Data Protection Act (Cap. 586)
Data Protection Act (Cap. 586), article 9
9. (1) Personal data processed for the purpose of
exercising the right to freedom of expression and information,
including processing for journalistic purposes or for the purposes of
academic, artistic or literary expression, shall be exempt from
compliance with the provisions of the Regulation specified in s ub-
article (2) where, having regard to the importance of the right o f
freedom of expression and inform ation in a democratic society,
compliance with any of the provisions as specified in sub-artic le (2)
would be incompatible with s uch processing purposes:
Provided that when reconciling the right to the
protection of personal data with the right to freedom of expres sion
and information, the controller sh all ensure that the processin g is
proportionate, necessary and justif ied for reasons of substanti al
public interest.
(2) For the purposes of the provisions of sub-article (1), the
provisions of the following chapters of the Regulation may be
exempted or derogated therefrom pursuant to Article 85(2) of the said
6 [CAP. 586. DATA PROTECTION
Regulation:
(a) Chapter II (Principles):
(i) Article 5(1)(a) to (e) (principles relating
to processing);
(ii) Article 6 (lawfulness);
(iii) Article 7 (conditions for consent);
(iv) Article 10 (data relating to criminal
convictions, etc);
(v) Article 11(2) (processing not requiring
identification);
(b) Chapter III (rights of the data subject):
(i) Article 13(1) to (3) (personal data
collected from data subject: information to be provided);
(ii) Article 14(1) to (4) (personal data
collected other than from data subject);
(iii) Article 15(1) to (3) (access to data and
safeguards for third country transfers);
(iv) Article 17(1) and (2 ) (right to erasure);
( v) Ar ticle 18( 1) (a ) , ( b) a nd ( d) (r e str ict ion
of processing);
(vi) Article 20(1) and (2) (right to data
portability);
(vii) Article 21(1) (objections to processing);
(c) Chapter IV (controller and processor):
(i) Article 25 (data protection by design and
by default);
(ii) Article 27 (representatives of controllers
or processors not established in the Union);
(iii) Article 30 (records of processing
activities);
(iv) Article 33 (notification of personal data
breach to supervisory authority);
(v) Article 34 (communication of personal
DATA PROTECTION [CAP. 586. 7
data breach to the data subject);
(vi) Article 42 (certification);
(vii) Article 43 (certification bodies);
(d) Chapter VII (co-opera tion and consistency):
(i) Articles 60 to 62 (co-operation);
(ii) Articles 63 to 67 (consistency).
PART IV
Transborder Data Transfers
Limits to
transborder data
transfers.
Text read from the consolidated PDF published by Legislation Malta. Tables, figures and marginal notes may be incomplete or out of place: the official PDF is authoritative. General information, not legal, tax or accounting advice.