Accessibility

Font size

Filters

Highlight

Colour

Zoom

FREQUENTLY ASKED QUESTIONS

This section has been designed to provide clear, practical answers to some of the most common questions about data protection and information rights. Whether you are an individual seeking to understand how your personal data is used, or an organisation looking for guidance on your obligations, these FAQs aim to explain key concepts, rights, and responsibilities in a straightforward and accessible way.

References to the ‘Gibraltar GDPR’ are to the Gibraltar General Data Protection Regulation – legislation available here.

References to the ‘DPA 04’ are to the Data Protection Act 2004 – legislation available here.

This document is not intended to provide legal advice, replace relevant legislation, or to give a complete account of Gibraltar’s data protection law or any relevant area. Readers should consult the legislation and/or seek legal advice as appropriate.

Gibraltar’s data protection framework is set out in the Gibraltar GDPR and the DPA 04. Together, these laws govern how personal data must be processed by organisations and public authorities, ensuring that individuals’ information is handled lawfully, fairly, and transparently. The legislation provides individuals with specific rights over their personal data and places obligations on organisations to protect that data, promote accountability, and respect privacy in line with internationally recognised data protection standards.

Section 123 of the DPA 04 appoints the Gibraltar Regulatory Authority (GRA) as Information Commissioner. Schedule 12 of the DPA 04 sets out the Information Commissioner’s powers. In general, the Information Commissioner is responsible for ensuring that individuals and organisations process personal data appropriately, respect people’s privacy, and comply with data protection laws. His office assists members of the public understand their data protection rights and may investigate complaints where there are concerns about how personal data has been processed.

Personal data is defined within Article 4(1) of the Gibraltar GDPR. It includes any information that can identify a living individual, either directly or indirectly. This can include obvious things like your name, address, or phone number, as well as less obvious details such as your email address, online identifiers, location data, or even opinions about you.

Article 9 of the Gibraltar GDPR specifically governs special categories of personal data. Special categories of personal data are types of information that are considered particularly sensitive and therefore require extra protection under the Gibraltar GDPR. This includes data about your health, racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic or biometric data, and sexual orientation. Because this information is more sensitive, organisations must have a clear and lawful reason for processing it and take additional steps to protect it.

Excessive information is personal data that is not necessary to fulfil the purpose for which it is being collected. Organisations should be able to justify why they need each piece of personal data collected. For example, when you visit a doctor, they may need your medical history and symptoms to provide proper care, but they don’t need to know your favourite music or your bank account balance. Collecting unnecessary details is considered excessive and goes against data protection principles such as the concept of ‘data minimisation’ as found within Article 5(1)(c) of the Gibraltar GDPR.

There is no prescribed period for which you can keep personal data, as it will very much depend on the particular circumstances including the type of personal data and purpose of processing. Personal data should however only be kept for as long as it is necessary for the purpose it was collected. Once the information is no longer needed, organisations are required to delete, anonymise, or securely dispose of it. Retaining data for longer than necessary can put individuals’ privacy at risk and may be a breach of data protection legislation, including Article 5(1)(e) of the Gibraltar GDPR which introduces the concept of ‘storage limitation’. It is therefore important for organisations to have clear retention policies in place of each type of data they process.

The rights provided under the Gibraltar GDPR are essential for giving individuals control over their personal data. They help ensure that people know how their data is being used, can correct inaccuracies, and can challenge or limit processing that they consider unfair. By protecting these rights, the law promotes transparency, accountability, and trust between individuals and organisations, while safeguarding privacy in an increasingly digital world.

Data subjects in Gibraltar have the following rights:

Click on the above links to access the applicable guidance note, infographic or explanatory video.

Importantly however, there are some exemptions that may apply in respect of the rights set out above, which means that, in certain circumstances, organisations may not be required to uphold these rights. For further information on exemptions please see the Information Commissioner’s Guidance note here.

Although consent is one of the bases organisations may rely on to process personal data, under Gibraltar law, personal data can also be processed for other reasons as set out in law. Article 6 of the Gibraltar GDPR sets out the relevant reasons organisations can look to rely on. Each potential reason is known as a ‘lawful basis’, and they include aspects such as fulfilling a contract, complying with a legal obligation, protecting someone’s vital interests, carrying out tasks in the public interest, or pursuing legitimate interests. It is up to the organisation to assess whether any of the lawful bases apply to their intended processing. If none apply, then the personal data should not be processed. Further guidance is available here and here.

Under the Gibraltar GDPR, organisations must have a lawful reason for processing personal data. The ‘lawful bases’ are found under Article 6 of the Gibraltar GDPR and include:

  • Contract – processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract.
  • Legal obligation – processing is necessary for compliance with a legal obligation to which the controller is subject.
  • Vital interests – processing is necessary to protect someone’s life.
  • Public task – processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller.
  • Legitimate interests – processing is necessary for legitimate interests pursued by the organisation or a third party, except where such rights are overridden by those of the data subject, especially where children are involved.
  • Consent – you have given clear permission for your data to be processed for specific purposes.

Having a lawful basis ensures that personal data is handled responsibly and in accordance with the law. Further guidance is available here.

Data protection legislation does not apply to the personal data of deceased individuals. This means that if your concern relates to the data of someone who has passed away, our office may be unable to investigate or take action, as it falls outside the scope of data protection law.

Yes, organisations can view information that is publicly available on social media platforms, such as posts, profiles, or comments that are visible to anyone. However, they must still follow data protection rules. This means they must use your information fairly, lawfully, and only for a legitimate reason. For example, a potential employer might check publicly available information as part of a background check, but they cannot collect or use personal data in a way that is misleading, excessive, or discriminatory. Similarly, any decisions made based on this information should be reasonable and justifiable.

In short, just because information is online it does not mean it can be used freely without consideration of privacy and data protection laws.

If your organisation experiences a data breach, you must act quickly to limit any potential harm. First, make reasonable attempts to contain the breach and assess its impact on the personal data and individuals involved.

Under Article 33 of the Gibraltar GDPR, personal data breaches must be reported to the Information Commissioner unless the breach is unlikely to result in a risk to the rights and freedoms of relevant individuals. Where a breach meets the reporting threshold, it must be reported without undue delay (i.e., within 72 hours), and in some cases, affected individuals must also be informed. Please see here for relevant guidance and the Information Commissioner’s Data Breach Notification Form.

Even where all information relating to a data breach is not yet available, where the breach is expected to meet the reporting threshold, it should be reported providing any available information, even if the initial report is followed thereafter by additional information (i.e. tiered reporting).

Keeping clear records of the breach, your assessment, and the steps taken to address it is essential. Acting promptly and transparently helps protect individuals’ data and demonstrates compliance with your legal obligations. Further guidance is available here.

Articles 5(1)(f) and 32 of the Gibraltar GDPR require organisations to keep personal data secure. This means putting sensible safeguards in place to prevent information from being lost, damaged, altered, accessed, or shared without permission. The level of security should reflect matters such as the type of personal data being processed, purposes of processing, potential severity of any impact if something went wrong, available technology, and the resources (financial or otherwise) reasonably available to the controller.

Security isn’t just about technology. Whilst it may include technical measures like passwords, encryption, and secure systems, it also includes organisational measures such as limiting who can access files, locking paper records away, controlling access to computers and servers, having appropriate policies and procedures in place, and appropriately training relevant staff on data protection matters.

Organisations should use up-to-date technology where appropriate and take reasonable steps to protect personal data at all times. Further guidance is available here.

Sometimes, yes. Employers may monitor work emails, internet use, or other workplace systems for legitimate reasons, such as protecting company systems, ensuring legal compliance, investigating misconduct, or maintaining security. However, this monitoring must be lawful, fair, and transparent. This means your employer should tell you in advance if monitoring may take place, explain why it is necessary, and limit it to what is strictly required. Employers should not carry out excessive or intrusive monitoring. Further guidance on Data Protection in the Employment Context is available here.

Yes, in accordance with Article 15 of the Gibraltar GDPR, you have the right to submit a SAR to a data controller. This allows you to ask the data controller for information about the personal data they hold about you, how it is used, who it is shared with, and how long it is kept.

As prescribed by Article 12 of the Gibraltar GDPR, data controllers are required to respond to a SAR within a set timeframe, usually one month, although this period may be extended by two further months where necessary, considering the complexity and number of requests. Organisations are also able to verify the identity of the requester prior to fully responding to a SAR. Notably, the clock will stop until reasonable identity verification documentation is provided.

The data controller must provide any relevant information in a clear and accessible format. Note that this does not always mean you will receive exact copies of all documents; organisations can provide summaries, extracts, redacted copies, or narrative descriptions, as long as the information accurately reflects the personal data they hold about you. Further guidance is available here.

Importantly also, there are some exemptions that may apply. In certain circumstances, organisations may not be required to provide data subjects with relevant information. For further information on exemptions please see the Information Commissioner’s Guidance note here.

In addition, where a SAR is found to be manifestly unfounded or excessive, Article 12(5) of the Gibraltar GDPR allows the organisation to charge a reasonable fee or to refuse to act on it. The organisation bears the burden of demonstrating the manifestly unfounded or excessive character of the request.

Many organisations provide a specific form for submitting a SAR, but the law does not require you to use a form. Often the simplest and most effective way is to either use the form as requested, or to make a written request directly to the organisation (e.g. via email).

Directing your SAR to the organisation’s data protection officer (“DPO”) would be the preferred option (if they have one) as it will help ensure your request reaches the right place and can be dealt with promptly. The DPO’s details should be available within the organisation’s Privacy Notice. Note however that a SAR can be made to anyone within the organisation. It is therefore important for organisations to have adequate procedures for handling SARs as well as relevant staff training.

Also, while SARs can be made verbally, keep in mind that without written evidence it may be harder to prove the request was made. By making the request in writing this creates an audit trail of your request.

Further guidance on SARs is available here.

You can request all the personal data an organisation holds about you through a SAR. However, this does not always mean you will receive every single document in full.

Organisations may redact or remove information that relates to other individuals or sensitive content, to protect their privacy. In addition, where an exemption applies, organisations may not be obliged to provide you with relevant data. For further information on exemptions please see the Information Commissioner’s Guidance note here.

To make your request more effective and to allow the organisation to process your request more quickly, it is advisable to be specific about the type of information you are looking for. Narrowing the scope of your SAR by for example asking for emails related to a particular project or records from a certain department or time period helps the organisation provide the information more quickly and accurately. Further guidance is available here.

Notably, where a SAR is found to be manifestly unfounded or excessive, the organisation may refuse to act on it but bears the burden of demonstrating the manifestly unfounded or excessive character of the request.

In accordance with Article 12 of the Gibraltar GDPR, data controllers must respond to SARs within one month of receipt of the request, although this one-month time frame can be extended by up to two further months if, for example, the request is complex. However, if the data controller requires this two-month extension of time to fulfil the SAR, they must inform the individual that such extension is required, giving reasons for the delay before the expiry of the initial one-month period.  The data controller does not need the permission of the individual or of the Information Commissioner for this extension of time, although they must ensure any extension is reasonable. Further guidance is available here.

Data protection law entitles you to access to your own personal data and not that of any third party. Should someone wish to request the personal data of another individual, they will need to provide written evidence that the relevant individual has provided them with the necessary authority to act on their behalf in requesting their personal data. Keep in mind that the organisation to which the request is being made must be satisfied with the letter of authority (or other similar documentation) before they provide any relevant information, as they are responsible for keeping personal data secure.

For children, any person with parental responsibility can make requests on behalf of a child, but only if it is in the best interests of the child. The data still belongs to the child and it should be taken into consideration that older children for example may be able to make their own requests.

Further guidance is available here.

Our office sometimes receives reports of organisations requesting that an individual submit a SAR to another organisation for employment vetting or similar purposes. Organisations and individuals should follow established vetting procedures in this regard and not rely on SARs. Under sub-sections 18(5) and 18(6) of the DPA 04, it is in fact a criminal offence, in certain circumstances and in relation to certain information to require another person (or a third party) to submit a SAR.

Article 12(5) of the Gibraltar GDPR provides that information provided in response to SAR shall be provided free of charge. However, the provision follows to say that where requests from a data subject are manifestly unfounded or excessive, in particular because of their repetitive character, the controller may charge a reasonable fee taking into account the administrative costs of providing the information. The controller shall bear the burden of demonstrating the manifestly unfounded or excessive character of the request.

There is no definitive answer as to what a ‘reasonable fee’ is, and each case needs to be assessed on its own merits.

Under Article 16 of the Gibraltar GDPR, you have the right to ask an organisation to correct personal data if it is inaccurate or incomplete. The data must be factually incorrect (e.g., a wrong date of birth or address) which can be easily verified and corrected.

If you believe your data is incorrect, the first step is to contact the organisation directly, clearly explaining what information you think is wrong or missing. Directing your request for rectification to the organisation’s data protection officer (“DPO”) would be the preferred option (if they have one) as it will help ensure your request reaches the right place and can be dealt with promptly. The DPO’s details should be available within the organisation’s Privacy Notice. Note however that a request can be made to anyone within the organisation. It is therefore important for organisations to have adequate procedures for handling data requests as well as relevant staff training.

Notably, if the data relates to someone else’s opinion about you, it is treated differently. Opinions are not facts, so the organisation is not required to change them, even if you disagree. However, you can ask the organisation to include a statement explaining your view. This allows your perspective to be recorded without altering the original opinion, which may be important for matters such as witness statements in incidents or disputes.

Governed by Article 35 of the Gibraltar GDPR, a Data Protection Impact Assessment (DPIA) is a tool that helps organisations identify and reduce the risks of processing personal data. By assessing matters such as the necessity of the particular processing, the risks involved, and any relevant safeguarding and security measures, DPIA’s assist in making sure that new or existing projects, systems, or technologies handle personal data responsibly and comply with the Gibraltar GDPR.

A DPIA is required when the processing is likely to result in a high risk to people’s privacy, such as when using new technologies to monitor individuals, handling sensitive personal data (also known as special category data – see Article 9 of the Gibraltar GDPR in this regard) on a large scale, or combining multiple data sources.

By carrying out a DPIA, organisations can prevent problems before they happen, mitigate any risks, and demonstrate accountability. Further guidance on DPIAs is available here.

Data controller and data processor are defined by Article 4 of the Gibraltar GDPR.

A data controller is the person or organisation that, either alone or jointly with others, decides why and how personal data is used. They are ultimately responsible for ensuring the information is handled correctly.

A data processor is a person or organisation that handles or processes personal data on behalf of a controller, following their instructions. Processors do not decide how the data is used; they simply carry out the tasks the controller asks them to.

Articles 24 to 31 of the Gibraltar GDPR deal with the general obligations of controllers and processors. Further guidance is available here.

Deceptive design patterns, sometimes called “dark patterns,” are methods used within websites or apps to manipulate users into doing something they might not want to do. For example, a website might:

  • Make it hard to unsubscribe from a newsletter
  • Automatically add items to your shopping cart
  • Hide privacy or cookie settings in confusing menus
  • Use misleading buttons or wording to get you to share personal information

These designs take advantage of people’s habits or attention and can lead to sharing more data than intended. The law encourages organisations to be clear, fair, and transparent when asking for personal information or consent online. Further guidance is available in this explanatory video.

Cookies are small text files stored on a device like a computer, phone, tablet, or even smart devices such as TVs that help websites remember information, including personal data. Think of them like little post-it notes a website sticks on your device to help it remember your preferences or what you were doing the last time you visited.

Cookies can do useful things, like:

  • Remembering what’s in your online shopping cart,
  • Keeping you logged in to your bank or other accounts,
  • Helping websites personalise content or show ads based on your interests.

The word “cookies” is often used broadly to describe other types of tracking technologies too. For example, there are flash cookies (like hidden post-its), local storage files, or device fingerprinting, which can track your activity across devices or websites.

In short, cookies help websites work more smoothly for you, but they can also be used to track your browsing habits. Further guidance on cookies is available here.

In accordance with the Regulation 5 of the Communications (Personal Data and Privacy) Regulations 2006 (the “Privacy Regs”), which can be found here, organisations must:

  • tell individuals which cookies will be set;
  • explain what the cookies will do; and
  • obtain consent from individuals to store a cookie on their device.

There are only two limited exceptions where consent is not required:

  • Strictly necessary cookies – these are essential for the website or app to work properly, such as remembering items in an online shopping basket or allowing a user to log in.
  • Communication cookies – these are used to help information travel across the network, for example to balance website traffic between servers.

Cookies used for things like advertising, analytics, or tracking user behaviour are not exempt and therefore require consent. Furthermore, whilst not all cookies collect personal data, in instances where personal data is collected, it is important that, besides the Privacy Regs, the requirements of the Gibraltar GDPR and DPA 04 are also upheld, including having a relevant lawful basis. See the Information Commissioner’s Guidance Note here for more information on lawful bases.

Importantly, users must not be encouraged or prompted in any way to provide consent for non-essential cookies and must be able to change or withdraw their consent at any time. It must be just as easy to withdraw consent as it is to give it. They should not have to search through a website or app to find how to change their cookie settings. Further guidance on cookies is available here.

If your website or app uses cookies or tracking, you must clearly explain this to users before any cookies are placed on their device. Most websites do this by using a cookie banner, pop-up, or notice that appears when someone first visits the site. This lets users understand what cookies are being used and gives them the chance to manage their cookie preferences.

If your website only uses strictly necessary cookies (e.g. cookies needed for the site to work properly), then you may not need a cookie banner or consent tool. However, it is still good practice to explain this in a cookie policy or privacy notice, so users know what cookies are in use and why. Further guidance is available here.

Direct marketing is when an organisation contacts individuals personally and directly to promote a product or service, or to encourage them to ask for more information. This can for example be done via communication methods such as emails, text messages, phone calls, or letters sent to an individual personally.

Whilst data protection law still applies where personal data is processed (e.g. where marketing is directed to a named individual), when done through electronic means, direct marketing is also governed by the Communications (Personal Data and Privacy) Regulations 2006 (the “Privacy Regs”), available here. For example, direct marketing by way of e-mail is governed by Regulation 23 of the Privacy Regs.

Not every organisation is required to have a Data Protection Officer (DPO). Under Article 37 of the Gibraltar GDPR, a DPO must be appointed if your organisation:

  • Is a public authority or body (except for courts acting in a judicial capacity), or
  • Carries out large-scale monitoring of individuals, or
  • Processes large amounts of sensitive personal data on a regular basis.

Even if it’s not legally required, having a DPO can help ensure your organisation manages personal data responsibly, stays compliant with the law, and provides a point of contact for individuals with data protection questions. Further guidance on data protection officers is available here.

If the CCTV footage can identify individuals then it is considered to contain personal data and is therefore subject to data protection rules. This includes not only clear images of people but also recordings where someone could be recognised indirectly. Because CCTV may capture personal data, organisations using it must handle the recordings responsibly, ensure they have a lawful reason for monitoring, and store the footage securely. Further guidance on CCTV is available here.

If the CCTV footage records areas beyond your private property and is used other than for personal or household reasons (see Article 2(2)(a) and Recital 18 of the Gibraltar GDPR), you must inform individuals that CCTV is in operation. This is typically done through clear signage that states:

  • That CCTV is in use,
  • The purpose of the recording (e.g., crime prevention),
  • Who operates the system, and
  • Contact details for further information.

Providing this information ensures that your use of CCTV is transparent, assists in complying with the Gibraltar GDPR, and respects individuals’ privacy. Further guidance on CCTV is available here.

Yes, you are allowed to install CCTV at your private residence for security purposes. However, you must only record what is necessary (e.g., your property and immediate entrance, not public areas or neighbours’ property). If your system records areas beyond your private property, such as public streets, shared corridors, or a neighbour’s property then data protection laws apply. This means for example that:

  • You must inform people that CCTV is in use through clear signage,
  • You must store footage securely, not share it unnecessarily, and only keep it as long as needed, and
  • You must only use the footage for legitimate purposes, such as protecting your home or investigating incidents.

Following these steps helps protect your privacy and the privacy of others while using CCTV responsibly. Further guidance on CCTV is available here.

Audio recording is considered more intrusive than video alone and may capture private conversations, which raises significant data protection concerns. Audio recording on CCTV systems is therefore generally not acceptable. If however you feel audio is necessary, you must have a lawful reason, clearly inform people that audio is being recorded, and ensure strict safeguards are in place to protect privacy. Further guidance on CCTV is available here.

Schools and clubs may wish to take photographs, or arrange for photographers, to capture events and special occasions. As with all personal data, the relevant organisation must have a lawful basis under the Gibraltar GDPR before taking or using photographs. See the Information Commissioner’s Guidance Note here for more information on lawful bases.

When deciding whether to process their personal data, the best interests of the child should always remain at the forefront. If a school decides that consent is the appropriate lawful basis for taking and publishing photographs, it will usually need to obtain consent from a person with parental responsibility, depending on the child’s age. In practice, this can be handled in simple and practical ways. For example, for a sports day or school outing, a school might inform parents in advance that photographs will be taken and use clear visual indicators, such as different-coloured stickers, to show which children may or may not be photographed.

Where a photograph of a child is published, even where a lawful basis exists, it is good practice where the child, or a personal with parental responsibility, requests its removal, to make reasonable efforts to remove the photograph or otherwise make the individual non-identifiable from the image.

Notably, Schedule 2 Part 5 of the DPA 04 makes an exemption where publication of personal data is for journalistic purposes. This may apply depending on the context.

A privacy notice is a document or statement that informs individuals how an organisation collects, uses, stores, and shares their personal data. It explains what data is being collected, why it’s needed, who it may be shared with, how long it will be kept, and the individual’s rights over that data. Generally, privacy notices are the mechanism used to ensure compliance with Articles 13 and 14 of the Gibraltar GDPR. Further guidance on privacy notices is available here.

Any organisation that collects or processes personal data must provide a privacy notice. This includes for example businesses, schools, recreational clubs, healthcare providers, government departments, and online services. The notice should be given at the time the data is collected or, if the data was obtained from sources other than the data subject, as soon as possible thereafter.

Providing a privacy notice ensures transparency and helps individuals understand how their personal data is being used. Further guidance on privacy notices is available here.

Whilst the terms are not defined in law, ‘privacy notice’ and ‘privacy policy’ are generally used to refer to documents that serve different purposes:

  • In practice, a privacy notice is aimed at data subjects whose data may be processed by the organisation. It explains in simple terms how and why their personal data is collected, used, stored, and shared. It also informs people of their rights and how they can exercise them.
  • In practice, a privacy policy is usually an internal document, aimed at employees or other relevant personnel within an organisation. It sets out the rules, procedures, and responsibilities for personnel to ensure the organisation complies with data protection laws.

Further guidance is available here.

The guidance notes available on the Gibraltar Regulatory Authority’s website can be found here. Amongst other important topics, there is a Guidance Note containing a Personal Data Inventory Tool, Readiness Checklist and Policy Guide, which can be accessed here

In addition, the website has a designated section, called the SME Resource Hub, which provides additional guidance and resources specifically for small to medium sized enterprises. This section can be found here.

The Information Commissioner does not deal with claims for compensation for data protection breaches. Whist our office may investigate complaints and take enforcement action if an organisation is found to be in breach of Gibraltar data protection laws, under Sections 173 and 174 of the DPA 04, individuals may pursue compensation through the courts. If you believe your personal data has been misused and you have suffered harm as a result, it is recommended that you seek independent legal advice.

You can make a complaint directly to the Information Commissioner’s office by submitting a Complaint Form as found on the Gibraltar Regulatory Authority website.

Complaints are typically received from individuals who have a concern about the use of their personal data by a third party e.g. an organisation, individual or public body. These are reported to the Information Commissioner through the Complaint Form as found on the Gibraltar Regulatory Authority website.

Breach Notifications on the other hand are reports to the Information Commissioner by organisations who themselves feel they have breached, or suffered a breach, of data protection legislation. There are specific rules within the Gibraltar GDPR that govern breach notifications, with further information available here. Breach Notifications are submitted to the Information Commissioner through the Breach Notification Form as found on the Gibraltar Regulatory Authority website.

The Information Commissioner deals with individuals regarding their own personal data and data protection rights. If you wish to act on behalf of someone else, a signed letter of authority from that individual will be required. The Information Commissioner will need to contact the individual directly to confirm their authorisation, so their contact details must be provided.

The Information Commissioner will assess your complaint and decide whether further investigation is appropriate. Not every complaint will lead to a formal investigation. For further information, please refer to our Complaints Procedure.