
Terms and Conditions for Relying Parties of the Malta Business Wallet
Version 1.0.
Last updated 14th May 2026
1.0. INTRODUCTION
1.1. Welcome to the Malta Business Registry’s (“MBR”) Terms and Conditions (the “T&Cs”) relating to the provision of the services provided via the Malta Business Wallet, a software application which users can download and install onto their mobile device and/or access via any related website, sub-website and/or associated domains (and/or sub-domains) under which the services of the Malta Business Wallet may be offered (“MBW”, “Software”), and which You, a relying party, and your officer/s and/or employee/s, shall use to, inter alia, request, obtain, collect and receive data, information and reports made available through the repository by users (“Relying Party”) .
1.2. We recommend that you read these T&Cs in full. For the ease of your understanding, these are the contents of these T&Cs:
4.0. OVERVIEW, PURPOSE AND SCOPE
5.0. ELIGIBILITY AND OBLIGATIONS OF RELYING PARTIES
6.0. DATA SUBMISSION, VERIFICATION, AND AUDIT
11.0. BREACHES, PENALTIES AND TERMINATION
13.0. FORCE MAJEURE AND MAINTENANCE
14.0. GOVERNING LAW AND JURISDICTION
15.0. ENTIRE AGREEMENT AND SEVERABILITY
2.0. DEFINITIONS
2.1 For the purposes of these T&Cs, unless defined elsewhere in these T&Cs, the following terms shall have the respective meanings or reference as indicated:
“Credentials” includes identity documents, licences, or other professional authorisations submitted to evidence User status.
“Data” means all information and materials that are submitted, uploaded, transmitted, provided, or otherwise made available by the User to the Software and/or the MBR and/or the Registrar, in any form or medium, including content, documents, files, data sets, messages and other communications, and any associated metadata to the extent relating to the foregoing.
“GDPR” means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data.
“Intellectual Property” means patents, rights to inventions, copyright and neighbouring and related rights, trademarks, domain names, rights in designs, rights in computer software, database rights, rights to use, and protect the confidentiality of, confidential information and all other intellectual property rights, in each case whether registered or unregistered and including all applications and rights to apply for and be granted, renewals or extensions of, and rights to claim priority from, such rights and all similar or equivalent rights or forms of protection which subsist or will subsist now or in the future in any part of the world.
“User” or “Users” means any natural person, whether acting on his behalf or on behalf of another natural or legal person, who has created an account on the Software and is utilising the MBR’s services as provided by the Software, including but not limited to submitting Data, information, documents, or any other Credentials to the Software.
“Personal Data” means any information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked (directly or indirectly) to an identified or identifiable natural person, as referred to in Regulation (EU) 2016/679.
“Registrar” means the Registrar of Companies as referred to under article 400 of the Companies Act, Cap. 386 of the Laws of Malta.
“Subject Person” or “Subject Persons” means subject persons within the meaning of the Prevention of Money Laundering Act (Chapter 373 of the Laws of Malta).
3.0. GENERAL
3.1. The Software and all associated Intellectual Property is owned and operated by the Malta Business Registry, a Government Agency registered in Malta whose address is Malta Business Registry, AM Business Centre, Triq il-Labour, Zejtun, ZTN 2401.
3.2. These Terms and Conditions govern the use by Relying Parties of the Software as maintained and administered by the MBR under the direct responsibility of the Registrar.
3.3. In these T&Cs, “you” means you, as a Relying Party of the Software and “your” shall be interpreted accordingly.
3.4. By accepting these T&Cs and/or by using or accessing any features of the Software, you confirm that, You, including any officer/s and/or employee/s, have the authority to bind the entity you represent and agree to be legally bound by these T&Cs on its behalf. If you do not read, understand, or agree to these T&Cs or any part of them, you must not use the Software, register for an account, or access any of its features.
3.5. The application of any other general T&Cs other than these is expressly excluded. However, you understand and agree that you may have entered into further agreements dictating the use of the Software and you understand that you are equally bound by such agreements and it is your responsibility to be informed of the contents of such agreements and any obligations arising therefrom.
4.0. OVERVIEW, PURPOSE AND SCOPE
4.1. The Software is established to facilitate the lawful collection, secure storage, transfer and verification of Data in accordance with the Companies Act (Chapter 386 of the Laws of Malta), the Prevention of Money Laundering Act (Chapter 373 of the Laws of Malta), and any other applicable legislation.
4.2. The Software allows users to store virtual representations of Data, and to consequently share it with you, any public body, public authority, or third party who has been granted access to the Software by the MBR and/or the Registrar. Without prejudice to any legal obligations that the MBR and/or the Registrar may have to lawfully disclose the Data, users have complete control with whom they share their Data with, including you, and may opt to not share it with you, even if you have requested access to such Data. Similarly, they may opt to share one specific document with you that they have uploaded onto the Software but not the entire Data.
4.3. The use of the Software and its features, although considered to be legally binding and formally accepted as an official means of Data verification and transfer, remains a fully voluntary and optional service, meaning that nothing will stop Users from manually (and in any other manner as prescribed by you) sending Data (even if not uploaded to the Software), for whatever reasons, to you. Similarly, the Software does not bind and force you to request, collect, and verify Data solely through the Software.
4.4. Furthermore, the Software allows Subject Persons to act on behalf of their clients and to store virtual representations of their clients’ Data, and to consequently share it with you, in the same mode and manner in which the User would share their own Data.
5.0. ELIGIBILITY AND OBLIGATIONS OF RELYING PARTIES
5.1. Only duly authorised persons may access the Software and its features, and you warrant and represent that you are duly authorised to bind the entity you are representing and to access User’s Data on its behalf, and that such entity and yourself remain severally responsible for your acts and omissions.
5.2. If applicable, to set up and use the Software, you must also have a supported device running a version of an operating software that supports the Software (we always recommended, and in some instances require, that you use the latest available version).
5.3. You warrant that you understand that the collection, transmission, processing, or use of Data through the Software does not relieve the User of any legal, regulatory or statutory obligations to submit accurate, complete, and correct Data, and you expressly acknowledge that the submission of accurate and complete Data is a statutory requirement and remains the User’s sole responsibility for the purposes of regulatory compliance and oversight.
5.4. You are responsible for (i) maintaining the confidentiality and security of any account credentials issued to you or used by you to access the Software, (ii) ensuring that only authorised personnel access and use the Software under your account, and (iii) promptly notifying MBR of any actual or suspected unauthorised access or misuse.
5.5. You will ensure that all personnel accessing the Software on your behalf are appropriately trained and subject to confidentiality and data protection obligations at least as protective as those in these T&Cs.
5.6. You further represent and warrant that:
I. Access by you to Data stored on the Software shall be limited to such data, information and reports as are necessary and proportionate for the purpose for which your access is requested, and done so in line with any applicable laws and regulations, in particular the Companies Act (Central Data Repository) Regulations;
II. In accessing the Software and any of the Data contained therein, you shall comply with all applicable data protection legislation, including the General Data Protection Act (the “GDPR”), the provisions of the Data Protection Act and any relevant regulations thereunder in relation to any personal data which you may access or receive through the repository;
III. You will not use the Software for any illegal or fraudulent purposes, or any other purposes that are prohibited by the MBR and/or the Registrar including through these T&Cs;
IV. Without prejudice to any other rights or remedies available at law, any Data accessed or otherwise obtained by you through the repository shall be treated as confidential and shall not be disclosed to any third party;
V. You understand and agree that the MBR shall in no way or form be held liable for the submission of any false information by Users in connection with the Software and that you indemnify and hold the MBR harmless in accordance with the same;
VI. You will not interfere with or disrupt the Software (including accessing the Software through any automated means), or any servers or networks connected to the Software, or any policies, requirements, or regulations of networks connected to the Software (including any unauthorised access to, use, or monitoring of data or traffic therein);
VII. You shall not rely on the Registrar, the MBR and/or the Software as your sole or primary means of retaining, accessing, or retrieving copies of any Data that is submitted to the Software by a User; and
VIII. Notwithstanding the MBR’s obligations at law, you remain responsible for maintaining your own complete, accurate, and up-to-date records, in accordance with applicable law and their internal record-retention requirements.
6.0. DATA SUBMISSION, VERIFICATION, AND AUDIT
6.1. You acknowledge that the Registrar, and in certain instances you, may from time to time, and in accordance with the Companies Act (Central Data Repository) Regulations, require the User to provide additional supporting documents, credentials, confirmations, or declarations in relation to any Data submitted to the MBR and/or the Registrar through the Software..
6.2. The User will provide the requested information promptly and in any event within the period specified in the request. If the User does not respond within the applicable timeframe, or if the response is incomplete or inadequate, the Registrar and/or the MBR may, to the extent permitted by law and without prejudice to any other rights or remedies under the Regulations:
I. Decline to process the relevant submission;
II. Suspend review or acceptance of the Data pending receipt of a satisfactory response; and/or
III. Require the User to resubmit or supplement the Data.
6.3. The Registrar will verify the Data submitted by the User to the extent required or permitted under applicable law and may, to the extent permitted by law, consult with or seek confirmation from any third party identification verification provider, competent authority or official body in Malta and/or in other jurisdictions for the purposes of verification, validation, or compliance checks.
6.4. Without limiting the foregoing, the MBR may verify, audit, and validate any Data submitted and may reject, suspend, or revoke acceptance of any Data where it has reasonable grounds to doubt the authenticity, legality, accuracy, completeness, or regulatory compliance of that Data, including where supporting evidence is not provided when requested.
7.0. DATA PROTECTION
7.1. You understand that the MBR shall process Personal Data relating to Users in its capacity as a Data Controller in accordance with the latest version of its Privacy Policy for the Software (the “Privacy Policy”) which is available at https://www.mbr.mt/website-pages/privacy-policy and details what Personal Data is processed by the MBR, the purposes for which Personal Data is processed, the applicable lawful bases under the GDPR, the categories of recipients and circumstances in which Personal Data may be shared, applicable retention periods including the criteria used to determine them, and the rights available to Users under the GDPR.
7.2. When accessing the Software, you agree that you will be processing Data relating to Users in your capacity as a separate and independent Data Controller and in accordance with ‘Annex I - Data Sharing Agreement’ to these T&Cs, which is for all intents and purposes of the law incorporated into these T&Cs by reference and forms an integral part of them.
7.3. Your acceptance of these T&Cs includes your full acceptance of the ‘Annex I - Data Sharing Agreement’.
7.4. Questions relating to ‘Annex I - Data Sharing Agreement’ may be directed to the MBR’s Data Protection Officer (the “DPO”) at dpo.mbr@mbr.mt.
8.0. DEVICE SECURITY
8.1. If you authorise or allow any other person other than those lawfully allowed to access the Software, you expressly agree and acknowledge that, without prejudice to any rights that the MBR and/or Registrar may have under these T&Cs and/or any applicable legislation, you will be held fully responsible for all access, verifications, and actions made by that person.
8.2. If you make any unauthorised modifications to your device, such as by disabling hardware or software controls, your device may no longer be eligible to access or use the Software. You acknowledge that the use of a modified device in connection with the Software is expressly prohibited, constitutes a violation of these T&Cs and the MBR and/or Registrar may exercise any rights they have against you arising from these T&Cs and/or any applicable legislation.
8.3. You may need to enable additional security measures as may be dictated by the MBR from time to time, such as two-factor authentication in order to access the Software or any particular features therein. If you subsequently decide to remove and/or decline the use of such additional security measures, you may not be able to continue to access the Software or any particular features therein.
9.0. LIABILITY & INDEMNITY
9.1. To the maximum extent permitted by applicable law, and without limiting any mandatory statutory duties that apply to the MBR in its capacity as a public authority, the MBR will not be liable for any losses, damages, claims, fines, penalties, costs, or expenses arising out of or relating to your receipt, processing, publication, retention, or other reliance on any Data submitted by a User that is inaccurate, incomplete, unlawful, misleading, or fraudulent, as well as any acts by the User or you which breach these T&Cs and/or any applicable legislation.
9.2. You shall indemnify, defend, and hold harmless the MBR and its officers, employees, agents, and representatives from and against any and all claims, actions, proceedings, investigations, demands, liabilities, losses, damages, judgments, settlements, fines, penalties, interest, and legal and professional fees arising out of or relating to:
I. Your breach of these T&Cs; or
II. Any allegation that the Data submitted by the User is unlawful, infringing, misleading, inaccurate, incomplete, fraudulent, or otherwise non-compliant with applicable law.
10.0. INTELLECTUAL PROPERTY
10.1. MBR is the sole owner of the Software and all Intellectual Property rights therein, including but not limited to brands, trademarks, logos, and all registered and unregistered names, signs and distinctive devices that may be used in the Software. Any unauthorised use of the above will result in legal action being taken against the infringer.
10.2. The Software and its contents may not be reproduced, transmitted or stored in whole or in part without the MBR’s written consent. Your registration and use of the Software does not confer any rights whatsoever to the Intellectual Property contained in or on the same Software.
10.3. You agree not to use any automatic or manual device to monitor the Software, or any content therein. Any unauthorised use or reproduction will result in legal action being taken against the infringer.
11.0. BREACHES, PENALTIES AND TERMINATION
11.1. Without prejudice to any other rights or remedies available to the MBR and/or the Registrar under these T&Cs, the Companies Act, Companies Act (Central Data Repository) Regulations, or otherwise at law, where the MBR and/or the Registrar reasonably considers that you have failed to comply with these T&Cs or applicable law, the MBR may, acting proportionately and to the extent permitted by law, take such measures as it considers appropriate, including suspending, restricting or terminating your access to the Software.
11.2. The MBR may terminate and restrict your access by electronic notice if:
I. You commit a material breach of these T&Cs or any applicable law and, where capable of remedy, you do not remedy it within the period indicated by the MBR; or
II. You commit repeated breaches of these T&Cs or any applicable law; or
III. Your credentials are compromised/misused or you otherwise create a security risk; or
IV. Termination is required or advisable to comply with law/regulatory requirements.
Notwithstanding the above, and for the avoidance of doubt, the MBR may terminate and restrict your access immediately for fraud, deliberate misrepresentation, serious or non-curable breach, unlawful submissions, material security/integrity risk, or where required by law.
11.3. The MBR may also suspend, restrict, or terminate your access to the Software if the Software is discontinued, withdrawn, replaced, or materially modified, or if continued provision of the Software is not reasonably practicable due to legal or regulatory requirements, security risks, operational constraints, or decisions of the Registrar or any other competent authority. Where reasonably practicable, the MBR will provide advance notice of any discontinuance or material changes affecting the User.
12.0. AMENDMENTS
12.1. The MBR may amend, update, or replace these T&Cs from time to time. Unless a different effective date is stated in the notice, any amendment will take effect on the date in which the notice was published (the “Effective Amendment Date”) and will apply only from that Effective Amendment Date onwards.
12.2. By continuing to access or use the Software on or after the Effective Amendment Date, are deemed to have accepted the amended T&Cs. For clarity, unless and to the extent required by applicable law, amendments will not apply retroactively to any Data or submission that was accepted, processed, or otherwise finally recorded by the MBR prior to the Amendment Effective Date.
13.0. FORCE MAJEURE AND MAINTENANCE
13.1. The MBR will not be liable for any failure or delay in performing its obligations under these T&Cs to the extent caused by an event beyond MBR’s reasonable control (an “Excusable Event”). Excusable Events include, without limitation, natural disasters and public health emergencies; war, terrorism, civil unrest, sabotage, or malicious damage; acts, directions, restrictions, or failures of any government, court, regulator, or other competent authority; utility/telecommunications outages; failures or unavailability of third-party infrastructure or services (including hosting/cloud/network providers); cyber incidents (including ransomware or denial-of-service attacks); and software, system, or security failures (including planned or emergency maintenance).
13.2. Where reasonably practicable, MBR will;
I. Notify you of an Excusable Event; and
II. Take reasonable steps to mitigate the impact of the Excusable Event and restore service to the Software and its features.
MBR may implement temporary procedures and may suspend, restrict, or defer access to the Software (in whole or in part) as reasonably necessary to address the Excusable Event and protect the integrity, security, and lawful operation of the Software.
13.3. Notwithstanding the above, you acknowledge that access to, availability of, or retrieval of Data from the Software (including any viewing, download, extract, or copy functionality) may be unavailable, restricted, suspended, delayed, or limited from time to time (including due to maintenance, security, legal, or operational reasons).
14.0. GOVERNING LAW AND JURISDICTION
14.1. These T&Cs shall be governed by and construed under the Laws of Malta.
14.2. Any dispute arising from these T&Cs shall fall under the exclusive jurisdiction of the Courts of Malta.
15.0. ENTIRE AGREEMENT AND SEVERABILITY
15.1. These T&Cs, including any other annexes that have been incorporated by reference, constitute the entire agreement between the MBR and you in relation to your access to and use of the Software and supersedes and replaces all prior and contemporaneous understandings, communications, representations, and agreements.
15.2. If any provision of these T&Cs is held to be invalid, unlawful, or unenforceable, that provision will be severed and, where permitted, modified to the minimum extent necessary to make it valid, lawful, and enforceable while preserving its intent as far as possible. If that is not possible, the invalid, unlawful, or unenforceable provision will be deemed replaced by a valid, lawful, and enforceable provision that most closely reflects the regulatory intent of the original provision. The remaining provisions will remain in full force and effect.
ANNEX I - DATA SHARING AGREEMENT
This Data Sharing Agreement is made by and between the Parties, and unless defined elsewhere, the following terms shall have the respective meanings or reference as indicated:
‘Agreement’ means the terms and conditions, and any other agreement that may have been entered into between MBR and the Relying Party as amended or further supplemented by any additional agreements which may apply from time to time;
‘DSA’ means this Data Sharing Agreement, including any Appendices attached or referred to herein and including any future amendments and additions in writing;
‘Data Breach’ means a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data;
‘Data Protection Laws’ means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27th April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data (hereinafter ‘GDPR’), as amended from time to time, including national supplementary or implementation measures as applicable, together with any other regulation, law, including national legal instruments in the field of protection of personal data, as may be applicable by virtue of territorial or extra-territorial scope of application;
‘Delete’ shall mean deleting data in such a manner that restoring or recovering such data shall be impossible;
‘Personal Data’ means Personal Data that are shared by the MBR with the Accessing Party pursuant to this DSA, and vice versa as may be the case, and this in the mode and manner already specified and stipulated in this DSA;
The terms “Controller”, “Processing”, “Data Subject”, “Personal Data Breach”, “Joint Controller”, and “Supervisory Authority” shall have the same meaning as in the Data Protection Laws.
1.0 BACKGROUND
1.1. The MBR and You, the Relying Party, are sharing Personal Data in their roles of separate controllers in conjunction with the MBR’s provision of services via the Malta Business Wallet, a software deployed by the MBR to facilitate the sharing of information, inclusive of personal data, between individuals involved in legal entities, government bodies, agencies, and other third parties.
1.2. The Parties hereby acknowledge that this DSA shall apply to any and all Personal Data that have been and shall be shared in conjunction with the above purpose.
1.3. This DSA expressly replaces and supersedes any and all other agreements, oral or written, between the Parties hereto with respect to the subject matter hereof.
1.4. In consideration of the above, in order to protect Personal Data and to ensure they are shared in accordance with Data Protection Laws, the Parties have, for their mutual benefit and for good and valuable consideration, agreed to the following terms for the said sharing of Personal Data.
1.5. Personal Data shared for the Purpose shall mean, the data which is stored on the Malta Business Wallet, which at the sole choice and discretion of the User of the Malta Business Wallet, or otherwise if required by applicable laws, is shared with you, which includes:
I. Registration Data provided by the User when they register and/or open an account on the Malta Business Wallet for the first time including their first name, last name, date of birth, gender, nationality, country of birth, and profile image;
II. Company Involvement Data which includes data related to Users’ involvements and positions within any legal entities;
III. Identification Document Data which includes any identification documents that the user has uploaded onto the Malta Business Wallet, including the Users’ ID Card, Residence Card, Passport, or any other form of identification document which is accepted by the Malta Business Wallet, and any personal information that may be contained within such documents;
IV. Verification of Address Data which includes any personal data contained within documents that the user has uploaded onto the Malta Business Wallet that may be used to verify any residential and/or commercial address, including rental agreements, bank statements, utility bills, and any government issued documentation; and
V. Source of Wealth Data which includes any personal data contained within documents that the user has uploaded onto the Malta Business Wallet that may be used to verify the users’ source of wealth/income such as bank issued statements, statements of investments/shares, evidence of inheritance, contract of employment, payslips, income statements, profit and loss accounts, and receipts.
2.0 GENERAL DATA PROTECTION PROVISIONS
2.1. Each Party is acting as a separate Controller in its own right with respect to the Processing of the Personal Data it carries out towards its customers and/or users as understood under the Data Protection Laws. Each of the Parties independently determines the purposes and means of processing of Personal Data and acts Independently of the other Party. The Parties do not jointly determine the purposes and means of the processing and do not act as Joint Controllers. Neither of the Parties processes personal data on behalf of the other Party and neither of the Parties acts as a Data Processor of the other Party. Each of the Parties shall independently take all necessary measures to comply with applicable Data Protection Laws.
2.2. Each Party shall independently ensure that all processing of Personal Data carried out as an Independent Controller is done on the basis of the appropriate legal basis.
2.3. Any legal basis established for the processing of Personal Data by one Party, shall in no way affect the rights and/or obligations of the other Party.
2.4. Each Party, acting as an Independent Controller, shall ensure that the legal basis used for the sharing of Personal Data with the other Party, is valid and appropriate in terms of the Data Protection Laws.
2.5. Each Party shall ensure, to the best of its abilities, that any Personal Data it is responsible for is only shared with or sent to the other Party in a manner which is in full compliance with Data Protection Laws and such sending Party must also ensure, to the best of its abilities, that such Personal Data has been collected or otherwise processed lawfully and that where required, appropriate consent or other authorisation has been granted for sharing the personal data with the other Party.
2.6. Each Party shall ensure that Data Subjects to whom such Personal Data relates (to be shared with or sent to the other Party) have been provided with all the necessary information as required by the Data Protection Laws.
2.7. Each Party undertakes to fulfill all of its obligations arising under the Data Protection Laws which it may have with respect to the Data Subjects to whom the Personal Data Subject of this DSA relates and such Party shall be solely responsible for any of its failures to carry out any such obligations.
2.8. The Parties recognise that this DSA shall be interpreted in full compliance with the Data Protection Laws as well as any relevant applicable legislation.
2.9. For the avoidance of all doubt and in addition to anything else agreed between them, the Parties, in whatever role they may occupy and with respect to any sharing of Personal Data they may be involved in together, undertake to comply with the provisions of the Data Protection Laws.
3.0 OBLIGATIONS
3.1. The Parties confirm their ability to comply with the GDPR.
3.2. The Parties confirm that they both separately implement and/or provide sufficient guarantees to implement appropriate technical and organizational measures as well as any other additional measures which satisfy the requirements of Data Protection Laws and ensure the security of the Personal Data and the protection of the rights of the Data Subjects.
3.3. The Parties shall provide each other with all information necessary to demonstrate compliance with this DSA and the Data Protection Laws upon request.
3.4. You shall share Personal Data with MBR as an independent Controller in accordance with this DSA and in compliance with the Data Protection Laws.
3.5. The Parties shall not share any Personal Data with each other except as may be necessary for the performance of any service or task provided for MBR and, in particular, shall share the Personal Data strictly in line with the T&Cs and this DSA.
3.6. Each Party warrants that it shall not perform any of its obligations under this DSA in such a way as to cause either Party to breach any of its obligations arising under the Data Protection Laws or otherwise act or fail to act in such a manner that leads to such breach.
3.7. You shall inform MBR immediately if you think that any obligation pursuant to the T&Cs or this DSA does not comply with the Data Protection Laws.
4.0 AUTHORISED PERSONS AND THIRD PARTIES
4.1. The Parties shall ensure that Personal Data shall only be disclosed to persons authorized to process the Personal Data on a need-to-know basis (including employees).
4.2. Each Party shall ensure that Personal Data is not disclosed or transferred to any third party without the prior explicit written consent of the other Party, except as specifically stated in this DSA or as explicitly required by law. For the avoidance of doubt, third parties as understood in this clause do not constitute and/or include Relying Party or MBR subsidiaries, subcontractors, processors or sub-processors. Each Party shall assume its own responsibilities (in full) for any disclosures to such subsidiaries, subcontractors, processors and/or sub-processors.
5.0 ACCURACY OF DATA
5.1. The Parties shall ensure that all Personal Data, as provided by you to MBR and vice versa in the ordinary course of business, are kept accurate and complete, and where necessary (including upon any MBR Instructions), updated and/or rectified.
5.2. You shall use and are authorized to use all reasonable efforts to ensure that any Personal Data, which is inaccurate or incomplete, is erased or rectified. You agree that you shall not make any other changes to the Personal Data except as agreed with MBR.
6.0 ASSISTANCE
6.1. You shall assist MBR in ensuring compliance with the obligations pursuant to (i) Article 32 of the GDPR relating to the obligation to keep Personal Data Secure, (ii) Article 33 of the GDPR relating to the obligation to notify Personal Data Breaches to the supervisory authority, (iii) Article 34 of the GDPR relating to the obligation to advise data subjects when there has been a Personal Data Breach, (iv) Article 35 of the GDPR relating to the obligation to carry out data protection impact assessment (DPIA), (v) Article 36 of the GDPR relating to the obligation of prior consultation with the supervisory authority where the DPIA indicates there is an unmitigated high risk to the processing.
6.2. You shall assist MBR in responding to Data Subjects Rights requests as required by MBR.
6.3. You shall ensure that you will respond within a reasonable timeframe, provided that the response shall be provided by not later than 48 hours, to every request of MBR for the purpose of verification in relation to the processing of Personal Data as per this DSA.
7.0 DATA BREACHES
7.1. In the case of a Data Breach, you shall immediately and, in any case, not later than 24 hours after having become aware of it, notify such Data Breach to MBR, whether or not the breach was caused by yourself.
7.2. On its part, should MBR become aware of a Data Breach that MBR believes to be your responsibility, MBR shall, within reasonable time, inform you accordingly.
7.3. When notifying MBR of the Data Breach, you shall provide MBR with all information that may be considered necessary in addressing, restricting and minimizing the effects of the Data Breach and/or preventing further Personal Data Breaches. When notifying MBR of the Data Breach, you shall provide, at least, (i) a description of the Data Breach, including in so far as is possible the categories and approximate number of data subjects concerned, and the categories and approximate number of Personal Data records concerned, (ii) the name and contact details of a person who can provide more information on the matter, (iii) a description of the likely consequences of the Data Breach, (iv) a description of the remedial measures taken by you to address the Data Breach and (v) measures to mitigate its possible adverse effects.
8.0 TRANSPARENCY
8.1. Without prejudice to your rights at law, you shall be responsible for ensuring that Data Subjects are informed of all Data Sharing activity that you shall be undertaking and their rights in accordance with Data Protection Laws
9.0 DATA PROTECTION OFFICER
9.1. You shall ensure that you have appointed a Data Protection Officer (‘DPO');
9.2. You shall communicate the name and contact details of the DPO to MBR without undue delay.
10.0 TERM AND TERMINATION
10.1. This DSA shall become effective as of the effective date of the T&Cs.
10.2. After the termination of T&Cs, the Parties shall not share any Personal Data and shall continue to be bound by all the obligations relating to the processing of any Personal Data as independent controllers.
10.3. Without prejudice to your rights at law, upon termination of the T&Cs and insofar as the processing of personal data is exclusively required for the purposes of this Agreement, the Parties shall agree upon the process to delete and/or procure deletion of all Personal Data in your possession or control.
10.4. For the avoidance of doubt, this clause shall be without prejudice to any rights or obligations that either Party may have or be subject to at law to retain and/or further process the Personal Data in its capacity as Data Controller even after termination of the T&Cs. In such a case, each Party shall independently assume responsibility for ensuring that such Personal Data may be retained and/or otherwise processed lawfully by itself.
11.0 CONFIDENTIALITY
11.1. In virtue of the above, and without prejudice to anything stipulated in the T&Cs or any separate agreement on the matter, you may become privy to confidential information (which may or may not amount to Personal Data) pertaining to MBR, and therefore you agree to ensure that you and any of your employees, consultants, or agents to whom such confidential information is lawfully disclosed and/or made available to, covenant to keep such information confidential.
11.2. MBR may also become privy to confidential information (which may or may not amount to Personal Data) pertaining to the Relying Party, and therefore, without prejudice to anything stipulated in the T&Cs or any separate agreement on the matter, MBR agrees to ensure that itself and any of its employees and/or consultants and/or agents and/or any other authorized entity to whom such confidential information is lawfully disclosed and/or made available to, covenant to keep such information confidential.
11.3. The Parties agree that the confidentiality obligations described within this DSA shall survive the termination of the T&Cs.
12.0 LIABILITY
12.1. Notwithstanding anything to the contrary contained herein and/or in the T&Cs, you shall fully indemnify and hold and keep MBR (and its directors, officers, employees, shareholders, agents and representatives, consultants) fully indemnified and harmless:
I. From and against any and all liabilities, claims, actions, proceedings, damages (including indirect damages), loss suffered (including loss of profits, revenue, business, contracts, anticipated savings) including costs of legal representation, attorney’s fees, court's fees; and/or
II. From and against any finally awarded penalties, administrative or other fines or sanctions paid or to be paid by MBR, including costs of legal representation, attorney's fees, court's fees; and/or
III. From and against any and all third-party liabilities, compensation claims, actions, proceedings, damages, loss suffered (including loss of profits, revenue, business, contracts, anticipated savings) including costs of legal representation, attorney's fees, court's fees; and/or
IV. From and against any other expenses whatsoever; suffered or incurred by MBR or awarded against MBR in relation to or as consequence of or arising out of any breach, non-compliance or non-performance of any or all of the covenants, guarantees, warranties, representations, obligations, or provisions on the Relying Party's part (or any of its subcontractors or sub-processors) contained in this DSA and/or any other agreement between the Parties involving processing of Personal Data (including but not limited to the T&Cs) and/or any applicable laws, including without limitation the Data Protection Laws.
13.0 NO WAIVER
13.1. The failure of either Party hereto to insist upon the strict adherence to any term of this DSA on any occasion shall not be considered as a waiver of any right hereunder nor shall it deprive that Party of the right to insist upon the strict adherence to that term or any other term of this DSA at some other time.
14.0 DISPUTES AND GOVERNING LAW
14.1. Notwithstanding anything to the contrary in the T&Cs, this DSA shall be subject to the laws of Malta, and any dispute on the subject matter shall be settled exclusively by the competent court(s), tribunal(s) or other adjudicating authority/ies in Malta.
14.2. Each Party irrevocably submits to the exclusive jurisdiction of the Maltese courts over any claim, dispute or matter arising under or in connection with this DSA (including non-contractual disputes or claims) or its enforceability or formation or the legal relationships established by this DSA and waives any objection to proceedings in such courts on the grounds of venue or on the grounds that proceedings have been brought in an inconvenient forum.
