Skip to content
Content type · 15 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Malta (15) Clear filter
1–15 of 15 sort newestlargest fineoldest
€20,000 Hospital: Non-compliance with general data processing principles Data Protection Commissioner of Malta fined Hospital €20,000 on 2025-04-02 for: Non-compliance with general data processing principles. Malta ·Art. 5, 6, 14 +2 ·Non-compliance with general data processing principles Processing IP Address Healthcare Apr 2, 2025
€5,000 MALTA DPA: Non-compliance with general data processing principles The controller unlawfully gained access to audio recordings from a surveillance camera. Art. 5, 6 ·Non-compliance with general data processing principles Controllers Processing Supervisory Authorities Jan 1, 2023
€2,500 MALTA DPA: Insufficient fulfilment of data subjects rights Multiple data protection shortcomings Art. 5, 12, 13 +4 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Jan 1, 2023
€65,000 C-Planet (IT Solutions) Limited: Insufficient technical and organisational measures to ensure information security The DPA of Malta has imposed a fine of EUR 65,000 on C-Planet (IT Solutions) Limited. The DPA had initiated an investigation against C-Planet in April 2020 after being informed of… MALTA ·Art. 5, 6, 9 +4 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Jan 17, 2022
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 24, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2022
€250,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has failed to implement appropriate technical and organizational measures to protect personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Personal Data Jan 1, 2022
€65,000 MALTA DPA: Non-compliance with general data processing principles The controller has violated numerous GDPR regulations, involving special categories of personal data of numerous individuals. Art. 5, 6, 9 +3 ·Non-compliance with general data processing principles Supervisory Authorities Types of Special Categories of Personal Data Controllers Jan 1, 2022
€4,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller had sent unsolicited commercial messages. In addition, the privacy policy did not comply with transparency requirements and the controller failed to comply with… Art. 13, 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Fairness & Transparency Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2020
€2,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security A third party has gained unauthorized access to another person's account. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Integrity and Confidentiality Principle Supervisory Authorities Jan 1, 2020
€5,000 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has unlawfully disclosed personal data of a data subject. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Personal Data Security Controllers Jan 1, 2020
€20,000 MALTA DPA: Insufficient fulfilment of data subjects rights The controller failed to comply with a data subject's right to information. In addition, the data protection policy did not meet the transparency requirements. Art. 13, 15 ·Insufficient fulfilment of data subjects rights Supervisory Authorities Personal Data Fairness & Transparency Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security Accidental loss of personal data. Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Supervisory Authorities Jan 1, 2020
€2,500 MALTA DPA: Insufficient technical and organisational measures to ensure information security The controller has disclosed a personal email address to all recipients of the email. Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Supervisory Authorities Jan 1, 2020
€5,000 Lands Authority: Insufficient technical and organisational measures to ensure information security As a result of the lack of appropriate security measures on the Lands Authority website, over 10 gigabytes of personal data became easily accessible to the public via a simple… MALTA ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Integrity and Confidentiality Principle Security Personal Data Feb 18, 2019