Data Protection Laws

Return to GDPR page

Current European Union Data Protection Legislation

  • GDPR
    Regulation (EU) 2016/679 of the European Parliament and of the council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
  • ePrivacy
    Directive Directive 2002/58/EC of the European Parliament and of the Council of 12 July 2002 concerning the processing of personal data and the protection of privacy in the electronic communications sector (Directive on Privacy and Electronic Communications)
  • Directive on the Processing of Personal Data by Competent Authorities
    Directive (EU) 2016/680 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data by competent authorities for the purposes of the prevention, investigation, detection or prosecution of criminal offences or the execution of criminal penalties, and on the free movement of such data, and repealing Council Framework Decision 2008/977/JHA
  • Passenger Name Record Directive
    Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime
  • Regulation (EU) 2023/2854 of the European Parliament and of the Council of 13 December 2023 on harmonised rules on fair access to and use of data and amending Regulation (EU) 2017/2394 and Directive (EU) 2020/1828 (Data Act)

Current Local Data Protection Legislation

Stay updated with our latest insights

Telecoms, Media & Technology

EU Commission Classifies ChatGPT as a Search Engine: A Brief Look at What This Means

The European Commission has recently designated OpenAI’s ChatGPT as a Very Large Online Search Engine (“VLOSE”), whilst Roblox and Reddit have been designated as Very Large Online Platforms (“VLOPs”), making all three subject to the Digital Services Act (“DSA”) . Having each exceeded an average of 45 million monthly users throughout the European Union (“EU”), the newly designated services now have four months (until January 2027) to comply with all additional requirements mandated by the DSA for both VLOSEs and VLOPs. This is particularly noteworthy in the case of ChatGPT, which has now joined the two other VLOSEs, 'Bing' (operated…
Data Protection and Privacy

Ian Deguara Joins Mamo TCV Advocates

In August 2026, Mr Ian Deguara, the former Maltese Information and Data Protection Commissioner, joined Mamo TCV Advocates as Senior Regulatory Advisor. Mr Deguara’s term at the Office of the Information and Data Protection Commissioner (IDPC) came to an end in March 2026. Mamo TCV Advocates’ Managing Partner, Dr Joe Borg Bartolo, welcomed Mr Deguara to the firm, describing his appointment as an important milestone for both the firm and Mr Deguara as he begins this new chapter of his distinguished career in the field of privacy and data protection. Dr Claude Micallef Grimaud and Dr Antoine Camilleri, both partners heading the…
Telecoms, Media & Technology

EU AI Act Update: What Will Apply From 2 August 2026 And What Is Being Postponed?

In a recent press release, the Council of the European Union announced that a provisional agreement on the Digital Omnibus Regulation on AI (hereinafter the “Omnibus”) was reached, introducing certain amendments to the EU AI Act (hereinafter the “Act”). Most notably, the provisional agreement revises the timeline for the applicability of certain provisions of the Act, particularly concerning the obligations applicable to high-risk AI systems. In this respect, the application of the obligations with respect to high-risk AI systems listed under Annex III of the Act would be postponed to 2 December 2027. For high-risk AI systems which are embedded…
DORA
Reminder: DORA Register of Information Submission Deadline Approaching
The EU AI Act
DORA
European Commission Proposes Updated EU Cybersecurity Act (The Cybersecurity Act 2)
DORA
NIS 2 and Critical Entities Resilience Framework Enter into Force in Malta

Join our mailing list

Get in touch by sending us a message or by contacting us directly.


How can we help you?