Law / Maldives

Maldives

9 of 14 named instruments researched to a stage, across three of the six areas of law we track: 3 in force and 6 proposed. As of 19 September 2026.

  1. AI law none researched
  2. Privacy law 6
  3. Scraping law 2
  4. Cybersecurity law none researched
  5. Age gating law none researched
  6. News aggregation law 1

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Privacy law6 instruments, 6 proposed

Research summary (119 words)

No comprehensive personal-data or biometric-privacy law is currently binding law in the Maldives. Secondary sources describe a "Data Protection Act" dated around 2017, but that instrument has no Act number and no gazette citation of record, so whether it exists as law is an open question rather than a settled absence, and it is not carried as an instrument here.

A separate, government-backed Personal Data Protection Bill, a complete General Data Protection Regulation (GDPR)-shaped draft covering controller/processor obligations, special categories of personal data, a Data Protection Authority, 72-hour breach notification, and cross-border transfer conditions, was submitted to the People's Majlis on 11 May 2026, per a dated Maldivian news report, and it had not passed a chamber as of the most recent reporting.

Breach notification

Maldives Personal Data Protection Bill, personal data breach notification

Personal Data Protection Bill, section 34 (personal data breach notification)draft bill text hosted at mifps.com.mv, not an official government publication

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Section 34(a) would require the Controller to notify both the Data Protection Authority and the affected data subjects within seventy-two hours upon knowledge of, or a reasonable belief in, a personal data breach, where the breach involves special categories of personal data or any personal data that could be used to enable identity theft or fraud and the further elements the section lists are present.

The same subsection restates the duty to the Authority alone in the same terms and on the same seventy-two-hour period, counted from the receipt of knowledge of or a reasonable belief that a breach has occurred. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.

What it requires

Comprehensive regime

Personal Data Protection Bill, pending before the People's Majlis

Personal Data Protection Bill, chapters 1-3, 5 and 10 (introduction, the Authority, principles, security and miscellaneous provisions)draft bill text hosted at mifps.com.mv, not an official government publication

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Section 3 would apply the Bill to the processing of all types of personal data by a Controller or Processor in both the public and private sectors within the Maldives, including processing equipment located there and anyone maintaining an Authority, branch or agency there, and to the processing of the personal data of data subjects located in the Maldives.

Chapter 2 would establish a Data Protection Authority, whose functions the Bill proposes be carried out by the existing Information Commissioner.

Section 14 would set the principles: collection for specific, explicit and legitimate purposes declared before collection and no further processing incompatible with them, lawful, impartial and transparent processing, data adequate, relevant and necessary to those purposes, data accurate and kept up to date with inaccurate or outdated data erased or rectified without delay, retention in identifiable form no longer than the purpose needs, and processing that ensures appropriate security against unauthorized or unlawful processing and against accidental loss, destruction or damage using appropriate technical, physical or organizational measures.

Chapter 5 would carry the security duties and chapter 10 the miscellaneous provisions, including technological neutrality and the definitions the rest of the Bill turns on. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.

What it requires

Cross border transfer

Maldives Personal Data Protection Bill, cross-border transfers

Personal Data Protection Bill, chapters 7-8 (personal data transfers and cross-border transfers)draft bill text hosted at mifps.com.mv, not an official government publication

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Section 43 would require a cross-border data transfer by a Controller to be carried out on the conditions the Act specifies.

Section 44 would let a Controller or Processor transfer personal data to a jurisdiction outside the Maldives only where it has provided appropriate safeguards, and only on condition that enforceable data subject rights and effective legal remedies are available there; the safeguards would be the corporate process the Bill describes and an agreement with the receiving entity carrying a data protection process the Data Protection Authority endorses, with the Authority formulating the process by regulation.

Section 45 would let the Authority approve binding corporate rules and fixes what they must specify, including the structure and contact details of the group, the transfers and categories of data concerned, and their legally binding nature. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.

What it requires

Data subject rights

Maldives Personal Data Protection Bill, rights of data subjects

Personal Data Protection Bill, chapter 4 (rights of data subjects)draft bill text hosted at mifps.com.mv, not an official government publication

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Chapter 4 would carry the rights of data subjects, opening on the general provisions that govern how they are exercised and running through the right to be informed about the processing, to obtain access to the personal data held, to have it corrected where it is inaccurate or incomplete, to have it erased, to restrict its processing, to receive it in a portable form, and to object to processing including profiling.

Section 55 would give every person a right to compensation for damage caused by a breach of the Act, which the enforcement row carries. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.

What it requires

Enforcement supervision

Maldives Personal Data Protection Bill, investigation, enforcement and compensation

Personal Data Protection Bill, chapter 9 and sections 52-55 (investigation, enforcement and compensation)draft bill text hosted at mifps.com.mv, not an official government publication

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Section 46 would give any person the right to lodge a complaint with the Data Protection Authority about an alleged infringement of their rights, and section 47 would give the Authority the right to investigate, including to enter premises, search and copy documents and interview people, while letting it halt, suspend or decline an investigation in the cases it lists and requiring investigation records to be kept for at least five years.

Section 52 would let the Authority order processing to stop temporarily or permanently where it determines that sharing personal data across borders threatens national security or the stability of society, and section 53 would let it exempt a person or category from part of the Act.

Section 54 would require the Authority to impose administrative penalties including fines, on top of any other sanction, weighing the nature, scope and duration of the conduct and the harm caused, whether it was intentional or negligent, the steps taken to mitigate it, the responsibility assumed, any prior breaches, the degree of cooperation, the categories of data and groups affected, the timeliness and completeness of the notifications made, any previous enforcement, and the financial impact.

Section 55 would give every person a right to compensation for damage caused by a breach of the Act. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.

What it requires

Sensitive categories

Maldives Personal Data Protection Bill, special categories of personal data

Personal Data Protection Bill, section 17 and the section 56 definition (special categories of personal data)draft bill text hosted at mifps.com.mv, not an official government publication

Proposed: draft date not recorded. Binds public and private bodies.

What this law does

Section 17 would prohibit the processing of special categories of personal data except in the instances it lists, beginning with the data subject's explicit consent to one or more specified purposes.

The Bill's definition of Special Categories of Personal Data would take in personal data revealing racial or ethnic origin, political opinions or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, and data concerning a natural person's sex life or sexual orientation.

Section 16 would treat a child's position as a reason the interests and fundamental rights of the data subject override a legitimate interest relied on for processing. The Bill's own text carries no Act number and no record of ratification or gazette publication, and it was still at the submission stage in the most recent reporting located, so nothing in this row binds anyone today.

What it requires

Scraping law2 instruments, 2 in force

Research summary (232 words)

Maldives has no scraping-specific statute.

The Copyright and Related Rights Act (Law No. 23/2010, current text amended through Act No. 31/2024, though the only English translation located covers the original 2010 version) permits quoting a short part of a published work compatible with fair practice, and permits reproducing a newspaper or periodical article on current economic, political or religious topics, or a short excerpt of a work for reporting a current event, in each case with source and author attribution.

The Act creates no text-and-data-mining exception, and its exception for private reproduction for personal purposes expressly excludes reproduction of the whole or a substantial part of a database in digital form.

Collections of data are protected as derivative works only where they are original in their selection or arrangement, mere data and ideas receive no protection at all even where embodied in a work, so Maldives protects a database only as a compilation under general copyright rather than through a sui generis database right.

Computer-misuse and unauthorized-access law, terms-of-service enforceability, unfair competition or misappropriation doctrine, and the legal weight of a robots.txt directive are not addressed here, because no primary text for the Information and Communication Technology Act 2017 or the Penal Code's computer-access provisions could be located.

Personal-data reach over scraped public data is addressed under this jurisdiction's own privacy-topic record, where no comprehensive personal-data statute is confirmed currently in force.

News aggregation law1 instrument, 1 in force

Research summary (160 words)

Maldives has no press-publisher neighbouring right, no compelled platform-to-publisher bargaining regime, no hot-news or misappropriation doctrine, and no statute or reported case addressing whether linking to or framing a publisher's page is an act requiring authorization.

The Copyright and Related Rights Act (Law No. 23/2010, current text amended through Act No. 31/2024, though the only English translation located covers the original 2010 version) permits quoting a short part of a published work compatible with fair practice, and separately permits reproducing a newspaper or periodical article on current economic, political or religious topics, or a short excerpt of a work for reporting a current event, in each case with source and author attribution and, for the newspaper-article exception, only where the right to authorize reproduction has not been expressly reserved.

The Act creates no text-and-data-mining exception or machine-readable opt-out mechanism, so an aggregator's indexing of news content is governed by the ordinary reproduction right subject only to these two narrow exceptions.

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.