Malta - AI Commissioner Designation (227/2025)

227 of 2025 - Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (Legal Notice)

Malta

RAI-MT-NA-22AIDXX-2025
Effective: October 10, 2025
In Force(In Force)
RegulationGovernance and OversightMarket SurveillanceData Protection and Privacy
Export PDF

Legal Notice 227 of 2025 designates the Information and Data Protection Commissioner (IDPC) as Malta’s Market Surveillance Authority (MSA) for specific high‑risk AI systems listed under Annex III of Regulation (EU) 2024/1689 (the EU AI Act). The Notice sets notification and magistrate‑authorisation requirements for remote biometric identification systems and grants the Commissioner enforcement powers including administrative penalties for infringements.

Overview

Legal Notice 227 of 2025, titled the Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025, was published in the Government Gazette of Malta (No. 21,519) on 10 October 2025. The Notice designates the Information and Data Protection Commissioner (IDPC) as Malta’s Market Surveillance Authority (MSA) for a defined set of high‑risk AI systems listed under Annex III (Schedule III) of the European Union’s Artificial Intelligence Regulation (Regulation (EU) 2024/1689). The designation is made under the powers conferred by the Data Protection Act (Cap. 586) and is intended to integrate the national supervisory authority responsible for personal data protection into the enforcement and market surveillance architecture of the EU AI Act. The text of the Legal Notice and the ELI entry are available from the Maltese legislation portal at legislation.mt - LN 227/2025 and the IDPC’s official announcement at IDPC - AI Regulations come into force (13 Oct 2025). The Notice focuses on balancing market oversight, data protection safeguards and judicial checks for biometric and other sensitive high‑risk AI uses.

Definitions

The Legal Notice relies on definitions contained in Regulation (EU) 2024/1689 (the AI Act) and the Data Protection Act (Cap. 586). Key defined or cross‑referenced concepts include: "AI system" (as per the AI Act); "high‑risk AI system" (categories listed in Annex III / Schedule III of the EU AI Act); "market surveillance" (tasks performed by the designated authority to ensure compliance with the Regulation); "operator" or "provider" (entities placing AI systems on the market or putting them into service); "real‑time remote biometric identification" (RBI) and "post‑remote biometric identification"; and "notification" and "authorisation" procedures (notification to the Commissioner; prior Magistrate authorisation where required). The Notice adopts the AI Act’s terminology for obligations such as conformity assessment, technical documentation and registration where applicable, and prescribes how certain duties will interact with national law on criminal justice, border management and public security.

Governance and Institutional Framework

The Notice designates the Information and Data Protection Commissioner (IDPC) as Market Surveillance Authority for the enumerated high‑risk AI system classes; accordingly, the IDPC is responsible for carrying out market surveillance functions in relation to those systems, including inspections, requests for information, investigations and the imposition of remedial actions. The designation aligns the national data protection supervisory authority with the enforcement architecture of the AI Act, reflecting that the designated systems frequently process personal and sensitive data. The Commissioner is required to cooperate with other national authorities and with the European Artificial Intelligence Board established under the AI Act, and to provide information to the AI Office and other Member State authorities as necessary. The Notice also creates procedural safeguards for oversight over law‑enforcement uses of RBI by linking deployment to prior authorisation by a Magistrate and by requiring notification to the Commissioner in a format consistent with Article 5(6) of the AI Act. The IDPC’s role encompasses both market surveillance (ensuring operators comply with obligations in the AI Act) and the protection of fundamental rights (privacy/data protection), thereby acting as a bridge between product/system safety oversight and rights‑based supervision. See the AI Act text at EUR-Lex - Regulation (EU) 2024/1689 for the EU governance context.

Key Focus Areas

The Legal Notice concentrates oversight and procedural controls on a set of high‑risk AI categories where the intersection of AI capabilities and personal data processing produces heightened risks to privacy, bodily integrity and democratic processes. These focus areas include: (1) biometric identification systems (real‑time and post‑remote) used in publicly accessible spaces by law‑enforcement or border control; (2) AI systems for emergency call processing, classification and dispatch prioritisation (due to potential life‑safety impacts); (3) AI systems used for law enforcement functions (investigation, detection, predictive tools where permitted by law); (4) AI systems used for migration, asylum and border management (EES and other border‑management tools where personal data/biometrics are processed); and (5) AI systems supporting administration of justice and democratic processes (court assistance, case classification, voting‑related technologies). For biometric and law‑enforcement uses, the Notice imposes stronger procedural checks: Magistrate authorisation for RBI deployment in public spaces and mandated notifications to the Commissioner excluding sensitive operational details. The Notice therefore prioritises fundamental‑rights protection, judicial oversight and transparent surveillance of operators handling particularly sensitive AI deployments. Risk mitigation measures implied by the designation include record‑keeping, documentation, transparency to affected persons (where feasible), and the IDPC’s investigatory and corrective toolkit to address non‑compliance swiftly.

Implementation Framework

Operationally, the Notice requires operators, deployers and public authorities to submit notifications to the IDPC for specified systems using the content set out in Article 5(6) of the AI Act (excluding sensitive operational data). In cases of real‑time RBI in public spaces and in certain post‑RBI contexts, an ex‑ante application for judicial authorisation must be submitted to a Magistrate before deployment; the Magistrate’s authorisation is a precondition to lawful use. The IDPC will receive notifications, coordinate inspections and issue compliance orders, and may liaise with other national agencies (police, migration authorities, courts) to ensure that system use is both lawful and proportionate. The IDPC will also maintain a record of notifications and actions taken and will participate in cooperation mechanisms under the AI Act (including exchanges within the European Artificial Intelligence Board). The Notice requires alignment with conformity assessment and registration mechanisms in the EU AI Act; where conformity assessment or third‑party certification applies, operators must maintain and produce technical documentation and logs for IDPC review during market surveillance activities.

Monitoring and Evaluation

The IDPC is empowered to perform proactive and reactive market surveillance activities, including audits, on‑site inspections, requests for documentation and ordering remedial measures. Monitoring will focus on operators’ adherence to documentation and logging requirements, transparency obligations (where applicable), data governance measures and human‑oversight arrangements. The IDPC may require corrective measures, impose warnings or non‑monetary measures, and escalate to administrative penalties for persistent or serious breaches. The Commissioning Notice anticipates cooperation with other national authorities and cross‑border exchanges through the European Artificial Intelligence Board. The IDPC is expected to publish periodic enforcement reports and to provide information to the public about authorisations granted for RBI in public spaces and the safeguards associated with those authorisations (subject to operational confidentiality where justified by law).

Penalties, Liability, and Appeals

The Notice grants the IDPC the ability to impose administrative penalties and remedial measures for infringements of Regulation (EU) 2024/1689 committed by operators in the scope of the designation. For public authorities or bodies found in breach, the Legal Notice specifies an administrative penalty up to EUR 50,000 for each infringement plus a daily penalty of EUR 50 for each day the infringement persists. The IDPC may also impose warnings and non‑monetary measures. Affected parties retain legal remedies under national law: operators and public bodies can challenge administrative decisions and penalties in the Maltese courts and follow appeal procedures available under administrative and judicial law. Liability for damages may arise under existing Maltese civil law and the Data Protection Act where wrongful processing causes harm; the Notice does not displace civil liability mechanisms but complements enforcement by the IDPC. The interplay between EU AI Act sanctions (as applied by other national competent authorities) and Maltese administrative penalties is governed by the AI Act’s enforcement and cooperation provisions and national procedural law.

Relationship to Other Instruments

The Legal Notice expressly implements national arrangements for enforcing provisions of Regulation (EU) 2024/1689 by designating a national MSA for specified high‑risk categories. It operates alongside and in interaction with: (1) the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) — primary normative source; (2) the Data Protection Act (Cap. 586) and the GDPR (Regulation (EU) 2016/679) for personal data protection obligations; (3) sectoral rules on law enforcement, border control and public security; and (4) national criminal and administrative law governing authorisations and judicial oversight. The Notice does not replace sectoral authorisation requirements where these exist (for example, laws governing police powers or immigration), but requires that AI‑specific uses which intersect with data protection and fundamental rights are subject to the combined oversight of the IDPC and national judicial safeguards. For the EU AI Act text reference see EUR-Lex - Regulation (EU) 2024/1689 and for the Maltese ELI record see legislation.mt - LN 227/2025.

International Alignment

The designation aligns Malta’s national enforcement architecture with the EU AI Act and the EU’s approach to concentrating oversight of sensitive AI systems in authorities with data‑protection mandates. The IDPC’s designation as MSA for niche high‑risk categories echoes practices in other Member States that allocate oversight of biometric and privacy‑critical systems to data protection agencies. The Notice further positions Malta to participate in the European Artificial Intelligence Board and cooperation mechanisms established by the AI Act, enabling cross‑border enforcement coordination, exchange of best practices and consistent interpretation of high‑risk categories and procedural safeguards. By linking Magistrate authorisation to certain biometric uses, Malta also signals adherence to robust judicial oversight norms recommended by EU fundamental‑rights bodies and international human‑rights standards for biometric surveillance.

Implementation Timeline

EventDate
Publication in Government Gazette (LN 227/2025)2025-10-10
IDPC public announcement2025-10-13
Operators must notify IDPC for specified systems (as required by AI Act / LN)Immediate upon publication; obligations effective from publication date
Magistrate authorisation requirement for RBI in public spaces becomes applicableImmediate upon publication; authorisations required prior to deployment
Ongoing market surveillance and enforcement activities beginFrom 2025-10-10 onwards

Compliance Checklist

Action for Operators / Public BodiesYes / No / Notes
Determine whether AI system falls into Annex III (Schedule III) categoriesYes — perform assessment
Prepare and submit notification to IDPC per Article 5(6) content (excluding sensitive operational data)Yes — prior to deployment where required
Where real‑time RBI in public spaces is intended for law enforcement, obtain Magistrate authorisationYes — authorisation required before deployment
Maintain technical documentation, logs and records for IDPC inspectionYes — retain for prescribed retention period
Ensure conformity assessment and CE marking obligations (if applicable)Yes — comply with AI Act conformity requirements
Implement data protection safeguards and DPIAs where personal data are processedYes — GDPR / Data Protection Act obligations apply

Sources and References

SourceType
227 of 2025 - Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (ELI entry / PDF)Primary Source
IDPC announcement: AI Regulations come into force (13 Oct 2025)Primary Source
Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-LexPrimary Source
Plain English

Malta has designated its Information and Data Protection Commissioner (IDPC) as the primary authority responsible for overseeing specific high-risk artificial intelligence (AI) systems deployed within the country, as defined by the European Union’s new AI Act (Regulation (EU) 2024/1689). This regulation applies to any entity – whether a private company or a public authority – that develops, provides, or uses these designated high-risk AI systems in Malta.

The scope covers AI systems listed in Annex III of the EU AI Act, which include those with significant potential impact on fundamental rights and safety. Key examples are: - AI systems for real-time or post-remote biometric identification in public spaces. - AI used in emergency services, law enforcement, or border management. - AI supporting the administration of justice or democratic processes.

If you are involved with such systems, you face several critical obligations. You must notify the IDPC before deploying these specified high-risk AI systems. Crucially, for real-time remote biometric identification systems used in publicly accessible spaces, especially by law enforcement, you must obtain prior authorisation from a Magistrate before deployment. Additionally, operators must maintain comprehensive technical documentation and logs, ready for IDPC inspection, and ensure their systems comply with the EU AI Act’s conformity assessment and registration requirements.

These regulations took effect on October 10, 2025, meaning all obligations are immediately applicable from that date. The IDPC has significant enforcement powers, including conducting audits, requesting information, and ordering corrective measures. For public authorities, infringements can lead to administrative penalties of up to EUR 50,000 per breach, plus a daily penalty of EUR 50 for ongoing non-compliance. Affected parties retain the right to challenge IDPC decisions in Maltese courts.

A key practical pitfall to note is the dual layer of oversight for biometric systems: not only must you notify the IDPC, but the requirement for a Magistrate’s prior authorisation for real-time remote biometric identification in public spaces introduces a significant judicial hurdle. This underscores Malta’s strong emphasis on fundamental rights and judicial checks when deploying sensitive AI technologies.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Malta - AI Commissioner Designation (227/2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore deployment

    Applies to: Deployers of real-time remote biometric identification systems in public spaces.

    an ex‑ante application for judicial authorisation must be submitted to a Magistrate before deployment; the Magistrate’s authorisation is a precondition to lawful use.
  2. #2CriticalArticle 5(6) of the AI ActBefore deployment

    Applies to: Operators, deployers, and public authorities of specified high-risk AI systems.

    requires operators, deployers and public authorities to submit notifications to the IDPC for specified systems using the content set out in Article 5(6) of the AI Act.
  3. #3CriticalBefore placing on market

    Applies to: Operators of high-risk AI systems.

    Ensure conformity assessment and CE marking obligations (if applicable)
  4. #4ImportantBefore placing on market or putting into service

    Applies to: Operators and deployers of AI systems.

    Determine whether AI system falls into Annex III (Schedule III) categories
  5. #5ImportantOngoing

    Applies to: Operators of high-risk AI systems requiring conformity assessment.

    operators must maintain and produce technical documentation and logs for IDPC review during market surveillance activities.
  6. #6ImportantUpon request during market surveillance

    Applies to: Operators of high-risk AI systems requiring conformity assessment.

    operators must maintain and produce technical documentation and logs for IDPC review during market surveillance activities.
  7. #7ImportantBefore processing personal data

    Applies to: Operators and deployers of AI systems processing personal data.

    Implement data protection safeguards and DPIAs where personal data are processed
  8. #8ImportantOngoing

    Applies to: Operators of high-risk AI systems.

    Monitoring will focus on operators’ adherence to... transparency obligations (where applicable).
  9. #9ImportantOngoing

    Applies to: Operators of high-risk AI systems.

    Monitoring will focus on operators’ adherence to... data governance measures.
  10. #10ImportantOngoing

    Applies to: Operators of high-risk AI systems.

    Monitoring will focus on operators’ adherence to... human‑oversight arrangements.
  11. #11ImportantBefore deployment

    Applies to: Deployers of AI systems subject to sectoral rules (e.g., law enforcement, immigration).

    The Notice does not replace sectoral authorisation requirements where these exist.

© Regulations.AI — created on 13-Jun-2026