Accessibility

Font size

Filters

Highlight

Colour

Zoom

DATA PROTECTION INTRODUCTION

The Gibraltar Regulatory Authority (the “Authority”), as the Information Commissioner, recognises the important and crucial role of data protection in today’s world.

What is Data Protection?

Data protection relates to the processes and controls used to safeguard information about individuals and their privacy. The Gibraltar GDPR and the Data Protection Act 2004 (“DPA”) primarily govern how organisations (both private and public) and in applicable cases how individuals, process information about individuals, whether by automated means or not, including but not limited to, the collection, recording, structuring, storage, use and disclosure or transfer of personal data to third parties.  

Legislative Overview

25 May 2018 up to and including 31 December 2020 - The EU General Data Protection Regulation 2016/679 (the “EU GDPR”) governed data protection law within Gibraltar, supplemented by the DPA. Notably, Part III of the DPA deals with aspects relating to the European Union (the “EU”) Law Enforcement Directive 2016/680, a piece of EU legislation, parallel to the EU GDPR but which specifically deals with the processing of personal data by data controllers for ‘law enforcement purposes’ – which falls outside of the scope of the EU GDPR.

1 January 2021 up to and including 14 July 2026 - Following the United Kingdom’s (the “UK”), and consequently Gibraltar’s exit from the EU and the end of the Brexit transition period (i.e. as of 1 January 2021), Gibraltar implemented the Gibraltar GDPR by virtue of section 6 of the European Union (Withdrawal) Act 2019. This in effect made the previously applicable EU GDPR provisions local law by mirroring the same. There were however some differences as set out in the Data Protection, Privacy and Electronic Communications (Amendments etc) (EU Exit) Regulations 2020. Through the Gibraltar GDPR and the DPA, which must be read together, Gibraltar maintained the data protection standards that applied prior to 1 January 2021, when the EU GDPR and the EU Law Enforcement Directive were in force.

15 July 2026 onwards - Following an agreement on Gibraltar between the UK and the EU, the Gibraltar GDPR was amended to re-instate the EU GDPR, albeit still with some derivations. This was done through the Data Protection Regulations 2026. For further information in this regard, please refer to our dedicated Brexit section here and/or our Legislation section here.  The amended Gibraltar GDPR and the DPA must continue to be read together.

In addition, the Communications (Personal Data and Privacy) Regulations 2006 are applicable to electronic communications containing or making use of personal data, and, as the name suggests, the Data Protection (Search and Seizure) Regulations 2006 govern the rules surrounding search and seizure by the Information Commissioner.

What is our role?

The DPA designates the Authority, as Information Commissioner, to be the supervisory authority in Gibraltar. The general functions conferred on the Information Commissioner in relation to the tasks and powers of the supervisory authority are assigned under Part V and VI of the DPA. 

The Authority is thereby the independent statutory body responsible for the enforcement of the Gibraltar GDPR and the DPA, and carries out the functions assigned to it, to uphold the rights of individuals and their privacy. Amongst other things, this includes the provision of guidance on data protection related matters and the investigation of complaints, as well as raising awareness on privacy issues. The tasks conferred on the Information Commissioner are undertaken by the Information Rights Division.