top of page

Privacy Policy - Malta Business Wallet

Version 1.0.

Last updated 14th May 2026

 

1.0. INTRODUCTION

 

Welcome to the Malta Business Registry’s (“MBR”, “Controller”) Privacy Policy relating to the provision of the Services provided via the Malta Business Wallet, a software application which you can download and install onto your mobile device and/or access via any related website, sub-website and/or associated domains (and/or sub-domains) under which the services of the Malta Business Wallet may be offered (“MBW”, “Software”), where Personal Data is processed by the same relating to you.

 

This Privacy Policy supplements the MBRs Master Privacy Policy which may be accessed via https://mbr.mt/privacy-policy/. Whilst the storage, collection and other related processing activities relating to the Personal Data stored on the Software is dictated by this Privacy Policy, when the user of the Software decides to share documentation and/or reports he may have uploaded or generated through the Software with the MBR (as explained in this Privacy Policy), that Personal Data will be processed by the MBR in accordance with its Master Privacy Policy.

 

MBR respects your privacy and is committed to protecting your Personal Data and processing it in compliance with any applicable data protection legislation. As a Government agency established in Malta, EU, the main privacy laws that are applicable to us in so far as you are concerned, are as follows:

 

  • The Maltese Data Protection Act (Chapter 586 of the Laws of Malta) as well as the various subsidiary legislation issued under the same (the “DPA”); and

  • The Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of Personal Data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (the “GDPR”).

All the above, as may be amended from time to time, referred to together as the “Applicable Data Protection Laws”. 

 

2.0. SUMMARY AND CONTENTS OF THIS PRIVACY POLICY

 

In summary of this Privacy Policy we think that the following information is the most relevant for you:

 

  • Purpose of processing: Primarily, we process your personal data for the purpose of providing you with our services, to allow your access and use of the Software, and to comply with our legal obligations;

  • Controller: When processing your Personal Data, MBR acts as a controller;

  • Your rights: You have a number of rights afforded by applicable laws. When we process your data on the basis of your consent, you can withdraw it at any time. You also have a right to request access to all of the personal data that is undergoing processing and a right to erasure of the data that are no longer necessary; and

  • Implications of processing: Processing of personal data will result in the provision of services (or denial thereof of part or the entire use of the Software if certain data is not provided).

 

We however recommend that you read this Privacy Policy in full, with care. For the ease of your understanding, these are the contents of this Privacy Policy:

 

1.0. INTRODUCTION

2.0. SUMMARY AND CONTENTS OF THIS PRIVACY POLICY

3.0. IMPORTANT INFORMATION AND WHO WE ARE

3.1. PURPOSE OF THIS PRIVACY POLICY

3.2. CONTROLLER

3.3. CONTROLLER’S CONTACT DETAILS

3.4. CHANGES TO THE PRIVACY POLICY AND OUR DUTY TO INFORM YOU OF CHANGES

4.0. THE PERSONAL DATA WE COLLECT ABOUT YOU

4.1. WHAT IS PERSONAL DATA?

4.2. WHAT ABOUT INFORMATION RELATING TO COMMERCIAL PARTNERSHIPS AND LEGAL ENTITIES?

4.3. DATA WE COLLECT ABOUT YOU

4.4. PERSONAL DATA RELATING TO THIRD PARTIES

4.5. SPECIAL CATEGORIES OF PERSONAL DATA

4.6. IF YOU FAIL TO PROVIDE PERSONAL DATA

5.0. WHY AND HOW WE USE YOUR PERSONAL DATA

5.1. WHY WE USE YOUR PERSONAL DATA

5.2 DETAILED PURPOSES AND LEGAL BASIS

6.0. RETENTION

7.0. RECIPIENTS OF YOUR PERSONAL DATA

7.1. DETAILS ON THE CATEGORIES OF RECIPIENTS OF THE PERSONAL DATA

7.2. AUTHORISED DISCLOSURE

8.0. DATA ACCURACY

9.0. INTERNATIONAL TRANSFERS

10.0. DATA SECURITY

11.0. YOUR RIGHTS UNDER THE DATA PROTECTION LAWS

11.1. YOUR RIGHT OF ACCESS

11.2. THE RIGHT TO RECTIFICATION

11.3. THE RIGHT TO ERASURE (THE RIGHT TO BE FORGOTTEN)

11.4. THE RIGHT TO DATA RESTRICTION

11.5. THE RIGHT TO DATA PORTABILITY

11.6. THE RIGHT TO OBJECT TO CERTAIN PROCESSING

11.7. RIGHT TO WITHDRAW CONSENT (WHEN WE PROCESS YOUR DATA ON THE BASIS OF CONSENT)

11.8. THE RIGHT TO LODGE A COMPLAINT

11.9. WHAT WE MAY NEED FROM YOU

11.10. TIME LIMIT TO RESPOND

12.0. AUTOMATED PROCESSING

13.0. COOKIES


 

 

3.0. IMPORTANT INFORMATION AND WHO WE ARE

 

3.1. PURPOSE OF THIS PRIVACY POLICY

 

This Privacy Policy aims to give you information on how we collect and process your personal data through or in conjunction with your use of the Software.

 

This Privacy Policy stipulates details and conditions of collecting and processing your Personal Data and provides you with information in accordance with the transparency principle and requirements under the Applicable Data Protection Laws.

 

3.2. CONTROLLER

 

The Malta Business Registry is a Government Agency registered in Malta whose address is Malta Business Registry, AM Business Centre, Triq il-Labour, Zejtun ZTN 2401, Malta and is the data controller responsible for processing your Personal Data that takes place via the Software.

 

3.3. CONTROLLER’S CONTACT DETAILS

 

Although our goal is to always be as clear and transparent as possible, if you need any clarification on this Privacy Policy or a specific legal basis we are relying on to process your Personal Data for a specific processing operation, we would be happy to provide you with any such information you may need.

 

Please feel free to contact Us at: info.mbr@mbr.mt or by writing to Malta Business Registry, AM Business Centre, Triq il-Labour, Zejtun ZTN 2401 or by phoning us using telephone number (+356) 2258 2300 (during normal office hours Monday – Thursday: 09:00 – 12:00 & 13:00 – 14:30 and Friday: 09:00-13:00).

 

We have appointed a data protection officer (The “DPO”) who is also responsible for overseeing questions in relation to this Privacy Policy. If you have any questions about this Privacy Policy, including any requests to exercise rights please feel free to contact our DPO directly at dpo.mbr@mbr.mt

 

3.4. CHANGES TO THE PRIVACY POLICY AND OUR DUTY TO INFORM YOU OF CHANGES

 

We reserve the right, at our complete discretion, to change, modify, add and/or remove portions of this Privacy Policy at any time. You shall be, in advance, informed by us of any material changes made to this Privacy Policy. We shall also archive and store previous versions of the Privacy Policy for your review.

 

4.0. THE PERSONAL DATA WE COLLECT ABOUT YOU

4.1. WHAT IS PERSONAL DATA?

 

Personal Data means any information that identifies you as an individual or that relates to an identifiable individual. Information relating to legal persons (such as companies) does not amount to Personal Data. For more information on this important distinction, please read the section “WHAT ABOUT INFORMATION RELATING TO COMPANIES?” below.

 

Whenever it is not possible or feasible for us to make use of anonymous and/or anonymised data (in a manner that does not identify any users of the Software or recipients of our services through the Software), we are nevertheless committed to protecting your privacy and the security of your Personal Data at all times.

 

4.2. WHAT ABOUT INFORMATION RELATING TO COMMERCIAL PARTNERSHIPS AND LEGAL ENTITIES?

 

Information relating to legal persons as opposed to natural persons does not amount to Personal Data. Limited liability companies and other legal entities have a distinct legal personality that is separate from that of their owners or even their directors. This means that information relating to such legal entities (as opposed to the details of the owners, shareholders or even directors) will not, in most cases, constitute Personal Data and falls outside the scope of the Applicable Data Protection Laws.

 

Having said the above, in all those cases where natural persons (such as company directors, shareholders, partners and even sole traders) are individually identifiable, and where information relates to such individuals in their personal capacity as opposed to them acting as representatives of a legal person, MBR will treat such information as Personal Data and will afford to such individuals (who would be deemed as data subjects) all the data protection rights listed below, as may be applicable.

 

4.3. DATA WE COLLECT ABOUT YOU

 

You may, at your own choice and discretion (with the exception of data necessary to register, authenticate and securely verify your use of the Software), through your use of the Software, choose to upload onto the Software different forms of personal data relating to you which we have grouped together as follows:

 

  1. Registration Data provided by you when you register and/or open your account on the Software for the first time including first name, last name, date of birth, gender, nationality, country of birth, and your profile image.

To simplify your registration, as well as for identification, security and verification purposes, the sign-up procedure is facilitated through third party providers including third party identity verification providers, the Electronic Identity Account or the eIDAS Node as issued by the Government of Malta. Once this procedure is utilised, the personal data (Registration and Contact Data) which would typically be provided by you during your registration, where available, will be automatically fed to your profile from such third party sources and used as further specified in this Privacy Policy.

Any documents that you may upload onto the portal of any third party identity verification providers during your registration are only temporarily stored by such third party sources, until such documents are verified and authorised and any relevant metadata is extracted from such documents and fed into your profile as described above, upon which such documents will be securely deleted in line with the third party identity verification provider’s applicable privacy policies and/or notices.

  1. Company Involvement Data includes data related to your involvement and position within any legal entities. As explained above, whilst information relating to legal persons does not constitute personal data, information that directly identifies you and your involvement in a legal entity constitutes personal data. 

  2. Identification Document Data includes any identification documents that you may freely choose to upload onto the Software, including your ID Card, Residence Card, Passport, or any other form of identification document which is accepted by the Software, and any personal information that may be contained within such documents.

  3. Verification of Address Data includes any personal data contained within documents which you may freely choose to upload onto the Software that may be used to verify any residential and/or commercial address, including rental agreements, bank statements, utility bills, and any government issued documentation.

  4. Source of Wealth Data includes includes any personal data contained within documents which you may freely choose to upload onto the Software that may be used to verify your source of wealth/income such as bank issued statements, statements of investments/shares, evidence of inheritance, contract of employment, payslips, income statements, profit and loss accounts, and receipts.

  5. Know Your Customer (KYC) Data refers to data stored within KYC reports generated through the Software by us at your request, which includes a compilation of your Registration Data, your Company Involvement Data, your Identification Document Data, your Verification of Address Data, and your Source of Wealth Data, as applicable.

  6. Contact Data includes your email address and telephone numbers.

  7. Payments Data includes bank/payment account details, as well as information pertaining to a transaction such as currency, location, amount/value, client IP, user ID, and token.

  8. Log in Data includes internet protocol (IP) address, your login logs, duration of logins, device/browser type and version, time zone setting and location, browser plug-in types and versions, operating system and platform and other technology on the devices you use to access the Software. In order to prevent and detect fraud and misuse of our systems, certain Log In Data such as; IP address, device model/type, browser information, operating system and device or other identification data may be sourced and processed by us through the services of third-party fraud detection software providers.

  9. Profile Data includes internal notes to your account, your preferences, and feedback.

  10. Communications Data includes your preferences in receiving communications from us (opt in/opt out), as well as your Contact and Registration Data. It also includes other Communication Data generated as part of communications with us or with other third parties via the Software which may include various data such as network communication data, the free-text content of the communications, as well as internal communication and notes.

  11. Analytics Data include various data generated with respect to your use of our Software such as your language, location, browser data and device data. Certain information may be collected using cookies and/or similar tracking technology, for which we kindly direct you to the section “COOKIES” below.

 

Many of the categories of Personal Data above are collected directly from you when you opt to upload documents and information on the Software. However, there are also instances where we may also collect personal data from other sources, including authorised members (e.g. directors or company secretaries) of the company or other legal entities you may be associated with as well as other Government agencies and Government bodies (both local as well as foreign bodies within the EU) and other third parties.

 

4.4. PERSONAL DATA RELATING TO THIRD PARTIES


By providing us with or allowing us to access Personal Data relating to individuals other than yourself (such as when you list other involved persons pertaining to company registration or registration of other entities with MBR), you are letting us know that you have the authority to send us those Personal Data or the authority to permit us to access those data in the manner described in this Privacy Policy.

 

4.5. SPECIAL CATEGORIES OF PERSONAL DATA

 

We do not knowingly and purposefully collect any Special Categories of Personal Data about you (this includes details about your race or ethnicity, religious or philosophical beliefs, sex life, sexual orientation, political opinions, trade union membership, information about your health and genetic and biometric data). However, from our experience, we may not exclude that you, at your own discretion and on the basis of your own explicit consent, upload such personal data on the Software.

 

Please note that although ID cards and other forms of official government issued documentation are processed, images contained therein are not technically processed by the Controller to allow or confirm a unique identification match. Therefore, such data is not to be considered biometric data, and consequently shall not be considered a special category of personal data.

 

Please also note that although there are instances where biometric authentication may be utilised to access the Software, this process will be carried out on the basis of your explicit consent and the MBR will have no access to or controls on any biometric data that may be utilised by any third party identity verification providers to allow your access to the Software, as the MBR only receives a positive or negative check by such third party identity verification providers. Please also note that in case you do not consent to biometric authentication you may still opt for a manual verification but please bear in mind that such manual verification may not be as time efficient and may delay your access to the Software until such manual verification is completed.

 

4.6. IF YOU FAIL TO PROVIDE PERSONAL DATA

 

Where we need to collect personal data by law, or under the terms of a contract we have with you and you fail to provide that data when requested, we may not be able to perform the contract we have with you for the provision of our services via the Software.

5.0. WHY AND HOW WE USE YOUR PERSONAL DATA

5.1. WHY WE USE YOUR PERSONAL DATA

 

We will only use your personal data when the Applicable Data Protection laws allow us to. Most commonly, we will use your Personal Data in the following circumstances:

 

  • To allow you access and use of our services via the Software;

  • For identification, security, authentication and verification proposes;

  • To facilitate and expedite your interaction/s with Government agencies, Government bodies and other third parties;

  • To abide by our legal requirements to collect/use and to keep such personal data for a predetermined period of time;

  • For the performance of a task carried out in the public interest;

  • For the performance of a task carried out in the exercise of official authority vested in us as a Government agency;

  • For the prevention and detection of illegal or fraudulent behaviour; and

  • for analytics purposes.

 

5.2. DETAILED PURPOSES AND LEGAL BASIS

 

We have set out below, in a table format, a description of the possible ways we plan to use your Personal Data, and which of the legal bases we rely on to do so. Note that we may process your Personal Data for more than one lawful ground depending on the specific purpose for which we are using your data. Please contact us if you need details about the specific legal ground we are relying on to process your Personal Data where more than one ground has been set out in the table below.

 

PURPOSE OF PROCESSING

CATEGORIES OF PERSONAL DATA

LEGAL BASIS FOR PROCESSING

To register you as a user of the Software; to allow you to access the Software   

  • Registration Data

  • Contact Data

  • Log-in Data

  • Company Involvement Data      

  • Contractual Necessity

  • Official Authority

  • Public Interest

  • Legal Obligations

To manage our relationship with you; to communicate with you; to give you access to our service via the Software

  • Registration Data

  • Contact Data

  • Log-in Data

  • Company Involvement Data      

  • Profile Data

  • Communications Data

  • Contractual Necessity

  • Official Authority

  • Public Interest

  • Legal Obligations

To set up a record on our system

  • Registration Data

  • Contact Data

  • Log-in Data

  • Company Involvement Data      

  • Profile Data

  • Identification Documents Data (if provided)

  • Verification of Address Data (if provided)

  • Source of Wealth Data (if provided)

  • Know Your Customer (KYC) Data (if report is generated)

 

  • Contractual Necessity

  • Official Authority

  • Public Interest

  • Legal Obligations

  • Consent

To pass on certain information to public authorities (including the Malta Financial Services Authority and National Statistics Office) & compile internal statistics and reports

  • Registration Data

  • Company Involvement Data      

  • Profile Data

  • Identification Documents Data (if provided)

  • Verification of Address Data (if provided)

  • Source of Wealth Data (if provided)

  • Know Your Customer (KYC) Data (if report is generated

  • Legal Obligation

  • Public Interest

  • Further processing for archiving purposes in the public interest, scientific or historical research purposes or statistical purposes (within the limits permitted by law).

To allow you to upload your documents onto our Software

  • Identification Documents Data (if provided)

  • Verification of Address Data (if provided)

  • Source of Wealth Data (if provided)

  • Contractual necessity

  • Consent

  • Public Interest

  • Official Authority

 

To generate KYC reports for you, as requested by yourself through the Software

  • Registration Data

  • Company Involvement Data      

  • Identification Documents Data (if provided)

  • Verification of Address Data (if provided)

  • Source of Wealth Data (if provided)

  • Know Your Customer (KYC) Data (if report is generated)

  • Contractual necessity

  • Official Authority

To allow you to share documents, information and Know Your Customer (KYC) reports you have uploaded and/or generated on the Software with Government agencies, Government bodies, and other third parties (where applicable)

  • Registration Data

  • Company Involvement Data      

  • Profile Data

  • Communications Data

  • Identification Documents Data (if provided)

  • Verification of Address Data (if provided)

  • Source of Wealth Data (if provided)

  • Know Your Customer (KYC) Data (if report is generated)

  • Contractual necessity

  • Consent

  • Public Interest

  • Official Authority

  • Legal obligations

To establish and investigate and suspicious behaviour in order to protect ourselves from risk and fraud

  • Registration Data

  • Company Involvement Data      

  • Profile Data

  • Log-in Data

  • Identification Documents Data (if provided)

  • Verification of Address Data (if provided)

  • Source of Wealth Data (if provided)

  • Public Interest

  • Official Authority

  • Legal obligations

 

To process and manage payments transactions (where applicable)

  • Payments Data

  • Registration Data

  • Profile Data

  • Contractual necessity

Web & Software Analytics

  • Analytics Data

  • Official Authority

  • Public Interest

  • Legal Obligations

 

 

Should we need to process your Personal Data for a new purpose in the future, which is entirely unrelated to the above, we will inform you of such processing in advance and you may exercise your applicable rights (as explained below) in relation to such processing.

 

When relying on consent, mainly when choosing, at your own discretion, to upload documents to the Software, the consent is granted by you when registering on our site.

 

6.0. RETENTION

 

We will only retain your personal data for as long as necessary to fulfil the purposes we collected it for, including for the purposes of satisfying any legal or reporting requirements.

 

The criteria we use to determine what is ‘necessary’ depends on the nature of the particular personal data in question. Our normal practice is to determine whether there is/are any specific EU and/or national law(s) permitting or even obliging us to keep certain personal data for a period of time (in which case we will keep the personal data for the maximum period indicated by any such law) and if not, whether there are any laws and/or contractual provisions that may be invoked against us by you and/or third parties and if so, what the prescriptive periods for such actions are. In the latter case, We will keep any relevant personal data that we may need to defend ourselves against any claim(s), challenge(s) or other such action(s) by you and/or third parties.

 

Where your personal data is no longer required by us, We will either securely delete or anonymise the personal data in question. We will generally retain your personal data for a maximum period of five (5) years from the closure of your account on the Software or after five (5) years of inactivity on your account. There are some exceptions to this retention period, namely:

  • If you are under investigation or where we have identified possible fraudulent or other criminal activity, we may retain your personal data for longer and as required in order to cooperate with the relevant authorities; and

  • If there is a legal dispute, we will retain your personal data for at least the entire duration of the dispute and as may be required in order to defend our rights in any subsequent claim or any subsequent proceeding arising from the same.

 

Further details of retention periods for different aspects of your personal data are available in our retention policy which you can request by contacting us.

 

7.0. RECIPIENTS OF YOUR PERSONAL DATA

 

As the Controller’s business partners, suppliers or service providers are responsible for certain parts of the overall functioning or operation of the Software, Personal Data is also processed by them for the above-mentioned purposes on behalf of the Controller. We require all third parties to respect the security of your personal data and to treat it in accordance with the law. We do not allow third-party service providers to use your personal data for their own purposes unless this is permitted or required by law, and only allow them to process your personal data for specified purposes and in accordance with our instructions, after thorough vetting of these partners and on the basis of strict data processing agreements.

 

Furthermore, you have the faculty, at your own discretion, to share any documentation and/or reports you may seek to upload and/or generate through the software with Government agencies, Government bodies and other third parties. Such access to your personal data, unless required to do so by our legal obligations, is not done automatically by us and you may freely choose with whom to share such documentation and/or reports with. However, in such scenarios, the recipients of your personal data with whom you may choose to share personal data with through the Software will not be acting on our behalf but will be acting in their own capacity as data controllers separate and independent from us. We are not responsible for whatever these entities may do with your personal data and encourage you to read through their respective privacy policies and/or notices to find out more about how they handle your personal data.

 

7.1. DETAILS ON THE CATEGORIES OF RECIPIENTS OF THE PERSONAL DATA

 

The third parties who we may disclose to and/or share your Personal Data with are, at the date of this Privacy Policy, the following:

 

 

CATEGORY OF RECIPIENT

PURPOSE OF PROCESSING

Malta Information Technology Agency (MITA)

Hosting of data under state of the art security protocols and our exclusive control

Binderr Ltd

Maintenance and support of our Software - with restricted access and under our strict controls

Digital Application Providers

To offer you our services on the Software and comply with our legal obligations, including the use of camera and/or recordings and audio permissions in relation to the verification of the user.

Identity Verification Service Providers

The IDV provider simply follows your instructions to check the ID against a database or perform a biometric "liveness" check.

Auditors

Compliance with our auditing obligations - with access granted only to essential personal data

Advocates and/or Lawyers

Compliance with our legal obligations or when necessary for the establishment, exercise or defence of legal claims.

Subject Persons in terms of the Prevention of Money Laundering and Financing of Terrorism Regulations (PMLFTR)

To offer you our services on the Software and comply with our legal obligations, during onboarding and due diligence as legally required by law.

Government agencies, departments or entities and The Malta Police Force

To offer you our services on the Software and comply with our legal obligations, in the public interest and/or our exercise of official authority 

Competent Authorities

To offer you our services on the Software and comply with our legal obligations, in the public interest and/or our exercise of official authority in terms of the AML/CFT Laws. 

Other third parties with whom you choose to share your personal data

To offer you our services on the Software

Payment service providers (where necessary)

 

To perform payment transactions and for the purposes of preventing fraud and enabling compliance with AML obligations

 

 


 

7.2. AUTHORISED DISCLOSURE

 

Without prejudice to anything contained in this Privacy Policy and in the interest of full transparency, we reserve the right to disclose (and otherwise process) any relevant Personal Data relating to you which we may be processing (including in certain cases relevant IP addresses) to authorised third parties in or outside the EU/EEA if such disclosures are allowed under the Data Protection Laws (whether or not you have provided your consent) including but not limited to:

 

  • For the purpose of preventing, detecting or suppressing fraud (for example, if you provide false or deceptive information about yourself or attempt to pose as someone else, we may disclose any information we may have about you in our possession so as to assist any type of investigation into Your actions);

  • in the event of MBR being involved in a restructure, transfer or absorption into another Government department (or similar event analogously applicable to Government agencies);

  • to protect and defend our rights (including the right to property), safety, or those of our affiliates, of users of our Software, of our members or even your own;

  • to protect against abuse, misuse or unauthorised use of our Software;

  • for any purpose that may be necessary for the performance of any agreement you may have entered into with us (including the request for provision of services by third parties) or in order to take steps at your request prior to entering into a contract;

  • to comply with any legal obligations such as may arise by way of response to any Court subpoena or order or similar official request for Personal Data; or

  • as may otherwise be specifically allowed or required by or under any applicable law, for example, under anti-money laundering legislation.

 

8.0. DATA ACCURACY

All reasonable efforts are made to keep any Personal Data we may hold about you up to date and as accurate as possible. You can check the information that we hold about you at any time by contacting us in the manner explained above or by going on your profile page. If you find any inaccuracies, we will correct them and where required and in accordance with the law (provided that the law permits such deletion), delete them as necessary. Please see below for a detailed list of your legal rights in terms of any applicable data protection law.

 

Kindly note that if any inaccuracies relates to any documentation you have uploaded onto the Software, you have the technical ability to delete such documentation unilaterally and upload the correct and/or updated documentation. If you require any assistance with this process please contact us.

9.0. INTERNATIONAL TRANSFERS

Generally, the recipients of your Personal Data (as listed above) are based within the European Economic Area (EEA). However, if the processing of your Personal Data will involve a transfer of data outside the EEA, we will ensure that a similar degree of protection is afforded to it by ensuring at least one of the following safeguards is implemented:

 

  • The transfer of your personal data is performed to countries, territories, or subject to arrangements or mechanisms that have been deemed to provide an adequate level of protection for personal data by the European Commission.

  • Where we use service providers which are not subject to an adequacy mechanism, we will ensure that additional contractual and non-contractual safeguards and measures are put in place as required (including by incorporating specific contracts approved by the European Commission such as the Standard Contractual Clauses).

 

Please Contact us if you want further information on the specific mechanism used by us when transferring your personal data out of the EEA.

 

10.0. DATA SECURITY

We have put in place appropriate security measures to prevent your Personal Data from being accidentally lost, used or accessed in an unauthorised way, altered or disclosed. This ensures confidentiality and integrity at all times. At an organisational level, the handling of all information is governed by our comprehensive Information Security Policies. This is complemented by an Information Security Awareness Programme designed specifically to ensure we embrace security best practices whenever it comes to handling information.

 

In addition, we limit access to your Personal Data to those employees, agents, contractors and other third parties who have a need-to-know business requirement. They will only process your Personal Data on our instructions or subject to a lawful ground, as well as their duty of confidentiality. We have put in place procedures to deal with any suspected Personal Data breach and will notify you and any applicable regulator of a breach where we are legally required to do so.

 

Despite all the above, we cannot guarantee that a data transmission or a storage system can ever be fully secure. For more information about our security measures please contact us in the manner described above.

 

Authorised third parties acting as our data processors with permitted access to your Personal Data (as explained in this Privacy Policy) are specifically required to apply appropriate technical and organisational security measures that may be necessary to safeguard the Personal Data being processed from unauthorised or accidental disclosure, loss or destruction and from any unlawful forms of processing.

 

11.0. YOUR RIGHTS UNDER THE DATA PROTECTION LAWS

11.1. YOUR RIGHT OF ACCESS

 

You may, at any time, with reasonable intervals, request us to confirm whether or not we are processing any Personal Data that concerns you and, if we are, you shall have the right to access that Personal Data and to the following information: what personal data we have, why we process them, who we disclose them to, how long we intend on keeping them for (where possible), whether we transfer them abroad and the safeguards we take to protect them, what your rights are, how you can make a complaint, where we got your personal data from and whether we have carried out any automated decision-making as well as related information.

 

11.2. THE RIGHT TO RECTIFICATION

 

Although all reasonable efforts will be made to keep your Personal Data updated, you are kindly requested to inform us promptly of any changes. To this end you have the right to ask us to rectify inaccurate Personal Data and to complete incomplete Personal Data concerning you. We may seek to verify the accuracy of the data before rectifying it.

 

11.3. THE RIGHT TO ERASURE (THE RIGHT TO BE FORGOTTEN)

 

You have the right to ask us to delete your Personal Data and we shall comply without undue delay but only where:

 

  • The personal data are no longer necessary for the purposes for which they were collected;

  • You have withdrawn your consent (in those instances where we process on the basis of your consent) and we have no other legal ground to process your personal data;

  • You have successfully exercised your right to object (as explained below); 

  • Your personal data have been processed unlawfully;

  • There exists a legal obligation to erase the data to which We are subject; or

  • Special circumstances exist in connection with certain children’s rights.

 

Please note that if you wish to delete any data related to any documentation you have uploaded onto the Software, you have the technical ability to delete such documentation and any metadata derived therefrom unilaterally. If you require any assistance with this process please contact us.

 

In any case, we shall not be legally bound to comply with your erasure request if the processing of your Personal Data is necessary:

 

  • For compliance with a legal obligation to which we are subject (including but not limited to our data retention obligations); or

  • For the establishment, exercise or defence of legal claims.

 

There are other legal grounds entitling us to refuse erasure requests although the two instances above are the most likely grounds that may be invoked by us to deny such requests. You may request the erasure by contacting us.

 

11.4. THE RIGHT TO DATA RESTRICTION

 

You have the right to ask us to restrict (that is, store but not further process) your Personal Data but only where:

 

  • The accuracy of your personal data is contested (see the right to data rectification above), for a period enabling us to verify the accuracy of the personal data;

  • The processing is unlawful, and you oppose the erasure of your personal data;

  • We no longer need the personal data for the purposes for which they were collected but you need the personal data for the establishment, exercise or defence of legal claims; or

  • You exercised your right to object and verification of our legitimate grounds to override Your objection is pending.

 

Following your request for restriction, except for storing your personal data, we may only process your Personal Data:

 

  • Where we have your consent; 

  • For the establishment, exercise or defence of legal claims;

  • For the protection of the rights of another natural or legal person; or

  • For reasons of important public interest.

 

You may request the restriction by contacting us.

 

11.5. THE RIGHT TO DATA PORTABILITY

 

You have the right to ask us to provide your Personal Data (that you shall have provided to us) to you in a structured, commonly used, machine-readable format, or (where technically feasible) to have it 'ported' directly to another data controller, provided this does not adversely affect the rights and freedoms of others. This right shall only apply where:

 

  • The processing is based on your consent or on the performance of a contract with you; and

  • The processing is carried out by automated means.

 

11.6. THE RIGHT TO OBJECT TO CERTAIN PROCESSING

 

In those cases where we process your personal data for the performance of a task carried out in the public interest, you shall have the right to object to processing of your personal data by us.

 

For the avoidance of all doubt, when we process your personal data when this is necessary for the performance of a contract, when necessary for compliance with a legal obligation to which we are subject or when processing is necessary to protect your vital interests or those of another natural person, this general right to object shall not subsist.

 

11.7. RIGHT TO WITHDRAW CONSENT (WHEN WE PROCESS YOUR DATA ON THE BASIS OF CONSENT)

 

In those cases where we process Personal Data on the basis of your consent (which we will never presume but which we shall have obtained in a clear and manifest manner from you), you have the right to withdraw your consent at any time and this, in the same manner as you shall have provided it to us.

 

Should you exercise your right to withdraw your consent, we will determine whether at that stage an alternative legal basis exists for processing your Personal Data (for example, on the basis of a legal obligation to which we are subject) where we would be legally authorised (or even obliged) to process your Personal Data without needing your consent and if so, notify you accordingly.

 

When we ask for such Personal Data, you may always decline, however should you decline to provide us with necessary data that we require to provide the services of the Software, we may not necessarily be able to provide you with such services (especially if consent is the only legal ground that is available to us).

 

Please note that consent is not the only ground that permits us to process your Personal Data as there are various grounds that we rely on when processing your Personal Data for specific purposes.

 

11.8. THE RIGHT TO LODGE A COMPLAINT

 

You also have the right to lodge complaints with the appropriate Data Protection Supervisory Authority. Since the Malta Business Registry is a Government Agency registered in Malta, our Lead Supervisory Authority is the Maltese Information and Data Protection Commissioner (IDPC). We kindly ask that you please attempt to resolve any issues you may have with us first (even though, as stated above, you have a right to contact the competent authority at any time).

 

11.9. WHAT WE MAY NEED FROM YOU

 

When exercising your rights by contacting us, we may need to request specific information from you to help us confirm your identity and ensure your right to access your Personal Data (or to exercise any of your other rights). This is a security measure to ensure that personal data is not disclosed to any person who has no right to receive it. We may also contact you to ask you for further information in relation to your request to speed up our response.

 

11.10. TIME LIMIT TO RESPOND

 

We try to respond to all legitimate requests within one month (unless a shorter period is required by law). Occasionally it may take us longer than a month if your request is particularly complex or you have made a number of requests. In this case, we will notify you and keep you updated.

 

12.0 AUTOMATED PROCESSING

 

Your personal data will not be used for any decision solely taken on the basis of automated decision-making processes.

 

13.0. COOKIES

 

If you are using a website instance of the Software, the Software uses cookies. For further information on what cookies are, which cookies we use, how and why we use cookies, and how you can control which cookies are dropped, please read our Cookies Policy.

Advisory Committee
Registrar / CEO
Deputy Registrar / COO
Unità tar-Reġistru
Compliance Unit
Unità Legali u Infurzar
Unità tas-Servizz ta' Insolvenza u Riċeviment
Unità tal-Finanzi u l-Amministrazzjoni
Unità tar-Riżorsi Umani u l-Iżvilupp
Unità tat-Teknoloġiji tal-Informazzjoni u tal-Komunikazzjoni
Unità għall-Affarijiet Internazzjonali, ir-Riċerka u l-Komunikazzjoni
Money Laundering Reporting Officer
Kumitat tal-Verifika
Unità tal-Verifika Interna
bottom of page