Technology, Media & Telecommunications (TMT)
Legal 500 Country Comparative Guides 2026 TMT
Author: Jean Pierre Scerri
Legal 500 Country Comparative Guides 2026 TMT
37 min read
Author: Jean Pierre Scerri
Software – How are proprietary rights in software and associated materials protected?
Computer programs qualify as literary works under the Copyright Act (Cap. 415 of the Laws of Malta). The term ‘literary work’ is defined to include ‘computer programs’. The term ‘computer program’ in turn includes, in its definition, preparatory design material and hardware interfaces. Literary works are eligible for copyright protection provided they have an original character and are reduced to material form. No registration is required.
Under the Copyright Act, the standard term of protection for a computer program is 70 years after the death of the author. Where the program is subject to joint authorship, then the 70 years start counting from the end of the calendar year in which the last surviving co-author dies, while in case of anonymous or pseudonymous works, protection lasts for 70 years from the end of the calendar year in which the software was first lawfully made available to the public. Material that does not meet the originality threshold for copyright, such as algorithms, technical know-how and internal documentation, may instead qualify as a trade secret under the Trade Secrets Act (Cap. 589 of the Laws of Malta) as long as the information they contain is secret, has commercial value because of that secrecy, and has been subject to reasonable steps to keep it secret. Software-related inventions may in narrow circumstances attract patent protection through the European Patent Office or the Malta IP Office under the European Patent Convention, where the invention provides a technical solution to a technical problem rather than software ‘as such’.
Software – In the event that software is developed by a software developer, consultant or other party for a customer, who will own the resulting proprietary rights in the newly created software in the absence of any agreed contractual position?
Under Article 11(1) of the Copyright Act, copyright vests initially in the author. However, Article 11(1) provides an exception insofar as computer programs and databases are concerned. Where these are created by an employee in the course of employment, in the execution of the employee’s duties or on the employer’s instructions, the economic rights are deemed transferred to the employer by default, subject to any agreement to the contrary.
Where the developer is an independent contractor or consultant rather than an employee, Article 11 does not operate in the customer’s favour. Ownership remains with the developer unless expressly assigned in writing under Article 24(4). Absent such an assignment, the customer will generally only obtain an implied licence to use the software for the purpose for which it was commissioned. For this reason, technology contracts subject to Maltese law routinely include express IP assignment or licence clauses to displace this default position.
Software – Are there any specific laws that govern the harm / liability caused by Software / computer systems?
No, there are no specific laws that deal exclusively with harm or liability caused by software or computer
systems. Liability instead arises under general contract and tort principles in the Civil Code (Cap. 16 of the Laws of Malta). It is important to note that with the revised EU Product Liability Directive (Directive (EU) 2024/2853, due for transposition into Maltese law by 9 December 2026), the definition of the term ‘Product’ will be broadened to include digital products and software capable of triggering strict liability for commercial software defects under Article 4(1). Consumer contracts for digital content and digital
services are governed by the Digital Content and Digital Services Contracts Regulations (S.L. 378.20),
implementing Directive (EU) 2019/770, which imposes conformity and remedy obligations on suppliers.
Software – To the extent not covered by (3) above, are there any specific laws that govern the use (or misuse) of software / computer systems?
Articles 337B to 337H of the Criminal Code (Cap. 9 of the Laws of Malta) contain provisions relating to cybercrime offences. Article 337C criminalises, amongst other things, unauthorised access to, use, copying or modification of data, software or supporting documentation, and unauthorised hindrance of a computer system’s functioning or the integrity or reliability of any data. The Electronic Commerce Act (Cap. 426 of the Laws of Malta) and the eIDAS Regulation (EU 910/2014) govern electronic signatures, trust services and the validity of electronic transactions. Where software processes personal data, the GDPR and the Data Protection Act (Cap. 586 of the Laws of Malta) apply to its use.
Software Transactions (Licence and SaaS) – Other than as identified elsewhere in this overview, are there any technology-specific laws that govern the provision of software between a software vendor and customer, including any laws that govern the use of cloud technology?
There are no technology-specific rules which govern the provision of software between a software vendor and a customer. Any such relationship would be governed by general contract law under the Civil Code, together with the Consumer Rights Act (Cap. 378 of the Laws of Malta) which transposes rules on digital content and services for business-to-consumer transactions. The Electronic Commerce Act validates electronic contracts, online signatures and intermediary rules for information society services.
At EU level, the Data Act (Regulation (EU) 2023/2854), applicable from September 2025, imposes obligations on cloud and data-processing providers to facilitate switching between providers, remove unfair contractual terms restricting portability, and phase out switching charges. By Legal Notice 222 of 2025 (the Fair Access to and Use of Data Regulations), the Malta Digital Innovation Authority (MDIA) is designated as national data coordinator and competent authority for the Data Act generally, while the MCA is separately designated as competent authority specifically for the cloud-switching provisions and the international-access safeguards (which are the provisions most directly relevant to cloud contracting).
Where personal data is processed in the cloud, the GDPR applies directly, and NIS2 imposes supply-chain security obligations on essential and important entities that rely on cloud services.
Software Transactions (License and SaaS) – Is it typical for a software vendor to cap its maximum financial liability to a customer in a software transaction? If ‘yes’, what would be considered a market standard level of cap?
Yes, it is typical for a software vendor to cap its maximum financial liability. A common benchmark is a cap set at between 100% and 200% of the fees paid, or payable, by the customer in the twelve months preceding the event giving rise to the claim. However, higher multiples (between 10% and 200% of the total contract value) are sometimes negotiated for critical systems or larger enterprise and cloud transactions. Certain liabilities cannot be capped – as discussed further below.
Software Transactions (License and SaaS) – Please comment on whether any of the following areas of liability would typically be excluded from any financial cap on the software vendor’s liability to the customer or subject to a separate enhanced cap in a negotiated software transaction (i.e. unlimited liability): (a) confidentiality breaches; (b) data protection breaches; (c) data security breaches (including loss of data); (d) IPR infringement claims; (e) breaches of applicable law; (f) regulatory fines; (g) wilful or deliberate breaches; (h) claims arising out of or in relation to artificial intelligence.
Negotiations vary from party to party and contract to contract. However, it is indeed the practice in Malta to seek to negotiate a separate enhanced cap or to push for an uncapped liability for confidentiality breaches. Due to the quantum of penalties that can be applicable under GDPR, a separate super cap (rather than unlimited liability) is typically negotiated for data protection and data security breaches.
Typically, in IPR infringement claims, the vendor/licensor provides an unlimited indemnity to defend the customer against any third-party IPR infringement claims – provided the customer uses the software as
authorised/licensed. Breaches of applicable law are frequently addressed through indemnities rather than being wholly uncapped. Regulatory fines imposed directly on a party are commonly excluded from indemnities as a matter of market practice and drafting caution – reflecting the public policy principle against indemnifying one’s own unlawful conduct.
Given the enforcement of the EU AI Act, claims arising from artificial intelligence are a rapidly evolving area in Malta. Vendors seek to keep such claims within the general cap, while sophisticated customers are beginning to push for carve-outs comparable to those applied to data protection breaches. Liability for wilful or deliberate breaches cannot, by law, be capped or excluded.
Software Transactions (License and SaaS) – Is it normal practice for software source codes to be held in escrow for the benefit of the software licensee? If so, who are the typical escrow providers used? Is an equivalent service offered for cloud-based software?
It is common for software source codes to be held in escrow as a protective mechanism especially for highvalue, bespoke, or business-critical software, allowing the licensee to obtain access to the source code on the occurrence of defined release events such as the vendor’s insolvency or abandonment of support. For standard commercial off-the-shelf software, such a practice is less common. At present, Malta does not have a dedicated domestic escrow institution; escrow arrangements are typically structured through Maltese law firms or notaries acting as escrow agents, or through specialist international escrow providers used across the EU or the UK. For cloud-based and SaaS software, an equivalent service is offered less frequently and in a modified form, usually addressing data export rights, continuity of hosting arrangements and, in more sophisticated deals, deposit of build scripts or infrastructure-as-code rather than a static source code copy.
IT Outsourcing – Other than as identified elsewhere in this questionnaire, are there any specific technology laws that govern IT outsourcing transactions?
Malta does not have a standalone framework governing IT outsourcing transactions. Regulated entities are, however, subject to the Malta Financial Services Authority’s sector-specific outsourcing rules, for example Banking Rule BR/14/2020, which applies to credit institutions and requires at least 60 days’ advance written notice to the MFSA before outsourcing a material service or activity, together with maintenance of an outsourcing register. Chapter 3 of the Financial Institutions Rulebook (FIR/03) also imposes separate outsourcing obligations on financial institutions licensed under the Financial Institutions Act (Cap. 376 of the Laws of Malta) to issue e-money or provide payment services. Comparable outsourcing provisions also apply under the MFSA’s Investment Services Rules and Insurance Rules for those respective licence classes. In addition, the Digital Operational Resilience Act (DORA) imposes detailed ICT third-party risk management, contractual and register-ofinformation obligations on financial entities from January 2025.
It is also worth noting that the Malta Gaming Authority (MGA) separately regulates outsourcing by gaming licensees under the Gaming Authorisations Regulations (S.L. 583.05) and Directive 3 of 2018 (the Gaming Authorisations and Compliance Directive), which require notification to the MGA within 30 days of outsourcing a material supply, and prior MGA approval before entering into any arrangement classified as a critical supply or critical service, as further detailed in the MGA’s Policy for Outsourcing by Authorised Persons.
Data protection law applies where personal data is processed by an outsource provider, and NIS2 imposes supply-chain security due diligence obligations on essential and important entities to manage vulnerabilities tied to direct suppliers, service providers, and the broader ICT product and service supply chain.
IT Outsourcing – Please summarise the principal laws (present or impending), if any, that protect individual staff in the event that the service they perform is transferred to a third party IT outsource provider, including a brief explanation of the general purpose of those laws.
The Transfer of Business (Protection of Employment) Regulations (S.L. 452.85), originally enacted as Legal
Notice 433 of 2002 under the Employment and Industrial Relations Act (Cap. 452 of the Laws of Malta) and transposing the EU Acquired Rights Directive (2001/23/EC), apply whenever a business, undertaking or part of one is transferred to another employer by legal transfer or merger, provided the transferred entity retains its identity as an organised grouping of resources pursuing an economic activity. The definition of ‘transfer’ expressly includes a change in service provision, which is the scenario most relevant to IT outsourcing.
Where the Regulations apply, the outgoing provider’s contracts of employment, and all rights and obligations arising from them, including accrued seniority, pay and other terms, pass automatically to the incoming outsource provider as if those contracts had originally been made with it. The transferor remains responsible for settling any wages and other dues owed to affected employees up to the transfer date, which must be paid by the next pay date following the transfer, while the transferee assumes the employees’ rights and obligations arising on and after the transfer date, as if it had always been the employer. Dismissal by reason of the transfer alone is void, although dismissal remains permissible for economic, technical or organisational reasons entailing changes in the workforce. Separately, Article 38 of the Employment and Industrial Relations Act requires the transferor and transferee to inform the representatives of their respective affected employees, in practice in writing and with advance notice,
of the date or proposed date of the transfer, the reasons for it, its legal, economic and social implications for the employees, and any measures envisaged in relation to them, and to consult where measures are envisaged.
The purpose of this framework is to safeguard employees’ job security together with their existing terms
and conditions when the business or service they support changes hands, so that an IT outsourcing transaction cannot itself be used to strip away accrued employment benefits.
Telecommunications – Please summarise the principal laws (present or impending), if any, that govern telecommunications networks and/or services, including a brief explanation of the general purpose of those laws.
Two principal acts govern telecommunications networks and services. The Malta Communications Authority Act (Cap. 418 of the Laws of Malta) establishes the Malta Communications Authority (MCA) itself and sets out its statutory functions and objectives. In essence, the MCA is responsible for promoting and safeguarding a communications environment conducive to investment, innovation, economic growth and social well-being, encompassing competition, transparency and value for money for users, digital inclusion, spectrum management, and supervision of electronic signature and trust services.
The Electronic Communications (Regulation) Act (Cap. 399 of the Laws of Malta – (ECRA)) and its principal
subsidiary legislation, the Electronic Communications Networks and Services (General) Regulations (S.L.
399.48), provide the substantive regulatory content, transposing the European Electronic Communications
Code (Directive (EU) 2018/1972). This substantive framework covers the general authorisation regime,
market analysis and the imposition of remedies (including functional separation) on operators found to
have significant market power, universal service obligations, number portability and numbering resources,
and interconnection and access obligations, applied on a technology-neutral basis regardless of whether the underlying network is fixed or wireless. Part IV of the ECRA deals with the licensing of radio spectrum and radiocommunications equipment.
The framework’s consumer and competition remit has more recently been extended to cover the Platform-to-Business Regulation (Regulation (EU) 2019/1150), implemented through the Online Intermediation Services for Business Users (Enforcement Measures) Regulations (S.L. 399.49), which gives business users of online intermediation services a right of redress before the Civil Court for non-compliance by the intermediary. MCA decisions under Cap. 399 are appealable to the Administrative Review Tribunal.
Several directly applicable EU regulations enforced by the MCA sit alongside this domestic framework, including the Roaming Regulation (Regulation (EU) 2022/612) and the Open Internet (net neutrality) Regulation (Regulation (EU) 2015/2120).
Sector-specific privacy obligations, including rules on traffic and location data, cookies and unsolicited
electronic marketing, are separately governed by the Processing of Personal Data (Electronic Communications Sector) Regulations (S.L. 586.01), transposing the ePrivacy Directive (2002/58/EC, as amended).
Collectively, the purpose of this framework is to harmonise the regulation of electronic communications
networks and services across the EU, encouraging investment, innovation and competition while protecting end users and safeguarding the efficient management of scarce resources such as spectrum and numbering.
Telecommunications – Please summarise any licensing or authorisation requirements applicable to the provision or receipt of telecommunications services in your country.Please include a brief overview of the relevant licensing or authorisation regime in your response.
Malta operates a light-touch, notification-based general authorisation regime. Individual licences are therefore no longer required for the provision of electronic communications networks or services, and an
undertaking need only notify the MCA, using the prescribed notification form. Following submission of the notification form, the notifying undertaking is deemed authorised (subject to the conditions attached to that category of general authorisation), for an unlimited term. Separately, Part IV of Cap. 399, including Article 30A, governs the installation or use of radiocommunications equipment and the use of radio spectrum, which require either an individual licence, a lighter form of licensing (such as the apparatus general authorisation regime), or fall within a licence-exempt category under the Radiocommunications Apparatus Exemption Order (S.L.399.42), depending on the equipment and frequency band concerned, with individual licences sometimes granted by auction or beauty contest for scarce spectrum.
Telecommunications – Please summarise the principal laws (present or impending) that govern access to communications data by law enforcement agencies, government bodies, and related organisations. In your response, please outline the scope of these laws, including the types of data that can typically be requested, how these laws are applied in practice (e.g., whether requests are confidential, subject to challenge, etc.), and any legal or procedural safeguards that apply.
Access to communications data by law enforcement is governed by the Security Service Act (Cap. 391 of the Laws of Malta), S.L. 399.28, and S.L. 586.01. The Security Service Act empowers the Malta Security
Service (MSS) to conduct covert surveillance and intercept communications. S.L. 399.28 requires
commercial providers to configure systems and networks to accommodate lawful interception. Under this
framework, telecom operators are required to implement Unified Lawful Interception (ULI) capabilities. S.L. 586.01 sets the boundaries for data retention and establishes privacy protections for electronic communications data, governing when data must be erased or anonymised versus when it may be accessed by authorities.
Requests typically concern traffic and location data, subscriber identification and, in defined circumstances, content data. Requests for content data are authorised by a warrant issued by the Minister responsible for the Security Service and are generally valid for six months. If an immediate threat exists and the Minister cannot physically sign the document but has given express oral authorisation, a warrant can be endorsed by a senior government official (such as the Permanent Secretary or Cabinet Secretary). These emergency urgent warrants have a significantly restricted lifespan and are valid for only two days unless formally replaced by a standard ministerial warrant. Oversight is retrospective, through an independent Commissioner who reviews the exercise of these powers and investigates complaints. However, Maltese superior courts have repeatedly ruled that the current system where executive ministers hold the sole power to authorise content interception is devoid of independent or judicial oversight in violation of fundamental human rights. Reform proposals, including a recommendation from the UN Special Rapporteur on Privacy for an independent Security Commissioner to approve warrants, remain pending.
All requests are strictly confidential, with independent oversight by the Information and Data Protection Commissioner (IDPC) over compliance with data protection law. Affected persons retain a right of judicial
challenge, including through constitutional proceedings where fundamental rights are engaged.
Telecommunications – Please summarise the principal laws present or impending) that impose cyber security and/or operational resiliency obligations applicable to the operation of telecommunications infrastructure and/or provision of telecommunications services.
Telecommunications providers, as part of the digital infrastructure sector, generally fall within scope of Malta’s NIS2 transposition, the Measures for a High Common Level of Cybersecurity across the European
Union (Malta) Order (S.L. 460.41), which entered fully into force on 23 January 2026. Affected providers are legally bound to strict governance, risk-management and incident-reporting obligations. The Critical Infrastructure Protection Department (CIPD) acts as the overarching competent authority for the majority of NIS2 sectors in Malta (including energy, banking and transport). The MCA is, however, the designated competent authority explicitly tasked with supervising and enforcing NIS2 compliance for the digital infrastructure sector (including telecommunications, DNS providers, and cloud services). Security-of-network obligations are also embedded directly in Cap. 399 and its subsidiary legislation, reflecting Articles 40 and 41 of the European Electronic Communications Code.
Mobile communications and connected technologies – What are the principle standard setting organisations (SSOs) governing the development of technical standards in relation to mobile communications and newer connected technologies such as digital health or connected and autonomous vehicles?
The principal organisation governing the adoption and development of technical standards across all these sectors in Malta is the Malta Competition and Consumer Affairs Authority (MCCAA). The Standards and Metrology Institute within the MCCAA adopts and transposes harmonised European and international standards into Maltese National Standards. The principal standard-setting bodies relevant to Malta are the European Telecommunications Standards Institute (ETSI); the 3rd Generation Partnership Project (3GPP); the Institute of Electrical and Electronics Engineers (IEEE) (most notably the IEEE 802.11 suite (Wi-Fi) and IEEE 802.3 (Ethernet)); and the International Telecommunication Union’s radiocommunication and telecommunication sectors (ITU-R and ITU-T). For connected and autonomous vehicles, the standards adopted by the International Organization for Standardization (ISO), SAE International, 5G Automotive Association (5GAA) and CEN/CENELEC are relied on.
Mobile communications and connected technologies – How do technical standards facilitating interoperability between connected devices impact the development of connected technologies?
Harmonised interoperability standards, reinforced at EU level by instruments such as the Radio Equipment Directive and the Data Act’s interoperability requirements for connected devices and data spaces, lower barriers to market entry, reduce vendor lock-in and enable crossborder service provision. Because Malta’s local market is small, tech startups and developers based in Malta might find it prohibitive to build proprietary ecosystems.
Adopting global interoperability protocols (like 3GPP for 5G, MQTT/CoAP for IoT, and HL7/FHIR for digital health) therefore allows Maltese developers to create connected products that are instantly compatible worldwide.
Technical standards that facilitate interoperability also introduce cost efficiency because Maltese usinesses and public entities can source hardware and software from different vendors, ensuring cost-competitive
procurement without being trapped in closed, proprietary ecosystems.
It is also worth noting that under the EU’s New Legislative Framework, particularly Regulation (EC) No 765/2008 and Decision No 768/2008/EC, products matching harmonised European standards receive a legal presumption of conformity, facilitating CE marking and single market access. This is particularly relevant for Maltese companies because it dramatically speeds up the process for securing a CE mark and exporting technologies across the European Single Market.
Data Protection – Please summarise the principal laws (present or impending), if any, that govern data protection, including a brief explanation of the general purpose of those laws.
The General Data Protection Regulation (EU) 2016/679 applies directly in Malta and is complemented by the Data Protection Act (Cap. 586 of the Laws of Malta), which by Article 2 implements and further specifies the GDPR, and by Article 11 establishes the IDPC as the national supervisory authority responsible for monitoring and enforcing the Act and the GDPR. Subsidiary legislation addresses sector-specific processing, including law enforcement processing (S.L. 586.08, implementing the Law Enforcement Directive (EU) 2016/680), health data for insurance purposes (S.L.586.10) and education (S.L. 586.07). As discussed earlier,S.L. 586.01 transposes the European ePrivacy Directive (Directive 2002/58/EC) into Maltese national law. Itintroduces unique, strict privacy mandates on top of the general GDPR requirements for providers of electronic communications services. The EU ePrivacy Regulation, once implemented, will apply directly to Malta, extending strict privacy rules beyond traditional telecom operators to cover ‘Over-the-Top’ (OTT) communication services.
Data Protection – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable data protection laws?
Under Article 83 of the GDPR, the IDPC may impose administrative fines of up to the higher of €20 million or 4% of an undertaking’s total worldwide annual turnover for the preceding financial year for the most serious infringements. For public authorities and bodies, Article 21 of the Data Protection Act instead caps fines at €25,000 per violation, plus a daily fine of €25, for infringements of Article 83(4) of the GDPR, rising to €50,000 per violation plus a daily fine of €50 for infringements of Article 83(5) or (6). Separately, Article 22 of the Data Protection Act criminalises the knowing provision of false information to the IDPC, or noncompliance with a lawful IDPC request, punishable on conviction by a fine of between €1,250 and €50,000 and/or up to six months’ imprisonment, and breaches of the Processing of Personal Data (Electronic Communications Sector) Regulations attract administrative fines of up to €23,293.73 per breach, plus €2,329.37 for each day the breach persists.
Data Protection – What data protection rules are relevant to technology contracts in your country? Do they typically refer to external data protection regimes, e.g. EU GDPR or CCPA, even where the contract has no clear international element?
Technology contracts involving the processing of personal data must contain GDPR-mandated Article 28
processor terms, covering the subject matter and duration of processing, sub-processor consent, security
measures, audit rights, breach notification and end-ofcontract data return or deletion. If a technology vendor processes personal data on behalf of a client (such as a cloud provider storing customer data), the parties must execute a legally binding Data Processing Agreement (DPA). The contract must explicitly restrict the vendor to processing data only on the client’s documented instructions. Given the GDPR’s direct effect, Maltese contracts typically reference it expressly rather than any other regime, even in purely domestic transactions.
References to non-European frameworks like the California Consumer Privacy Act (CCPA) or other US state privacy laws are rarely included in purely Maltese contracts. However, they do appear under two specific domestic scenarios: (a) White-Label and Reseller Software: If a Maltese IT company contracts to resell or integrate software created by US technology companies, the standard flow-through legal terms automatically include comprehensive global addenda referencing the GDPR, CCPA, and UK GDPR; and (b) Maltese iGaming and Fintech Operators: Malta is a global hub for online gaming and financial technology. Even if a contract is signed locally between a Malta-based platform provider and a local developer, these industries naturally target international users. Therefore, their contracts proactively build in compliance templates that account for both the GDPR and the CCPA to avoid cross-border compliance fragmentation.
Cybersecurity – Please summarise the principal laws (present or impending), if any, that govern cybersecurity (to the extent they differ from those governing data protection), including a brief explanation of the general purpose of those laws.
The Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41), transposing Articles 21 (security risk-management measures) and 23 (incident reporting) of the NIS2 Directive (Directive (EU) 2022/2555) among its other provisions, entered fully into force on 23 January 2026 and establishes cybersecurity risk-management, governance and incident-reporting obligations for essential and important entities across a broad range of sectors. It is complemented by S.L. 460.43, transposing the Critical Entities Resilience Directive (Directive (EU) 2022/2557), which addresses the physical and operational resilience of critical entities, and by the cybercrime provisions of the Criminal Code (Cap. 9 of the Laws of Malta). The purpose of this framework is to raise the common baseline of cyber resilience across critical sectors and deter and punish malicious cyber activity.
Cybersecurity – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable cybersecurity laws?
Under S.L. 460.41, essential entities may be fined up to the higher of €10 million or 2% of total worldwide annual turnover, while important entities face fines of up to the higher of €7 million or 1.4% of turnover, with daily penalties for continuing non-compliance. Beyond financial penalties, Malta’s competent
cybersecurity authorities, such as the Critical Infrastructure Protection Department (CIPD) and the MCA, hold expansive administrative enforcement powers under Article 32 of the Measures for a High Common
Level of Cybersecurity across the European Union (Malta) Order (S.L. 460.41) to compel compliance. For instance, regulators can hold corporate directors, CEOs, or legal representatives personally liable for failing to implement cyber risk-management policies or neglecting mandatory cybersecurity training.
Cybersecurity – Are there any cybersecurity regulatory frameworks in your jurisdiction which require registration for certain sectors or services?
Yes. S.L. 460.41 requires in-scope essential and important entities to self-register with the CIPD, feeding into a national register of regulated entities, in addition to sectoral licensing or notification regimes maintained by the MGA, the MCA and the MFSA which carry parallel cybersecurity registration or notification duties.
Cybersecurity – Please summarise the regulatory framework for the reporting of cybersecurity incidents.
Under S.L. 460.41, mirroring Article 23 of the NIS2 Directive, in-scope entities must submit an early warning to CSIRT Malta within 24 hours of becoming aware of a significant incident, followed by a fuller incident notification within 72 hours, and a final report within one month. These obligations sit alongside the GDPR’s separate 72-hour personal data breach notification duty to the IDPC under Article 33 of the GDPR, and DORA’s incident-reporting regime for financial entities. Telecom operators must notify the IDPC within 24 hours following the detection of a personal data breach. Separately, providers of public electronic communications networks or services must immediately notify the MCA of any security incident that has a significant impact on the operation or integrity of networks or services. On the other hand, banks, investment firms, payment providers, and crypto-asset operators are required under DORA to
report major ICT-related incidents directly to the Malta Financial Services Authority (MFSA) and submit an initial notification within 4 hours of classification (or by the end of the business day), followed by an intermediate report within 1 week, and a final root-cause report within 1 month.
Artificial Intelligence – Which body(ies), if any, is/are responsible for the regulation of artificial intelligence?
The Malta Digital Innovation Authority (MDIA) has been designated, by Legal Notice 226 of 2025 (the Artificial Intelligence Regulations, 2025), as Malta’s primary market surveillance authority, single point of contact for the EU AI Act, and the national competent authority responsible for the national AI regulatory sandbox under Article 57 of the AI Act. The IDPC has, by Legal Notice 227 of 2025, been designated as the market surveillance authority for specified data-sensitive and lawenforcement-related high-risk AI systems. The MFSA, the MGA and the MCA retain sectoral oversight of AI used in financial services, gaming and telecommunications respectively, typically coordinated with the MDIA through
memoranda of understanding.
Artificial Intelligence – Please summarise the principal laws (present or impending), if any, that govern the deployment and use of artificial intelligence, including a brief explanation of the general purpose of those laws.
The EU AI Act (Regulation (EU) 2024/1689) is the principal instrument, adopting a risk-based approach: Article 5 prohibits certain AI practices outright, Articles 8 to 27 impose strict obligations on high-risk AI systems, and lighter transparency duties apply to lower-risk systems. It is implemented domestically through the Artificial Intelligence Regulations (S.L. 591.05), which designate the national competent authorities referred to above. The prohibited-practice rules under Article 5 have applied since 2 February 2025, and most other operative provisions, including the high-risk system requirements, apply from 2 August 2026, subject to a proposed further deferral of the Annex III high-risk deadline to 2 December
2027 under the pending EU ‘Digital Omnibus’ simplification package. The purpose of the framework is
to ensure AI systems placed on the EU market are safe and respect fundamental rights, while supporting
innovation through measures such as regulatory sandboxes.
The AI Act (Fundamental Rights and Enforcement) Regulations (S.L. 586.14) ensure strict human rights protections during AI deployment. It designates the Information and Data Protection Commissioner (IDPC) as Malta’s official Fundamental Rights Authority (FRA), and carve out separate enforcement powers for the IDPC to oversee, register, and audit any high-risk AI deployments that directly impact biometric privacy, police profiling, or democratic processes.
The EU AI Liability Directive has been drafted to complement the AI Act by updating civil liability and tort laws across EU member states. Once fully adopted and introduced into Maltese civil courts, it will ease the
burden of proof for consumers seeking financial compensation for damages or privacy violations caused
by a faulty, biased, or negligent AI system by introducing a presumption of causality.
Artificial Intelligence – Are there any specific legal provisions (present or impending) in respect of the deployment and use of Large Language Models and/or generative AI (including agentic AI)?
The AI Act imposes specific transparency obligations on providers of general-purpose AI models, including large language models, under Article 53, requiring technical documentation, information for downstream deployers, a policy to comply with EU copyright law, and a publicly available summary of training content; under Article 55, models presenting systemic risk, broadly those trained above 10^25 FLOPs of cumulative compute, are subject to enhanced obligations including adversarial testing and
incident reporting, enforced directly by the European Commission’s AI Office rather than national authorities. There is no separate Maltese statute targeting agentic AI specifically; existing consumer protection, data protection and, where relevant, financial services rules apply to autonomous decision-making by such systems.
Artificial Intelligence – Do technology contracts in your jurisdiction typically contain either mandatory (e.g. mandated by statute) or recommended provisions dealing with AI risk? If so, what issues or risks need to be addressed or considered in such provisions?
There is no Maltese statutory requirement to include AI-specific clauses in private contracts, although AI Act obligations flow contractually through the supply chain from providers to deployers, backed by Article 99 fines of up to the higher of €35 million or 7% of worldwide turnover for breach of the Article 5 prohibited-practice rules, up to €15 million or 3% for other operator obligations, and up to €7.5 million or 1% for supplying incorrect information to authorities. Market practice increasingly includes provisions addressing the parties’ respective roles and compliance obligations under the AI Act, warranties as to the lawfulness and provenance of training data, human oversight and override mechanisms, accuracy and ‘hallucination’ risk, allocation of liability for AI-generated outputs, and, in view of the withdrawal of
the proposed EU AI Liability Directive, express contractual allocation of fault-based liability which is no longer addressed by a harmonised EU regime.
Artificial Intelligence – Do software or technology contracts in your jurisdiction typically contain provisions regarding the application or treatment of copyright or other intellectual property rights, or the ownership of outputs in the context of the use of AI systems?
Yes. Contracts typically assign ownership of AIgenerated outputs to the customer, subject to warranties from the vendor regarding the lawfulness of the underlying training data and input materials. Since
copyright protection under the Copyright Act generally requires human authorship, the copyright status of purely AI-generated outputs remains uncertain, and Maltese technology contracts increasingly include indemnities addressing third-party IP infringement claims arising from AI outputs, alongside warranties reflecting the AI Act’s training-data transparency requirements.
Blockchain – What are the principal laws (present or impending), if any, that govern (i) blockchain specifically (if any) and (ii) digital assets, including a brief explanation of the general purpose of those laws?
Malta was among the first jurisdictions to legislate specifically for blockchain, through a trio of statutes enacted together in 2018: the Malta Digital Innovation Authority Act (Cap. 591 of the Laws of Malta), establishing the MDIA; the Innovative Technology Arrangements and Services Act (Cap. 592 of the Laws of
Malta), providing for voluntary certification of distributed ledger technology arrangements and smart contracts, including the audit and registration of technical administrators and systems auditors; and the Virtual Financial Assets Act (Cap. 590 of the Laws of Malta, the ‘VFA Act’), which originally regulated initial virtual financial asset offerings, DLT exchanges and related services. Since 30 December 2024, the EU Markets in Crypto-Assets Regulation (Regulation (EU) 2023/1114,‘MiCA’) has applied directly, and the VFA Act was itself repealed with effect from 3 July 2026, pursuant to Article 64 of Act 36 of 2024, without prejudice to anything already done under it. Malta’s local implementing legislation for MiCA is now the Markets in Crypto-Assets Act (Chapter 647), introduced by the same Act 36 of 2024, which consolidates and replicates the token-related provisions previously found in the VFA Act in a MiCA aligned form, and under which the Malta Financial Services Authority acts as competent authority for assetreferenced
tokens, e-money tokens and crypto-asset services. Existing VFA-licensed service providers benefited from a transitional window, which closed on 1 July 2026, during which they could continue operating under the VFA Act pending the grant or refusal of authorisation as a crypto-asset service provider under MiCA; no new applications may now be made under the VFA Act. The MDIA Act and ITAS Act remain unaffected
by this repeal and continue to provide the separate, voluntary DLT and smart contract certification
framework.
Search Engines and Marketplaces – Please summarise the principal laws (present or impending), if any, that govern search engines and marketplaces, including a brief explanation of the general purpose of those laws.
Search engines and online marketplaces are subject to the Digital Services Act (Regulation (EU) 022/2065),
transposed by the Digital Services (Designation and Enforcement) Order (S.L. 418.05), which designates the MCA as Malta’s Digital Services Coordinator responsible for supervising intermediary service providers established in Malta. The e-commerce Directive is transposed as the Electronic Commerce Act, and the EU Platform-to-Business Regulation (Regulation (EU) 2019/1150) imposes transparency and fairness obligations on online intermediation services and search engines towards business users. It prevents arbitrary commercial blacklisting by imposing strict transparency, disputeresolution, and fairness mandates on search engines and online marketplaces specifically concerning how they treat their business users. Together, these laws aim to create a safer, fairer and more transparent online
marketplace environment.
Social Media – Please summarise the principal laws (present or impending), if any, that govern social media and online platforms, including a brief explanation of the general purpose of those laws?
The Digital Services Act is the principal instrument, imposing tiered due diligence obligations on hosting services, online platforms and, for very large online platforms, additional systemic-risk mitigation duties
enforced jointly by the European Commission and the MCA as Digital Services Coordinator. The Digital Services (Designation and Enforcement) Order (S.L. 418.05) formally implements the DSA in Malta. Video-sharing platforms also fall within the scope of the audiovisual media services framework, extending certain obligations under the Broadcasting Act (Cap. 350 of the Laws of Malta), and child-safety and content obligations are reinforced by the Criminal Code’s provisions on child exploitation material and grooming.
Social Media – What is the maximum sanction that can be imposed by a regulator in the event of a breach of any applicable online safety laws?
Under Article 52(3) of the Digital Services Act, fines of up to 6% of a provider’s total worldwide annual turnover for the preceding financial year may be imposed for failure to comply with an obligation under the Regulation, with Article 52(4) permitting periodic penalty payments of up to 5% of average daily worldwide turnover for continuing non-compliance, and Article 52 separately setting a lower 1% cap for supplying incorrect, incomplete or misleading information to the Digital Services Coordinator.
Breaches in relation to harmful content and video-sharing platforms sanctionable under the Broadcasting Act attract administrative fines ranging up to €46,587.47, plus escalating daily penalties for ongoing non-compliance.
Spatial Computing – Please summarise the principal laws (present or impending), if any, that govern spatial computing, including a brief explanation of the general purpose of those laws?
Malta has no dedicated statute for spatial computing, augmented, extended or virtual reality. Such echnologies are instead governed by a combination of overlapping frameworks: the GDPR, for biometric and behavioural data captured by immersive devices; the Radio Equipment Directive and general product safety rules, for hardware; the Digital Services Act, where a metaversestyle service functions as an intermediary or platform; the AI Act, where AI is embedded in the experience; and general consumer protection rules for virtual goods and in-world transactions.
Quantum Computing – Please summarise the principal laws (present or impending), if any, that govern quantum computing and/or issues around quantum cryptography, including a brief explanation of the general purpose of those laws?
There is no Maltese or EU quantum-specific statute at present. Relevant obligations instead arise indirectly, through the EU cybersecurity acquis, including NIS2 and the ongoing eIDAS 2.0 preparations for migration towards post-quantum cryptography, and through the EU dualuse export control regime (Regulation (EU) 2021/821), which may capture certain quantum computing and cryptographic hardware. Malta participates in the EU’s EuroQCI initiative to develop quantum-safe communications infrastructure and in the PRISM Project, which is managed locally with support from the Malta Digital Innovation Authority (MDIA). The PRISM project (Public Government Quantum Infrastructure) oversees the deployment of physical Quantum Key Distribution (QKD) nodes across Malta. This technology uses the
physical laws of quantum mechanics to generate unhackable cryptographic keys, detecting any unauthorised eavesdropping instantly.
Datacentres – Does your jurisdiction have any specific regulations that apply to data centres?
Malta, unlike most EU member states, has enacted a bespoke national instrument on this point: the Data Centres (Sustainability Reporting Obligations) Regulations (S.L. 545.42), made as Legal Notice 271 of 2025 under the Regulator for Energy and Water Services Act (Cap. 545) and in force since 28 November 2025. It
implements Article 12 of the recast Energy Efficiency Directive (Directive (EU) 2023/1791) at national level.
Regulation 3 requires owners and operators of ‘obligated data centres’ (defined to include all co-hosting, colocation and enterprise data centres located in Malta with an installed IT power demand of at least 500 kW) to make the information set out in the First Schedule publicly available by 15 May of every year, save for data centres used exclusively for defence or civil protection purposes.
Beyond this sustainability reporting regime, data centres remain subject to general planning and building permit requirements administered by the Planning Authority, to NIS2 risk-management and incident-reporting obligations where they qualify as digital infrastructure, and to GDPR security and, where relevant, datalocalisation considerations for hosted personal data. Under Malta’s overarching cybersecurity law, S.L. 460.41 (the Measures for a High Common Level of Cybersecurity across the European Union (Malta) Order), data centres are legally categorised as ‘Essential Entities’ within the
digital infrastructure sector. Data centre operators must implement rigorous risk-management architectures, execute physical and perimeter security controls, secure their hardware supply chains, and maintain continuous vulnerability patching. Operators are bound to the 24-hour tiered incident reporting cycle. Any cyber incident causing a significant disruption to data hosting infrastructure must be reported to CSIRT-Malta within 24 hours. Furthermore, data processing services and data centres are subject to the Fair Access to and Use of Data Regulations (S.L. 418.06). Data centres offering colocation, cloud, or infrastructure-as-a-service (IaaS) solutions are prohibited from trapping commercial clients in their ecosystem. The law forces operators to actively remove commercial, technical, and contractual barriers,
allowing clients to seamlessly switch between data processing services or migrate their data loads back to
on-premise hardware.
General – What are your top 3 predictions for significant developments in technology law in the next 3 years?
First, the full application of the EU AI Act from August 2026 is expected to drive a wave of sandbox activity and the first enforcement decisions by the MDIA and IDPC. Second, Malta’s cybersecurity architecture will continue to mature following the entry into force of the NIS2 and Critical Entities Resilience frameworks and the shift to an Enforcement Committee model for administrative
penalties. Third, the crypto-asset regulatory landscape will continue to consolidate around MiCA, with the
domestic VFA framework narrowing to cover only DLT assets falling outside MiCA’s scope, alongside growing regulatory attention to data centre energy reporting and sustainability. I also believe that data centres will play an important role in Malta’s ecosystem in the next few years. Leveraging its historical and geo-political proximity to North Africa, Malta could act as the gateway for large Content Application Platforms (CAPs) to service that market. As such, at a local level, I anticipate that Malta will look at introducing legislative and regulatory reform.
General – Do technology contracts in your country commonly include provisions to address sustainability / net-zero obligations or similar environmental commitments?
Not yet as a standard feature of purely domestic technology contracts, though such provisions are becoming more common in cloud and data centre procurement, where energy-efficiency and reporting
commitments are increasingly tied to obligations under the Energy Efficiency Directive, and in public-sector ICT tenders reflecting Malta’s green public procurement policy. Net-zero warranties remain more typical in outsourcing and framework agreements involving multinational customers than in domestic-only arrangements.