← Malta

L.S. 258.04 Regolamenti dwar in-National Identity Management System

[ S.L. 258.04 NATIONAL IDENTITY MANAGEMENT SYSTEM 1 SUBSIDIARY LEGISLATION 258.04 NATIONAL IDENTITY MANAGEMENT SYSTEM REGULATIONS 1st August, 2025 LEGAL NOTICE 162 of 2025. 1.

(1)The title of these regulations is the National Identity Management System Regulations. Citation and scope.
(2)The scope of these regulations is to provide for the establishment of the National Identity Management System which shall contain electronic records of data related to the processing and issuance of identity cards and residence documents.
  1. requires: In these regulations, unless the context otherwise Interpretation. "Act" means the Identity Card and other Identity Documents Act; Cap.
  2. "Agency" means the Identity Malta Agency established by article 3 of the Identity Malta (Establishment) Order;  S.L. 595.
  3. "authorised officer" shall have the same meaning as assigned to in the Act; "biometric identifiers" means personal data resulting from specific technical processing of the facial image and fingerprints of a natural person that allows or confirms the unique identification of the said natural person; "controller" shall have the same meaning as assigned to it in Article 4
(7)of Regulation (EU) 2016/679; "facial image" means an image captured by the authorised officer during the registration phase; "identification document" shall meaning as assigned to it in the Act; have the same "identity card" means a document issued in accordance with Part A of the Act; "identity document" shall have the same meaning as assigned to it in the Act; "NIDMS" means the National Identity Management System; 2 [ S.L. 258.04 NATIONAL IDENTITY MANAGEMENT SYSTEM "personal data" shall have the same meaning as assigned to it in Article 4
(1)of Regulation (EU) 2016/679; "Regulation (EU) 2016/679" means Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation); "residence document" means a document issued in accordance with Part B of the Act. Functions of NIDMS. 3. There shall be a centralised electronic identity database known as NIDMS, which shall have the following functions: (
  1. a)electronically record personal data which is captured during the registration phase; (
  2. b)process an application and the issuance of an identity document, excluding an identification document; and (
  3. c)provide a secure source of identification of the holder of the document referred in paragraph (b). NIDMS management. 4. The Agency shall be responsible for the technical and operational management of NIDMS as referred to in regulation 3. Data protection.  Cap. 586. 5.
(1)These regulations shall not prejudice the applicability of Regulation (EU) 2016/679 and of the Data Protection Act, including the regulations made thereunder and the fundamental rights and freedoms of the data subjects.
(2)The Agency acting in its capacity of a controller in accordance with Article 4
(7)of the Regulation (EU) 2016/679 shall perform the relevant data processing operations which are limited to the extent needed for the purposes of these regulations and to what is necessary and proportionate to the objectives pursued by the Agency.
(3)For the purposes of these regulations, the processing of personal data, including the processing of special categories of personal data, shall fully comply with the principles relating to the processing of personal data pursuant to Article 5 of Regulation (EU) 2016/
  1. Data stored in NIDMS.
  2. In addition to the data prescribed in Part A and Part B of the Act, there shall also be stored in NIDMS the biometric identifiers of each person applying for an identity document excluding an identification document: Provided that the authorised officer may exempt an applicant from having his fingerprints captured where this is NATIONAL IDENTITY MANAGEMENT SYSTEM [ S.L. 258.04 3 specifically provided for by law.
  3. The biometric identifiers shall be captured in accordance with the applicable mandatory technical specifications established by law and shall be stored in a highly secure manner in the NIDMS. Capture and storage of biometric identifiers.
  4. The biometric identifiers shall be captured for the purpose of personalisation of an identity card or a residence document. Purpose of capture of biometric identifiers.
  5. The biometric identifiers captured for the purpose of being included in a registration certificate, a residence card, a permanent residence certificate or a permanent residence card as defined in the Free Movement of European Nationals and their Family Members Order shall only be retained in the NIDMS until the date of collection of the document by the holder: Retention of biometric identifiers.    S.L. 460.
  6. Provided that the said period shall not be longer than ninety
(90)days from the date of issue of such document. 10. Upon the lapse of the date or of the period established in regulation 9, biometric identifiers stored in the NIDMS shall be immediately erased or destroyed: Deletion of biometric identifiers. Provided that prior to erasing or destroying the biometric identifiers of an identity document referred to in regulation 9, the facial images shall be retained in the NIDMS beyond such date or period for identification purposes: Provided further that the said facial images shall not qualify as biometric identifiers and are not processed through specific means allowing the technical unique identification or authentication of a natural person. 11.
(1)The controller, taking into account the nature, scope, context and purposes of processing as well as the risks of varying likelihood and severity for the rights and freedoms of the data subjects, both at the time of the determination of the means for processing and at the time of the processing itself, shall implement appropriate technical and organisational measures, in an effective manner and to integrate the necessary safeguards into the processing, in order to protect the rights of the data subjects and to ensure a level of security appropriate to the risk.
(2)The data protection officer designated by the controller in accordance with Article 37 of Regulation (EU) 2016/679 shall be involved and consulted properly and in a timely manner on all issues in relation to the protection of personal data processed for the purposes of these regulations.
(3)For the purposes of ensuring and to be able to demonstrate that the processing of personal data is performed in Appropriate safeguards. 4 [ S.L. 258.04 NATIONAL IDENTITY MANAGEMENT SYSTEM accordance with the provisions of Regulation (EU) 2016/679, the controller shall implement the appropriate data protection policies, which policies shall be periodically reviewed and updated where necessary.

🔗 Għas-sors uffiċjali

AI explanation based on the official legal text. Indicative, not a substitute for legal advice.