Data Protection

We are deeply committed to upholding the highest standards of data protection and privacy. We recognize the critical importance of safeguarding the personal information of the individuals we interact with, as well as the sensitive data that is essential to our operations. Our data protection policies, detailed on this page, provide transparency about the safeguards in place and outline your rights. Here, you can also learn about the systems we employ to protect your information.

What Are Your Rights In Relation To Your Personal Data Processed By The Malta Police Force?

Personal data processed by the Malta Police Force is regulated by the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations (Subsidiary Legislation 586.08) and the GDPR1 when the processing is conducted for other purposes.

However, there are instances when such processing is regulated by specific legislative instruments of the European Union.

In any case, any person has the right to:

  • request access to personal data relating to them being processed by the Malta Police Force;
  • request the correction of factually inaccurate personal data relating to them or the deletion of their personal data in the case of unlawfully stored information;
  • the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC) or to request verification of lawfulness of the processing.

How To Exercise Your Rights?

In Malta, any individual has the right to request access, correction or deletion of their personal data by contacting directly the data controller which in this case is the Commissioner of Police, via the Data Protection Officer, or indirectly via the Office of the IDPC as explained below.

Such rights may be exercised directly by submitting a formal request to the Data Protection Officer, on any of the following:

  • Address: The Data Protection Officer, Legal & Data Protection Unit, Police General Headquarters, St. Calcedonius Square, Floriana, FRN 1530, Malta
  • Email: [email protected]

Requests submitted by electronic means will be replied through the same means. Due to potential risks of submitting copies of personal documents and other sensitive information via open internet, it is advisable that the security of such electronic means is ensured before submitting the request.

Applicants should provide the following identification details in order to facilitate the responsible authority in dealing with the request:

  1. Name and surname of applicant;
  2. ID Card or Passport Number;
  3. What particular information they would like to see;
  4. A copy of the ID Card or Passport is also to be submitted for identification verification purposes.

In accordance with Maltese law, the request must be submitted in writing and signed by the data subject. The request must be made in Maltese or English.

In order to facilitate the exercise of your rights, the Malta Police Force has prepared a generic access request letter. It is imperative that when using this letter, one indicates clearly the type of personal data which he is requesting to access, rectify or delete.

Are there any limitations to your right?

The right of the data subject may be delayed, restricted or omitted, for as long as this constitutes a necessary and proportionate measure in a democratic society with due regard for the fundamental rights and the legitimate interests of the natural person concerned in terms of the law.

Such measures may be imposed in order to:

  1. Avoid obstructing official or legal inquiries, investigations or procedures.
  2. Avoid prejudicing the prevention, detection, investigation or prosecution of criminal offences or the execution of criminal penalties.
  3. Protect public security.
  4. Protect national security.
  5. Protect the rights and freedoms of others.

In the eventuality of a restriction or refusal, the individual is informed in writing of the decision, including reasons for the decision, unless such communication would have a bearing on the work of competent authorities or on the rights and freedoms of other individuals.

Right To Lodge A Complaint

Any person not satisfied with a reply to his request as outlined above may file a complaint with the office of the IDPC or request that the IDPC verifies that his/her data protection rights are being respected and that his/her personal data are processed according to law.

The Information and Data Protection Commissioner

The Information and Data Protection Commissioner (IDPC) is the national supervisory authority in Malta responsible to conduct independent supervision, monitoring and enforcement of data protection legislation.

To that end, the IDPC is empowered to have access and inspect all the personal data and filing systems in Malta.

The Office of the IDPC may be reached on the following contact details:


1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)

The use of Body Worn Cameras (BWCs) is an effective tool in the prevention, investigation, detection and prosecution of criminal offences. It also demonstrates the commitment of the Malta Police Force to transparency and accountability, enhances public confidence in policing, supports the collection of reliable evidence, assists in the resolution of complaints and incidents, and contributes to the safety and protection of police officers and members of the public.

The Malta Police Force, following the practices adopted by a number of Law Enforcement Authorities, including those within European Union Member States, has introduced the use of BWCs by operational Police Officers. In accordance with the applicable Standard Operating Procedures, BWCs may be activated whenever officers know or reasonably expect that they will interact with members of the public in the discharge of their law enforcement duties, particularly in connection with the prevention, investigation, detection or prosecution of criminal offences, the maintenance of public order and public safety, or the protection of life and property.

When activated, the BWCs display a green LED indicator to provide a visible indication that recording is taking place. The recordings are securely uploaded and stored within systems managed by the Malta Police Force and are subject to strict access controls, security measures, and oversight arrangements designed to protect the rights and freedoms of individuals.

Legal Basis

The processing of personal data captured via BWCs is based on various legal provisions:

  • Article 346(1) of the Criminal Code (Chapter 9 of the Laws of Malta), which imposes upon the Police the duty to preserve public order and peace, prevent, detect and investigate offences, collect evidence both against and in favour of persons suspected of criminal offences, and bring offenders before the competent judicial authorities.
  • Article 4(a) of the Police Act (Chapter 164 of the Laws of Malta), which establishes as one of the principal functions of the Malta Police Force the preservation of public order and peace, the prevention of offences, and the promotion of compliance with the law.
  • Article 62(1) of the Police Act (Chapter 164 of the Laws of Malta), which empowers the Police to hold, process and classify information relevant to the commission of crimes in Malta or abroad, including information stored electronically.
  • Regulation 8(3) of the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations (S.L. 586.08), which permits the collection of personal data through technical surveillance or other automated means for law enforcement purposes.

Purposes Of Processing

Personal data collected through BWCs may be processed for one or more of the following purposes:

  • the prevention, investigation, detection and prosecution of criminal offences;
  • the preservation of public order and public safety;
  • the protection of life and property;
  • the collection, preservation and presentation of evidence;
  • the handling, investigation and resolution of complaints, incidents and allegations involving police officers or members of the public;
  • internal disciplinary, professional standards or misconduct investigations;
  • operational review, supervision, auditing and quality assurance activities;
  • training, professional development, lessons learned exercises and the improvement of operational practices, where necessary and proportionate and subject to appropriate safeguards;
  • any other purpose authorised by applicable law and compatible with the law enforcement functions of the Malta Police Force.

Personal Data Captured By BWCs

The categories of personal data that may be captured through BWCs include:

  • video recordings;
  • audio recordings;
  • GPS location data;
  • date and time information;
  • information concerning individuals involved in incidents attended by the Police.

Disclosure Of Data

Data captured through BWCs shall be accessed only by authorised personnel who require access for the performance of their duties.

Where permitted or required by law, recordings may be disclosed to:

  • the Attorney General;
  • the Courts and judicial authorities;
  • other competent authorities in Malta;
  • other law enforcement authorities and agencies authorised by law;
  • foreign competent authorities, including law enforcement authorities of other Member States or third countries, where such disclosure is authorised by law, international agreement, mutual legal assistance arrangements, police cooperation mechanisms or other applicable legal instruments.

Recordings may also be processed internally for professional standards investigations, auditing, quality assurance, training, operational review and lessons learned purposes, provided that appropriate safeguards are implemented to protect the rights and freedoms of the individuals concerned.

Where recordings are used for training or professional development purposes, the Malta Police Force shall, wherever reasonably practicable, implement safeguards such as restricting access to authorised personnel, removing or masking identifying information, blurring faces, redacting audio, limiting the footage used to what is strictly necessary, or implementing other appropriate technical and organisational measures.

Retention Period

All data collected from BWCs are kept for period of ninety (90) days in accordance with the Data Retention Schedule, as approved by the Information and Data Protection Commissioner.

All data will be automatically deleted upon the expiration of such period in a secure way.

However, recordings may be retained for a longer period where this is necessary for law enforcement, evidential, disciplinary, training, oversight, legal or other authorised purposes.

In such cases, the recordings shall only be retained for as long as necessary to fulfil the relevant purpose and in accordance with applicable legal requirements and retention schedules.

What Are Your Rights In Relation To Your Personal Data Captured By BWCs?

The processing of personal data collected through BWCs is regulated by the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations (S.L. 586.08).

Subject to the limitations and restrictions established by law, individuals have the right to:

  • request access to personal data relating to them;
  • request the rectification of inaccurate personal data;
  • request the completion of incomplete personal data;
  • request the erasure of unlawfully processed personal data;
  • request the restriction of processing where permitted by law;
  • lodge a complaint with the Information and Data Protection Commissioner.

How To Exercise Your Rights?

Requests concerning personal data processed through BWCs may be submitted to the Malta Police Force through its Data Protection Officer.

Such rights are exercisable by submitting a formal request, preferably by using the following form, including in an electronic form, to the In-Field Tech Unit, on any of the following:

Address

Att. In-Field Tech Office
The Data Protection Officer
Legal & Data Protection Unit,
Police Headquarters,
Floriana

Email: [email protected]

Telephone: +356 21224001

The exercise of data subject rights may be delayed, restricted or omitted where this constitutes a necessary and proportionate measure in a democratic society, having due regard to the fundamental rights and legitimate interests of the individual concerned, in accordance with applicable law.

Where a request is refused or restricted, the individual shall be informed of the decision and the reasons for it, unless the provision of such information would prejudice criminal investigations, law enforcement activities, national security, public security, judicial proceedings, or the rights and freedoms of others.

Where recordings have been obtained, seized or retained as part of criminal proceedings or criminal investigations, the exercise of rights may be subject to the specific provisions of criminal procedural law and any other applicable legislation.

The Entry/Exit System (EES) is a large-scale information system established by the European Union to improve the management of the Schengen external borders. It registers entry data, exit data and refusal of entry data of third-country nationals crossing the external borders of the Schengen Area and replaces the manual stamping of passports.

The EES supports border management, facilitates border crossings, contributes to internal security, and enables the identification of overstayers (persons who remain in the territory of the Member States longer than authorised).

The EES is used for border management and facilitation purposes, as well as for law enforcement purposes, in accordance with Regulation (EU) 2017/2226.

 

Legal Basis

The EES is established and regulated by:

  • Regulation (EU) 2017/2226 of the European Parliament and of the Council of 30 November 2017 establishing an Entry/Exit System (EES), determining the purposes of the system, the categories of data processed, retention periods, and the conditions for access, including for law enforcement purposes;
  • Regulation (EU) 2019/1896 on the European Border and Coast Guard, insofar as it amends and supplements certain provisions relating to the EES;
  • Delegated and Implementing Acts adopted by the European Commission pursuant to Articles 36 and 68 of Regulation (EU) 2017/2226, laying down technical specifications, operational procedures and data protection safeguards;
  • National legislation, including:
    • The Immigration Act (Cap. 217 of the Laws of Malta) and subsidiary legislation;
    • The Entry and Exit System (EES) Regulations implementing the EES in Malta;
    • Other applicable laws governing the competent authorities and the processing of personal data, including data protection legislation.

 

Structure Of The EES

The EES consists of:

  • A central system operated by eu-LISA;
  • A national system (N.EES) in each Member State (in Malta, hosted by the Malta Police Force);
  • A secure communication infrastructure connecting the central and national systems.

Data entered by one Member State is stored centrally and may be accessed and processed by competent authorities of other Member States, by Europol for law enforcement purposes, and by other authorised entities, strictly in accordance with Regulation (EU) 2017/2226.

 

Controllers & Competent Authorities In Malta

The Malta Police Force has been designated as the controller with central responsibility for the operation of the national Entry/Exit System (N.EES).

Without prejudice to this central responsibility, other national competent authorities act as controllers in their own right, and solely in respect of the processing operations carried out within the scope of their respective legal mandates and functions, as provided for under Regulation (EU) 2017/2226 and applicable national legislation.

In accordance with the EES Regulation, duly authorised staff of the following authorities may enter, amend, erase, verify and consult EES data within the limits of their legal competences:

  • Malta Police Force
  • Principal Immigration Officer
  • Identity Malta Agency (Identity Management and Ancillary Services)
  • Community Malta Agency
  • Ministry responsible for Foreign Affairs (for authorised diplomatic missions)

 

Personal Data Processed In The EES

The EES processes the following categories of personal data relating to third-country nationals subject to registration:

  • Alphanumeric Data:
    • First name(s), surname, date of birth, nationality and sex
    • Travel document details (type, number, issuing authority and validity)
    • Three-letter ISO code of the issuing country
    • Date, time and place of entry, exit or refusal of entry
    • Visa number or residence permit data, where applicable
  • Biometric Data:
    • Facial image, which is mandatory for all third-country nationals subject to registration in the EES
    • Fingerprints, which are mandatory for visa-exempt third-country nationals and holders of a Facilitation Transit Document
  • Data Relating To Refusals Of Entry:
    • Authority issuing the refusal
    • Reasons for refusal
  • Administrative Data:
    • Records of the authorities that entered, consulted, modified or erased data
    • Links to previous entries and exits for the purpose of establishing travel history

 

Mandatory Nature Of Data Collection

The collection of personal data for registration in the EES is mandatory for the examination of entry conditions at the external borders of the Schengen Area.

Entry will be refused if a third-country national refuses to provide the required biometric data (facial image and, where applicable, fingerprints) for registration, verification or identification in the EES.

 

Use Of Data For Overstay Detection And Authorised Stay Calculation

EES data is used to calculate the authorised duration of stay of third-country nationals.

Overstays are automatically detected, and where applicable, the individual’s data is added to the list of identified overstayers referred to in Article 12(3) of Regulation (EU) 2017/2226.

Overstaying may result in legal and administrative consequences, including refusal of entry and the initiation of return procedures.

Individuals have the right to receive information on the maximum remaining duration of their authorised stay, in accordance with Article 11(3) of Regulation (EU) 2017/2226.

 

Transfers Of Personal Data

Personal data stored in the EES may be transferred:

  • To third countries or international organisations listed in Annex I to Regulation (EU) 2017/2226 for the purposes of return;
  • To third countries in accordance with Article 41(6) of Regulation (EU) 2017/2226;
  • To other Member States in accordance with Article 42 of Regulation (EU) 2017/2226.

Such transfers take place only under the conditions and safeguards laid down in EU law.

 

Retention Periods

In accordance with Regulation (EU) 2017/2226:

  • Entry and exit data and refusal of entry data are stored for three years from the date of exit or refusal of entry;
  • Where no exit record exists, data is stored for five years from the date of entry;
  • Records relating to non-EU family members of EU, EEA or Swiss nationals entitled to free movement, who do not hold a residence card or residence permit, are stored for one year from the date of exit.
  • After expiry of the applicable retention period, data is automatically erased.

 

Your Rights In Relation To Your Personal Data In The EES

Individuals whose personal data is processed in the EES have the right to:

  • Obtain access to personal data relating to them stored in the EES;
  • Request the rectification of inaccurate personal data;
  • Request the completion of incomplete personal data;
  • Request the erasure of unlawfully processed personal data;
  • Request the restriction of processing, where applicable;
  • Receive information on the procedures for exercising these rights.

Overstayers have the right to request erasure of their personal data from the list of identified persons referred to in Article 12(3) and rectification of EES data, where they provide evidence that the authorised duration of stay was exceeded due to unforeseeable and serious events.

Requests by data subjects may be submitted either to the Malta Police Force or to any national authority having lawful access to the EES, in accordance with Regulation (EU) 2017/2226.

Individuals wishing to exercise their rights through the Malta Police Force are encouraged to use the Model Letters made available to facilitate the submission and handling of such requests.

 

Complaints

Individuals have the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC).

Where applicable, complaints relating to processing carried out at EU level may also be addressed to the European Data Protection Supervisor (EDPS).

The Malta Police Force is the national authority with central responsibility for the European Travel Information and Authorisation System (ETIAS) in Malta.

The National ETIAS Unit, established in accordance with the applicable European Union legal framework, will be hosted within the Malta Police Force and shall perform the functions established by law in relation to ETIAS in Malta.

Starting from the last quarter of 2026, nationals of 59 visa-free countries travelling to Europe for a short stay will be required to obtain a travel authorisation prior to travel to participating European countries.

ETIAS forms part of the European Union’s efforts to strengthen internal security and border management by carrying out pre-travel screening of visa-free travellers to assess whether they may pose a:

  • security risk;
  • irregular migration risk; or
  • high epidemic or public health risk.

ETIAS applies to short stays in participating European countries and does not constitute a visa.

 

Before Travelling

Travellers from visa-free countries falling within the scope of ETIAS will be required to obtain a valid travel authorisation before commencing travel.

ETIAS applications are submitted electronically and assessed against relevant European information systems in accordance with the ETIAS legal framework. Most applications are expected to be processed automatically within minutes, while a limited number may require manual assessment by the competent authorities.

Travellers who are required to hold a valid ETIAS travel authorisation and fail to do so may be refused boarding by the carrier, including airlines, ferry operators, or bus companies.

Further information regarding who requires ETIAS, how to apply, and how the system operates may be accessed through the official European Union ETIAS webpages.

 

At The Border

Upon arrival at the external border of a participating European country, travellers may be subject to border checks in accordance with applicable European Union and national legislation.

Where applicable, border authorities may electronically verify whether a traveller holds a valid ETIAS travel authorisation and whether all other entry conditions are fulfilled.

In Malta, border control functions are carried out under the responsibility of the Principal Immigration Officer, in accordance with the applicable legal framework.

Possession of a valid ETIAS travel authorisation does not automatically guarantee entry, as the final decision regarding admission into the territory remains subject to compliance with all applicable entry conditions under law.

 

Malta’s National ETIAS Framework

At national level, ETIAS responsibilities in Malta will be exercised in accordance with the applicable European Union and national legal framework.

The National ETIAS Unit, which processes applications in Malta, will be hosted within the Malta Police Force. The latter is designated as the national authority with central responsibility for ETIAS in Malta.

In addition, the Malta Police Force shall act as the Central Access Point for access to personal data stored in ETIAS for law enforcement purposes, in accordance with the conditions and safeguards established by law.

Other Maltese competent authorities may also be granted access to ETIAS where authorised by law and formally designated for specific purposes established under the applicable legal framework.

These may include, for example:

  • border control authorities;
  • immigration authorities;
  • law enforcement authorities; and
  • other designated competent authorities.

At present, the formal designation or recognition of all competent Maltese authorities having access to ETIAS is still subject to the applicable legal and institutional framework and may be updated at a later stage.

 

Refusal, Revocation Or Annulment Of An ETIAS Travel Authorisation

Where an ETIAS application is refused, or a travel authorisation is revoked or annulled, the applicant will receive a notification indicating:

  • the grounds for the decision;
  • the authority responsible for taking the decision; and
  • information regarding the available appeal procedure.

Applicants have the right to appeal decisions refusing, revoking, or annulling an ETIAS travel authorisation.

Appeals are handled in accordance with the national law of the European country that took the decision.

Where a travel authorisation is revoked at the request of the traveller, no right of appeal shall apply.

Further information regarding appeals and ETIAS procedures is available through the official European Union ETIAS webpages.

 

Data Protection And Your Rights

Personal data processed within ETIAS is protected in accordance with applicable European Union and national data protection legislation.

The processing of personal data within ETIAS is subject to strict safeguards, access controls, and legal limitations.

 

Controllers Of Personal Data

Personal data contained in ETIAS may be processed by the Malta Police Force, including the National ETIAS Unit, and by other competent Maltese authorities authorised by law to access ETIAS, strictly within the limits established by law.

Each competent authority accessing ETIAS acts independently and processes personal data only for the purposes for which it has lawful access.

Accordingly, each authority acts as controller only in relation to personal data processed by that authority within ETIAS.

The Malta Police Force, including the National ETIAS Unit hosted within it, does not automatically act as controller for all personal data processed within ETIAS by other competent Maltese authorities.

Likewise, competent Maltese authorities may only act upon requests concerning personal data where they have processed such data and act as controller in respect of the relevant processing activity.

Maltese authorities cannot grant access to, rectify, complete, erase, restrict, or otherwise act upon personal data processed within ETIAS where they have not processed such data and do not act as controller in relation to that processing.

 

Your Rights

Subject to the applicable legal framework and any lawful restrictions provided by law, individuals whose personal data is processed in ETIAS may exercise, where applicable, the following rights:

  • the right to information regarding the processing of personal data;
  • the right of access to personal data;
  • the right to request rectification of inaccurate personal data;
  • the right to request completion of incomplete personal data;
  • the right to request erasure of unlawfully processed personal data, where applicable;
  • the right to request restriction of processing, where applicable;
  • the right to an effective judicial remedy; and
  • the right to lodge a complaint with the competent supervisory authority.

 

How To Exercise Your Rights

Requests concerning personal data processed within ETIAS may be submitted:

  • to the Malta Police Force, including the National ETIAS Unit, where the Malta Police Force processed the relevant personal data and acts as controller; or
  • directly to the competent Maltese authority that processed the personal data and acts as controller in relation to the relevant processing activity.

Where a Maltese authority has not processed the relevant personal data and does not act as controller, that authority cannot act upon the request.

Where appropriate, applicants may be directed to the competent authority responsible for the relevant processing.

 

Timeframe For Responding To Requests

Competent authorities shall respond to ETIAS-related requests without undue delay and, in any event, within one month from receipt of the request, in accordance with the ETIAS legal framework.

Certain rights may be restricted in accordance with applicable law where necessary and proportionate to safeguard public security, border management, or the prevention, detection, investigation, or prosecution of criminal offences.

 

Complaints And Remedies

If you are not satisfied with how your request has been handled, you may lodge a complaint with the competent supervisory authority or seek an effective judicial remedy in accordance with applicable law.

 

Legal Framework

ETIAS in Malta is governed by applicable European Union and national legislation, including, but not limited to:

  • Regulation (EU) 2018/1240 establishing a European Travel Information and Authorisation System (ETIAS);
  • the Immigration Act;
  • applicable subsidiary legislation implementing European Union obligations;
  • legislation governing border management, immigration, law enforcement access, and data protection; and
  • any other applicable national or European Union legal instruments.

Introduction

EURODAC is a European Union (EU) information system established under Regulation (EU) 2024/1358 of the European Parliament and of the Council of 14 May 2024 on the establishment of ‘Eurodac’ for the comparison of biometric data, which repealed Regulation (EU) No 603/2013.

EURODAC enables participating States to compare biometric data and other relevant information in order to support the effective application of the European Union asylum and migration framework, including:

  • determining the Member State responsible for examining an application for international protection;
  • supporting the implementation of asylum and migration management procedures;
  • identifying illegally staying third-country nationals and stateless persons;
  • facilitating procedures related to resettlement, humanitarian admission and temporary protection;
  • supporting the protection of children and vulnerable persons; and
  • enabling, under strictly regulated circumstances, access by designated law enforcement authorities and the European Union Agency for Law Enforcement Cooperation (Europol) for the prevention, detection and investigation of terrorist offences and other serious criminal offences.

EURODAC operates through a Central System containing the database and a secure communication infrastructure connecting participating States through a dedicated encrypted network.

This notice explains how personal data is processed by the Malta Police Force (MPF), through its Eurodac Office, in connection with the EURODAC system and informs you of your rights under applicable data protection legislation.

 

Role of the Malta Police Force and Scope of Responsibility

In Malta, the authority designated to access and process data within the EURODAC system is the Eurodac Office within the Malta Police Force.

The Malta Police Force, through its Eurodac Office, is responsible solely for the processing of personal data relating to Malta’s operation and use of the EURODAC system, in accordance with Regulation (EU) 2024/1358 and applicable national legislation.

 

Important Clarification Regarding Asylum Applications

The Malta Police Force is not responsible for the processing of personal data carried out in the context of asylum or international protection procedures generally, except insofar as personal data is processed within the EURODAC system.

Accordingly, where a request concerns personal data processed in relation to an asylum or international protection application other than personal data processed in EURODAC, such requests should be addressed to the competent authority responsible for asylum matters in Malta, namely the International Protection Agency (IPA).

 

What is EURODAC?

EURODAC is a European database used by participating States to store and compare biometric data, namely fingerprints and facial image data, together with other information relating to specific categories of third-country nationals and stateless persons.

EURODAC supports the implementation of:

  • Regulation (EU) 2024/1351;
  • Regulation (EU) 2024/1350; and
  • Council Directive 2001/55/EC.

EURODAC may be used in relation to the following categories of persons, as provided under Regulation (EU) 2024/1358:

  • persons applying for international protection;
  • persons apprehended in connection with the irregular crossing of an external border;
  • persons found illegally staying in a Member State;
  • persons disembarked following search and rescue operations at sea;
  • persons arriving through resettlement or humanitarian admission procedures;
  • persons benefitting from temporary protection;
  • persons subject to return procedures, where provided by law.

Biometric data may be collected and processed in relation to persons aged six (6) years and over, in accordance with the applicable legal framework.

EURODAC is accessible by the 27 Member States of the European Union, together with Iceland, Norway, Liechtenstein and Switzerland.

 

Legal Basis

The processing of personal data within the EURODAC system is carried out in accordance with:

  • Regulation (EU) 2024/1358 of the European Parliament and of the Council of 14 May 2024 on the establishment of EURODAC;
  • Regulation (EU) 2024/1351;
  • Regulation (EU) 2024/1350;
  • Council Directive 2001/55/EC;
  • Regulation (EU) 2016/679 (General Data Protection Regulation), where applicable; and/or
  • Directive (EU) 2016/680 and applicable national legislation governing processing by competent authorities for law enforcement purposes.

Where personal data is processed for law enforcement access to EURODAC, processing is subject to the specific safeguards, limitations and conditions established by Regulation (EU) 2024/1358.

 

Categories of Personal Data Processed

Depending on the category of person concerned and the applicable legal framework, the following categories of personal data may be processed within EURODAC.

 

Biometric Data

  • fingerprints;
  • facial image data.

 

Identification and Administrative Data

Depending on the applicable category, EURODAC may process:

  • Member State of origin;
  • place and date of registration, application, apprehension or relevant event;
  • sex;
  • nationality, where applicable;
  • reference number used by the Member State;
  • date on which biometric data was taken;
  • date on which data was transmitted to the Central System;
  • operator user identification number;
  • information relating to international protection, return, relocation, resettlement, humanitarian admission or temporary protection status, where applicable under law.

The exact categories of data processed depend on the legal category applicable to the person concerned and the requirements of Regulation (EU) 2024/1358.

 

Purpose of Processing

Personal data processed within EURODAC may be used for the following purposes:

 

International Protection and Migration Purposes

To:

  • assist in determining the Member State responsible for examining an application for international protection;
  • support the implementation of asylum and migration procedures;
  • support migration management and responsibility allocation between Member States;
  • identify illegally staying third-country nationals and stateless persons;
  • support relocation, resettlement and humanitarian admission procedures;
  • support temporary protection mechanisms;
  • protect children and vulnerable persons, including facilitating tracing where permitted by law;
  • support return-related procedures where authorised by law.

 

Law Enforcement Purposes

Under strictly regulated circumstances, designated law enforcement authorities and Europol may request comparison of EURODAC data where this is necessary for the prevention, detection or investigation of terrorist offences or other serious criminal offences.

Such access is permitted only where all legal conditions are fulfilled, including strict safeguards, necessity and proportionality requirements, and prior verification procedures established by law.

 

Retention of Data

The retention period applicable to personal data depends on the category under which data is recorded in EURODAC and the requirements of Regulation (EU) 2024/1358.

 

Applicants for International Protection

Personal data relating to applicants for international protection shall be retained in EURODAC for ten (10) years from the date on which biometric data is taken.

Data shall be erased before expiry of this period where:

  • the person concerned acquires citizenship of a Member State; or
  • erasure is otherwise required by law.

Where international protection is granted, the relevant data may be marked in accordance with Regulation (EU) 2024/1358.

 

Persons Apprehended in Connection with the Irregular Crossing of an External Border

Personal data relating to persons apprehended in connection with the irregular crossing of an external border shall be retained for five (5) years.

Data may be erased before expiry where legally required, including where the person concerned acquires citizenship of a Member State.

 

Persons Found Illegally Staying in a Member State

Personal data relating to persons found illegally staying in a Member State shall be retained for three (3) years, in accordance with Regulation (EU) 2024/1358.

 

Persons Disembarked Following Search and Rescue Operations at Sea

Personal data relating to persons disembarked following rescue operations at sea shall be retained for five (5) years, unless erased earlier in accordance with law.

 

Persons Admitted Through Resettlement or Humanitarian Admission Procedures

Personal data relating to persons admitted through resettlement or humanitarian admission procedures shall be retained for ten (10) years, unless erased earlier in accordance with law.

 

Persons Benefitting from Temporary Protection

Personal data relating to persons benefitting from temporary protection shall be retained for the duration provided by the applicable legal framework governing temporary protection and EURODAC.

 

Your Rights

Subject to the applicable legal framework and any lawful restrictions provided by legislation, you have the right to:

  • request access to personal data relating to you processed within the EURODAC system;
  • request correction of inaccurate or incomplete personal data;
  • request deletion of unlawfully processed or unlawfully stored personal data;
  • request restriction of processing in circumstances provided by law;
  • request verification of the lawfulness of processing; and
  • lodge a complaint with the national supervisory authority.

Where necessary to verify your identity and locate your EURODAC data, you may be requested to physically attend the Eurodac Office for biometric verification purposes. Any biometric data taken solely for verification purposes shall not be retained unless otherwise authorised by law.

 

How to Exercise Your Rights

Requests relating to personal data processed by the Malta Police Force within the EURODAC system may be submitted to the Eurodac Office or to the Data Protection Officer of the Malta Police Force.

To facilitate the exercise of these rights and enable the efficient handling of requests, data subjects are encouraged to make use of the model letters available on the Malta Police Force website by clicking here.

Requests concerning asylum or international protection case files, other than personal data processed in the EURODAC system, should be addressed to the competent authority responsible for asylum matters in Malta, namely the International Protection Agency (IPA).

 

Contact Details

Eurodac Office

Malta Police Force General Headquarters
St. Calcedonius Square
Floriana FRN 1530
Malta

Email: [email protected]

 

Data Protection Officer

Malta Police Force General Headquarters
St. Calcedonius Square
Floriana FRN 1530
Malta

Email: [email protected]

 

Right to Lodge a Complaint

If you believe that your personal data has been processed unlawfully or in breach of applicable data protection legislation, you may lodge a complaint with the national supervisory authority:

 

Information and Data Protection Commissioner (IDPC)

 

Further Information

This notice relates solely to the processing of personal data by the Malta Police Force in connection with the EURODAC system.

For information concerning the processing of personal data in the context of an asylum or international protection application, other than EURODAC processing, please contact the International Protection Agency (IPA).

What Are Hand-Held Speed Cameras (HSC)s?
 
Hand-Held Speed Cameras (HSCs) are gun-shaped technology devices that assist the operator to accurately determine the speed by which an object is moving. The Police make use of such devices in order to ensure that any proceedings instituted against an offender are based on reliable and accurate evidence.
 
 
When And Why Are Such Devices Ised?
 
The Police use such devices in cases where reasonable suspicion exists that a vehicle is driving with a speed beyond the set limit. This allows the Police to capture and preserve evidence that an offence has been committed.
 
 
How Are They Operated?
 
When, having regard to the circumstances, it appears to a Police Officer that a motor vehicle is moving with a speed beyond that established by law, the officer operating a HCSs pulls the trigger of the HSC to activate the device. A signal is emitted in the form of a straight laser beam. The officer points the device towards the fast-moving motor vehicle. If the signal hits a motor vehicle that is moving with a speed in excess to the set limit, the capturing function of the device is activated, and it starts capturing a series of frames and the relative speed. It is only if the vehicle is exceeding the set speed limit that it activates. Hence, no information is captured if the vehicle is not exceeding the set limit.
 
 
What Happens Next?
 
Once the reasonable suspicion of the Police has been verified, and therefore the Police has confirmation that an offence has been committed, the Police initiate proceedings against the offender. The owner of the vehicle is notified of the contravention according to law, and captured pertinent information is uploaded on the Law Enforcement System which is accessible by the offender over the web (les.gov.mt). In cases where the incident involves a more serious offence, proceedings are taken according to law in the circumstances.
 
 
Is The Use Of HSCs Regulated Ny Law?
 
The use of HSCs is based on Regulation 127 of the Motor Vehicles Regulations (S.L. 65.11 of the Laws of Malta) which establishes the framework for the different types of speed monitoring devices that may be employed. The HSCs used by the Police have been prescribed by the Minister responsible for Transport as indicated in the Government Gazettes No. 20,443 and No. 20,440 of 14 and 17 July 2020 respectively. They are calibrated biannually in accordance with the provisions of the Measurements Subject to Metrological Control Regulations (S.L. 454.17 of the Laws of Malta).
 
 
Legal Basis
 
The processing of personal data captured via HSCs is based on various legal provisions:
 
  • It is the duty of the Police to preserve public order and peace, to prevent and to detect and investigate offences, to collect evidence, whether against or in favour of the person suspected of having committed the offence, and to bring the offenders, whether principals or accomplices, before the judicial authorities in terms of Article 346(1) of the Criminal Code (Chapter 9 of the Laws of Malta).
  • Article 62(1) of the Police Act specifically empowers the Police to hold, process and classify any information relevant to the commission of any crime in or outside Malta which information may be preserved by any system whatsoever, including electronic format.
  • Regulation 127 of the Motor Vehicles Regulations (S.L. 65.11 of the Laws of Malta) sets the speed limit for motor vehicles and provides for the use of HSCs.
  • Moreover, the Malta Police Force, may collect personal data by technical surveillance or other automated means for the prevention, investigation, detection and prosecution of criminal offices in terms of Regulation 8(3) of S.L. 586.08.
 
Personal Data Captured By HSCs
 
The categories of personal data captured by HSCs is limited to images of the motor vehicle, which includes its registration plate, speed, location and time.
 
 
Disclosure Of Data Captured By HSCs
 
Data captured by HSCs will be used as for the issuing of traffic contraventions that are tried in the Local Tribunals. To that purpose, pertinent information is uploaded on the Law Enforcement System that is accessible by the offender over the web. In those cases that involve other more serious offences, the data is used as evidence before the Court before which proceedings are taken.
 
There may be instances where such data will be made available to foreign Law Enforcement Authorities, particularly Law Enforcement Authorities in other Member States, in pursue of a legal obligation or a bilateral agreement within the context of Police Cooperation.
 
 
Retention Period
 
Data collected from HSCs are generally kept for 2 years from the determination of the case. This is subject to longer periods, as established in the Data Retention Schedule, should the case involve more serious offences. Data will be disposed of accordingly once the relevant retention period expires.
 
 
What Are Your Rights In Relation To Your Personal Data Captured By HSCs?
 
The processing of personal data collected via HSCs is regulated by the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations (S.L. 586.08).
 
Any person has the right to:
 
  • request access to personal data relating to them processed by HSCs;
  • request the correction of factually inaccurate personal data relating to them or the;
  • deletion of their personal data in the case of unlawfully processed information;
  • request restriction of processing of their personal data according to law;
  • the right to lodge a complaint with the Information and Data Protection Commissioner.
 
The PNR/API System is an integrated system that processes:
 
  • information provided by passengers and collected by airlines, in the normal course of their business, for enabling reservations and carrying out the check-in process, known as Passenger Name Record (PNR), and

 

  •  Advanced Passenger Information (API) data, which is sent by air carriers upon departure, operating inbound Extra-Schengen flights to Malta.
 
The Passenger Information Unit (PIU) within the Malta Police Force, under the Organized Crime wing, is responsible for operating the PNR/API System. It is mainly responsible to:
 
  1. Collect the API and PNR data from air carriers;
  2. Carry out an assessment of passengers prior to their scheduled arrival in or departure from Malta, by comparing API and PNR data against relevant databases, such as the Schengen Information System (SIS) and the National Stop List (NSL), and process them against pre-determined criteria, in order to identify persons that may be involved in a terrorist offence or serious crime1, or that are hindered from entering the Schengen Area;
  3.  Inform and disseminate PNR and API data to the competent national authorities, Europol and PIUs of other Member States, as the case may be, either spontaneously or in response to duly reasoned requests.
The received data is compared against a watchlist implemented within the system with details of persons suspected of being involved in a terrorist offence or serious crime that has been provided by the competent authorities.
 
Risk based profiles have also been introduced, whereby upon matching with several selected criteria, passengers are automatically flagged.
 
Legal Basis
 
The processing of PNR data and API is conducted under an obligation imposed by different legislative instruments of the European Union. The relative two legal instruments are:
 
  • The Passenger Name Record (PNR) Data Act (Chapter 584 of the Laws of Malta), which implements Directive (EU) 2016/681 of the European Parliament and of the Council of 27 April 2016 on the use of passenger name record (PNR) data for the prevention, detection, investigation and prosecution of terrorist offences and serious crime;
  • The Communication of Passenger Data by Air or Sea Carriers Order (Subsidiary Legislation 460.18), which implements Council Directive 2004/82/EC of 29 April 2004 on the obligation of carriers to communicate passenger data.
 
Personal Data Processed In The API System
 
API data is collected by air carriers operating a flight to Malta from a third country and is transmitted electronically to the PNR/API System by the time of the closure of check-in in terms of Regulation 3 of Subsidiary Legislation 480.18.
 
Such data consists of:
 
  1. the number and type of travel document used;
  2. nationality;
  3. full names;
  4. the date of birth;
  5. the border crossing point of entry into the territory of Malta;
  6. code of transport;
  7. departure and arrival time of the transportation;
  8. total number of passengers carried on that transport; initial point of embarkation.
 
Personal Data Processed In The PNR System
 
PNR data is more informative in comparison to API and is considered to be an investigative tool, whereas same is received from air carriers operating both Intra and Extra-Schengen and inbound and outbound flights. Same is automatically sent by air carriers upon two push methods:
 
  • 24 hours prior departure
  • Upon departure
 
Such data consists of:
  1. PNR record locator
  2. Date of reservation/issue of ticket
  3. Date(s) of intended travel
  4. Name(s)
  5. Address and contact information (telephone number, e-mail address)
  6. All forms of payment information, including billing address
  7. Complete travel itinerary for specific PNR
  8. Frequent flyer information
  9. Travel agency/travel agent
  10. Travel status of passenger, including confirmations, check-in status, no-show or go-show information
  11. Split/divided PNR information
  12. General remarks (including all available information on unaccompanied minors under 18 years, such as name and gender of the minor, age, language(s) spoken, name and contact details of guardian on departure and relationship to the minor, name and contact details of guardian on arrival and relationship to the minor, departure and arrival agent)
  13. Ticketing field information, including ticket number, date of ticket issuance and one-way tickets, automated ticket fare quote fields
  14. Seat number and other seat information
  15. Code share information
  16. All baggage information
  17. Number and other names of travellers on the PNR
  18. Any Advance Passenger Information (API) data collected (including the type, number, country of issuance and expiry date of any identity document, nationality, family name, given name, gender, date of birth, airline, flight number, departure date, arrival date, departure port, arrival port, departure time and arrival time)
  19. All historical changes to the PNR listed in numbers 1 to 18.
 
Disclosure Of API And PNR Data
 
API and PNR data may be requested by the following competent authorities for the prevention, investigation and prosecution of serious crimes:
 
  • Malta Police Force
  • Principal Immigration Officer
  • Malta Security Services
  • Financial Investigation and Analysis Unit
  • Customs Department
  • Judicial authorities
  • Europol
  • PIUs in other Member States
  • Competent authorities in Third countries
 
Retention Period
 
In terms of Article 13 of the Passenger Name Record (PNR) Data Act, all data in the PNR/API System are kept for period of five years. However, after six months from collection, all data are depersonalised by masking, and disclosure of such data to the competent authorities takes place only upon the approval of a judicial authority or of the Information and Data Protection Commissioner.
 
What Are Your Rights In Relation To Your Personal Data Processed In The PNR/API System?
 
Personal data processed within the context of the PNR and API framework is regulated by the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties) Regulations (Subsidiary Legislation 586.08) and the GDPR2 when the processing is conducted for other purposes.
 
Any person has the right to:
 
  • request access to personal data relating to them stored in the PNR/API System;
  • request the correction of factually inaccurate personal data relating to them or the deletion of their personal data in the case of unlawfully stored information;
  • request restriction of processing of their personal data according to law;
  • the right to lodge a complaint with the Information and Data Protection Commissioner (IDPC) or to request verification of lawfulness of the processing.
 
In order to facilitate the exercise of your rights and to be able to handle request more efficiently, you are solicited to use the following model letters.
 
1 The categories of serious crimes in relation of which PNR data may be disclosed is listed under Schedule C to  CAP.584, where such crimes are punished by a custodial sentence or a detention order for a maximum period of at least three years.
 
2 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)
The SIS is the most widely used and largest information sharing system for security and border management in Europe that allows the competent authorities of participating Member States to enter and consult alerts on persons or objects.
 
In March 2023 a new legal framework came into force. The SIS is composed of a central system (“Central SIS II”), a national system (the “N.SIS II”) in each Member State (the national data systems that will communicate data with the Central SIS II), and a communication infrastructure between the central system and the national systems providing an encrypted virtual network dedicated to SIS II data and the exchange of data, including supplementary information between the authorities responsible for similar data exchanges (SIRENE Bureaux).
 
The system establishes communication amongst most EU member states and the Schengen associated countries and provides end-users with access to real time information. It is a vital factor in the smooth running of the Schengen area. It contributes to the implementation of the provisions on returns, border control, the free movement of persons and to police and judicial cooperation in criminal matters.
 
Legal Basis
 
The system assists the competent authorities in Europe to preserve internal security in the absence of internal border checks. The scope of SIS is defined in three legal instruments:
 
  • Regulation (EU) 2018/1860 of the European Parliament and of the Council of 28 November 2018 on the use of the Schengen Information System for the return of illegally staying third-country nationals
  • Regulation (EU) 2018/1861 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of border checks, and amending the Convention implementing the Schengen Agreement, and amending and repealing Regulation (EC) No 1987/2006
  • Regulation (EU) 2018/1862 of the European Parliament and of the Council of 28 November 2018 on the establishment, operation and use of the Schengen Information System (SIS) in the field of police cooperation and judicial cooperation in criminal matters, amending and repealing Council Decision 2007/533/JHA, and repealing Regulation (EC) No 1986/2006 of the European Parliament and of the Council and Commission Decision 2010/261/EU
 
Personal Data Processed In The SIS
 
Pursuant to the provisions of the SIS legal framework, information in the form of alerts concerning persons, objects, vehicles and documents is processed. When the alert concerns a person, the information includes:
 
  • Identification data: Data required to identify the person sought and other information relevant for the end user carrying out a search. The alert may also include data on misused identity victims (where applicable).
  • Identification documents: Data describing the identification document of the person who is the subject of the alert – a copy of the document can be attached.
  • Alert reason: A ‘reason for the alert’, describing, in a structured way, why the person is sought.
  • Required action: An ‘action to be taken’, describing, in a structured way, what the officer must do when the person is found.
  • Case information: Information about the case e.g., authority authorising the entry of the alert, the case reference number etc.  The copy of the European Arrest Warrant (EAW) of a person wanted for arrest is also attached to alerts for arrest for surrender.
  • Information on objects related to persons: Data on objects entered in SIS to locate a person who is the subject of an alert, for example the vehicle used by the person sought.
  • Photographs: Photographs of the person who is the subject of the alert.
  • Fingerprints and palm prints: Dactyloscopic data (fingerprints and/or palm prints) for the person who is the subject of the alert.
  • Fingermarks and palmmarks: Dactyloscopic data (fingermarks and/or palmmarks) discovered at crime scenes.
  • DNA profile: DNA profile of the person who is the subject of the alert or family members (only in case of missing persons who need to be placed under protection).
 
The SIS legal framework lays down the reasons where an alert containing personal data may be issued on the system, with respect to different categories of persons. 
 
Such are retained until the purpose for which they were issued is fulfilled. Nevertheless, Member States are obliged to review the need to keep an alert periodically.
 

List Of Alerts And The Respective Periodic Review Period:

Regulation (EU) 2018/1860

Type of Alert

Article No.

Review Period

Alerts in respect of third-country nationals subject to return decisions issued by the Schengen countries (Return decisions).

Article 3

3 Years

Regulation (EU) 2018/1861

Type of Alert

Article No.

Review Period

Alerts on third-country nationals who may not enter or stay in the Schengen Area (Refusal of entry or stay).

Articles 24, 25 and 26

3 Years

Regulation (EU) 2018/1862

Type of Alert

Article No.

Review Period

Alerts on persons who are subject to a European Arrest Warrant or other warrant for surrender (Norway and Iceland)/Extradition Request (Switzerland and Liechtenstein) (Persons wanted for arrest).

Article 26

5 Years

Alerts to find missing persons, including children, and to place them under protection if lawful and necessary (Missing persons).

Points (a) and (b) of Article 32(1)

5 Years

Alerts to find out the place of residence or domicile of persons sought to assist with criminal judicial procedures (for example witnesses, persons summoned to appear in Court or who are to be served with a criminal judgment or serve a penalty involving deprivation of liberty) (Persons sought to assist with a judicial procedure).

Articles 34

3 Years

Alerts for the identification of unknown persons wanted in relation to terrorist offences or other serious crimes under investigation (Unknown wanted persons).

Article 40

3 Years

Alerts to prevent children at risk from being abducted or going missing (Children at risk of being abducted by parents, relatives, or guardians).

Points (c) of Article 32(1)

1 Year

Alerts for the protection of vulnerable people (adults or children) from being taken unlawfully abroad or to prevent them from travelling without the necessary authorisations (Vulnerable persons whose travel must be prevented).

Points (d) and (e) of Article 32(1)

1 Year

Alerts to obtain information on persons or related objects for the purposes of prosecuting criminal offences and for the prevention of threats to public or national security (Persons and objects for discreet, inquiry or specific checks).

Article 36

1 Year

Alerts on objects (for example vehicles, travel documents, number plates and industrial equipment) being sought for seizure or use as evidence in criminal proceedings, and Alerts on travel documents for preventing the holders of such documents from travelling (Objects for seizure or use as evidence in criminal procedures).

Articles 36 and 38

10 Years

Articles 26, 32, 34, and 36 (If linked to an alert on a person)

The same review period of the linked alert on the person

 

What Are Your Rights In Relation To Your Personal Data Processed In The SIS?

The SIS legal framework lays down the rights of persons in relation to the personal data processed in the system and which could be exercised in accordance with the national law of the respective country. In Malta, the applicable laws are the Data Protection (Processing of Personal Data by Competent Authorities for the Purposes of the Prevention, Investigation, Detection or Prosecution of Criminal Offences or the Execution of Criminal Penalties).
 
​Regulations (Subsidiary Legislation 586.08) and the GDPR when the processing is conducted for other purposes.
 
 
Any person has the right to:
 
  • request access to personal data relating to them entered in the SIS;
  • request the correction of factually inaccurate personal data relating to them or the deletion of their personal data in the case of unlawfully stored information;
  • the right to lodge a complaint with the Information and Data Protection; Commissioner (IDPC) or to request verification of lawfulness of the processing.
 
In order to facilitate the exercise of your rights and to be able to handle your request more efficiently, you are solicited to use the following online form. Once the form is completed, you will be sent a confirmation email that your request has been received and is being vetted. A final response will then be sent to you via email. Otherwise, you may also use the following model letters.