Privacy Policy of the Property Market Agency (PMA) Website

Last Updated: 12/03/2026

1. Introduction

The Property Market Agency (hereafter also referred to as ‘the Agency’, ‘we’ or ‘us’) respects your privacy and is committed to protecting your personal data. The Agency is the data controller for the purposes of the General Data Protection Regulation (EU) 2016/679 (GDPR), the Data Protection Act (Chapter 586 of the Laws of Malta), any subsidiary legislation thereto and any applicable Maltese and European Union laws concerning data protection (hereinafter referred to as ‘Data Protection Legislation’).

This Privacy Policy explains how we collect, use, disclose, and protect information obtained through our website https://realestateregistration.gov.mt/ in accordance with the GDPR and the Data Protection Act.

What is Personal Data?

Personal Data is any information relating to an identified or identifiable natural living person, otherwise known as a ‘data subject’. A data subject is an individual who can be identified, directly or indirectly, by information such as name, identification number, location data, online identifier, or other data relating to their physical, physiological, genetic, mental, economic, cultural, or social identity. These categories of identifying information are known as ‘personal data’. Personal data excludes any data which has been rendered anonymous in such a manner that the data subject is no longer identifiable (anonymous data).

Special category data is data on racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, biometric data for the purpose of uniquely identifying a natural person, data concerning health, data concerning a natural person’s sex life or sexual orientation. The Agency will only process special categories of personal data (sensitive data) under strict conditions and with an appropriate legal basis.

We process personal data about the following categories of data subjects:

  • applicants and real estate agents licensed by the Agency;
  • suppliers and service providers of the Agency;
  • members of the public;
  • users of the Agency’s website;
  • job applicants and employees of the Agency.
  • names and identity reference numbers of all directors, partners, company secretary and beneficial owners.

Personal Data is only accessed by those Agency’s employees who are assigned to carry out the functions of the Agency in line with its duties prescribed at law. Personal Data will be disclosed to third parties when necessary but only as authorised by law. The Agency does not knowingly process personal data relating to minors.

The Agency collects and processes information to carry out its obligations in accordance with present legislation.  All data is collected and processed in accordance with Data Protection Legislation and the Property Market Agency Act, Chapter 644 of the Laws of Malta. In most cases, the provision of personal data arises either from statutory requirements or contractual provisions. Where applicable, failure of the provision thereof will prevent the Agency from complying with its legal or regulatory obligations; concluding contracts; and delivering the services requested.

2. Data Controller and Contact.

The data controller is the Property Market Agency, established by virtue of Chapter 644 of the Laws of Malta. This means we are responsible for determining the purposes and means of processing your personal data.

In certain cases, where the Agency provides services in conjunction with another public authority, we may act as joint controllers in accordance with Article 26 of the GDPR. In such cases, the Agency will provide any relevant information governing the joint processing activities.

Contact Details:

Address: Property Market Agency (PMA), AX Business Centre, Ground Floor, Triq id-Difiża Ċivili, Mosta, Malta

Email: [email protected]

Tel: 00356 2248 1508

Data Protection Officer (DPO):

The DPO is responsible for ensuring compliance with data protection obligations and handling related requests.

Email: [email protected]

The Information and Data Protection Commissioner’s Contact Details:

The Information and Data Protection Commissioner may be contacted at:

Address: Level 2, Airways House, High Street, Sliema, SLM 1549

Email: [email protected]

Telephone:  00356 2328 7100

3. Categories of Personal Data

The Agency collects and processes personal data strictly as necessary for the performance of its statutory functions at law, for the secure and effective operation of its official website, and for the delivery of services related to its public mandate. The specific categories of personal data collected and processed depend on the nature of your interaction with the Agency. These may include:

Personal Data Purpose of Processing Legal Basis
Identification data, such as name, surname, national identification number, date of birth, residential or business address, and other government-issued identifiers.
Identification data, such as name, surname, national identification number, date of birth, residential or business address, and other government-issued identifiers.
To perform our functions as an Agency under Chapter 644 of the Laws of Malta and to comply with our legal obligations.

To provide you with information about, and support in connection to the services, including changes to the services, technical updates and changes to terms and conditions as well as this Privacy Notice.

Professional and licensing information, such as employment details, business registration data, licence or permit numbers, professional qualifications, disciplinary records, or declarations submitted for regulatory or compliance purposes.

Different categories of personal data depending on the services offered to you.

To grant, renew, refuse, suspend or revoke any licence, certificate or other document as issued by the Agency.

Upon data collection you will be provided with information on how we will process your personal data within a specific ‘privacy notice’.

The legal basis we rely on to process your personal data is article 6(1)(e) of the GDPR, which allows us to process personal data when this is necessary to perform our public tasks and in the exercise of official authority vested in the Agency.

Certain processing activities may also be necessary to comply with specific legal obligations imposed on the Agency under Maltese law (Article 6(1)(c) GDPR).

This processing is necessary for the performance of tasks carried out in the public interest and in the exercise of official authority vested in the Agency under Chapter 644 of the Laws of Malta and any subsidiary legislation thereunder.

Information that you provide in any online application form, including Freedom of Information requests, enquiries and complaints.

Records of inspections, complaints, or enforcement proceedings, where relevant to the Agency’s regulatory and supervisory functions.

Website and communication data, including information submitted through online contact or application forms, inquiries, or correspondence with the Agency (via email, post, or online portals).

Any other data voluntarily provided by individuals in the course of communication, registration, or participation in Agency-led consultations, meetings, or events.

If you are acting on behalf of someone making a complaint, the Agency will require you to provide proof of authorisation to act on someone else’s behalf, to satisfy us of your identity.

To process application forms, including for Freedom of Information requests.

To respond to queries and feedback submitted by you.

To investigate and take regulatory action in line with our statutory duties.

The legal basis we rely on to process your personal data is article 6(1)(e) of the GDPR, which allows us to process personal data when this is necessary to perform our public tasks and in the exercise of official authority vested in the Agency.

Certain processing activities may also be necessary to comply with specific legal obligations imposed on the Agency under Maltese law (Article 6(1)(c) GDPR).

This processing is necessary for the performance of tasks carried out in the public interest and in the exercise of official authority vested in the Agency under Chapter 644 of the Laws of Malta and any subsidiary legislation thereunder.

Personal details of job applicants including full name and contact details, work experience, education and referees.
To assess your suitability for a role you have applied for.
The legal basis we rely on for processing your personal data is article 6(1)(b) of the GDPR, which relates to processing necessary to perform a contract or to take steps at your request, before entering a contract.

Certain processing activities may also be necessary to comply with specific legal obligations imposed on the Agency under Maltese law (Article 6(1)(c) GDPR).

Personal data of employees relating to their employment at the Agency.
Personal data is collected for purposes pertaining to the individual’s employment with the Authority, including but not limited to performance reviews, the administration of employee payroll, and for the purpose of complying with applicable employment legislation.
The legal basis we rely on for processing your personal data is article 6(1)(b) of the GDPR, which relates to processing necessary to perform a contract.

Certain processing activities may also be necessary to comply with specific legal obligations imposed on the Agency under Maltese law (Article 6(1)(c) GDPR).

Details relating to your visit to our premises, including full name, company name, mobile number, time in, time out, visitor pass number and signature.
For security and safety purposes.
The legal basis for this processing is Article 6(1)(e) GDPR, as it is necessary for the performance of tasks carried out in the public interest and in the exercise of official authority vested in the Agency, including ensuring the security and proper administration of its premises.

Where applicable, certain processing activities may also be required to comply with specific legal obligations under Maltese health and safety or security legislation, in line with Article 6(1)(c) GDPR.

Personal data relating to individuals or organisations providing us with a service.

Financial and administrative information, where necessary for fee payments, refunds, or financial audits (e.g. bank account details, proof of payment, or invoicing information).

To engage with potential and existing suppliers, to enter into and manage contracts for the provision of services, and to administer our business relationship including procurement activities, contract execution, financial administration, invoicing, payments, and compliance with applicable public procurement and audit obligations.
The legal basis we rely on for processing your personal data is article 6(1)(b) of the GDPR, which relates to processing necessary to perform a contract or to take steps at your request, before entering a contract.

In addition, certain processing activities—particularly those relating to public procurement procedures, financial management, and statutory audit requirements—may be carried out to comply with our legal obligations under Maltese law, in accordance with Article 6(1)(c) GDPR.

Any personal data relating to you that you provide to us or that we generate about you in connection with your use of our official website.

Technical and usage data, such as IP address, browser type, and device information, collected automatically through the Website for security, functionality, and analytics purposes.

No attempt is made to identify individual users or to associate the technical details listed above with any individual.

To ensure the security, integrity and proper functioning of this website and our systems.

To improve and develop this website and our mobile applications.

To generate and analyse statistics regarding usage of this website, including the frequency of use of individual pages (where possible, personal data will be anonymised before being used for this purpose).

The legal basis we rely on to process your personal data is article 6(1)(e) of the GDPR, which allows us to process personal data when this is necessary to perform our public tasks and in the exercise of official authority vested in the Agency.

For analytics or statistical cookies that are not strictly necessary, the legal basis is your consent under Article 6(1)(a) GDPR, in line with the requirements of the ePrivacy Directive and national implementing legislation. These cookies are only activated if you provide your consent via our cookie banner.

4. Principles of Data Processing

The Agency is committed towards compliance. If we need to collect, process, store or otherwise use your personal data, we will abide by the following data protection principles:

  1. Lawfulness, fairness and transparency: the processing of personal data shall take place in a lawful, fair and transparent manner;
  2. Purpose Limitation: the collection of personal data shall only be performed for specified, explicit and legitimate purposes and shall not be further processed in a manner that is incompatible with those purposes;
  3. Data Minimisation: the collection of personal data shall be adequate, relevant and limited to what is necessary in relation to the purpose for which they are processed;
  4. Accuracy: the personal data shall be accurate and where necessary, kept up to date. Every reasonable step shall be taken to ensure that personal data that are inaccurate having regard to the purposes for which they are processed, are erased or rectified without delay;
  5. Storage Limitation: personal data shall be kept in a form which permits identification of the data subject for no longer than it is necessary for the purpose for which the personal data are processed;
  6. Integrity and Confidentiality: personal data shall be kept confidential and stored in a manner that ensures appropriate security. Personal data shall not be shared with third parties except when necessary and with a justifiable legal basis.
  7. Accountability and Governance: The Agency is responsible for and able to demonstrate compliance with these principles, in line with Article 5(2) GDPR.
  8. Data Protection by Design and by Default: We incorporate data protection principles into all our projects, systems, and processes from the outset.

5. Recipients of Personal Data

The Agency may disclose personal data only to the extent necessary and in accordance with the principles of lawfulness, fairness, and transparency under the GDPR. Personal data may be shared with the following categories of recipients:

  1. Service providers and professional advisors engaged by the Agency who maintain or host the Website and any Agency systems;
  2. Auditors and legal advisors involved in reviewing or advising on our processes;
  3. Other public authorities or government entities when such disclosure is necessary to fulfil the Agency’s legal or regulatory functions;
  4. Law enforcement or judicial authorities where disclosure is required by applicable law or in connection with the establishment, exercise or defence of legal claims;

All recipients of personal data are contractually bound to process personal data only on the Agency’s instructions and to implement any technical and organisational measures to ensure the confidentiality, integrity and security of the personal data.

Personal data shall not be transferred outside the European Economic Area (EEA) unless such transfer is carried out in compliance with Chapter V of the GDPR, including the use of adequacy decisions or appropriate safeguards (such as standard contractual clauses or binding corporate rules), ensuring that data subjects continue to benefit from an equivalent level of protection.

6. Retention Periods

We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, including to comply with legal obligations, enforce agreements, or establish, exercise, or defend legal claims.

Where specific retention periods cannot be predetermined, we assess the appropriate duration based on:

  1. the purpose of collection;
  2. legal or regulatory obligations;
  3. the lawful basis for processing (e.g., consent, legal obligation);
  4. the value and sensitivity of the data;
  5. applicable industry standards; and
  6. the risks and costs of continued retention.

We regularly review the data we hold and securely delete or anonymise it when no longer needed.

For more information on specific retention periods, please contact the Data Protection Officer.

7. Security of Data

The Agency applies appropriate technical and organisational measures to protect personal data against loss, misuse, unauthorised access, alteration, or destruction. These safeguards ensure the confidentiality, integrity, and availability of our systems, and support recovery in case of technical or physical incidents.

While we take all reasonable steps to secure your data, no online transmission or storage method is fully secure. You transmit information at your own risk.

We maintain internal procedures to detect and respond to personal data breaches. Where legally required, we will notify the supervisory authority and, where applicable, affected individuals. Staff receive regular training on data protection and information security.

To report a potential breach or concern, contact our Data Protection Officer.

8. Data Subject Rights

In accordance with the General Data Protection Regulation (GDPR), you have a number of rights in relation to the personal data we process about you. These rights are intended to ensure transparency, fairness, and accountability in how your personal data is handled. The Agency is committed to respecting and facilitating the exercise of your rights as a data subject. The rights afforded to data subjects can be found below:

As a key part of the transparency requirements, you will be provided with various categories of information which are normally provided within a ‘privacy notice’. Any such privacy notice will inform you of:

  • the identity and contact details of the data controller;
  • the contact details of the Data Protection Officer;
  • the purpose and legal basis for processing;
  • the source that the personal data originated from;
  • the categories of personal data which we will process;
  • the categories of recipients with whom data has been or will be shared;
  • any transfers of data to countries outside of the EU/EEA and the safeguards in place where that occurs;
  • how long the data will be kept for or the criteria used to determine the retention period;
  • the rights to which you are entitled;
  • whether providing the personal data is a contractual or statutory requirement, and if so the possible consequences of not providing it;
  • whether automated decision which might significantly affect you will take place, and if so information about the logic involved and how it might affect you.

You have the right to obtain from us confirmation as whether or not personal data concerning you is being processed, and where that is the case, access to the personal data and the additional information.

You have the right to obtain from us without undue delay the rectification of inaccurate personal data concerning you.

You have the right to obtain from us the erasure of your personal data in terms of law.  This right is limited by, and subject to all our compliance, regulatory and legal obligations.

You have the right to obtain from us restriction of processing where, one of the following applies:

  • the accuracy of personal data is contested by yourself for a period enabling us to verify the accuracy of your personal data;
  • the processing is unlawful and you oppose to the erasure of your personal data and request the restriction of its use instead;
  • we no longer need the personal data, but it is required by yourself for the establishment, exercise or defence of legal claims;
  • you object to processing pursuant to your right to object pending the verification whether our legitimate grounds override yours.
  •  

You shall have the right to receive your personal data which you have provided to us, in a structured, commonly used and machine-readable format.

In certain circumstances, you have the right to object to us processing your personal data. Your objection must be based on your particular situation, and can only be considered where the processing is:

  • based on either the legitimate interests or public task condition;
  • for scientific and/or historical research and statistics purposes, unless the processing is in the public interest.

We shall no longer process your personal data unless we have a compelling legitimate ground for the processing to continue, or the processing related to legal claims.

Automated decision-making takes place when an electronic system uses personal information to make a decision without human intervention.

In establishing and carrying out our service, we generally do not use any automated decision-making pursuant to Article 22 of the GDPR. You will not be subject to decisions that will have a legally binding or significant impact on you based solely on automated decision-making, unless we have a lawful basis for doing so and we notify you accordingly.

Where our processing of your personal data is based on you having provided consent, you have the right to withdraw your consent to the processing at any time.

Should you require any clarification or need to discuss matters relating to the processing of your personal data, you may contact our Data Protection Officer by email at [email protected]

In the case you are not satisfied with the outcome, as a data subject, you also have a right to lodge a complaint with the Information and Data Protection Commissioner, either online, via the submission of a report by conventional mail, or by email at [email protected]

To exercise your data subject rights, you must submit a written request to the Agency. The request must include your full name, identification number, and any relevant information to help us identify you. If necessary, you may be asked to present an official identification document to verify your identity.

The Agency aims to respond to access requests as promptly as possible, and in any case within one month from the date of receipt, unless there is a valid reason for delay. If additional time is required, you will be informed in writing with the reason for the delay. In the event of a personal data breach affecting your rights, you will be informed in accordance with applicable legal obligations. We reserve the right to withhold personal data if disclosing it would adversely affect the rights and freedoms of others. Generally, no fees are applicable when exercising your rights. However, we may charge a reasonable administrative fee if your request is clearly unfounded, repetitive or excessive.

If you are not satisfied with the outcome of your request or believe that your data protection rights have been violated, you may file a complaint with the Information and Data Protection Commissioner.

9. Anonymised and Statistical Data

The Agency may collect and process anonymised or aggregated data relating to the use of its Website and online services. This information does not identify individual users and is processed solely for analytical and service improvement purposes.

Such data may include, for example:

  • general website usage statistics (e.g. pages visited, duration of visits, and navigation patterns);
  • technical information (e.g. browser type, operating system, and device category);
  • approximate geographic location (e.g. region or city, based on anonymised IP data);
  • data generated through cookies or similar technologies used for functional and analytical purposes.

This information is used to:

  • monitor and enhance the Website’s performance, accessibility, and security;
  • assess public engagement and improve the quality and delivery of the Agency’s digital and regulatory services;
  • produce statistical reports or research supporting the Agency’s policymaking or operational functions, ensuring that such outputs remain fully anonymous and non-identifiable.

All analytics data are either processed in aggregated form or anonymised at source so that no individual can be directly or indirectly identified. Any use of cookies or tracking technologies for analytics is carried out in accordance with the Agency’s Cookies Policy and applicable data protection and electronic communications laws.

10. Privacy by design and by default

Where we introduce new technologies, policies or processes, we will ensure that your privacy is considered from the outset i.e. at the ‘design stage’, and where applicable we will carry out a Data Protection Impact Assessment (DPIA) in line with Articles 35 – 36 of the GDPR.

We will always carry out a DPIA where we use new technologies or consider there is a high risk to your rights and freedoms. Where an assessment identifies risks that cannot be satisfactorily reduced or avoided, we will seek advice from the Supervisory Authority (Office of the Information and Data Protection Commissioner) before starting the processing.

11. Links to other websites

Where we provide links to websites of other organisations, this Privacy Notice does not cover how that organisation processes your personal information. We encourage you to read the privacy notices on the other websites you visit.

12. Updates to This Policy

This Policy may be updated periodically to reflect changes in legal or operational requirements.

The latest version will always be available on our Website, with the “Last Updated” date clearly displayed.