Welcome to the Gibraltar Regulatory Authority website
INVESTIGATIONS UNDERTAKEN BY THE INFORMATION COMMISSIONER
As part of his duties, the Information Commissioner (the “Commissioner”) conducts investigations on the application of data protection law in Gibraltar. Investigations may be as a result of information obtained that provokes compliance concerns, a complaint lodged or information/complaint referred by another data protection authority or other public authority. Investigations are also undertaken into breach notifications received, with appropriate action taken where necessary and appropriate.
Gibraltar’s data protection legislation was updated and strengthened on 25th May 2018 when the EU General Data Protection Regulation 2016/679 (the “GDPR”) came into force and the Data Protection Act 2004 (the “DPA”) was updated to complement the GDPR and transpose the Law Enforcement Directive 2016/680.
The document below titled “Investigations and Enforcement” provides a table listing all the investigations conducted by the Commissioner since 25th May 2018. Within the table there are short summaries relating to each referenced investigation. These include details of whether the Commissioner took any enforcement action.
The document below titled “Breach Notifications and Enforcement”, provides a table listing only the breach notifications (relating to Article 33 of the GDPR and section 76 of the DPA), received by the Commissioner since the 25th May 2018, in respect of which the Commissioner has taken enforcement action.
Please note that references to the DPA and the GDPR within the below linked documents are relevant to the legislation as defined above.