as the lead market surveillance authority, single point of contact, and national competent authority for Malta's AI regulatory sandbox.

Legal Notice 227 designates the Information and Data Protection Commissioner (IDPC) as a second market surveillance authority, for specific Annex III high-risk categories including biometric identification, emergency response dispatching, law enforcement, migration and border control, and the administration of justice, and requires a Magistrate's prior authorisation before a real-time or post-remote biometric identification system is deployed in a publicly accessible space for law enforcement.

Both designations' market-surveillance and enforcement powers become exercisable from 2 August 2026, in line with the AI Act's own Article 113 application timeline. No Maltese Criminal Code provision addressing AI-generated child sexual abuse material or non-consensual intimate imagery, distinct from the EU AI Act's own Article 5 prohibitions, was confirmed in the sources reached during this visit.

Privacy law6 instruments, 6 in force

Research summary (126 words)

Malta's private-sector regime is the General Data Protection Regulation (GDPR) plus the Data Protection Act, Chapter 586 of the Laws of Malta, in effect since 25 May 2018 alongside the GDPR itself.

Its most consequential national addition, per two independent secondary sources not independently confirmed against Cap. 586's own text, is a prior-authorization and ethics-consultation duty: a controller must consult, and obtain prior authorization from, the Information and Data Protection Commissioner (IDPC) before processing genetic, biometric, or health data for statistical or research purposes in the public interest.

A separate designation (Legal Notice 227 of 2025) makes the IDPC an EU AI Act market-surveillance authority for biometrics among other categories, an AI-topic matter not covered here. As at 24 August 2026; later amendment to Cap. 586 is not independently confirmed.

Biometric privacy

GDPR Article 9 and Cap. 586, Genetic, Biometric and Health Data Research Processing in Malta

Regulation (EU) 2016/679, Art. 9; Data Protection Act, Cap. 586Two independent secondary sources (Linklaters, Mondaq), not independently confirmed against Cap. 586's own text

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category.

Confirmed directly against Cap. 586's own text during the #8352 wave 4 review (Article 7, Consultation and prior authorisation): a controller must consult with, and obtain prior authorisation from, the Commissioner before processing genetic data, biometric data, or data concerning health for statistical or research purposes in the public interest, and where such data is required for research purposes the Commissioner must in turn consult a research ethics committee or an institution the Commissioner recognises for that purpose.

Two independent secondary sources (Linklaters, Mondaq) had already reported the same finding, but the document previously stated Cap. 586's own PDF did not yield extractable text; that PDF is in fact readable, and this article-level detail is confirmed against it directly.

This duty is scoped to statistical, research, and public-interest processing; a commercial product capturing voiceprints or faceprints for authentication or identification outside a research context is governed by GDPR Article 9 alone, with no Malta-specific addition identified for that use case.

What it requires

Breach notification

GDPR Articles 33-34, Breach Notification in Malta

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the IDPC without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Malta, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No Cap. 586 derogation from this timeline is identified.

What it requires

Comprehensive regime

Data Protection Act, Chapter 586 of the Laws of Malta

Data Protection Act, Cap. 586IDPC official PDF (idpc.org.mt), not independently extracted

In force since 25 May 2018. Binds public and private bodies.

What this law does

Malta's private-sector regime is the General Data Protection Regulation (GDPR) plus the Data Protection Act, Chapter 586 of the Laws of Malta, in effect since 25 May 2018 alongside the GDPR itself, supplying domestic derogations and procedural rules.

Subsidiary Legislation 586.11 sets the digital age of consent at 13, per secondary commentary; Cap. 586's own Article 33(g) (Minister's regulation-making power) sets the statutory floor for that ministerial discretion at not below thirteen years but does not itself state the currently adopted age.

The Information and Data Protection Commissioner (IDPC) is the supervisory authority; a second designation (Legal Notice 227 of 2025) makes it a market-surveillance authority for specific EU AI Act high-risk categories, including biometrics, an AI-topic matter not addressed here.

Corrected during the #8352 wave 4 review: Cap. 586's own official PDF does yield extractable text (confirmed while sourcing the risk-attribute pins below), so the 'commentary sourced' caveat below no longer holds for every provision; see the Article 9 sibling instrument for the specific correction.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Malta

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Malta outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier. No Cap. 586 derogation broadening or narrowing this is identified.

What it requires

Data subject rights

GDPR Article 22 and Cap. 586, Automated Decisions in Malta

Regulation (EU) 2016/679, Art. 22; Data Protection Act, Cap. 586Secondary commentary (Linklaters, Mondaq), not independently confirmed against Cap. 586's own text

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing, restated by Cap. 586 without narrowing per secondary commentary. Subsidiary Legislation 586.11 sets the digital age of consent at 13, a national exercise of the GDPR Article 8 discretion, which permits a range from 13 to 16.

What it requires

Enforcement supervision

GDPR Articles 82-83 and IDPC Enforcement in Malta

Regulation (EU) 2016/679, Arts. 82-83Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

The IDPC is the supervisory authority and enforces General Data Protection Regulation (GDPR) fines up to EUR 20 million or 4 percent of global annual turnover for private-sector controllers and processors. Corrected during the #8352 wave 4 review: Cap. 586's own Article 21 (Administrative fines on public authorities or bodies) shows a Malta-specific ceiling does exist for the public sector, distinct from the private-sector maximum.

A public authority or body faces a EUR 25,000 per-violation cap plus a EUR 25 daily fine for infringements of the Article 83(4) tier, and a EUR 50,000 per-violation cap plus a EUR 50 daily fine for infringements of the Article 83(5) or 83(6) tier. GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Scraping law2 instruments, 2 in force

Research summary (168 words)

Malta's principal scraping-relevant statute located here is the Criminal Code's computer-misuse subtitle. Article 337C makes it an offence to access, copy, output, or otherwise deal with data, software, or supporting documentation held in a computer without authorisation, turning on whether the actor was permitted by whoever is entitled to control the resource rather than on whether the resource sat behind a login.

Article 337D separately criminalises modifying, damaging, or impairing the operation of computer equipment, a computer, a computer system, or a computer network without authorisation. Article 337E extends both offences to conduct committed outside Malta that affects a computer, software, or data situated in or connected to Malta. No provision stating either article's maximum penalty was located in the sources this visit reached.

Malta's terms-of-service enforceability, database right, unfair-competition doctrine, and robots.txt weight were not independently confirmed in this visit; the reach of Malta's data-protection law over scraped personal data is addressed in the privacy topic's Data Protection Act (Cap. 586) and General Data Protection Regulation (GDPR) entries for this jurisdiction.

Computer misuse

Criminal Code Article 337C, Unlawful Access to, or Use of, Information

Criminal Code (Cap. 9), Art. 337CCriminal Code of Malta, official text reproduced by the United Nations Office on Drugs and Crime SHERLOC database

In force. Binds public and private bodies.

What this law does

Article 337C of the Criminal Code makes it an offence for a person, without authorisation, to access, use, copy, output, prevent or hinder access to, install, alter, or otherwise deal with data, software, or supporting documentation held in a computer, among the acts the article enumerates in paragraphs (a) to (l). A person acts without authorisation if they are not duly authorised by an entitled person, and an entitled person is one entitled to control the activities the article defines.

The article draws no distinction between a publicly accessible page and one requiring login or other access controls; whether a use is authorised turns on whether the actor was permitted by whoever controls the resource. No provision stating the article's maximum penalty was located in the source consulted.

What it requires

Criminal Code Article 337D, Misuse of Hardware

Criminal Code (Cap. 9), Art. 337DCriminal Code of Malta, official text reproduced by the United Nations Office on Drugs and Crime SHERLOC database

In force. Binds public and private bodies.

What this law does

Article 337D makes it an offence for a person, without authorisation, to modify computer equipment or supplies used or intended for use in a computer, computer system, or computer network, or to take possession of, damage, destroy, or impair the operation of such a computer, computer system, computer network, or supplies. No provision stating the article's maximum penalty was located in the source consulted.

What it requires

Cybersecurity law1 instrument, 1 in force

Research summary (624 words)

Malta's cyber-resilience posture for the private-sector duty-bearer rests mainly on directly applicable EU regulations, documented at the European Union jurisdiction level, plus one confirmed national implementing measure and one significant open gap.

The Cyber Resilience Act (Regulation (EU) 2024/2847) sets the essential cybersecurity requirements a manufacturer must meet before placing a product with digital elements on the EU market, applicable from 11 December 2027, and its vulnerability and incident reporting duties, applicable since 11 September 2026; both are documented at the eu jurisdiction level and are not restated here.

Malta's own legislation portal carries a consolidated Subsidiary Legislation record, S.L. 591.6, Cyber Resilience Regulations, under Chapter 591, the Malta Digital Innovation Authority Act, with a recorded point in time of 11 September 2026, and the Malta Digital Innovation Authority (MDIA) describes itself as the prospective Notifying Authority and Market Surveillance Authority under the Cyber Resilience Act.

The MDIA's own published complaints procedure nonetheless states, as of 18 September 2026, that the corresponding provisions under the Cyber Resilience Act are still to come into application, so S.L. 591.6's existence and stated role are recorded here without asserting the designation is yet fully operative; the regulation's own operative text could not be reached, because Malta's legislation portal serves this record only as a metadata card behind client-side JavaScript, with the underlying document published solely as a PDF the portal loads on a user click rather than at a stable address reachable directly.

No located instrument names Malta's transposition of the NIS2 Directive (Directive (EU) 2022/2555), which sets cybersecurity risk-management and incident-reporting duties for essential and important entities including the digital providers its Annex II names, and which Malta was due to transpose by 17 October 2024.

The MDIA's own list of the EU regulations it administers (the Artificial Intelligence Act, the Cybersecurity Act, the Cyber Resilience Act, the Data Act and the Data Governance Act) does not include NIS2.

The Critical Infrastructure Protection Department, which the MDIA names as its partner on Malta's National Coordinated Vulnerability Disclosure Policy, and the National Cybersecurity Coordination Centre, hosted by the Malta Information Technology Agency (MITA) as Malta's node in the EU's Cybersecurity Competence Centre network, both look like more likely holders of a Maltese NIS2 transposition than the MDIA, but no Act or Legal Notice naming either body as a NIS2 competent authority or CSIRT was located; both of their own websites were read and neither names a transposing instrument.

Malta's legislation portal's own full-text search runs only as a client-side form that posts to an anti-forgery-token-guarded endpoint, which could not be submitted with the tools available, and Malta's Ministry for Home Affairs and the Malta Communications Authority's own sites returned no matching content on direct navigation.

This is recorded as an unresolved research gap rather than a finding that Malta has not transposed NIS2, since Malta's EU Member State obligation makes an actual gap surprising.

The Cybersecurity Act (Regulation (EU) 2019/881) and Malta's own S.L. 591.02, Cybersecurity Certification Regulations, designate the MDIA as Malta's National Cybersecurity Certification Authority, but this is a voluntary EU-wide certification framework for ICT products, services and processes rather than a mandatory security duty, so it is named here and not filed as an instrument.

No general reasonable-security or information-security-programme statute with no sector gate was located for Malta; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Data Protection Act, Chapter 586, which sits in the privacy topic together with the Articles 33-34 breach-notification duty to the Information and Data Protection Commissioner, and neither is restated here.

No enforcement record specific to a Maltese cyber-resilience or product-security duty was located; the Cyber Resilience Act's own fine structure under its Article 64 is directly applicable EU-wide regardless of Malta's national designation.

Product security requirements

Cyber Resilience Regulations, MDIA Designation under the Cyber Resilience Act

S.L. 591.6, Cyber Resilience Regulations, made under Chapter 591 (Malta Digital Innovation Authority Act)Malta Digital Innovation Authority, official Cybersecurity services page and Legislation page

In force 12 days, effective 11 September 2026. Binds public and private bodies.

What this law does

The Malta Digital Innovation Authority (MDIA) describes itself as the prospective Notifying Authority and Market Surveillance Authority pursuant to the Cyber Resilience Act (Regulation (EU) 2024/2847). Malta's legislation portal carries this designation under a consolidated record, Subsidiary Legislation 591.6, Cyber Resilience Regulations, made under Chapter 591, the Malta Digital Innovation Authority Act, with a recorded point in time of 11 September 2026.

The Cyber Resilience Act's own essential requirements and market-placement duties for a manufacturer, applicable from 11 December 2027, and its vulnerability and incident reporting duties, applicable since 11 September 2026, are the Regulation's own and are documented at the European Union jurisdiction level rather than restated here.

The MDIA's own published complaints procedure states that the corresponding provisions under the Cyber Resilience Act are still to come into application, so whether the MDIA's Notifying Authority and Market Surveillance Authority role under this Regulation is yet fully operative is not established in the primary text read here.

What it requires

Age gating law1 instrument, 1 in force

Research summary (138 words)

Malta's principal age-related duty binds a video-sharing platform provider. The Broadcasting (Amendment) Act, 2020 (Act No. LVI of 2020), transposing the revised EU Audiovisual Media Services Directive (Directive (EU) 2018/1808), inserted Articles 16R and 16S into the Broadcasting Act, Cap. 350.

Article 16S requires a video-sharing platform provider under Maltese jurisdiction to take the necessary measures to protect minors from programmes, user-generated videos and audiovisual commercial communications that may impair their physical, mental or moral development, including the establishment and operation of age-verification systems for users in relation to such content and of parental-control systems under the end-user's control; the Broadcasting Authority is charged with ensuring providers under its jurisdiction apply those measures.

Malta has no dedicated social-media minor-access restriction, app-store age-verification requirement, or age-appropriate design code distinct from this video-sharing platform duty as of the date below.

Adult content age verification (AV)

Broadcasting Act, Cap. 350, Arts. 16R-16S (Video-Sharing Platform Minor-Protection Duties)

Broadcasting Act, Cap. 350, arts. 16R-16S, inserted by the Broadcasting (Amendment) Act, 2020 (Act No. LVI of 2020)Text of the Broadcasting (Amendment) Act, 2020 (Act No. LVI of 2020), reproduced by the Broadcasting Authority of Malta

In force. Binds private bodies.

What this law does

Article 16S requires a video-sharing platform provider under the jurisdiction of Malta to take the necessary measures to protect minors from programmes, user-generated videos and audiovisual commercial communications which may impair their physical, mental or moral development. Those measures include establishing and operating age verification systems for users of video-sharing platforms with respect to such content.

They also include providing for parental control systems that are under the control of the end-user with respect to such content. Personal data of minors collected or otherwise generated through those age-verification or parental-control measures may not be processed for commercial purposes such as direct marketing, profiling and behaviourally targeted advertising. The Broadcasting Authority ensures that all video-sharing platform providers under its jurisdiction apply such measures.

The Act was passed by the House of Representatives on 2 December 2020. It received presidential assent on 7 December 2020, and no separate commencement notice fixing a later day has been located.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (133 words)

Malta's Copyright Act, Chapter 415 of the Laws of Malta, carries a press and current-events reporting exception and a quotation exception at Article 9(1), each excepting a specified use from copyright control provided the source and author are credited.

No provision creating a press-publisher neighbouring right equivalent to the EU Digital Single Market Copyright Directive's Article 15, and no text-and-data-mining exception distinct from Article 9's existing exceptions list, was located in the Copyright Act's principal text as consolidated through Act XXXV of 2023; Malta's subsidiary legislation register could not be independently checked in this visit.

Malta carries no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from the general law was located in the sources this visit reached.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.