🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
GI · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 15 sources retrieved model claude-sonnet-5 ·

Gibraltar

GI schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 27 claims · 15 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute with active, named regulator and demonstrated enforcement activity.

Primary frameworkGibraltar GDPR (retained EU GDPR 2016/679) and Data Protection Act 2004 (as amended)
Traffic-light rationale — GreenComprehensive statute with active, named regulator and demonstrated enforcement activity.

Sub-modules (5)

Regulator And AuthorityGreen

GRA is the designated supervisory authority for data protection in Gibraltar and issues guidance and enforcement decisions under the DPA 2004/GDPR.

Claims: CLM-GI-a1b2c3d4

Act And InstrumentsGreen

Core instruments are the Gibraltar GDPR and the Data Protection Act 2004 as amended in 2019; the EU GDPR ceased to apply directly from 1 January 2021.

Claims: CLM-GI-b2c3d4e5

Material ScopeAmber

Material scope mirrors GDPR Article 2 — automated and structured-manual processing of personal data by controllers/processors.

Absence provenance: Only inferred via mirrored GDPR structure; no Gibraltar-specific material-scope guidance located in this pass.. Searched: Gibraltar Data Protection Act 2004 material scope text, GRA official material scope guidance.

Claims: CLM-GI-c3d4e5f6

Territorial ScopeGreen

Territorial scope extends to controllers/processors outside Gibraltar offering goods/services to, or monitoring, individuals in Gibraltar, mirroring GDPR Art 3, and continues to apply GDPR extraterritorially to Gibraltar-based controllers targeting the EEA.

Claims: CLM-GI-d4e5f6a7

Regulator Registration And FilingRed

No Gibraltar-specific controller registration/filing fee regime was identified in this research pass.

Absence provenance: No confirmed source located; absent rather than fabricated.. Searched: Gibraltar GRA controller registration fee, Gibraltar Data Protection Act 2004 notification requirement.

Category narrative61 words

Gibraltar operates a GDPR-style comprehensive regime supervised by the Gibraltar Regulatory Authority (GRA), which acts as the Information Commissioner's function under the Data Protection Act 2004 (as amended). Following the end of the Brexit transition period, the EU GDPR was superseded on 1 January 2021 by the Gibraltar GDPR (a retained/localised version of Regulation (EU) 2016/679), applied alongside the DPA 2004.

Sources and claims (4)
  1. ConfirmedGibraltar Regulatory AuthorityThe Gibraltar Regulatory Authority (GRA) is the supervisory authority responsible for enforcing the Data Protection Act 2004 and the Gibraltar GDPR, including issuing fines and guidance.
  2. ConfirmedOneTrust DataGuidanceFollowing the end of the Brexit transition period, the applicable law in Gibraltar is no longer the EU GDPR but the Gibraltar GDPR, which superseded it on 1 January 2021 pursuant to Section 6 of the European Union (Withdrawal) Act 2019, alongside the Data Protection Act 2004 (as amended in 2019).
  3. ProbableGibraltar Regulatory AuthorityMaterial scope of the Gibraltar regime mirrors GDPR Article 2, covering wholly/partly automated processing and structured manual filing systems of personal data.
  4. ConfirmedOneTrust DataGuidanceEven after the end of the Brexit transition period, a Gibraltar-based controller or processor offering goods or services to, or monitoring the behaviour of, individuals in the EEA must continue to comply with the EU GDPR.

#

Framework is GDPR-aligned but Gibraltar-specific consent-threshold and pseudonymisation guidance is thin in the public record.

Primary frameworkGibraltar GDPR Arts 6 & 9; Data Protection Act 2004 exemptions provisions
Traffic-light rationale — AmberFramework is GDPR-aligned but Gibraltar-specific consent-threshold and pseudonymisation guidance is thin in the public record.

Sub-modules (4)

Lawful BasesAmber

Lawful bases mirror GDPR Art 6 (consent, contract, legal obligation, vital interests, public task, legitimate interests).

Claims: CLM-GI-e5f6a7b8

Special CategoriesAmber

GRA guidance on exemptions confirms special-category-adjacent processing exemptions for health, social work and education contexts and clarifies exemptions cannot be routinely relied upon.

Claims: CLM-GI-f6a7b8c9

Pseudonymisation And AnonymisationAmber

GRA's COVID-era location-data guidance recommends anonymisation as preferred over identifiable location data, requiring consent where anonymisation is not applied.

Claims: CLM-GI-a7b8c9d0

Category narrative40 words

Gibraltar's lawful-basis and special-category framework is inherited directly from the GDPR structure (Arts 6 and 9) via the Gibraltar GDPR, supplemented by DPA 2004 exemptions guidance issued by GRA covering crime/law enforcement, journalism, research/archiving, health, social work and education processing.

Sources and claims (3)
  1. ProbableGibraltar Regulatory AuthorityThe Gibraltar GDPR retains the six lawful bases for processing set out in Article 6 of Regulation (EU) 2016/679.
  2. ConfirmedOneTrust DataGuidanceGRA guidance outlines exemptions from the Data Protection Act 2004 and GDPR available for, among others, crime, law enforcement and public protection, journalism, research and archiving, and health, social work and education processing, and clarifies these cannot be routinely relied upon and must be justified case-by-case.
  3. ConfirmedOneTrust DataGuidanceGRA guidance on location data states that anonymisation is preferred and that consent is required where location data is not anonymised, encouraging transparency about anonymisation methodology.

#

Rights framework is GDPR-aligned and actively enforced (SAR failures investigated) but Gibraltar-specific procedural guidance on erasure/portability/deadlines was not located in this pass.

Primary frameworkGibraltar GDPR Arts 12-22
Traffic-light rationale — AmberRights framework is GDPR-aligned and actively enforced (SAR failures investigated) but Gibraltar-specific procedural guidance on erasure/portability/deadlines was not located in this pass.

Sub-modules (5)

Access RightAmber

GRA enforcement/investigations reports document cases involving failure to respond to subject access requests.

Claims: CLM-GI-b8c9d0e1

Rectification And ErasureRed

No Gibraltar-specific erasure/rectification guidance located; presumed to mirror GDPR Arts 16-17.

Absence provenance: Not located in this pass.. Searched: GRA right to erasure guidance, Gibraltar data subject rights note.

Restriction And ObjectionRed

No Gibraltar-specific restriction/objection guidance located.

Absence provenance: Not located in this pass.. Searched: GRA restriction of processing guidance, Gibraltar objection to processing.

Data PortabilityRed

No Gibraltar-specific portability guidance located.

Absence provenance: Not located in this pass.. Searched: GRA data portability guidance.

Deadlines And Response WindowsAmber

Response deadlines presumed to mirror the GDPR one-month (extendable) standard; no Gibraltar-specific variance found.

Claims: CLM-GI-c9d0e1f2

Category narrative32 words

Data subject rights are inherited from the GDPR structure (Arts 12-22). GRA's published enforcement/investigations reports evidence real-world exercise of the access right, including failures by controllers to respond to subject access requests.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceGRA's published investigations and enforcement report addresses cases involving failure to respond to subject access requests, among other compliance failures under GDPR and the DPA 2004.
  2. ProbableGibraltar Regulatory AuthorityThe Gibraltar GDPR retains the GDPR Article 12(3) standard one-month response deadline for data subject requests, extendable by two further months for complex/numerous requests.

#

Strong enforcement record evidences the regime's teeth, but DPO-appointment thresholds and joint-controller-specific Gibraltar guidance were not located.

Primary frameworkData Protection Act 2004 (as amended) Part III; Gibraltar GDPR Arts 24-39
Traffic-light rationale — AmberStrong enforcement record evidences the regime's teeth, but DPO-appointment thresholds and joint-controller-specific Gibraltar guidance were not located.

Sub-modules (7)

Accountability And DpiaGreen

DPIA obligations are set out in Sections 73-74 of the DPA 2004, referencing GDPR Article 35 and recitals; GRA relies on WP29/EDPB DPIA guidelines.

Claims: CLM-GI-d0e1f2a3

Dpo RequirementsRed

No Gibraltar-specific DPO appointment threshold guidance was located in this pass; presumed to mirror GDPR Arts 37-39.

Absence provenance: Not located in this pass.. Searched: GRA DPO appointment guidance, Gibraltar Data Protection Act DPO section.

Ropa RequirementsAmber

The 2022 GRA fine against Royal Gibraltar Police cited failures in records of processing activities as a breach ground.

Claims: CLM-GI-e1f2a3b4

Joint Controller ArrangementsRed

No Gibraltar-specific joint-controller guidance was located.

Absence provenance: Not located in this pass.. Searched: GRA joint controller guidance.

Security MeasuresGreen

GRA's 2020 data-security guidance requires organisations to adopt a risk-based approach and outlines organisational/technical measures including certification, third-party audits, breach management and multi-factor authentication.

Claims: CLM-GI-f2a3b4c5

Breach NotificationGreen

Breach notification duties under Part III, Chapter 4, Section 76 of the DPA 2004 were directly enforced against the Royal Gibraltar Police for delayed notification to the GRA and data subjects.

Claims: CLM-GI-a3b4c5d6

Retention And DisposalAmber

The 2022 GRA fine cited storage-limitation failures (Section 48(1) DPA / Art 5(1)(e) GDPR) against Royal Gibraltar Police.

Claims: CLM-GI-b4c5d6e7

Category narrative52 words

Controller/processor duties (accountability, DPIA, ROPA, security, breach notification, retention) are set out across the DPA 2004 and Gibraltar GDPR and are actively enforced — the GRA's fines against the Royal Gibraltar Police (2020, 2022) cite specific DPA sections and GDPR articles covering storage limitation, security of processing, ROPA, and breach communication failures.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidanceSections 73 and 74 of the Data Protection Act 2004 (as amended in 2019), read with recitals 4, 75, 76, 84, 90, 92 and Article 35 of the GDPR, impose data protection impact assessment obligations in Gibraltar.
  2. ConfirmedOneTrust DataGuidanceThe GRA's 18 April 2022 decision fined the Royal Gibraltar Police £10,000 partly for failures relating to records of processing activities, in violation of Article 30 GDPR and corresponding DPA 2004 sections.
  3. ConfirmedOneTrust DataGuidanceGRA's 19 March 2020 guidance emphasises that organisations are accountable for establishing appropriate security measures and must adopt a risk-based approach, highlighting certification, third-party audits, breach management and multi-factor authentication.
  4. ConfirmedOneTrust DataGuidanceThe Royal Gibraltar Police was fined £10,000 for, among other violations, breaching Sections 65(1)-(2), 70, 75 and 77(1)-(2) of the DPA 2004 and Articles 24(1)-(2), 30, 32 and 34(1)-(2) GDPR concerning breach communication and security, having notified the GRA and data subjects only after delay.
  5. ConfirmedOneTrust DataGuidanceThe GRA's 2022 fine decision cited storage-limitation failures under Section 48(1)-(2) DPA 2004 and Article 5(1)(e) GDPR against the Royal Gibraltar Police.

#

Transfer mechanisms (SCCs, BCRs, UK adequacy, DPF extension) are well evidenced; EU-side adequacy specifically for Gibraltar remains unconfirmed and is held for regulator confirmation.

Primary frameworkGibraltar GDPR Arts 44-49; UK Data Protection (Adequacy) framework
Traffic-light rationale — AmberTransfer mechanisms (SCCs, BCRs, UK adequacy, DPF extension) are well evidenced; EU-side adequacy specifically for Gibraltar remains unconfirmed and is held for regulator confirmation.

Sub-modules (6)

Transfer MechanismsAmber

GRA's Transfers Guidance identifies SCCs and BCRs under Article 46 GDPR as safeguards for EEA-to-Gibraltar transfers absent an adequacy decision.

Claims: CLM-GI-c5d6e7f8

Adequacy ReceivedGreen

Gibraltar is listed by the UK ICO among jurisdictions with full UK adequacy status, permitting free-flow restricted transfers from the UK to Gibraltar.

Claims: CLM-GI-d6e7f8a9

Adequacy GrantedRed

No confirmed EU Commission adequacy decision specifically for Gibraltar was located; the Gibraltar Government's intent (as of 2020 guidance) to seek such a decision does not appear to have been finalised in sources reviewed.

Absence provenance: No EU Commission adequacy decision for Gibraltar specifically was found distinct from the UK-EU adequacy decisions.. Searched: Gibraltar EU adequacy decision 2025 2026, European Commission Gibraltar adequacy.

Claims: CLM-GI-e7f8a9b0

Sccs And BcrsAmber

SCCs approved by a supervisory authority and approved by the European Commission, and BCRs, are identified as available safeguards for EEA-Gibraltar transfers.

Claims: CLM-GI-c5d6e7f8

Transfer Impact AssessmentRed

No Gibraltar-specific TIA requirement or guidance was located.

Absence provenance: Not located in this pass.. Searched: GRA transfer impact assessment guidance.

Data LocalisationRed

No data-localisation mandate was identified for Gibraltar.

Absence provenance: No evidence of a localisation mandate found.. Searched: Gibraltar data localisation requirement.

Category narrative73 words

Gibraltar benefits from full UK adequacy status (it is listed among the countries/territories the UK deems fully adequate for restricted transfers), and Gibraltar-based organisations may use the UK Extension to the EU-US Data Privacy Framework for transfers to the US. However, no confirmed EU Commission adequacy decision specifically covering Gibraltar (distinct from the UK's own adequacy decisions) was located; the Gibraltar Government's 2020 stated intention to seek one appears unresolved in current sources.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidanceIn the absence of an EU adequacy decision for Gibraltar, GRA's Transfers Guidance directs that EEA controllers transferring to Gibraltar should rely on Article 46 GDPR safeguards, including Standard Contractual Clauses and Binding Corporate Rules.
  2. ConfirmedICOThe UK ICO lists Gibraltar among the countries and territories covered by full UK adequacy regulations, permitting restricted transfers from the UK to Gibraltar without additional safeguards; Gibraltar-based organisations may also rely on the UK Extension to the EU-US Data Privacy Framework for transfers to certain self-certified US businesses.
  3. UncertainOneTrust DataGuidanceAs of the guidance reviewed, the Government of Gibraltar intended to seek an EU adequacy decision to ensure continuing free flow of data from the EEA to Gibraltar, but no such decision had been finalised at that time.

#

Several sector overlays are evidenced (health, telecoms, employment, education); financial-sector-specific DP overlay guidance was not independently confirmed in this pass.

Primary frameworkCommunications (Personal Data and Privacy) Regulations 2006; Data Protection Act 2004 exemptions provisions
Traffic-light rationale — AmberSeveral sector overlays are evidenced (health, telecoms, employment, education); financial-sector-specific DP overlay guidance was not independently confirmed in this pass.

Sub-modules (7)

Financial Sector OverlayRed

Gibraltar's financial-services and online-gaming sectors are supervised by the Gibraltar Financial Services Commission; a distinct financial-sector DP overlay was not independently confirmed in sources reviewed.

Absence provenance: No dedicated financial-sector DP guidance located; flagged as plausible overlap given Gibraltar's finance/gaming centre status.. Searched: Gibraltar Financial Services Commission data protection overlay, GFSC GDPR guidance.

Claims: CLM-GI-f8a9b0c1

Health Sector OverlayAmber

GRA's contact-tracing guidance designates the Gibraltar Health Authority as controller for COVID-19 contact-tracing data, requiring DPIA and Data Protection by Design.

Claims: CLM-GI-a9b0c1d2

Telecoms And EprivacyGreen

The Communications (Personal Data and Privacy) Regulations 2006 govern electronic marketing including SMS/MMS in Gibraltar, alongside the Gibraltar GDPR.

Claims: CLM-GI-b0c1d2e3

Employment DataAmber

The 2022 GRA fine against the Royal Gibraltar Police confirmed violations relating to both law-enforcement and employment-purpose data processing.

Claims: CLM-GI-c1d2e3f4

Credit And ScoringRed

No Gibraltar-specific credit-scoring DP overlay was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar credit scoring data protection.

EducationAmber

GRA's exemptions guidance references education-sector processing exemptions under the DPA 2004/GDPR.

Claims: CLM-GI-d2e3f4a5

InsuranceRed

No Gibraltar-specific insurance-sector DP overlay was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar insurance sector data protection.

Category narrative69 words

Sectoral overlays identified include health (Gibraltar Health Authority as controller for contact tracing under GRA COVID guidance), telecoms/eprivacy (Communications (Personal Data and Privacy) Regulations 2006 for direct marketing), employment (the Royal Gibraltar Police case involved employment-purpose data), and education (referenced in GRA exemptions guidance). Gibraltar's significant financial-services and online-gaming sectors are regulated by the Gibraltar Financial Services Commission, creating a plausible but not independently confirmed overlay with data-protection duties.

Sources and claims (5)
  1. SpeculativeGibraltar Regulatory AuthorityGibraltar's finance and gaming industries, supervised separately by the Gibraltar Financial Services Commission, plausibly create sector-specific data-handling obligations that intersect with general DP duties, though a dedicated overlay instrument was not confirmed.
  2. ConfirmedOneTrust DataGuidanceGRA's guidance on contact tracing and location data identifies the Gibraltar Health Authority as controller, requiring robust security, data minimisation, transparency, Data Protection by Design and Default, and a DPIA for contact-tracing apps.
  3. ConfirmedOneTrust DataGuidanceThe Communications (Personal Data and Privacy) Regulations 2006 apply to SMS/MMS and electronic marketing in Gibraltar in addition to the Gibraltar GDPR and Data Protection Act 2004.
  4. ConfirmedOneTrust DataGuidanceThe GRA's investigation into the Royal Gibraltar Police confirmed data protection violations relating to both law-enforcement and employment-purpose processing of personal data.
  5. ConfirmedOneTrust DataGuidanceGRA's exemptions guidance outlines exemptions available under the DPA 2004 and GDPR for, among other things, health, social work, and education processing.

#

Direct marketing sub-module is well evidenced; most other sub-modules rely on inferred alignment with EU ePrivacy norms rather than confirmed Gibraltar-specific sources.

Primary frameworkCommunications (Personal Data and Privacy) Regulations 2006
Traffic-light rationale — AmberDirect marketing sub-module is well evidenced; most other sub-modules rely on inferred alignment with EU ePrivacy norms rather than confirmed Gibraltar-specific sources.

Sub-modules (6)

Cookies And TrackersRed

Cookie/tracker consent is presumed governed by the Communications (Personal Data and Privacy) Regulations 2006 (an ePrivacy-equivalent instrument), but no Gibraltar-specific cookie guidance was confirmed.

Absence provenance: Not located in this pass.. Searched: GRA cookie consent guidance, Gibraltar ePrivacy cookies.

Dark PatternsRed

No Gibraltar-specific dark-pattern prohibition was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar dark patterns data protection.

Opt Out SignalsRed

No Gibraltar-specific recognition of Global Privacy Control or similar opt-out signals was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar Global Privacy Control, GRA opt-out signal guidance.

Clean Rooms And DcrRed

No Gibraltar-specific data clean room guidance was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar data clean room.

Cross Context AdvertisingRed

No Gibraltar-specific cross-context advertising rules (e.g., CPRA-style sale/share definitions) were located; not applicable under the GDPR-style model.

Absence provenance: Not applicable/located under GDPR-style regime.. Searched: Gibraltar cross-context advertising rules.

Direct MarketingGreen

The Communications (Personal Data and Privacy) Regulations 2006 impose consent and suppression requirements for SMS/MMS and electronic direct marketing.

Claims: CLM-GI-e3f4a5b6

Category narrative33 words

Direct-marketing consent requirements under the Communications (Personal Data and Privacy) Regulations 2006 are confirmed for SMS/MMS marketing. No Gibraltar-specific cookie-consent enforcement, dark-pattern prohibition, opt-out-signal recognition, or clean-room/DCR guidance was located in this pass.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceThe Communications (Personal Data and Privacy) Regulations 2006 impose consent requirements applicable to SMS/MMS marketing in Gibraltar, operating alongside the Gibraltar GDPR and Data Protection Act 2004.

#

Almost no Gibraltar-specific guidance found on profiling, ADM transparency, AI risk assessment, biometrics or genetic data; only the state-surveillance carve-out is confirmed.

Primary frameworkGibraltar GDPR Arts 9 & 22
Traffic-light rationale — RedAlmost no Gibraltar-specific guidance found on profiling, ADM transparency, AI risk assessment, biometrics or genetic data; only the state-surveillance carve-out is confirmed.

Sub-modules (6)

Profiling RestrictionsRed

No Gibraltar-specific profiling-restriction guidance was located; presumed to mirror GDPR Art 22.

Absence provenance: Not located in this pass.. Searched: GRA profiling restrictions guidance.

Automated Decision Making TransparencyRed

No Gibraltar-specific ADM transparency guidance was located.

Absence provenance: Not located in this pass.. Searched: GRA automated decision-making guidance.

Ai Risk AssessmentsRed

No Gibraltar-specific AI risk-assessment regime or interface with the EU AI Act was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar AI Act data protection, GRA AI risk assessment guidance.

Biometric RegimeRed

No Gibraltar-specific biometric-data regime guidance was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar biometric data regime, GRA facial recognition guidance.

Genetic DataRed

No Gibraltar-specific genetic-data regime guidance was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar genetic data regime.

State Surveillance CarveoutsAmber

GRA's exemptions guidance confirms carve-outs from the DPA 2004/GDPR for crime, law enforcement and public protection purposes, subject to case-by-case justification.

Claims: CLM-GI-f4a5b6c7

Category narrative49 words

Algorithmic/biometric governance in Gibraltar is presumed to mirror GDPR Article 22 (automated decision-making) and Article 9 (biometric/genetic special categories) via the Gibraltar GDPR, but no Gibraltar-specific ADM, AI risk-assessment, or biometric-regime guidance was located. GRA's exemptions guidance confirms a state-surveillance carve-out for crime, law enforcement and public protection purposes.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceGRA guidance confirms exemptions from the Data Protection Act 2004 and GDPR for crime, law enforcement and public protection purposes, which cannot be routinely relied upon and require case-by-case justification and documentation under the accountability principle.

#

Coverage almost entirely absent for this module; only a general education-exemption reference was confirmed.

Traffic-light rationale — RedCoverage almost entirely absent for this module; only a general education-exemption reference was confirmed.

Sub-modules (5)

Age VerificationRed

No Gibraltar-specific age-verification requirement was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar age of digital consent, GRA age verification guidance.

Minor Profiling BansRed

No Gibraltar-specific minor-profiling ban was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar minor profiling ban.

Education SettingsAmber

GRA's exemptions guidance references education as one of the sectors with case-by-case DP exemptions.

Claims: CLM-GI-a5b6c7d8

Dependent AdultsRed

No Gibraltar-specific dependent-adults protection provision was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar dependent adults data protection, GRA vulnerable adults guidance.

Category narrative26 words

No Gibraltar-specific age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults provision was independently located in this pass, beyond the general education-sector exemption referenced in GRA's exemptions guidance.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidanceGRA's exemptions guidance identifies education as one of the sectors for which case-by-case processing exemptions from the DPA 2004/GDPR may apply.

#

Enforcement powers and activity are well evidenced; redress mechanisms, regulator capacity data, and GI-specific recent developments are not confirmed.

Primary frameworkData Protection Act 2004 Part IV (enforcement); Gibraltar GDPR Arts 83-84 (as retained)
Traffic-light rationale — AmberEnforcement powers and activity are well evidenced; redress mechanisms, regulator capacity data, and GI-specific recent developments are not confirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The GRA has statutory power to investigate and fine controllers/processors, as demonstrated by two fines issued against the Royal Gibraltar Police.

Claims: CLM-GI-b6c7d8e9

Enforcement Activity IndexAmber

GRA published enforcement-activity reports in June 2020 covering investigations into deletion failures, unlawful disclosure, unlawful processing, SAR failures, unlawful CCTV, and unsolicited marketing; it has also issued at least two fines against the same controller (2020, 2022).

Claims: CLM-GI-c7d8e9f0

Regulator Funding And CapacityRed

No GRA funding or headcount data was located in this pass.

Absence provenance: Not located in this pass.. Searched: GRA budget headcount data protection, Gibraltar Regulatory Authority annual report staffing.

Collective Redress And Class ActionsRed

No Gibraltar-specific collective-redress or class-action mechanism for data protection claims was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar data protection class action, Gibraltar collective redress data protection.

Private Right Of ActionRed

No Gibraltar-specific private right of action for data protection breaches (distinct from GRA enforcement) was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar private right of action data protection, Gibraltar Supreme Court data protection claim.

Recent Developments 180DRed

No Gibraltar-specific data-protection legislative, guidance, or case-law development within the last 180 days (i.e., since approximately February 2026) was located; UK-EU adequacy renewal activity in late 2025/2026 pertains to the UK's own adequacy status rather than a confirmed Gibraltar-specific instrument.

Absence provenance: No GI-specific development within the last 180 days was confirmed in this research pass.. Searched: Gibraltar data protection news 2026, GRA press release 2026, Gibraltar GDPR amendment 2026.

Category narrative68 words

The GRA has demonstrated active investigatory and fining powers, evidenced by two separate fines against the Royal Gibraltar Police (£5,000 in 2020 and £10,000 in 2022) for DPA 2004/GDPR breaches, and has published enforcement-activity and breach-notification reports. No Gibraltar-specific collective-redress, class-action, or private-right-of-action mechanism was located, and no distinctly Gibraltar-specific development within the last 180 days was confirmed (recent EU-UK adequacy renewal activity is UK-specific rather than GI-specific).

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidanceThe GRA fined the Royal Gibraltar Police £5,000 in August 2020 for unlawful disclosure of personal data, and £10,000 in April 2022 for multiple further breaches of the DPA 2004 and GDPR, demonstrating active use of its investigatory and fining powers.
  2. ConfirmedOneTrust DataGuidanceGRA published, on 2 June 2020, reports on investigations and enforcement covering deletion of personal data, unlawful disclosure to third parties, unlawful processing, failure to respond to subject access requests, unlawful CCTV installation, and unsolicited email marketing, alongside a breach-notification report on unlawful CCTV footage disclosure.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Gibraltar
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s), 31 source(s) in the cumulative register.