Regulatory Watch  /  Malta  /  Data protection authority action
Moderate impactData protection authority actionAnnounced

Maltese DPA orders C-PLANET to disclose data source within 20 days or face fine

The Maltese Data Protection Authority (IDPC) ordered IT company C-PLANET to provide details on the source of personal data collected on voters within 20 days. Failure to comply will result in a proportionate and dissuasive fine under the GDPR. The decision follows complaints that C-PLANET breached Article 15 GDPR by not supplying a copy of the data and source information.

Why it matters: The enforcement underscores GDPR transparency obligations for political data processing.

Summary generated from the sources below. Check the primary source before relying on it; this is not legal advice.

Sources
Data Breach in Malta: Company must disclose source within 20 days or face penalties
noyb · primary source · May 17, 2023
Data Breach in Malta: Company must disclose source within 20 days or face penalties
noyb · May 17, 2023
Details
JurisdictionMalta
RegulatorMaltese Data Protection Authority (IDPC)
LawGeneral Data Protection Regulation
StatusAnnounced
PublishedMay 17, 2023
Effectivenot stated
Penaltya fine that is both "proportionate and dissuasive" under the GDPR
OrganisationsC-PLANET IT Solutions
Topicstransparency, profiling, access, privacy
Datapersonal, sensitive