#
Comprehensive statute with active, named regulator and demonstrated enforcement activity.
Sub-modules (5)
Regulator And AuthorityGreen
GRA is the designated supervisory authority for data protection in Gibraltar and issues guidance and enforcement decisions under the DPA 2004/GDPR.
Claims (1):
- The Gibraltar Regulatory Authority (GRA) is the supervisory authority responsible for enforcing the Data Protection Act 2004 and the Gibraltar GDPR, including issuing fines and guidance.
Act And InstrumentsGreen
Core instruments are the Gibraltar GDPR and the Data Protection Act 2004 as amended in 2019; the EU GDPR ceased to apply directly from 1 January 2021.
Claims (1):
- Following the end of the Brexit transition period, the applicable law in Gibraltar is no longer the EU GDPR but the Gibraltar GDPR, which superseded it on 1 January 2021 pursuant to Section 6 of the European Union (Withdrawal) Act 2019, alongside the Data Protection Act 2004 (as amended in 2019).
Material ScopeAmber
Material scope mirrors GDPR Article 2 — automated and structured-manual processing of personal data by controllers/processors.
Absence provenance: Only inferred via mirrored GDPR structure; no Gibraltar-specific material-scope guidance located in this pass.. Searched: Gibraltar Data Protection Act 2004 material scope text, GRA official material scope guidance.
Claims (1):
- Material scope of the Gibraltar regime mirrors GDPR Article 2, covering wholly/partly automated processing and structured manual filing systems of personal data.
Territorial ScopeGreen
Territorial scope extends to controllers/processors outside Gibraltar offering goods/services to, or monitoring, individuals in Gibraltar, mirroring GDPR Art 3, and continues to apply GDPR extraterritorially to Gibraltar-based controllers targeting the EEA.
Claims (1):
- Even after the end of the Brexit transition period, a Gibraltar-based controller or processor offering goods or services to, or monitoring the behaviour of, individuals in the EEA must continue to comply with the EU GDPR.
Regulator Registration And FilingRed
No Gibraltar-specific controller registration/filing fee regime was identified in this research pass.
Absence provenance: No confirmed source located; absent rather than fabricated.. Searched: Gibraltar GRA controller registration fee, Gibraltar Data Protection Act 2004 notification requirement.
Regulator & Framework
The Gibraltar Regulatory Authority acts as Information Commissioner and is the supervisory authority for both the Data Protection Act 2004 and the Gibraltar GDPR. This standing status is confirmed at high confidence via the GRA's own published material.
The framework itself was materially amended this cycle: the Data Protection Regulations 2026, made under Legal Notice 96/2026, came into force on the Implementation Date of the Treaty on Gibraltar and the European Union Act 2026, amending both the Gibraltar GDPR and the Data Protection Act 2004. This is confirmed at high confidence, drawn directly from the government gazette instrument. The amendment's substantive effect on adequacy mechanisms is addressed in the Cross-Border & Adequacy module below; at the framework level, the significant fact is that Gibraltar's dual-instrument structure — a Gibraltar GDPR sitting alongside the Data Protection Act 2004 — has now been amended in tandem by a single implementing regulation tied to a constitutional treaty commencement date, rather than through separate incremental amendments to each instrument.
Outlook
The practical question going forward is whether further implementing regulations under the Treaty on Gibraltar and the European Union Act 2026 will touch the data protection framework again, given this cycle's amendment was explicitly tied to that treaty's Implementation Date rather than to a standalone data-protection policy review.
1 further periodic run re-emitted the standing brief unchanged and is not shown.
Sources and claims (4)
- ConfirmedGibraltar Regulatory Authority — The Gibraltar Regulatory Authority (GRA) is the supervisory authority responsible for enforcing the Data Protection Act 2004 and the Gibraltar GDPR, including issuing fines and guidance.observed
- ConfirmedOneTrust DataGuidance — Following the end of the Brexit transition period, the applicable law in Gibraltar is no longer the EU GDPR but the Gibraltar GDPR, which superseded it on 1 January 2021 pursuant to Section 6 of the European Union (Withdrawal) Act 2019, alongside the Data Protection Act 2004 (as amended in 2019).observed
- ProbableGibraltar Regulatory Authority — Material scope of the Gibraltar regime mirrors GDPR Article 2, covering wholly/partly automated processing and structured manual filing systems of personal data.observed
- ConfirmedOneTrust DataGuidance — Even after the end of the Brexit transition period, a Gibraltar-based controller or processor offering goods or services to, or monitoring the behaviour of, individuals in the EEA must continue to comply with the EU GDPR.observed