Malta - AI Commissioner Designation (227/2025)
227 of 2025 - Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025 (Legal Notice)
Malta
RAI-MT-NA-22AIDXX-2025Legal Notice 227 of 2025 designates the Information and Data Protection Commissioner (IDPC) as Malta’s Market Surveillance Authority (MSA) for specific high‑risk AI systems listed under Annex III of Regulation (EU) 2024/1689 (the EU AI Act). The Notice sets notification and magistrate‑authorisation requirements for remote biometric identification systems and grants the Commissioner enforcement powers including administrative penalties for infringements.
Summary
Read full text ↗Plain English
Overview
Legal Notice 227 of 2025, titled the Artificial Intelligence (Designation of the Information and Data Protection Commissioner for the purposes of Regulation (EU) 2024/1689) Regulations, 2025, was published in the Government Gazette of Malta (No. 21,519) on 10 October 2025. The Notice designates the Information and Data Protection Commissioner (IDPC) as Malta’s Market Surveillance Authority (MSA) for a defined set of high‑risk AI systems listed under Annex III (Schedule III) of the European Union’s Artificial Intelligence Regulation (Regulation (EU) 2024/1689). The designation is made under the powers conferred by the Data Protection Act (Cap. 586) and is intended to integrate the national supervisory authority responsible for personal data protection into the enforcement and market surveillance architecture of the EU AI Act. The text of the Legal Notice and the ELI entry are available from the Maltese legislation portal at legislation.mt - LN 227/2025 and the IDPC’s official announcement at IDPC - AI Regulations come into force (13 Oct 2025). The Notice focuses on balancing market oversight, data protection safeguards and judicial checks for biometric and other sensitive high‑risk AI uses.
Definitions
The Legal Notice relies on definitions contained in Regulation (EU) 2024/1689 (the AI Act) and the Data Protection Act (Cap. 586). Key defined or cross‑referenced concepts include: "AI system" (as per the AI Act); "high‑risk AI system" (categories listed in Annex III / Schedule III of the EU AI Act); "market surveillance" (tasks performed by the designated authority to ensure compliance with the Regulation); "operator" or "provider" (entities placing AI systems on the market or putting them into service); "real‑time remote biometric identification" (RBI) and "post‑remote biometric identification"; and "notification" and "authorisation" procedures (notification to the Commissioner; prior Magistrate authorisation where required). The Notice adopts the AI Act’s terminology for obligations such as conformity assessment, technical documentation and registration where applicable, and prescribes how certain duties will interact with national law on criminal justice, border management and public security.
Governance and Institutional Framework
The Notice designates the Information and Data Protection Commissioner (IDPC) as Market Surveillance Authority for the enumerated high‑risk AI system classes; accordingly, the IDPC is responsible for carrying out market surveillance functions in relation to those systems, including inspections, requests for information, investigations and the imposition of remedial actions. The designation aligns the national data protection supervisory authority with the enforcement architecture of the AI Act, reflecting that the designated systems frequently process personal and sensitive data. The Commissioner is required to cooperate with other national authorities and with the European Artificial Intelligence Board established under the AI Act, and to provide information to the AI Office and other Member State authorities as necessary. The Notice also creates procedural safeguards for oversight over law‑enforcement uses of RBI by linking deployment to prior authorisation by a Magistrate and by requiring notification to the Commissioner in a format consistent with Article 5(6) of the AI Act. The IDPC’s role encompasses both market surveillance (ensuring operators comply with obligations in the AI Act) and the protection of fundamental rights (privacy/data protection), thereby acting as a bridge between product/system safety oversight and rights‑based supervision. See the AI Act text at EUR-Lex - Regulation (EU) 2024/1689 for the EU governance context.
Key Focus Areas
The Legal Notice concentrates oversight and procedural controls on a set of high‑risk AI categories where the intersection of AI capabilities and personal data processing produces heightened risks to privacy, bodily integrity and democratic processes. These focus areas include: (1) biometric identification systems (real‑time and post‑remote) used in publicly accessible spaces by law‑enforcement or border control; (2) AI systems for emergency call processing, classification and dispatch prioritisation (due to potential life‑safety impacts); (3) AI systems used for law enforcement functions (investigation, detection, predictive tools where permitted by law); (4) AI systems used for migration, asylum and border management (EES and other border‑management tools where personal data/biometrics are processed); and (5) AI systems supporting administration of justice and democratic processes (court assistance, case classification, voting‑related technologies). For biometric and law‑enforcement uses, the Notice imposes stronger procedural checks: Magistrate authorisation for RBI deployment in public spaces and mandated notifications to the Commissioner excluding sensitive operational details. The Notice therefore prioritises fundamental‑rights protection, judicial oversight and transparent surveillance of operators handling particularly sensitive AI deployments. Risk mitigation measures implied by the designation include record‑keeping, documentation, transparency to affected persons (where feasible), and the IDPC’s investigatory and corrective toolkit to address non‑compliance swiftly.
Implementation Framework
Operationally, the Notice requires operators, deployers and public authorities to submit notifications to the IDPC for specified systems using the content set out in Article 5(6) of the AI Act (excluding sensitive operational data). In cases of real‑time RBI in public spaces and in certain post‑RBI contexts, an ex‑ante application for judicial authorisation must be submitted to a Magistrate before deployment; the Magistrate’s authorisation is a precondition to lawful use. The IDPC will receive notifications, coordinate inspections and issue compliance orders, and may liaise with other national agencies (police, migration authorities, courts) to ensure that system use is both lawful and proportionate. The IDPC will also maintain a record of notifications and actions taken and will participate in cooperation mechanisms under the AI Act (including exchanges within the European Artificial Intelligence Board). The Notice requires alignment with conformity assessment and registration mechanisms in the EU AI Act; where conformity assessment or third‑party certification applies, operators must maintain and produce technical documentation and logs for IDPC review during market surveillance activities.
Monitoring and Evaluation
The IDPC is empowered to perform proactive and reactive market surveillance activities, including audits, on‑site inspections, requests for documentation and ordering remedial measures. Monitoring will focus on operators’ adherence to documentation and logging requirements, transparency obligations (where applicable), data governance measures and human‑oversight arrangements. The IDPC may require corrective measures, impose warnings or non‑monetary measures, and escalate to administrative penalties for persistent or serious breaches. The Commissioning Notice anticipates cooperation with other national authorities and cross‑border exchanges through the European Artificial Intelligence Board. The IDPC is expected to publish periodic enforcement reports and to provide information to the public about authorisations granted for RBI in public spaces and the safeguards associated with those authorisations (subject to operational confidentiality where justified by law).
Penalties, Liability, and Appeals
The Notice grants the IDPC the ability to impose administrative penalties and remedial measures for infringements of Regulation (EU) 2024/1689 committed by operators in the scope of the designation. For public authorities or bodies found in breach, the Legal Notice specifies an administrative penalty up to EUR 50,000 for each infringement plus a daily penalty of EUR 50 for each day the infringement persists. The IDPC may also impose warnings and non‑monetary measures. Affected parties retain legal remedies under national law: operators and public bodies can challenge administrative decisions and penalties in the Maltese courts and follow appeal procedures available under administrative and judicial law. Liability for damages may arise under existing Maltese civil law and the Data Protection Act where wrongful processing causes harm; the Notice does not displace civil liability mechanisms but complements enforcement by the IDPC. The interplay between EU AI Act sanctions (as applied by other national competent authorities) and Maltese administrative penalties is governed by the AI Act’s enforcement and cooperation provisions and national procedural law.
Relationship to Other Instruments
The Legal Notice expressly implements national arrangements for enforcing provisions of Regulation (EU) 2024/1689 by designating a national MSA for specified high‑risk categories. It operates alongside and in interaction with: (1) the EU Artificial Intelligence Act (Regulation (EU) 2024/1689) — primary normative source; (2) the Data Protection Act (Cap. 586) and the GDPR (Regulation (EU) 2016/679) for personal data protection obligations; (3) sectoral rules on law enforcement, border control and public security; and (4) national criminal and administrative law governing authorisations and judicial oversight. The Notice does not replace sectoral authorisation requirements where these exist (for example, laws governing police powers or immigration), but requires that AI‑specific uses which intersect with data protection and fundamental rights are subject to the combined oversight of the IDPC and national judicial safeguards. For the EU AI Act text reference see EUR-Lex - Regulation (EU) 2024/1689 and for the Maltese ELI record see legislation.mt - LN 227/2025.
International Alignment
The designation aligns Malta’s national enforcement architecture with the EU AI Act and the EU’s approach to concentrating oversight of sensitive AI systems in authorities with data‑protection mandates. The IDPC’s designation as MSA for niche high‑risk categories echoes practices in other Member States that allocate oversight of biometric and privacy‑critical systems to data protection agencies. The Notice further positions Malta to participate in the European Artificial Intelligence Board and cooperation mechanisms established by the AI Act, enabling cross‑border enforcement coordination, exchange of best practices and consistent interpretation of high‑risk categories and procedural safeguards. By linking Magistrate authorisation to certain biometric uses, Malta also signals adherence to robust judicial oversight norms recommended by EU fundamental‑rights bodies and international human‑rights standards for biometric surveillance.
Implementation Timeline
| Event | Date |
|---|---|
| Publication in Government Gazette (LN 227/2025) | 2025-10-10 |
| IDPC public announcement | 2025-10-13 |
| Operators must notify IDPC for specified systems (as required by AI Act / LN) | Immediate upon publication; obligations effective from publication date |
| Magistrate authorisation requirement for RBI in public spaces becomes applicable | Immediate upon publication; authorisations required prior to deployment |
| Ongoing market surveillance and enforcement activities begin | From 2025-10-10 onwards |
Compliance Checklist
| Action for Operators / Public Bodies | Yes / No / Notes |
|---|---|
| Determine whether AI system falls into Annex III (Schedule III) categories | Yes — perform assessment |
| Prepare and submit notification to IDPC per Article 5(6) content (excluding sensitive operational data) | Yes — prior to deployment where required |
| Where real‑time RBI in public spaces is intended for law enforcement, obtain Magistrate authorisation | Yes — authorisation required before deployment |
| Maintain technical documentation, logs and records for IDPC inspection | Yes — retain for prescribed retention period |
| Ensure conformity assessment and CE marking obligations (if applicable) | Yes — comply with AI Act conformity requirements |
| Implement data protection safeguards and DPIAs where personal data are processed | Yes — GDPR / Data Protection Act obligations apply |
Sources and References
Malta has designated its Information and Data Protection Commissioner (IDPC) as the primary authority responsible for overseeing specific high-risk artificial intelligence (AI) systems deployed within the country, as defined by the European Union’s new AI Act (Regulation (EU) 2024/1689). This regulation applies to any entity – whether a private company or a public authority – that develops, provides, or uses these designated high-risk AI systems in Malta.
The scope covers AI systems listed in Annex III of the EU AI Act, which include those with significant potential impact on fundamental rights and safety. Key examples are: - AI systems for real-time or post-remote biometric identification in public spaces. - AI used in emergency services, law enforcement, or border management. - AI supporting the administration of justice or democratic processes.
If you are involved with such systems, you face several critical obligations. You must notify the IDPC before deploying these specified high-risk AI systems. Crucially, for real-time remote biometric identification systems used in publicly accessible spaces, especially by law enforcement, you must obtain prior authorisation from a Magistrate before deployment. Additionally, operators must maintain comprehensive technical documentation and logs, ready for IDPC inspection, and ensure their systems comply with the EU AI Act’s conformity assessment and registration requirements.
These regulations took effect on October 10, 2025, meaning all obligations are immediately applicable from that date. The IDPC has significant enforcement powers, including conducting audits, requesting information, and ordering corrective measures. For public authorities, infringements can lead to administrative penalties of up to EUR 50,000 per breach, plus a daily penalty of EUR 50 for ongoing non-compliance. Affected parties retain the right to challenge IDPC decisions in Maltese courts.
A key practical pitfall to note is the dual layer of oversight for biometric systems: not only must you notify the IDPC, but the requirement for a Magistrate’s prior authorisation for real-time remote biometric identification in public spaces introduces a significant judicial hurdle. This underscores Malta’s strong emphasis on fundamental rights and judicial checks when deploying sensitive AI technologies.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 11 marked completePlain-English obligations under Malta - AI Commissioner Designation (227/2025). Not legal advice — verify against the official text before relying on it.
- #1Critical⏰ Before deployment
Applies to: Deployers of real-time remote biometric identification systems in public spaces.
“an ex‑ante application for judicial authorisation must be submitted to a Magistrate before deployment; the Magistrate’s authorisation is a precondition to lawful use.”
- #2CriticalArticle 5(6) of the AI Act⏰ Before deployment
Applies to: Operators, deployers, and public authorities of specified high-risk AI systems.
“requires operators, deployers and public authorities to submit notifications to the IDPC for specified systems using the content set out in Article 5(6) of the AI Act.”
- #3Critical⏰ Before placing on market
Applies to: Operators of high-risk AI systems.
“Ensure conformity assessment and CE marking obligations (if applicable)”
- #4Important⏰ Before placing on market or putting into service
Applies to: Operators and deployers of AI systems.
“Determine whether AI system falls into Annex III (Schedule III) categories”
- #5Important⏰ Ongoing
Applies to: Operators of high-risk AI systems requiring conformity assessment.
“operators must maintain and produce technical documentation and logs for IDPC review during market surveillance activities.”
- #6Important⏰ Upon request during market surveillance
Applies to: Operators of high-risk AI systems requiring conformity assessment.
“operators must maintain and produce technical documentation and logs for IDPC review during market surveillance activities.”
- #7Important⏰ Before processing personal data
Applies to: Operators and deployers of AI systems processing personal data.
“Implement data protection safeguards and DPIAs where personal data are processed”
- #8Important⏰ Ongoing
Applies to: Operators of high-risk AI systems.
“Monitoring will focus on operators’ adherence to... transparency obligations (where applicable).”
- #9Important⏰ Ongoing
Applies to: Operators of high-risk AI systems.
“Monitoring will focus on operators’ adherence to... data governance measures.”
- #10Important⏰ Ongoing
Applies to: Operators of high-risk AI systems.
“Monitoring will focus on operators’ adherence to... human‑oversight arrangements.”
- #11Important⏰ Before deployment
Applies to: Deployers of AI systems subject to sectoral rules (e.g., law enforcement, immigration).
“The Notice does not replace sectoral authorisation requirements where these exist.”
Related Regulations
226 of 2025 - Artificial Intelligence Regulations, 2025 (Legal Notice)
Malta95% similar
Malta — The Ultimate AI Launchpad: A Strategy and Vision for Artificial Intelligence in Malta 2030
Malta91% similar
AI Innovative Technology Arrangement (AI ITA) scheme / National AI certification programme (MDIA)
Malta90% similar
Malta — Towards Ethical and Trustworthy AI (Malta's Ethical AI Framework)
Malta90% similar
Governance Framework for the Implementation of Regulation (EU) 2024/1689 on Artificial Intelligence in Cyprus
Cyprus90% similar
© Regulations.AI — created on 13-Jun-2026