
Mitla Smart City Malta
INPLP member firm · Malta, Malta
Address: MITLA, SmartCity Malta, SCM1001, Ricasoli, Malta Website: www.mitla.org.mt Email: info@mitla.org.mt Gege is a lawyer with extensive experience in ICT corporate strategy and operations. He is a founding member of ICON a Microsoft Partner company and a world-class software-applications development company based in malta. As a specialist in ICT law he provides advice on matters relating to Data Protection, Computer Misuse and ICT contracting. He is Vice President of the Malta IT-Law Association and is a specialist examiner in the field of ICT Law for Doctoral thesis submitted to the University of Malta. As an innovative and results-driven leader he focuses on achieving exceptional results in highly competitive ICT environments that demand continuous improvement. Gege holds a Bachelors degree in Sociology and a Doctoral degree in Laws from the University of Malta. He is a member of the Camera degli Avvocati (Malta), the British Computer Society and the Chamber of Commerce, Malta. Gege is ITIL certified, a regular contributor to Business-IT publications and a speaker at ICT events. Prior to admission to the Law Course at the University of Malta, Dr Marco Fagnano’s studieswere centred on computing & business at the university’s ICT Faculty, particularly onsoftware development, and Artificial Intelligence (AI) solutions, such as Machine Learning,as an area of interest. When deciding to pursue the Law Course, Dr Fagnano’s focus was drawn to IT Law subjects, utilising information architecture principles to address legal issues posed byinnovative technologies. During such time, Dr Fagnano began his traineeship practice witha local law firm specialising in IT Law, garnering DLT and cryptocurrency advisoryexperience at the height of the industry’s peak in 2017 – 2019. After graduating with a Bachelor of Laws (Honours), and for some time after obtaining hisMaster of Advocacy, Dr Fagnano was admitted to the Bar as a warranted lawyer, continuinghis practice with such firm, with continued exposure on IT law matters, such as DataProtection. Dr Fagnano then furthered his studies in Technology, Media and Telecommunications (TMT) law, obtaining a Master of Laws (LLM) in Information Technology Law with the University ofEdinburgh, Law School, with special focus on Data Protection Law. Following this, DrFagnano provided, during a span of three years, his legal services and consultancy withintwo of the country’s most prominent law firms, advising clients and the firms on Commercial& Corporate law, TMT legal matters, including DLT & Cryptocurrency legal advice, Privacy &Reputation Management for HNWI clients, and Data Protection legal consultancy, as hisprimary area of legal expertise. Marco Fagnano, who has been nominated once again with the MITLA Board, as itsTreasurer, has been accepted with the country’s Data Protection Authority for the position ofLegal Counsel to the Malta Information and Data Protection Commissioner (IDPC) on EUaffairs, domestic & regulatory affairs, legislative advisory and legal advisor to theCommissioner on Data Protection regulatory interpretation and advice concerninginnovative technologies and emerging EU Data law regimes, such as the AI Act.
Representatives

Marco Fagnano
member

Gege Gatt
member
Contact
Mitla Smart City Malta
Business Address Smart City Ricasoli, Kalkara SCM 1001
SGN3000 Malta, Malta
mitla.org.mtPublications
- Malta at the Intersection of IT Law, Data Protection and Artificial Intelligence. A 2025 Legal ReviewMalta’s digital regulatory landscape underwent significant consolidation during 2025, shaped primarily by the transposition of key EU instruments and the maturation of domestic enforcement practice. This article reviews the principal developments in IT law, data protection and artificial intelligence regulation in Malta, with particular emphasis on cybersecurity under NIS2, the national implementation of the EU AI Act, the forthcoming application of the EU Data Act, and the evolving enforcement posture of Maltese supervisory authorities. Together, these developments position Malta as a jurisdiction seeking to balance innovation enablement with regulatory discipline and legal certainty.24 March 2026
- Data Protection ramifications emerging from the now in force Digital Services Act (DSA)This article seeks to inform businesses and industry professionals such as marketing specialists and data engineers on the data protection ramifications which may have a bearing on their commercial efforts in the area of online advertising practices, notably via online platforms10 September 2024
- The Digital Operational Resilience Act (DORA)The Digital Operational Resilience Act (Regulation (EU) 2022/2554) solves an important problem in the EU financial regulation, as it “aims to consolidate and upgrade ICT risk requirements as part of the operational risk requirements that have, up to this point, been addressed separately in various Union legal acts. While those acts covered the main categories of financial risk (e.g. credit risk, market risk, counterparty credit risk and liquidity risk, market conduct risk), they did not comprehensively tackle, at the time of their adoption, all components of operational resilience.”4 April 2023
- Cross Border Transfers: Recent DevelopmentsGenerally, data transfers to third countries are prohibited unless the receiving country has received an adequacy decision from the European Commission. In the absence of this, outward transfers may only be conducted if the receiving jurisdiction proves that they have implemented appropriate safeguards that guarantee data subject’s rights and effective legal remedies.8 July 2022
- Malta amends its rules relating to personal data processing in educationMalta has recently amended its rules in relation to the processing of personal data in the educational sector.29 November 2021
- Scientific research using health data: Is the GDPR in contradiction with FAIR principles?Medical research is becoming increasingly reliant on the analysis of large amounts of biologically derived data. Greater scientific and societal value are achievable if these research data are processed in accordance with the FAIR – Findable, Accessible, Interoperable and Reusable – principles. Contemporary scientific research within the EU is guided by these principles; for example, the European Cloud Initiative. They ensure verifiability, transparency and trustworthiness of research, as well as the availability of the raw data for further scientific research. The implementation of FAIR data goes hand-in-hand with the principle that research data must be “as Open as possible and as closed as necessary”.30 April 2021
- Detecting Online Terrorist Content and the Confines of PrivacyTerrorist attacks aren’t new: they’ve been a feature of warfare ever since humans formed societies. As humanity evolves, the methods we devise in torturing fellow humans and using terror as a tool for imposing power will unfortunately evolve in tandem.3 February 2021
- The re-use of public sector informationThe re-use of Public Sector information has to be built on a balanced approach where the public interests of such use have to be properly weighted against other important rights especially privacy. A recent bill was tabled in Maltese Parliament entitled ‘An Act to amend the Re-Use of Public Sector Information’ – how does this it measure up?17 March 2020
- iGaming and Privacy in Malta: Tensions?Data, and not FIAT or digital currency, is the real currency that measures the worth of a gambling operation, and the single common feature between every gaming operator.9 December 2019
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.