{
 "jurisdiction_id": "MT",
 "jurisdiction": "Malta",
 "url": "https://dataprotection.gi/jurisdictions/malta/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 41,
  "sub_modules": 57,
  "source_register": 15
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Fully GDPR-aligned omnibus regime with an operational, independent supervisory authority and established subsidiary legislation; no material derogation gaps identified.",
   "claims": [
    {
     "statement": "The IDPC is the national independent supervisory authority responsible for upholding the fundamental right of individuals to have their personal data protected and to monitor the application of data protection law in Malta.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/media2/migrated/4026299/ico-malta-idpc-signed-mou-23062023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act (Chapter 586 of the Laws of Malta), implementing the GDPR, came into effect on 28 May 2018, replacing the former Data Protection Act (Chapter 440).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Malta applies no national variation to the GDPR definitions of data controller, data processor, personal data, sensitive data, or health data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC has, in prior enforcement matters, investigated and made determinations on whether a controller's main establishment is genuinely located in Malta for GDPR one-stop-shop jurisdictional purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EDPB / IDPC",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/article-60-final-decisions/publishable_mt_2019-10_right_to_object_marketing_emails_decisionpublic.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Direct-effect GDPR bases plus targeted, identified national derogations for insurance/health and credit referencing.",
   "claims": [
    {
     "statement": "The GDPR Article 6 lawful bases for processing apply with direct effect in Malta without a materially different national framework.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 7 consent standards requiring free, specific, informed and unambiguous consent, revocable without detriment, apply directly in Malta.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Malta's subsidiary legislation takes advantage of national derogations allowing processing of health information for insurance purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC has published guidelines for the promotion of good practice in the processing of personal data by credit referencing institutions and on disclosure of health data in occupational medicine contexts.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "GDPR direct effect plus active IDPC enforcement/consultation record on subject rights.",
   "claims": [
    {
     "statement": "The IDPC launched a consultation on the data access right for individuals in Malta in mid-2024.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/malta-idpc-launches-consultation-data-access-right",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Articles 16 and 17 rectification and erasure rights apply directly in Malta with no identified national variation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC issued a decision assessing a controller's compliance with a data subject's right to object to direct marketing emails, examining the controller's establishment and cooperation with the investigation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IDPC",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/article-60-final-decisions/publishable_mt_2019-10_right_to_object_marketing_emails_decisionpublic.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The standard GDPR one-month controller response window, extendable by two additional months for complex requests, applies directly in Malta.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Comprehensive GDPR-direct-effect duties with demonstrated enforcement precedent and sector-specific retention overlay for gambling regulatory data.",
   "claims": [
    {
     "statement": "GDPR Articles 5, 24, 25 and 35 accountability, privacy-by-design and DPIA obligations apply directly to controllers and processors in Malta.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC released a set of 20 FAQs on data protection officers on 29 January 2025, addressing DPO role and appointment questions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/malta-idpc-releases-faqs-dpos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 30 records-of-processing-activities obligations apply directly in Malta with no identified national variation.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC found the Lands Authority to have infringed Article 32 GDPR for lacking necessary technical and organisational measures on its online application portal, and served an administrative fine of €5,000 under Article 21 of the Data Protection Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IDPC",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/idpc-lands-authority-personal-data-breach_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The fine level for GDPR Article 32 breaches under Article 21 of the Data Protection Act is set with reference to the aggravating/mitigating circumstances listed in GDPR Article 83(2).",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IDPC",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/idpc-lands-authority-personal-data-breach_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC fined the controller C-Planet €65,000 in relation to a data breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/malta-idpc-fines-c-planet-eu65000-data-breach",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Retention of Data (Malta Gaming Authority) Regulations (Subsidiary Legislation 583.12) regulate the retention by the Malta Gaming Authority of personal data collected or otherwise processed in the pursuit of its regulatory functions.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/legal-research/retention-data-malta-gaming-authority",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "green",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Fully harmonised EU transfer regime; no Malta-specific derogation or independent adequacy determinations identified.",
   "claims": [
    {
     "statement": "The IDPC is responsible for facilitating the free flow of personal data between Malta and other EU Member States under Part V of the Data Protection Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "EU Standard Contractual Clauses and BCRs approved under GDPR Article 47 apply directly to transfers from Malta as an EU Member State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Core sectoral overlays (ePrivacy, insurance, gaming, employment, credit) are documented, but financial-services (MFSA) and education-sector specifics were not independently verified in this pass.",
   "claims": [
    {
     "statement": "The IDPC's credit-referencing guidelines are the primary identified sector-specific data-protection instrument touching the financial sector; a distinct MFSA-issued data-protection overlay was not independently confirmed.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Uncertain",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Malta's subsidiary legislation allows processing of health information for insurance purposes, and IDPC guidelines address disclosure of health data in occupational medicine and assessment of working capacity.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC is the competent authority responsible for monitoring the application of the ePrivacy Directive as implemented by the Processing of Personal Data (Electronic Communications Sector) Regulations, Subsidiary Legislation 586.01.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/media2/migrated/4026299/ico-malta-idpc-signed-mou-23062023.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC has published guidelines on the data protection aspects related to the collection of employees' COVID-19 vaccination status.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC has published guidelines for the promotion of good practice in the processing of personal data by credit referencing institutions.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Malta's subsidiary legislation includes a national derogation permitting processing of health data for insurance purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie/marketing consent regime is documented; several newer adtech sub-modules (dark patterns, opt-out signals, clean rooms) lack Malta-specific coverage.",
   "claims": [
    {
     "statement": "The IDPC published cookie-consent guidance addressing the use of cookies and trackers under the ePrivacy transposition.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC and the UK Information Commissioner's Office signed a Memorandum of Understanding establishing cross-border enforcement cooperation, referencing enforcement powers over unsolicited marketing analogous to PECR.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/media2/migrated/4026299/ico-malta-idpc-signed-mou-23062023.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "green",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Direct GDPR Article 22 effect plus a confirmed, current AI Act competent-authority designation for the IDPC; biometric/genetic-specific and surveillance-carve-out detail remain thinner.",
   "claims": [
    {
     "statement": "GDPR Article 22 restrictions on decisions based solely on automated processing, including profiling, which produce legal effects or similarly significantly affect the data subject, apply directly in Malta.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Articles 13-15 transparency obligations, including information on the existence of automated decision-making and its logic, apply directly in Malta.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC was designated as a Fundamental Rights Authority (FRA) and a Market Surveillance Authority (MSA) under the EU AI Act.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/malta-idpc-designated-fra-and-msa-under-ai-act",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "All EU Member States, including Malta, were required to designate national competent authorities under the EU AI Act by 2 August 2025.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/resources/article/eu-ai-act-regulatory-directory",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC is the competent authority in Malta for monitoring the application of the Law Enforcement Directive (2016/680), which governs national-security/law-enforcement processing carve-outs from the general GDPR regime.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "ICO",
     "source_url": "https://ico.org.uk/media2/migrated/4026299/ico-malta-idpc-signed-mou-23062023.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core age-of-consent and education-setting derogations are well documented; minor-profiling and dependent-adult protections remain unconfirmed gaps.",
   "claims": [
    {
     "statement": "Article 8 of the GDPR as well as Article 4 of the Processing of Children's Data Regulations states that processing of the personal data of a child in relation to information society services is lawful where the child is 13 years of age.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "For children below the applicable age threshold, GDPR Article 8 requires that the holder of parental responsibility consent to information-society-service processing, as transposed into Malta's Protection of Minors Regulations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under the Protection of Minors Regulations, where information is derived by a teacher, school administration member, or person acting in a professional capacity in place of a minor's parents, such information may be processed without requiring consent from the minor's parents or guardian where consent would be prejudicial to the minor's best interest, and the parent/guardian shall not have access to such data.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "amber",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/malta/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Core enforcement powers, penalty ceiling, and appeal mechanism are well documented; recent (180-day) enforcement activity and regulator funding/capacity data were not located.",
   "claims": [
    {
     "statement": "The IDPC may impose administrative fines under Article 21 of the Data Protection Act, with fine levels set by reference to the aggravating and mitigating circumstances under GDPR Article 83(2), up to the GDPR statutory maxima.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IDPC",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/idpc-lands-authority-personal-data-breach_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The IDPC fined the Lands Authority €5,000 in 2019 for an Article 32 GDPR security-of-processing breach, and fined the controller C-Planet €65,000 in relation to a data breach.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / IDPC",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2019/idpc-lands-authority-personal-data-breach_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 80 representative-action rights, permitting not-for-profit bodies to lodge complaints and seek judicial remedies on behalf of data subjects, apply directly in Malta.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Pursuant to Article 26 of the Data Protection Act, any person aggrieved by a decision of the IDPC regarding data breaches has the right to appeal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://legacy.dataguidance.com/notes/malta-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}