ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) [ S.L. 330.20 1 SUBSIDIARY LEGISLATION 330.20 MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) REGULATIONS 17th Januar
Article 46
(
- a)of the DORA Regulation; and (
- b)the European Securities and Markets Authority (ESMA) as the designated competent authority for: (
- i)trade repositories in accordance with Article 22 of Regulation (EU) No 648/2012,
Article 46
(
- h)of the DORA Regulation; (
- ii)credit rating agencies in accordance with Article 21 of Regulation (EC) No 1060/2009,
Article 46
(n) of the DORA Regulation; and (iii) administrators of critical benchmarks in accordance with Articles 40 and 41 of Regulation (EU) 2016/1011,
Article 46(o) of the DORA Regulation.
(3)The Authority shall exercise all the functions, obligations and powers, and shall satisfy all the requirements imposed on competent authorities by the DORA Regulation, including the 3 4 [ S.L. 330.20 MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) receiving of any reports of any major ICT-related incidents reports and any voluntary notifications of significant cyber threats, in accordance with Article 19 of the DORA Regulation.
(4)For the purposes of Article 32
(5)of the DORA Regulation, the Authority shall be the relevant competent authority whose staff member shall be the high-level representative for the purposes of Article 32
(4)(b) of the DORA Regulation.
(5)Without prejudice to sub-regulation
(1)and to any other power conferred on the Authority under any other relevant law, the Authority may, for the better implementation of the DORA Regulation, exercise any of the powers conferred to it under the Act.
(6)In terms of Article 26
(10)of the DORA Regulation, without prejudice to the power to identify the financial entities that are required to perform Threat-Led Penetration Testing, the Authority may delegate the exercise of some or all of the tasks referred to in Articles 26 and 27 of the DORA Regulation to another national authority in the financial sector, and any delegation so made shall be published on the Authority’s official website without undue delay. Cooperation and exchange of information. 5.
(1)In the case of receival of any major ICT-related incidents and any voluntary notifications of significant cyber threats made by credit institutions classified as significant, in accordance with Article 6
(4)of Regulation (EU) No 1024/2013, the Authority shall, in terms of the third sub-paragraph of Article 19
(1)and the second subparagraph of Article 19
(2)of the DORA Regulation, immediately transmit the said reports and notifications to the European Central Bank (ECB).
(2)For the purposes of fulfilling its duties and responsibilities as set out in Article 19 of the DORA Regulation, the Authority may transmit to the national CSIRT any major ICT-related incident reports and any voluntary notifications of significant cyber threats in terms of Article 19 of the DORA Regulation.
(3)The Authority shall have the power to disclose any major ICT-related incidents reports and any voluntary notifications of significant cyber threats or any other information related thereto, to any other relevant body or authority in accordance with Article 19 of the DORA Regulation and with article 17 of the Act. Power of the Authority to issue Rules. 6. The Authority may issue Rules in accordance with article 16
(2)(a) and article 20A
(3)of the Act for the better carrying out of the provisions of these regulations and the DORA Regulation. Supervisory powers of the Authority. 7. Without prejudice to any other power assigned to the Authority under the Act, these regulations, the DORA Regulation and any other applicable law, the Authority shall also have the power to: MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) [ S.L. 330.20 5 (
- a)access any document or data held in any form that the Authority considers relevant for the performance of its duties and receive or take a copy of it; (
- b)carry out on-site inspections or investigations, which shall include: (
- i)summoning representatives of the financial entities for oral or written explanations on facts or documents relating to the subject matter and purpose of the investigation and to record the answers; and (
- ii)interviewing any other natural or legal person who consents to be interviewed for the purpose of collecting information relating to the subject matter of an investigation; and (
- c)require corrective and remedial measures for breaches of the requirements of the DORA Regulation, the Act, these regulations or any other regulations or rules issued thereunder which implement the DORA Regulation: Provided that any decision so taken under this paragraph shall be properly reasoned: Provided further that where such corrective and remedial measures are taken with respect to a legal person, the Authority shall have the power to apply the said corrective and remedial measures, subject to any conditions that may be provided for in any other law, to members of the management body, and to other individuals who under national law are responsible for the breach. 8.
(1)Without prejudice to any other power of the Authority conferred to it under the DORA Regulation, the Act or any regulations issued thereunder, including these regulations, where the Authority is satisfied that a person’s conduct amounts to a breach of any of the provisions of the DORA Regulation, the Act, these regulations, or of any regulations or Rules made thereunder and implementing the provisions of the DORA Regulation, or otherwise that a person has contravened or failed to comply with any condition, obligation, requirement, order or directives made or given by the Authority under any of the provisions thereof, including failure to cooperate in an investigation or an on-site inspection, the Authority may, by notice in writing and without recourse to a court hearing, impose on any such person administrative measures and, or administrative penalties which may not exceed one hundred and fifty thousand euro (€150,000) for each infringement or failure to comply, as the case may be. The provisions of article 16
(4)of the Act shall apply mutatis mutandis. The Authority’s powers to impose administrative penalties and other administrative measures. 6 [ S.L. 330.20 MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA))
(2)Without prejudice to the generality of sub-regulation
(1), the Authority shall also have the power to impose the following administrative penalties and administrative measures for any breach of any of the provisions of the DORA Regulation, the Act, these regulations and any regulations or Rules issued thereunder implementing the DORA Regulation: (
- a)issue an order requiring the natural or legal person to cease the conduct in breach of the DORA Regulation, the Act, any regulations or rules issued thereunder implementing the DORA Regulation, and to desist from a repetition of such conduct; (
- b)require the temporary or permanent cessation of any practice or conduct that the Authority considers to be contrary to the provisions of the DORA Regulation, the Act, any regulations or Rules issued thereunder implementing the DORA Regulation, and prevent repetition of such practice or conduct; (
- c)adopt any type of measure, including of a pecuniary nature, permitted in terms of the DORA Regulation, the Act or these regulations, to ensure that financial entities in terms of the DORA Regulation continue to comply with their legal requirements; (
- d)require existing data traffic records held by a telecommunication operator, where there is a reasonable suspicion of a breach of the DORA Regulation, the Act, these regulations and any regulations or rules issued thereunder implementing the DORA Regulation, and where such records may be relevant to an investigation into such breaches; and (
- e)issue public notices, including public statements, which indicate the identity of the natural or legal person and the nature of the breach: Provided that where administrative penalties and administrative measures are taken in terms of this sub-regulation with respect to a legal person, the Authority shall have the power to apply such penalties and measures, subject to any conditions that may be provided for in any other law, to members of the management body, and to other individuals who under national law are responsible for the breach.
(3)Administrative penalties and other administrative measures imposed by the Authority shall be effective, proportionate and dissuasive.
(4)When determining the type and level of an administrative penalty or other administrative measures to be imposed under these MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) [ S.L. 330.20 7 regulations, the Authority shall take into account the extent to which the breach is intentional or results from negligence, and all the relevant circumstances including, where appropriate: (
- a)breach; the materiality, gravity and the duration of the (
- b)the degree of responsibility of the natural or legal person responsible for the breach; (
- c)the financial strength of the natural or legal person responsible for the breach; (
- d)the importance of profits gained or losses avoided by the natural or legal person responsible for the breach, insofar as they can be determined; (
- e)the losses for third parties caused by the breach, insofar as they can be determined; (
- f)the level of cooperation with the competent authority of the natural or legal person responsible for the breach, without prejudice to the need to ensure disgorgement of profits gained or losses avoided by such person; and (
- g)previous breaches by the natural or legal person responsible for the breach.
(5)The imposition by the Authority of an administrative penalty or administrative measure in terms of these regulations shall be without prejudice to any other consequence of the act or omission of the offender under civil or criminal law: Provided that in all cases where the Authority imposes an administrative penalty or administrative measure in respect of anything done or omitted to be done by any person and such act or omission also constitutes a criminal offence, no proceedings may be taken or continued against the said person in respect of such criminal offence. 9.
(1)The Authority shall publish any decision imposing an administrative penalty or other administrative measures which it shall take under these regulations on its official website, without undue delay, after the person on whom the penalty was imposed has been notified of such decision. The publication shall include information on the type and nature of the breach, the identity of the persons responsible and the administrative penalty or other administrative measures imposed: Provided that where the Authority publishes a decision imposing an administrative penalty or other administrative measures Publication of administrative penalties and other administrative measures. 8 [ S.L. 330.20 MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) against which there is an appeal before the Financial Services Tribunal or the relevant judicial authorities, the Authority shall immediately add on its official website that information and, at later stages, any subsequent related information on the outcome of such appeal: Provided further that any decision of the Financial Services Tribunal or other judicial decision annulling a decision of the Authority imposing an administrative penalty or other administrative measures shall also be published.
(2)Where the Authority, following a case-by-case assessment, considers that the publication of the identity of legal persons or of the identity and personal data of natural persons, as the case may be, would: (
- a)be disproportionate, including risks in relation to the protection of personal data; (
- b)jeopardise the stability of financial markets; (
- c)jeopardise the pursuit of an ongoing criminal investigation; or (
- d)cause, insofar as these can be determined, disproportionate damages to the person involved; the Authority shall adopt one of the following solutions in respect of the decision imposing an administrative penalty or other administrative measures: (
- i)defer the publication of the decision until all the reasons for non-publication cease to exist; (
- ii)publish the decision on an anonymous basis; or (iii) refrain from publishing the decision, where the options referred to in paragraphs (
- i)and (ii): (
- a)are considered to be insufficient to guarantee a lack of any danger for the stability of financial markets; or (
- b)where such publication would be disproportionate to the leniency of the imposed administrative penalty or other administrative measures.
(3)In the case of a decision to publish an administrative penalty or other administrative measures on an anonymous basis in terms of paragraph (ii) of sub-regulation
(2), the publication of the relevant data may be postponed. MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) [ S.L. 330.20
(4)The Authority shall ensure that any publication in accordance with this regulation shall remain on its official website only for the period which is necessary to bring forth this regulation: Provided that this period shall not exceed five
(5)years after its publication. 10. Subject to the provisions of the Act, any person in respect of whom a decision is taken by the Authority under the Act, these regulations or the DORA Regulation, may appeal to the Financial Services Tribunal in terms of article 21 of the Act and the provisions of the said article shall mutatis mutandis apply. 11.
(1)Any person who: (
- a)fails to comply with any order or directive issued by the Authority under the DORA Regulation, the Act, these regulations or any regulations issued thereunder which implement the DORA Regulation; (
- b)without reasonable excuse alters, suppresses, conceals, destroys or refuses to produce any document which he is lawfully required to produce under the DORA Regulation, the Act, these regulations or any regulations made or rules issued thereunder which implement the DORA Regulation; (
- c)for the purposes of, or pursuant to, any of the provisions of the DORA Regulation, the Act, these regulations or of any regulations or Rules issued thereunder, or any condition, obligation, requirement, directive or order made or given as aforesaid, furnishes information or makes a statement which he knows to be inaccurate, false or misleading in any material respect, or recklessly furnishes information or makes a statement which is inaccurate, false or misleading in any material respect; (
- d)intentionally obstructs a person from exercising rights or powers conferred by the DORA Regulation, the Act, these regulations or any regulations issued under the Act; or (
- e)contravenes or fails to comply with any of the provisions of the DORA Regulation, the Act, these regulations or any regulations made or rules issued thereunder which implement the DORA Regulation; shall on conviction, be liable to the punishment of imprisonment for a term not exceeding one
(1)year or to a fine (multa) not exceeding one hundred and fifty thousand euro (€150,000) or to both such fine and imprisonment.
(2)The provisions of the Act or these regulations shall not Right of appeal. Offences. 9 10 MALTA FINANCIAL SERVICES AUTHORITY ACT (DIGITAL OPERATIONAL RESILIENCE ACT (DORA)) [ S.L. 330.20 affect any criminal proceedings that may be competent under any other applicable law.
(3)The Authority shall have the power to: (
- a)liaise with the Commissioner of Police to receive specific information related to criminal investigations or proceedings commenced for breaches of the DORA Regulation. The Commissioner of Police shall cooperate with the Authority, thereby providing such specific information related to any criminal investigations or proceedings commenced in relation to such breaches; and Cap. 9. (
- b)provide the same information received in terms of paragraph (a), and transmit copies of acts and documents of the courts of criminal justice in accordance with the second proviso to article 518 of the Criminal Code, to other authorities which are deemed competent authorities for the purposes of Article 46 of the DORA Regulation, as well as to the European Banking Authority (EBA), European Securities and Markets Authority (ESMA) or the European Insurance and Occupational Pensions Authority (EIOPA), for the purpose of fulfilling its obligations to cooperate for the purposes of the DORA Regulation and these regulations.