Skip to content
News · noyb - European Center for Digital Rights EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Data Breach in Malta: Company must disclose source within 20 days or face penalties

Full text

Political Microtargeting, Manipulation & Tracking Data Breach in Malta: Company must disclose source within 20 days or face penalties The Maltese Data Protection Authority (IDPC) has taken decisive action against C-PLANET, the IT company responsible for a voter data breach in Malta. Following a second complaint filed by noyb, the IDPC has ordered C-PLANET to reveal the specific details regarding the collection of data belonging to Maltese citizens within a strict 20-day deadline. If the company does not comply with this order they will face a “dissuasive” fine. Blog post: Political data breach in Malta, C-Planet refuses right to access and information Decision by the IDPC Initial Complaint. In November 2020, noyb filed a complaint against C-PLANET IT Solutions following a significant data leak compromising voter information in Malta. The breach exposed sensitive details, including telephone numbers, dates of birth, voting intentions, and party affiliations of over 330,000 individuals,

How it connects

C-768/21 TR v Land Hessen In Case C-768/21, the Court of Justice of the European Union (First Chamber) ruled on a preliminary reference from the Verwaltungsgericht Wiesbaden concerning TR's challenge of… CJEU ·First Chamber Sep 26, 2024 Supervision Data Breaches Integrity and Confidentiality Principle
C‑313/23, C‑316/23 and C‑332/23 Inspektorat kam Visshia sadeben savet C‑313/23, C‑316/23 and C‑332/23 - Inspektorat kam Visshia sadeben savet Following the expiration of the prescribed time limit for submission of annual declarations of assets of judges, public prosecutors and investigating magistrates and their… CJEU Apr 30, 2025 Supervision Monitoring Data Breaches
2016 IEHC 323 High Court examines DPA inquiry into Meta's refusal of raw data access and portability On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (MPIL) (then Facebook Ireland Limited), the… Aug 21, 2026 Data Portability Supervisory Authorities Personal Data
Opinion 2/2026 EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework ( EDPB, EDPB-EDPS Joint opinion 2/2026 on the Proposal for a Regulation as regards the simplification of the digital legislative framework (Digital Omnibus) Opinion Feb 11, 2026 Notified Body Reporting and Notification Obligations Notification Obligation Data Breaches
10 A 5144/23 VG Hannover: Controller appeals DPA reprimand over unlawful workplace video surveillance The owner of a doner kebab production facility (the controller) had installed video cameras to monitor virtually every room of the business premises. Cameras were placed in the… Administrative Court Hannover Aug 7, 2026 Controllers Supervisory Authorities Legitimate Interest