We are deeply committed to upholding the highest standards of data protection and privacy. We recognize the critical importance of safeguarding the personal information of the individuals we interact with, as well as the sensitive data that is essential to our operations. Our data protection policies, detailed on this page, provide transparency about the safeguards in place and outline your rights. Here, you can also learn about the systems we employ to protect your information.
What Are Your Rights In Relation To Your Personal Data Processed By The Malta Police Force?
Personal data processed by the Malta Police Force is regulated by the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations (Subsidiary Legislation 586.08) and the GDPR1 when the processing is conducted for other purposes.
However, there are instances when such processing is regulated by specific legislative instruments of the European Union.
In any case, any person has the right to:
How To Exercise Your Rights?
In Malta, any individual has the right to request access, correction or deletion of their personal data by contacting directly the data controller which in this case is the Commissioner of Police, via the Data Protection Officer, or indirectly via the Office of the IDPC as explained below.
Such rights may be exercised directly by submitting a formal request to the Data Protection Officer, on any of the following:
Requests submitted by electronic means will be replied through the same means. Due to potential risks of submitting copies of personal documents and other sensitive information via open internet, it is advisable that the security of such electronic means is ensured before submitting the request.
Applicants should provide the following identification details in order to facilitate the responsible authority in dealing with the request:
In accordance with Maltese law, the request must be submitted in writing and signed by the data subject. The request must be made in Maltese or English.
In order to facilitate the exercise of your rights, the Malta Police Force has prepared a generic access request letter. It is imperative that when using this letter, one indicates clearly the type of personal data which he is requesting to access, rectify or delete.
Are there any limitations to your right?
The right of the data subject may be delayed, restricted or omitted, for as long as this constitutes a necessary and proportionate measure in a democratic society with due regard for the fundamental rights and the legitimate interests of the natural person concerned in terms of the law.
Such measures may be imposed in order to:
In the eventuality of a restriction or refusal, the individual is informed in writing of the decision, including reasons for the decision, unless such communication would have a bearing on the work of competent authorities or on the rights and freedoms of other individuals.
Right To Lodge A Complaint
Any person not satisfied with a reply to his request as outlined above may file a complaint with the office of the IDPC or request that the IDPC verifies that his/her data protection rights are being respected and that his/her personal data are processed according to law.
The Information and Data Protection Commissioner
The Information and Data Protection Commissioner (IDPC) is the national supervisory authority in Malta responsible to conduct independent supervision, monitoring and enforcement of data protection legislation.
To that end, the IDPC is empowered to have access and inspect all the personal data and filing systems in Malta.
The Office of the IDPC may be reached on the following contact details:
1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
The use of Body Worn Cameras (BWCs) is an effective tool in the prevention, investigation, detection and prosecution of criminal offences. It also demonstrates the commitment of the Malta Police Force to transparency and accountability, enhances public confidence in policing, supports the collection of reliable evidence, assists in the resolution of complaints and incidents, and contributes to the safety and protection of police officers and members of the public.
The Malta Police Force, following the practices adopted by a number of Law Enforcement Authorities, including those within European Union Member States, has introduced the use of BWCs by operational Police Officers. In accordance with the applicable Standard Operating Procedures, BWCs may be activated whenever officers know or reasonably expect that they will interact with members of the public in the discharge of their law enforcement duties, particularly in connection with the prevention, investigation, detection or prosecution of criminal offences, the maintenance of public order and public safety, or the protection of life and property.
When activated, the BWCs display a green LED indicator to provide a visible indication that recording is taking place. The recordings are securely uploaded and stored within systems managed by the Malta Police Force and are subject to strict access controls, security measures, and oversight arrangements designed to protect the rights and freedoms of individuals.
Legal Basis
The processing of personal data captured via BWCs is based on various legal provisions:
Purposes Of Processing
Personal data collected through BWCs may be processed for one or more of the following purposes:
Personal Data Captured By BWCs
The categories of personal data that may be captured through BWCs include:
Disclosure Of Data
Data captured through BWCs shall be accessed only by authorised personnel who require access for the performance of their duties.
Where permitted or required by law, recordings may be disclosed to:
Recordings may also be processed internally for professional standards investigations, auditing, quality assurance, training, operational review and lessons learned purposes, provided that appropriate safeguards are implemented to protect the rights and freedoms of the individuals concerned.
Where recordings are used for training or professional development purposes, the Malta Police Force shall, wherever reasonably practicable, implement safeguards such as restricting access to authorised personnel, removing or masking identifying information, blurring faces, redacting audio, limiting the footage used to what is strictly necessary, or implementing other appropriate technical and organisational measures.
Retention Period
All data collected from BWCs are kept for period of ninety (90) days in accordance with the Data Retention Schedule, as approved by the Information and Data Protection Commissioner.
All data will be automatically deleted upon the expiration of such period in a secure way.
However, recordings may be retained for a longer period where this is necessary for law enforcement, evidential, disciplinary, training, oversight, legal or other authorised purposes.
In such cases, the recordings shall only be retained for as long as necessary to fulfil the relevant purpose and in accordance with applicable legal requirements and retention schedules.
What Are Your Rights In Relation To Your Personal Data Captured By BWCs?
The processing of personal data collected through BWCs is regulated by the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations (S.L. 586.08).
Subject to the limitations and restrictions established by law, individuals have the right to:
How To Exercise Your Rights?
Requests concerning personal data processed through BWCs may be submitted to the Malta Police Force through its Data Protection Officer.
Such rights are exercisable by submitting a formal request, preferably by using the following form, including in an electronic form, to the In-Field Tech Unit, on any of the following:
Address
Att. In-Field Tech Office
The Data Protection Officer
Legal & Data Protection Unit,
Police Headquarters,
Floriana
Email: [email protected]
Telephone: +356 21224001
The exercise of data subject rights may be delayed, restricted or omitted where this constitutes a necessary and proportionate measure in a democratic society, having due regard to the fundamental rights and legitimate interests of the individual concerned, in accordance with applicable law.
Where a request is refused or restricted, the individual shall be informed of the decision and the reasons for it, unless the provision of such information would prejudice criminal investigations, law enforcement activities, national security, public security, judicial proceedings, or the rights and freedoms of others.
Where recordings have been obtained, seized or retained as part of criminal proceedings or criminal investigations, the exercise of rights may be subject to the specific provisions of criminal procedural law and any other applicable legislation.
The Entry/Exit System (EES) is a large-scale information system established by the European Union to improve the management of the Schengen external borders. It registers entry data, exit data and refusal of entry data of third-country nationals crossing the external borders of the Schengen Area and replaces the manual stamping of passports.
The EES supports border management, facilitates border crossings, contributes to internal security, and enables the identification of overstayers (persons who remain in the territory of the Member States longer than authorised).
The EES is used for border management and facilitation purposes, as well as for law enforcement purposes, in accordance with Regulation (EU) 2017/2226.
Legal Basis
The EES is established and regulated by:
Structure Of The EES
The EES consists of:
Data entered by one Member State is stored centrally and may be accessed and processed by competent authorities of other Member States, by Europol for law enforcement purposes, and by other authorised entities, strictly in accordance with Regulation (EU) 2017/2226.
Controllers & Competent Authorities In Malta
The Malta Police Force has been designated as the controller with central responsibility for the operation of the national Entry/Exit System (N.EES).
Without prejudice to this central responsibility, other national competent authorities act as controllers in their own right, and solely in respect of the processing operations carried out within the scope of their respective legal mandates and functions, as provided for under Regulation (EU) 2017/2226 and applicable national legislation.
In accordance with the EES Regulation, duly authorised staff of the following authorities may enter, amend, erase, verify and consult EES data within the limits of their legal competences:
Personal Data Processed In The EES
The EES processes the following categories of personal data relating to third-country nationals subject to registration:
Mandatory Nature Of Data Collection
The collection of personal data for registration in the EES is mandatory for the examination of entry conditions at the external borders of the Schengen Area.
Entry will be refused if a third-country national refuses to provide the required biometric data (facial image and, where applicable, fingerprints) for registration, verification or identification in the EES.
Use Of Data For Overstay Detection And Authorised Stay Calculation
EES data is used to calculate the authorised duration of stay of third-country nationals.
Overstays are automatically detected, and where applicable, the individual’s data is added to the list of identified overstayers referred to in Article 12(3) of Regulation (EU) 2017/2226.
Overstaying may result in legal and administrative consequences, including refusal of entry and the initiation of return procedures.
Individuals have the right to receive information on the maximum remaining duration of their authorised stay, in accordance with Article 11(3) of Regulation (EU) 2017/2226.
Transfers Of Personal Data
Personal data stored in the EES may be transferred:
Such transfers take place only under the conditions and safeguards laid down in EU law.
Retention Periods
In accordance with Regulation (EU) 2017/2226:
Your Rights In Relation To Your Personal Data In The EES
Individuals whose personal data is processed in the EES have the right to:
Overstayers have the right to request erasure of their personal data from the list of identified persons referred to in Article 12(3) and rectification of EES data, where they provide evidence that the authorised duration of stay was exceeded due to unforeseeable and serious events.
Requests by data subjects may be submitted either to the Malta Police Force or to any national authority having lawful access to the EES, in accordance with Regulation (EU) 2017/2226.
Individuals wishing to exercise their rights through the Malta Police Force are encouraged to use the Model Letters made available to facilitate the submission and handling of such requests.
Complaints
Individuals have the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC).
Where applicable, complaints relating to processing carried out at EU level may also be addressed to the European Data Protection Supervisor (EDPS).
The Malta Police Force is the national authority with central responsibility for the European Travel Information and Authorisation System (ETIAS) in Malta.
The National ETIAS Unit, established in accordance with the applicable European Union legal framework, will be hosted within the Malta Police Force and shall perform the functions established by law in relation to ETIAS in Malta.
Starting from the last quarter of 2026, nationals of 59 visa-free countries travelling to Europe for a short stay will be required to obtain a travel authorisation prior to travel to participating European countries.
ETIAS forms part of the European Union’s efforts to strengthen internal security and border management by carrying out pre-travel screening of visa-free travellers to assess whether they may pose a:
ETIAS applies to short stays in participating European countries and does not constitute a visa.
Before Travelling
Travellers from visa-free countries falling within the scope of ETIAS will be required to obtain a valid travel authorisation before commencing travel.
ETIAS applications are submitted electronically and assessed against relevant European information systems in accordance with the ETIAS legal framework. Most applications are expected to be processed automatically within minutes, while a limited number may require manual assessment by the competent authorities.
Travellers who are required to hold a valid ETIAS travel authorisation and fail to do so may be refused boarding by the carrier, including airlines, ferry operators, or bus companies.
Further information regarding who requires ETIAS, how to apply, and how the system operates may be accessed through the official European Union ETIAS webpages.
At The Border
Upon arrival at the external border of a participating European country, travellers may be subject to border checks in accordance with applicable European Union and national legislation.
Where applicable, border authorities may electronically verify whether a traveller holds a valid ETIAS travel authorisation and whether all other entry conditions are fulfilled.
In Malta, border control functions are carried out under the responsibility of the Principal Immigration Officer, in accordance with the applicable legal framework.
Possession of a valid ETIAS travel authorisation does not automatically guarantee entry, as the final decision regarding admission into the territory remains subject to compliance with all applicable entry conditions under law.
Malta’s National ETIAS Framework
At national level, ETIAS responsibilities in Malta will be exercised in accordance with the applicable European Union and national legal framework.
The National ETIAS Unit, which processes applications in Malta, will be hosted within the Malta Police Force. The latter is designated as the national authority with central responsibility for ETIAS in Malta.
In addition, the Malta Police Force shall act as the Central Access Point for access to personal data stored in ETIAS for law enforcement purposes, in accordance with the conditions and safeguards established by law.
Other Maltese competent authorities may also be granted access to ETIAS where authorised by law and formally designated for specific purposes established under the applicable legal framework.
These may include, for example:
At present, the formal designation or recognition of all competent Maltese authorities having access to ETIAS is still subject to the applicable legal and institutional framework and may be updated at a later stage.
Refusal, Revocation Or Annulment Of An ETIAS Travel Authorisation
Where an ETIAS application is refused, or a travel authorisation is revoked or annulled, the applicant will receive a notification indicating:
Applicants have the right to appeal decisions refusing, revoking, or annulling an ETIAS travel authorisation.
Appeals are handled in accordance with the national law of the European country that took the decision.
Where a travel authorisation is revoked at the request of the traveller, no right of appeal shall apply.
Further information regarding appeals and ETIAS procedures is available through the official European Union ETIAS webpages.
Data Protection And Your Rights
Personal data processed within ETIAS is protected in accordance with applicable European Union and national data protection legislation.
The processing of personal data within ETIAS is subject to strict safeguards, access controls, and legal limitations.
Controllers Of Personal Data
Personal data contained in ETIAS may be processed by the Malta Police Force, including the National ETIAS Unit, and by other competent Maltese authorities authorised by law to access ETIAS, strictly within the limits established by law.
Each competent authority accessing ETIAS acts independently and processes personal data only for the purposes for which it has lawful access.
Accordingly, each authority acts as controller only in relation to personal data processed by that authority within ETIAS.
The Malta Police Force, including the National ETIAS Unit hosted within it, does not automatically act as controller for all personal data processed within ETIAS by other competent Maltese authorities.
Likewise, competent Maltese authorities may only act upon requests concerning personal data where they have processed such data and act as controller in respect of the relevant processing activity.
Maltese authorities cannot grant access to, rectify, complete, erase, restrict, or otherwise act upon personal data processed within ETIAS where they have not processed such data and do not act as controller in relation to that processing.
Your Rights
Subject to the applicable legal framework and any lawful restrictions provided by law, individuals whose personal data is processed in ETIAS may exercise, where applicable, the following rights:
How To Exercise Your Rights
Requests concerning personal data processed within ETIAS may be submitted:
Where a Maltese authority has not processed the relevant personal data and does not act as controller, that authority cannot act upon the request.
Where appropriate, applicants may be directed to the competent authority responsible for the relevant processing.
Timeframe For Responding To Requests
Competent authorities shall respond to ETIAS-related requests without undue delay and, in any event, within one month from receipt of the request, in accordance with the ETIAS legal framework.
Certain rights may be restricted in accordance with applicable law where necessary and proportionate to safeguard public security, border management, or the prevention, detection, investigation, or prosecution of criminal offences.
Complaints And Remedies
If you are not satisfied with how your request has been handled, you may lodge a complaint with the competent supervisory authority or seek an effective judicial remedy in accordance with applicable law.
Legal Framework
ETIAS in Malta is governed by applicable European Union and national legislation, including, but not limited to:
Introduction
EURODAC is a European Union (EU) information system established under Regulation (EU) 2024/1358 of the European Parliament and of the Council of 14 May 2024 on the establishment of ‘Eurodac’ for the comparison of biometric data, which repealed Regulation (EU) No 603/2013.
EURODAC enables participating States to compare biometric data and other relevant information in order to support the effective application of the European Union asylum and migration framework, including:
EURODAC operates through a Central System containing the database and a secure communication infrastructure connecting participating States through a dedicated encrypted network.
This notice explains how personal data is processed by the Malta Police Force (MPF), through its Eurodac Office, in connection with the EURODAC system and informs you of your rights under applicable data protection legislation.
Role of the Malta Police Force and Scope of Responsibility
In Malta, the authority designated to access and process data within the EURODAC system is the Eurodac Office within the Malta Police Force.
The Malta Police Force, through its Eurodac Office, is responsible solely for the processing of personal data relating to Malta’s operation and use of the EURODAC system, in accordance with Regulation (EU) 2024/1358 and applicable national legislation.
Important Clarification Regarding Asylum Applications
The Malta Police Force is not responsible for the processing of personal data carried out in the context of asylum or international protection procedures generally, except insofar as personal data is processed within the EURODAC system.
Accordingly, where a request concerns personal data processed in relation to an asylum or international protection application other than personal data processed in EURODAC, such requests should be addressed to the competent authority responsible for asylum matters in Malta, namely the International Protection Agency (IPA).
What is EURODAC?
EURODAC is a European database used by participating States to store and compare biometric data, namely fingerprints and facial image data, together with other information relating to specific categories of third-country nationals and stateless persons.
EURODAC supports the implementation of:
EURODAC may be used in relation to the following categories of persons, as provided under Regulation (EU) 2024/1358:
Biometric data may be collected and processed in relation to persons aged six (6) years and over, in accordance with the applicable legal framework.
EURODAC is accessible by the 27 Member States of the European Union, together with Iceland, Norway, Liechtenstein and Switzerland.
Legal Basis
The processing of personal data within the EURODAC system is carried out in accordance with:
Where personal data is processed for law enforcement access to EURODAC, processing is subject to the specific safeguards, limitations and conditions established by Regulation (EU) 2024/1358.
Categories of Personal Data Processed
Depending on the category of person concerned and the applicable legal framework, the following categories of personal data may be processed within EURODAC.
Biometric Data
Identification and Administrative Data
Depending on the applicable category, EURODAC may process:
The exact categories of data processed depend on the legal category applicable to the person concerned and the requirements of Regulation (EU) 2024/1358.
Purpose of Processing
Personal data processed within EURODAC may be used for the following purposes:
International Protection and Migration Purposes
To:
Law Enforcement Purposes
Under strictly regulated circumstances, designated law enforcement authorities and Europol may request comparison of EURODAC data where this is necessary for the prevention, detection or investigation of terrorist offences or other serious criminal offences.
Such access is permitted only where all legal conditions are fulfilled, including strict safeguards, necessity and proportionality requirements, and prior verification procedures established by law.
Retention of Data
The retention period applicable to personal data depends on the category under which data is recorded in EURODAC and the requirements of Regulation (EU) 2024/1358.
Applicants for International Protection
Personal data relating to applicants for international protection shall be retained in EURODAC for ten (10) years from the date on which biometric data is taken.
Data shall be erased before expiry of this period where:
Where international protection is granted, the relevant data may be marked in accordance with Regulation (EU) 2024/1358.
Persons Apprehended in Connection with the Irregular Crossing of an External Border
Personal data relating to persons apprehended in connection with the irregular crossing of an external border shall be retained for five (5) years.
Data may be erased before expiry where legally required, including where the person concerned acquires citizenship of a Member State.
Persons Found Illegally Staying in a Member State
Personal data relating to persons found illegally staying in a Member State shall be retained for three (3) years, in accordance with Regulation (EU) 2024/1358.
Persons Disembarked Following Search and Rescue Operations at Sea
Personal data relating to persons disembarked following rescue operations at sea shall be retained for five (5) years, unless erased earlier in accordance with law.
Persons Admitted Through Resettlement or Humanitarian Admission Procedures
Personal data relating to persons admitted through resettlement or humanitarian admission procedures shall be retained for ten (10) years, unless erased earlier in accordance with law.
Persons Benefitting from Temporary Protection
Personal data relating to persons benefitting from temporary protection shall be retained for the duration provided by the applicable legal framework governing temporary protection and EURODAC.
Your Rights
Subject to the applicable legal framework and any lawful restrictions provided by legislation, you have the right to:
Where necessary to verify your identity and locate your EURODAC data, you may be requested to physically attend the Eurodac Office for biometric verification purposes. Any biometric data taken solely for verification purposes shall not be retained unless otherwise authorised by law.
How to Exercise Your Rights
Requests relating to personal data processed by the Malta Police Force within the EURODAC system may be submitted to the Eurodac Office or to the Data Protection Officer of the Malta Police Force.
To facilitate the exercise of these rights and enable the efficient handling of requests, data subjects are encouraged to make use of the model letters available on the Malta Police Force website by clicking here.
Requests concerning asylum or international protection case files, other than personal data processed in the EURODAC system, should be addressed to the competent authority responsible for asylum matters in Malta, namely the International Protection Agency (IPA).
Contact Details
Eurodac Office
Malta Police Force General Headquarters
St. Calcedonius Square
Floriana FRN 1530
Malta
Email: [email protected]
Data Protection Officer
Malta Police Force General Headquarters
St. Calcedonius Square
Floriana FRN 1530
Malta
Email: [email protected]
Right to Lodge a Complaint
If you believe that your personal data has been processed unlawfully or in breach of applicable data protection legislation, you may lodge a complaint with the national supervisory authority:
Information and Data Protection Commissioner (IDPC)
Further Information
This notice relates solely to the processing of personal data by the Malta Police Force in connection with the EURODAC system.
For information concerning the processing of personal data in the context of an asylum or international protection application, other than EURODAC processing, please contact the International Protection Agency (IPA).
List Of Alerts And The Respective Periodic Review Period:
Regulation (EU) 2018/1860 | ||
Type of Alert | Article No. | Review Period |
Alerts in respect of third-country nationals subject to return decisions issued by the Schengen countries (Return decisions). | Article 3 | 3 Years |
Regulation (EU) 2018/1861 | ||
Type of Alert | Article No. | Review Period |
Alerts on third-country nationals who may not enter or stay in the Schengen Area (Refusal of entry or stay). | Articles 24, 25 and 26 | 3 Years |
Regulation (EU) 2018/1862 | ||
Type of Alert | Article No. | Review Period |
Alerts on persons who are subject to a European Arrest Warrant or other warrant for surrender (Norway and Iceland)/Extradition Request (Switzerland and Liechtenstein) (Persons wanted for arrest). | Article 26 | 5 Years |
Alerts to find missing persons, including children, and to place them under protection if lawful and necessary (Missing persons). | Points (a) and (b) of Article 32(1) | 5 Years |
Alerts to find out the place of residence or domicile of persons sought to assist with criminal judicial procedures (for example witnesses, persons summoned to appear in Court or who are to be served with a criminal judgment or serve a penalty involving deprivation of liberty) (Persons sought to assist with a judicial procedure). | Articles 34 | 3 Years |
Alerts for the identification of unknown persons wanted in relation to terrorist offences or other serious crimes under investigation (Unknown wanted persons). | Article 40 | 3 Years |
Alerts to prevent children at risk from being abducted or going missing (Children at risk of being abducted by parents, relatives, or guardians). | Points (c) of Article 32(1) | 1 Year |
Alerts for the protection of vulnerable people (adults or children) from being taken unlawfully abroad or to prevent them from travelling without the necessary authorisations (Vulnerable persons whose travel must be prevented). | Points (d) and (e) of Article 32(1) | 1 Year |
Alerts to obtain information on persons or related objects for the purposes of prosecuting criminal offences and for the prevention of threats to public or national security (Persons and objects for discreet, inquiry or specific checks). | Article 36 | 1 Year |
Alerts on objects (for example vehicles, travel documents, number plates and industrial equipment) being sought for seizure or use as evidence in criminal proceedings, and Alerts on travel documents for preventing the holders of such documents from travelling (Objects for seizure or use as evidence in criminal procedures). | Articles 36 and 38 | 10 Years |
Articles 26, 32, 34, and 36 (If linked to an alert on a person) | The same review period of the linked alert on the person | |
What Are Your Rights In Relation To Your Personal Data Processed In The SIS?