{
 "jurisdiction_id": "GI",
 "jurisdiction": "Gibraltar",
 "url": "https://dataprotection.gi/jurisdictions/gibraltar/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 27,
  "sub_modules": 57,
  "source_register": 31
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive statute with active, named regulator and demonstrated enforcement activity.",
   "claims": [
    {
     "statement": "The Gibraltar Regulatory Authority (GRA) is the supervisory authority responsible for enforcing the Data Protection Act 2004 and the Gibraltar GDPR, including issuing fines and guidance.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Gibraltar Regulatory Authority",
     "source_url": "https://www.gra.gi/data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following the end of the Brexit transition period, the applicable law in Gibraltar is no longer the EU GDPR but the Gibraltar GDPR, which superseded it on 1 January 2021 pursuant to Section 6 of the European Union (Withdrawal) Act 2019, alongside the Data Protection Act 2004 (as amended in 2019).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/gibraltar-smsmms-marketing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Material scope of the Gibraltar regime mirrors GDPR Article 2, covering wholly/partly automated processing and structured manual filing systems of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Gibraltar Regulatory Authority",
     "source_url": "https://www.gra.gi/data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Even after the end of the Brexit transition period, a Gibraltar-based controller or processor offering goods or services to, or monitoring the behaviour of, individuals in the EEA must continue to comply with the EU GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/gibraltar-navigating-brexit-and-data-protection",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "amber",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Framework is GDPR-aligned but Gibraltar-specific consent-threshold and pseudonymisation guidance is thin in the public record.",
   "claims": [
    {
     "statement": "The Gibraltar GDPR retains the six lawful bases for processing set out in Article 6 of Regulation (EU) 2016/679.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Gibraltar Regulatory Authority",
     "source_url": "https://www.gra.gi/data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GRA guidance outlines exemptions from the Data Protection Act 2004 and GDPR available for, among others, crime, law enforcement and public protection, journalism, research and archiving, and health, social work and education processing, and clarifies these cannot be routinely relied upon and must be justified case-by-case.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-guidance-exemptions-data-protection-legislation",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GRA guidance on location data states that anonymisation is preferred and that consent is required where location data is not anonymised, encouraging transparency about anonymisation methodology.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-guidance-gdpr-and-location-data",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is GDPR-aligned and actively enforced (SAR failures investigated) but Gibraltar-specific procedural guidance on erasure/portability/deadlines was not located in this pass.",
   "claims": [
    {
     "statement": "GRA's published investigations and enforcement report addresses cases involving failure to respond to subject access requests, among other compliance failures under GDPR and the DPA 2004.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-reports-enforcement-activity",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Gibraltar GDPR retains the GDPR Article 12(3) standard one-month response deadline for data subject requests, extendable by two further months for complex/numerous requests.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "Gibraltar Regulatory Authority",
     "source_url": "https://www.gra.gi/data-protection",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Strong enforcement record evidences the regime's teeth, but DPO-appointment thresholds and joint-controller-specific Gibraltar guidance were not located.",
   "claims": [
    {
     "statement": "Sections 73 and 74 of the Data Protection Act 2004 (as amended in 2019), read with recitals 4, 75, 76, 84, 90, 92 and Article 35 of the GDPR, impose data protection impact assessment obligations in Gibraltar.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/gibraltar-data-protection-impact-assessment",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GRA's 18 April 2022 decision fined the Royal Gibraltar Police £10,000 partly for failures relating to records of processing activities, in violation of Article 30 GDPR and corresponding DPA 2004 sections.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-fines-royal-gibraltar-police-%C2%A310000",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GRA's 19 March 2020 guidance emphasises that organisations are accountable for establishing appropriate security measures and must adopt a risk-based approach, highlighting certification, third-party audits, breach management and multi-factor authentication.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-issues-data-security-guidance-under-gdpr",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Royal Gibraltar Police was fined £10,000 for, among other violations, breaching Sections 65(1)-(2), 70, 75 and 77(1)-(2) of the DPA 2004 and Articles 24(1)-(2), 30, 32 and 34(1)-(2) GDPR concerning breach communication and security, having notified the GRA and data subjects only after delay.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-fines-royal-gibraltar-police-%C2%A310000",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GRA's 2022 fine decision cited storage-limitation failures under Section 48(1)-(2) DPA 2004 and Article 5(1)(e) GDPR against the Royal Gibraltar Police.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-fines-royal-gibraltar-police-%C2%A310000",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer mechanisms (SCCs, BCRs, UK adequacy, DPF extension) are well evidenced; EU-side adequacy specifically for Gibraltar remains unconfirmed and is held for regulator confirmation.",
   "claims": [
    {
     "statement": "In the absence of an EU adequacy decision for Gibraltar, GRA's Transfers Guidance directs that EEA controllers transferring to Gibraltar should rely on Article 46 GDPR safeguards, including Standard Contractual Clauses and Binding Corporate Rules.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/gibraltar-navigating-brexit-and-data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The UK ICO lists Gibraltar among the countries and territories covered by full UK adequacy regulations, permitting restricted transfers from the UK to Gibraltar without additional safeguards; Gibraltar-based organisations may also rely on the UK Extension to the EU-US Data Privacy Framework for transfers to certain self-certified US businesses.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/international-transfers/adequacy-regulations/is-the-restricted-transfer-covered-by-adequacy-regulations/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As of the guidance reviewed, the Government of Gibraltar intended to seek an EU adequacy decision to ensure continuing free flow of data from the EEA to Gibraltar, but no such decision had been finalised at that time.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/opinion/gibraltar-navigating-brexit-and-data-protection",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Several sector overlays are evidenced (health, telecoms, employment, education); financial-sector-specific DP overlay guidance was not independently confirmed in this pass.",
   "claims": [
    {
     "statement": "Gibraltar's finance and gaming industries, supervised separately by the Gibraltar Financial Services Commission, plausibly create sector-specific data-handling obligations that intersect with general DP duties, though a dedicated overlay instrument was not confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Speculative",
     "source_publisher": "Gibraltar Regulatory Authority",
     "source_url": "https://www.gra.gi/data-protection",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GRA's guidance on contact tracing and location data identifies the Gibraltar Health Authority as controller, requiring robust security, data minimisation, transparency, Data Protection by Design and Default, and a DPIA for contact-tracing apps.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-guidance-gdpr-and-location-data",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Communications (Personal Data and Privacy) Regulations 2006 apply to SMS/MMS and electronic marketing in Gibraltar in addition to the Gibraltar GDPR and Data Protection Act 2004.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/gibraltar-smsmms-marketing",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GRA's investigation into the Royal Gibraltar Police confirmed data protection violations relating to both law-enforcement and employment-purpose processing of personal data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-fines-royal-gibraltar-police-%C2%A310000",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GRA's exemptions guidance outlines exemptions available under the DPA 2004 and GDPR for, among other things, health, social work, and education processing.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-guidance-exemptions-data-protection-legislation",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Direct marketing sub-module is well evidenced; most other sub-modules rely on inferred alignment with EU ePrivacy norms rather than confirmed Gibraltar-specific sources.",
   "claims": [
    {
     "statement": "The Communications (Personal Data and Privacy) Regulations 2006 impose consent requirements applicable to SMS/MMS marketing in Gibraltar, operating alongside the Gibraltar GDPR and Data Protection Act 2004.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/gibraltar-smsmms-marketing",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "red",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Almost no Gibraltar-specific guidance found on profiling, ADM transparency, AI risk assessment, biometrics or genetic data; only the state-surveillance carve-out is confirmed.",
   "claims": [
    {
     "statement": "GRA guidance confirms exemptions from the Data Protection Act 2004 and GDPR for crime, law enforcement and public protection purposes, which cannot be routinely relied upon and require case-by-case justification and documentation under the accountability principle.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-guidance-exemptions-data-protection-legislation",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "red",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Coverage almost entirely absent for this module; only a general education-exemption reference was confirmed.",
   "claims": [
    {
     "statement": "GRA's exemptions guidance identifies education as one of the sectors for which case-by-case processing exemptions from the DPA 2004/GDPR may apply.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-guidance-exemptions-data-protection-legislation",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/gibraltar/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers and activity are well evidenced; redress mechanisms, regulator capacity data, and GI-specific recent developments are not confirmed.",
   "claims": [
    {
     "statement": "The GRA fined the Royal Gibraltar Police £5,000 in August 2020 for unlawful disclosure of personal data, and £10,000 in April 2022 for multiple further breaches of the DPA 2004 and GDPR, demonstrating active use of its investigatory and fining powers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-fines-royal-gibraltar-police-%C2%A35000",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GRA published, on 2 June 2020, reports on investigations and enforcement covering deletion of personal data, unlawful disclosure to third parties, unlawful processing, failure to respond to subject access requests, unlawful CCTV installation, and unsolicited email marketing, alongside a breach-notification report on unlawful CCTV footage disclosure.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "OneTrust DataGuidance",
     "source_url": "https://www.dataguidance.com/news/gibraltar-gra-publishes-reports-enforcement-activity",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}