🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
GI v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 1 failing15 sources retrieved model claude-sonnet-5 · 2026-08-05

Gibraltar

GI schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM

Last updated · 10 categories · 27 claims · 24 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
27Claimsbaseline..claims[]
16Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)

Jurisdiction brief

Latest update · 21 September 2026

Lead Signal

Gibraltar's data protection framework underwent a material adequacy-mechanism re-basing this cycle. The Data Protection Regulations 2026, made under Legal Notice 96/2026, came into force on the Implementation Date of the Treaty on Gibraltar and the European Union Act 2026, amending both the Gibraltar GDPR and the Data Protection Act 2004. The most consequential change replaces references in Gibraltar GDPR Article 45(1) to UK adequacy regulations with references to European Commission adequacy decisions, and re-bases the equivalent law-enforcement-transfer adequacy mechanism in section 83A of the 2004 Act on the same footing. This is confirmed at high confidence, corroborated across a T1 government gazette instrument and T3 legal commentary describing the same substitution mechanism.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive statute with active, named regulator and demonstrated enforcement activity.

Primary frameworkGibraltar GDPR (retained EU GDPR 2016/679) and Data Protection Act 2004 (as amended)
Traffic-light rationale — GreenComprehensive statute with active, named regulator and demonstrated enforcement activity.

Sub-modules (5)

Regulator And AuthorityGreen

GRA is the designated supervisory authority for data protection in Gibraltar and issues guidance and enforcement decisions under the DPA 2004/GDPR.

Claims (1):

  • The Gibraltar Regulatory Authority (GRA) is the supervisory authority responsible for enforcing the Data Protection Act 2004 and the Gibraltar GDPR, including issuing fines and guidance.

Act And InstrumentsGreen

Core instruments are the Gibraltar GDPR and the Data Protection Act 2004 as amended in 2019; the EU GDPR ceased to apply directly from 1 January 2021.

Claims (1):

  • Following the end of the Brexit transition period, the applicable law in Gibraltar is no longer the EU GDPR but the Gibraltar GDPR, which superseded it on 1 January 2021 pursuant to Section 6 of the European Union (Withdrawal) Act 2019, alongside the Data Protection Act 2004 (as amended in 2019).

Material ScopeAmber

Material scope mirrors GDPR Article 2 — automated and structured-manual processing of personal data by controllers/processors.

Absence provenance: Only inferred via mirrored GDPR structure; no Gibraltar-specific material-scope guidance located in this pass.. Searched: Gibraltar Data Protection Act 2004 material scope text, GRA official material scope guidance.

Claims (1):

  • Material scope of the Gibraltar regime mirrors GDPR Article 2, covering wholly/partly automated processing and structured manual filing systems of personal data.

Territorial ScopeGreen

Territorial scope extends to controllers/processors outside Gibraltar offering goods/services to, or monitoring, individuals in Gibraltar, mirroring GDPR Art 3, and continues to apply GDPR extraterritorially to Gibraltar-based controllers targeting the EEA.

Claims (1):

  • Even after the end of the Brexit transition period, a Gibraltar-based controller or processor offering goods or services to, or monitoring the behaviour of, individuals in the EEA must continue to comply with the EU GDPR.

Regulator Registration And FilingRed

No Gibraltar-specific controller registration/filing fee regime was identified in this research pass.

Absence provenance: No confirmed source located; absent rather than fabricated.. Searched: Gibraltar GRA controller registration fee, Gibraltar Data Protection Act 2004 notification requirement.

Category narrative61 words

Gibraltar operates a GDPR-style comprehensive regime supervised by the Gibraltar Regulatory Authority (GRA), which acts as the Information Commissioner's function under the Data Protection Act 2004 (as amended). Following the end of the Brexit transition period, the EU GDPR was superseded on 1 January 2021 by the Gibraltar GDPR (a retained/localised version of Regulation (EU) 2016/679), applied alongside the DPA 2004.

Periodic update · new data 2026-09-21

Regulator & Framework

The Gibraltar Regulatory Authority acts as Information Commissioner and is the supervisory authority for both the Data Protection Act 2004 and the Gibraltar GDPR. This standing status is confirmed at high confidence via the GRA's own published material.

The framework itself was materially amended this cycle: the Data Protection Regulations 2026, made under Legal Notice 96/2026, came into force on the Implementation Date of the Treaty on Gibraltar and the European Union Act 2026, amending both the Gibraltar GDPR and the Data Protection Act 2004. This is confirmed at high confidence, drawn directly from the government gazette instrument. The amendment's substantive effect on adequacy mechanisms is addressed in the Cross-Border & Adequacy module below; at the framework level, the significant fact is that Gibraltar's dual-instrument structure — a Gibraltar GDPR sitting alongside the Data Protection Act 2004 — has now been amended in tandem by a single implementing regulation tied to a constitutional treaty commencement date, rather than through separate incremental amendments to each instrument.

Outlook

The practical question going forward is whether further implementing regulations under the Treaty on Gibraltar and the European Union Act 2026 will touch the data protection framework again, given this cycle's amendment was explicitly tied to that treaty's Implementation Date rather than to a standalone data-protection policy review.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (4)
  1. ConfirmedGibraltar Regulatory Authority — The Gibraltar Regulatory Authority (GRA) is the supervisory authority responsible for enforcing the Data Protection Act 2004 and the Gibraltar GDPR, including issuing fines and guidance.observed
  2. ConfirmedOneTrust DataGuidance — Following the end of the Brexit transition period, the applicable law in Gibraltar is no longer the EU GDPR but the Gibraltar GDPR, which superseded it on 1 January 2021 pursuant to Section 6 of the European Union (Withdrawal) Act 2019, alongside the Data Protection Act 2004 (as amended in 2019).observed
  3. ProbableGibraltar Regulatory Authority — Material scope of the Gibraltar regime mirrors GDPR Article 2, covering wholly/partly automated processing and structured manual filing systems of personal data.observed
  4. ConfirmedOneTrust DataGuidance — Even after the end of the Brexit transition period, a Gibraltar-based controller or processor offering goods or services to, or monitoring the behaviour of, individuals in the EEA must continue to comply with the EU GDPR.observed

#

Framework is GDPR-aligned but Gibraltar-specific consent-threshold and pseudonymisation guidance is thin in the public record.

Primary frameworkGibraltar GDPR Arts 6 & 9; Data Protection Act 2004 exemptions provisions
Traffic-light rationale — AmberFramework is GDPR-aligned but Gibraltar-specific consent-threshold and pseudonymisation guidance is thin in the public record.

Sub-modules (4)

Lawful BasesAmber

Lawful bases mirror GDPR Art 6 (consent, contract, legal obligation, vital interests, public task, legitimate interests).

Claims (1):

  • The Gibraltar GDPR retains the six lawful bases for processing set out in Article 6 of Regulation (EU) 2016/679.

Special CategoriesAmber

GRA guidance on exemptions confirms special-category-adjacent processing exemptions for health, social work and education contexts and clarifies exemptions cannot be routinely relied upon.

Claims (1):

  • GRA guidance outlines exemptions from the Data Protection Act 2004 and GDPR available for, among others, crime, law enforcement and public protection, journalism, research and archiving, and health, social work and education processing, and clarifies these cannot be routinely relied upon and must be justified case-by-case.

Pseudonymisation And AnonymisationAmber

GRA's COVID-era location-data guidance recommends anonymisation as preferred over identifiable location data, requiring consent where anonymisation is not applied.

Claims (1):

  • GRA guidance on location data states that anonymisation is preferred and that consent is required where location data is not anonymised, encouraging transparency about anonymisation methodology.
Category narrative40 words

Gibraltar's lawful-basis and special-category framework is inherited directly from the GDPR structure (Arts 6 and 9) via the Gibraltar GDPR, supplemented by DPA 2004 exemptions guidance issued by GRA covering crime/law enforcement, journalism, research/archiving, health, social work and education processing.

Sources and claims (3)
  1. ProbableGibraltar Regulatory Authority — The Gibraltar GDPR retains the six lawful bases for processing set out in Article 6 of Regulation (EU) 2016/679.observed
  2. ConfirmedOneTrust DataGuidance — GRA guidance outlines exemptions from the Data Protection Act 2004 and GDPR available for, among others, crime, law enforcement and public protection, journalism, research and archiving, and health, social work and education processing, and clarifies these cannot be routinely relied upon and must be justified case-by-case.observed
  3. ConfirmedOneTrust DataGuidance — GRA guidance on location data states that anonymisation is preferred and that consent is required where location data is not anonymised, encouraging transparency about anonymisation methodology.observed

#

Rights framework is GDPR-aligned and actively enforced (SAR failures investigated) but Gibraltar-specific procedural guidance on erasure/portability/deadlines was not located in this pass.

Primary frameworkGibraltar GDPR Arts 12-22
Traffic-light rationale — AmberRights framework is GDPR-aligned and actively enforced (SAR failures investigated) but Gibraltar-specific procedural guidance on erasure/portability/deadlines was not located in this pass.

Sub-modules (5)

Access RightAmber

GRA enforcement/investigations reports document cases involving failure to respond to subject access requests.

Claims (1):

  • GRA's published investigations and enforcement report addresses cases involving failure to respond to subject access requests, among other compliance failures under GDPR and the DPA 2004.

Rectification And ErasureRed

No Gibraltar-specific erasure/rectification guidance located; presumed to mirror GDPR Arts 16-17.

Absence provenance: Not located in this pass.. Searched: GRA right to erasure guidance, Gibraltar data subject rights note.

Restriction And ObjectionRed

No Gibraltar-specific restriction/objection guidance located.

Absence provenance: Not located in this pass.. Searched: GRA restriction of processing guidance, Gibraltar objection to processing.

Data PortabilityRed

No Gibraltar-specific portability guidance located.

Absence provenance: Not located in this pass.. Searched: GRA data portability guidance.

Deadlines And Response WindowsAmber

Response deadlines presumed to mirror the GDPR one-month (extendable) standard; no Gibraltar-specific variance found.

Claims (1):

  • The Gibraltar GDPR retains the GDPR Article 12(3) standard one-month response deadline for data subject requests, extendable by two further months for complex/numerous requests.
Category narrative32 words

Data subject rights are inherited from the GDPR structure (Arts 12-22). GRA's published enforcement/investigations reports evidence real-world exercise of the access right, including failures by controllers to respond to subject access requests.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidance — GRA's published investigations and enforcement report addresses cases involving failure to respond to subject access requests, among other compliance failures under GDPR and the DPA 2004.observed
  2. ProbableGibraltar Regulatory Authority — The Gibraltar GDPR retains the GDPR Article 12(3) standard one-month response deadline for data subject requests, extendable by two further months for complex/numerous requests.observed

#

Strong enforcement record evidences the regime's teeth, but DPO-appointment thresholds and joint-controller-specific Gibraltar guidance were not located.

Primary frameworkData Protection Act 2004 (as amended) Part III; Gibraltar GDPR Arts 24-39
Traffic-light rationale — AmberStrong enforcement record evidences the regime's teeth, but DPO-appointment thresholds and joint-controller-specific Gibraltar guidance were not located.

Sub-modules (7)

Accountability And DpiaGreen

DPIA obligations are set out in Sections 73-74 of the DPA 2004, referencing GDPR Article 35 and recitals; GRA relies on WP29/EDPB DPIA guidelines.

Claims (1):

  • Sections 73 and 74 of the Data Protection Act 2004 (as amended in 2019), read with recitals 4, 75, 76, 84, 90, 92 and Article 35 of the GDPR, impose data protection impact assessment obligations in Gibraltar.

Dpo RequirementsRed

No Gibraltar-specific DPO appointment threshold guidance was located in this pass; presumed to mirror GDPR Arts 37-39.

Absence provenance: Not located in this pass.. Searched: GRA DPO appointment guidance, Gibraltar Data Protection Act DPO section.

Ropa RequirementsAmber

The 2022 GRA fine against Royal Gibraltar Police cited failures in records of processing activities as a breach ground.

Claims (1):

  • The GRA's 18 April 2022 decision fined the Royal Gibraltar Police £10,000 partly for failures relating to records of processing activities, in violation of Article 30 GDPR and corresponding DPA 2004 sections.

Joint Controller ArrangementsRed

No Gibraltar-specific joint-controller guidance was located.

Absence provenance: Not located in this pass.. Searched: GRA joint controller guidance.

Security MeasuresGreen

GRA's 2020 data-security guidance requires organisations to adopt a risk-based approach and outlines organisational/technical measures including certification, third-party audits, breach management and multi-factor authentication.

Claims (1):

  • GRA's 19 March 2020 guidance emphasises that organisations are accountable for establishing appropriate security measures and must adopt a risk-based approach, highlighting certification, third-party audits, breach management and multi-factor authentication.

Breach NotificationGreen

Breach notification duties under Part III, Chapter 4, Section 76 of the DPA 2004 were directly enforced against the Royal Gibraltar Police for delayed notification to the GRA and data subjects.

Claims (1):

  • The Royal Gibraltar Police was fined £10,000 for, among other violations, breaching Sections 65(1)-(2), 70, 75 and 77(1)-(2) of the DPA 2004 and Articles 24(1)-(2), 30, 32 and 34(1)-(2) GDPR concerning breach communication and security, having notified the GRA and data subjects only after delay.

Retention And DisposalAmber

The 2022 GRA fine cited storage-limitation failures (Section 48(1) DPA / Art 5(1)(e) GDPR) against Royal Gibraltar Police.

Claims (1):

  • The GRA's 2022 fine decision cited storage-limitation failures under Section 48(1)-(2) DPA 2004 and Article 5(1)(e) GDPR against the Royal Gibraltar Police.
Category narrative52 words

Controller/processor duties (accountability, DPIA, ROPA, security, breach notification, retention) are set out across the DPA 2004 and Gibraltar GDPR and are actively enforced — the GRA's fines against the Royal Gibraltar Police (2020, 2022) cite specific DPA sections and GDPR articles covering storage limitation, security of processing, ROPA, and breach communication failures.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. ConfirmedOneTrust DataGuidance — Sections 73 and 74 of the Data Protection Act 2004 (as amended in 2019), read with recitals 4, 75, 76, 84, 90, 92 and Article 35 of the GDPR, impose data protection impact assessment obligations in Gibraltar.observed
  2. ConfirmedOneTrust DataGuidance — The GRA's 18 April 2022 decision fined the Royal Gibraltar Police £10,000 partly for failures relating to records of processing activities, in violation of Article 30 GDPR and corresponding DPA 2004 sections.observed
  3. ConfirmedOneTrust DataGuidance — GRA's 19 March 2020 guidance emphasises that organisations are accountable for establishing appropriate security measures and must adopt a risk-based approach, highlighting certification, third-party audits, breach management and multi-factor authentication.observed
  4. ConfirmedOneTrust DataGuidance — The Royal Gibraltar Police was fined £10,000 for, among other violations, breaching Sections 65(1)-(2), 70, 75 and 77(1)-(2) of the DPA 2004 and Articles 24(1)-(2), 30, 32 and 34(1)-(2) GDPR concerning breach communication and security, having notified the GRA and data subjects only after delay.observed
  5. ConfirmedOneTrust DataGuidance — The GRA's 2022 fine decision cited storage-limitation failures under Section 48(1)-(2) DPA 2004 and Article 5(1)(e) GDPR against the Royal Gibraltar Police.observed

#

Transfer mechanisms (SCCs, BCRs, UK adequacy, DPF extension) are well evidenced; EU-side adequacy specifically for Gibraltar remains unconfirmed and is held for regulator confirmation.

Primary frameworkGibraltar GDPR Arts 44-49; UK Data Protection (Adequacy) framework
Traffic-light rationale — AmberTransfer mechanisms (SCCs, BCRs, UK adequacy, DPF extension) are well evidenced; EU-side adequacy specifically for Gibraltar remains unconfirmed and is held for regulator confirmation.

Sub-modules (6)

Transfer MechanismsAmber

GRA's Transfers Guidance identifies SCCs and BCRs under Article 46 GDPR as safeguards for EEA-to-Gibraltar transfers absent an adequacy decision.

Claims (1):

  • In the absence of an EU adequacy decision for Gibraltar, GRA's Transfers Guidance directs that EEA controllers transferring to Gibraltar should rely on Article 46 GDPR safeguards, including Standard Contractual Clauses and Binding Corporate Rules.

Adequacy ReceivedGreen

Gibraltar is listed by the UK ICO among jurisdictions with full UK adequacy status, permitting free-flow restricted transfers from the UK to Gibraltar.

Claims (1):

  • The UK ICO lists Gibraltar among the countries and territories covered by full UK adequacy regulations, permitting restricted transfers from the UK to Gibraltar without additional safeguards; Gibraltar-based organisations may also rely on the UK Extension to the EU-US Data Privacy Framework for transfers to certain self-certified US businesses.

Adequacy GrantedRed

No confirmed EU Commission adequacy decision specifically for Gibraltar was located; the Gibraltar Government's intent (as of 2020 guidance) to seek such a decision does not appear to have been finalised in sources reviewed.

Absence provenance: No EU Commission adequacy decision for Gibraltar specifically was found distinct from the UK-EU adequacy decisions.. Searched: Gibraltar EU adequacy decision 2025 2026, European Commission Gibraltar adequacy.

Claims (1):

  • As of the guidance reviewed, the Government of Gibraltar intended to seek an EU adequacy decision to ensure continuing free flow of data from the EEA to Gibraltar, but no such decision had been finalised at that time.

Sccs And BcrsAmber

SCCs approved by a supervisory authority and approved by the European Commission, and BCRs, are identified as available safeguards for EEA-Gibraltar transfers.

Claims (1):

  • In the absence of an EU adequacy decision for Gibraltar, GRA's Transfers Guidance directs that EEA controllers transferring to Gibraltar should rely on Article 46 GDPR safeguards, including Standard Contractual Clauses and Binding Corporate Rules.

Transfer Impact AssessmentRed

No Gibraltar-specific TIA requirement or guidance was located.

Absence provenance: Not located in this pass.. Searched: GRA transfer impact assessment guidance.

Data LocalisationRed

No data-localisation mandate was identified for Gibraltar.

Absence provenance: No evidence of a localisation mandate found.. Searched: Gibraltar data localisation requirement.

Category narrative73 words

Gibraltar benefits from full UK adequacy status (it is listed among the countries/territories the UK deems fully adequate for restricted transfers), and Gibraltar-based organisations may use the UK Extension to the EU-US Data Privacy Framework for transfers to the US. However, no confirmed EU Commission adequacy decision specifically covering Gibraltar (distinct from the UK's own adequacy decisions) was located; the Gibraltar Government's 2020 stated intention to seek one appears unresolved in current sources.

Periodic update · new data 2026-09-21

Cross-Border & Adequacy

Gibraltar's cross-border transfer adequacy mechanism was materially re-based this cycle. The Data Protection Regulations 2026 (LN 96/2026) replaced Gibraltar GDPR Article 45(1) references to UK adequacy regulations with references to European Commission adequacy decisions, and similarly re-based the law-enforcement-transfer adequacy mechanism under section 83A of the Data Protection Act 2004. This is confirmed at high confidence, corroborated across a T1 gazette source and T3 legal commentary independently describing the same substitution.

The practical effect is that Gibraltar's adequacy determinations for international transfers now track the European Commission's adequacy findings rather than the UK's own post-Brexit adequacy regulations, a reorientation consistent with Gibraltar's position under the Treaty on Gibraltar and the European Union Act 2026. This does not resolve every open question about Gibraltar's adequacy basis given its dual post-Brexit and Treaty-on-Gibraltar constitutional position; the exact current adequacy basis beyond this substitution was not fully resolved this cycle.

Outlook

Controllers relying on transfers previously justified under UK adequacy regulations should expect to need to re-confirm their legal basis against European Commission adequacy decisions instead. No enforcement or guidance testing the practical application of the re-based mechanism has surfaced yet, and that is the clearest indicator to watch for in the coming cycle.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (3)
  1. ConfirmedOneTrust DataGuidance — In the absence of an EU adequacy decision for Gibraltar, GRA's Transfers Guidance directs that EEA controllers transferring to Gibraltar should rely on Article 46 GDPR safeguards, including Standard Contractual Clauses and Binding Corporate Rules.observed
  2. ConfirmedICO — The UK ICO lists Gibraltar among the countries and territories covered by full UK adequacy regulations, permitting restricted transfers from the UK to Gibraltar without additional safeguards; Gibraltar-based organisations may also rely on the UK Extension to the EU-US Data Privacy Framework for transfers to certain self-certified US businesses.observed
  3. UncertainOneTrust DataGuidance — As of the guidance reviewed, the Government of Gibraltar intended to seek an EU adequacy decision to ensure continuing free flow of data from the EEA to Gibraltar, but no such decision had been finalised at that time.observed

#

Several sector overlays are evidenced (health, telecoms, employment, education); financial-sector-specific DP overlay guidance was not independently confirmed in this pass.

Primary frameworkCommunications (Personal Data and Privacy) Regulations 2006; Data Protection Act 2004 exemptions provisions
Traffic-light rationale — AmberSeveral sector overlays are evidenced (health, telecoms, employment, education); financial-sector-specific DP overlay guidance was not independently confirmed in this pass.

Sub-modules (7)

Financial Sector OverlayRed

Gibraltar's financial-services and online-gaming sectors are supervised by the Gibraltar Financial Services Commission; a distinct financial-sector DP overlay was not independently confirmed in sources reviewed.

Absence provenance: No dedicated financial-sector DP guidance located; flagged as plausible overlap given Gibraltar's finance/gaming centre status.. Searched: Gibraltar Financial Services Commission data protection overlay, GFSC GDPR guidance.

Claims (1):

  • Gibraltar's finance and gaming industries, supervised separately by the Gibraltar Financial Services Commission, plausibly create sector-specific data-handling obligations that intersect with general DP duties, though a dedicated overlay instrument was not confirmed.

Health Sector OverlayAmber

GRA's contact-tracing guidance designates the Gibraltar Health Authority as controller for COVID-19 contact-tracing data, requiring DPIA and Data Protection by Design.

Claims (1):

  • GRA's guidance on contact tracing and location data identifies the Gibraltar Health Authority as controller, requiring robust security, data minimisation, transparency, Data Protection by Design and Default, and a DPIA for contact-tracing apps.

Telecoms And EprivacyGreen

The Communications (Personal Data and Privacy) Regulations 2006 govern electronic marketing including SMS/MMS in Gibraltar, alongside the Gibraltar GDPR.

Claims (1):

  • The Communications (Personal Data and Privacy) Regulations 2006 apply to SMS/MMS and electronic marketing in Gibraltar in addition to the Gibraltar GDPR and Data Protection Act 2004.

Employment DataAmber

The 2022 GRA fine against the Royal Gibraltar Police confirmed violations relating to both law-enforcement and employment-purpose data processing.

Claims (1):

  • The GRA's investigation into the Royal Gibraltar Police confirmed data protection violations relating to both law-enforcement and employment-purpose processing of personal data.

Credit And ScoringRed

No Gibraltar-specific credit-scoring DP overlay was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar credit scoring data protection.

EducationAmber

GRA's exemptions guidance references education-sector processing exemptions under the DPA 2004/GDPR.

Claims (1):

  • GRA's exemptions guidance outlines exemptions available under the DPA 2004 and GDPR for, among other things, health, social work, and education processing.

InsuranceRed

No Gibraltar-specific insurance-sector DP overlay was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar insurance sector data protection.

Category narrative69 words

Sectoral overlays identified include health (Gibraltar Health Authority as controller for contact tracing under GRA COVID guidance), telecoms/eprivacy (Communications (Personal Data and Privacy) Regulations 2006 for direct marketing), employment (the Royal Gibraltar Police case involved employment-purpose data), and education (referenced in GRA exemptions guidance). Gibraltar's significant financial-services and online-gaming sectors are regulated by the Gibraltar Financial Services Commission, creating a plausible but not independently confirmed overlay with data-protection duties.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (5)
  1. SpeculativeGibraltar Regulatory Authority — Gibraltar's finance and gaming industries, supervised separately by the Gibraltar Financial Services Commission, plausibly create sector-specific data-handling obligations that intersect with general DP duties, though a dedicated overlay instrument was not confirmed.observed
  2. ConfirmedOneTrust DataGuidance — GRA's guidance on contact tracing and location data identifies the Gibraltar Health Authority as controller, requiring robust security, data minimisation, transparency, Data Protection by Design and Default, and a DPIA for contact-tracing apps.observed
  3. ConfirmedOneTrust DataGuidance — The Communications (Personal Data and Privacy) Regulations 2006 apply to SMS/MMS and electronic marketing in Gibraltar in addition to the Gibraltar GDPR and Data Protection Act 2004.observed
  4. ConfirmedOneTrust DataGuidance — The GRA's investigation into the Royal Gibraltar Police confirmed data protection violations relating to both law-enforcement and employment-purpose processing of personal data.observed
  5. ConfirmedOneTrust DataGuidance — GRA's exemptions guidance outlines exemptions available under the DPA 2004 and GDPR for, among other things, health, social work, and education processing.observed

#

Direct marketing sub-module is well evidenced; most other sub-modules rely on inferred alignment with EU ePrivacy norms rather than confirmed Gibraltar-specific sources.

Primary frameworkCommunications (Personal Data and Privacy) Regulations 2006
Traffic-light rationale — AmberDirect marketing sub-module is well evidenced; most other sub-modules rely on inferred alignment with EU ePrivacy norms rather than confirmed Gibraltar-specific sources.

Sub-modules (6)

Cookies And TrackersRed

Cookie/tracker consent is presumed governed by the Communications (Personal Data and Privacy) Regulations 2006 (an ePrivacy-equivalent instrument), but no Gibraltar-specific cookie guidance was confirmed.

Absence provenance: Not located in this pass.. Searched: GRA cookie consent guidance, Gibraltar ePrivacy cookies.

Dark PatternsRed

No Gibraltar-specific dark-pattern prohibition was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar dark patterns data protection.

Opt Out SignalsRed

No Gibraltar-specific recognition of Global Privacy Control or similar opt-out signals was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar Global Privacy Control, GRA opt-out signal guidance.

Clean Rooms And DcrRed

No Gibraltar-specific data clean room guidance was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar data clean room.

Cross Context AdvertisingRed

No Gibraltar-specific cross-context advertising rules (e.g., CPRA-style sale/share definitions) were located; not applicable under the GDPR-style model.

Absence provenance: Not applicable/located under GDPR-style regime.. Searched: Gibraltar cross-context advertising rules.

Direct MarketingGreen

The Communications (Personal Data and Privacy) Regulations 2006 impose consent and suppression requirements for SMS/MMS and electronic direct marketing.

Claims (1):

  • The Communications (Personal Data and Privacy) Regulations 2006 impose consent requirements applicable to SMS/MMS marketing in Gibraltar, operating alongside the Gibraltar GDPR and Data Protection Act 2004.
Category narrative33 words

Direct-marketing consent requirements under the Communications (Personal Data and Privacy) Regulations 2006 are confirmed for SMS/MMS marketing. No Gibraltar-specific cookie-consent enforcement, dark-pattern prohibition, opt-out-signal recognition, or clean-room/DCR guidance was located in this pass.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidance — The Communications (Personal Data and Privacy) Regulations 2006 impose consent requirements applicable to SMS/MMS marketing in Gibraltar, operating alongside the Gibraltar GDPR and Data Protection Act 2004.observed

#

Almost no Gibraltar-specific guidance found on profiling, ADM transparency, AI risk assessment, biometrics or genetic data; only the state-surveillance carve-out is confirmed.

Primary frameworkGibraltar GDPR Arts 9 & 22
Traffic-light rationale — RedAlmost no Gibraltar-specific guidance found on profiling, ADM transparency, AI risk assessment, biometrics or genetic data; only the state-surveillance carve-out is confirmed.

Sub-modules (6)

Profiling RestrictionsRed

No Gibraltar-specific profiling-restriction guidance was located; presumed to mirror GDPR Art 22.

Absence provenance: Not located in this pass.. Searched: GRA profiling restrictions guidance.

Automated Decision Making TransparencyRed

No Gibraltar-specific ADM transparency guidance was located.

Absence provenance: Not located in this pass.. Searched: GRA automated decision-making guidance.

Ai Risk AssessmentsRed

No Gibraltar-specific AI risk-assessment regime or interface with the EU AI Act was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar AI Act data protection, GRA AI risk assessment guidance.

Biometric RegimeRed

No Gibraltar-specific biometric-data regime guidance was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar biometric data regime, GRA facial recognition guidance.

Genetic DataRed

No Gibraltar-specific genetic-data regime guidance was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar genetic data regime.

State Surveillance CarveoutsAmber

GRA's exemptions guidance confirms carve-outs from the DPA 2004/GDPR for crime, law enforcement and public protection purposes, subject to case-by-case justification.

Claims (1):

  • GRA guidance confirms exemptions from the Data Protection Act 2004 and GDPR for crime, law enforcement and public protection purposes, which cannot be routinely relied upon and require case-by-case justification and documentation under the accountability principle.
Category narrative49 words

Algorithmic/biometric governance in Gibraltar is presumed to mirror GDPR Article 22 (automated decision-making) and Article 9 (biometric/genetic special categories) via the Gibraltar GDPR, but no Gibraltar-specific ADM, AI risk-assessment, or biometric-regime guidance was located. GRA's exemptions guidance confirms a state-surveillance carve-out for crime, law enforcement and public protection purposes.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidance — GRA guidance confirms exemptions from the Data Protection Act 2004 and GDPR for crime, law enforcement and public protection purposes, which cannot be routinely relied upon and require case-by-case justification and documentation under the accountability principle.observed

#

Coverage almost entirely absent for this module; only a general education-exemption reference was confirmed.

Traffic-light rationale — RedCoverage almost entirely absent for this module; only a general education-exemption reference was confirmed.

Sub-modules (5)

Age VerificationRed

No Gibraltar-specific age-verification requirement was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar age of digital consent, GRA age verification guidance.

Minor Profiling BansRed

No Gibraltar-specific minor-profiling ban was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar minor profiling ban.

Education SettingsAmber

GRA's exemptions guidance references education as one of the sectors with case-by-case DP exemptions.

Claims (1):

  • GRA's exemptions guidance identifies education as one of the sectors for which case-by-case processing exemptions from the DPA 2004/GDPR may apply.

Dependent AdultsRed

No Gibraltar-specific dependent-adults protection provision was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar dependent adults data protection, GRA vulnerable adults guidance.

Category narrative26 words

No Gibraltar-specific age-of-consent, parental-consent mechanism, minor-profiling ban, or dependent-adults provision was independently located in this pass, beyond the general education-sector exemption referenced in GRA's exemptions guidance.

Sources and claims (1)
  1. ConfirmedOneTrust DataGuidance — GRA's exemptions guidance identifies education as one of the sectors for which case-by-case processing exemptions from the DPA 2004/GDPR may apply.observed

#

Enforcement powers and activity are well evidenced; redress mechanisms, regulator capacity data, and GI-specific recent developments are not confirmed.

Primary frameworkData Protection Act 2004 Part IV (enforcement); Gibraltar GDPR Arts 83-84 (as retained)
Traffic-light rationale — AmberEnforcement powers and activity are well evidenced; redress mechanisms, regulator capacity data, and GI-specific recent developments are not confirmed.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The GRA has statutory power to investigate and fine controllers/processors, as demonstrated by two fines issued against the Royal Gibraltar Police.

Claims (1):

  • The GRA fined the Royal Gibraltar Police £5,000 in August 2020 for unlawful disclosure of personal data, and £10,000 in April 2022 for multiple further breaches of the DPA 2004 and GDPR, demonstrating active use of its investigatory and fining powers.

Enforcement Activity IndexAmber

GRA published enforcement-activity reports in June 2020 covering investigations into deletion failures, unlawful disclosure, unlawful processing, SAR failures, unlawful CCTV, and unsolicited marketing; it has also issued at least two fines against the same controller (2020, 2022).

Claims (1):

  • GRA published, on 2 June 2020, reports on investigations and enforcement covering deletion of personal data, unlawful disclosure to third parties, unlawful processing, failure to respond to subject access requests, unlawful CCTV installation, and unsolicited email marketing, alongside a breach-notification report on unlawful CCTV footage disclosure.

Regulator Funding And CapacityRed

No GRA funding or headcount data was located in this pass.

Absence provenance: Not located in this pass.. Searched: GRA budget headcount data protection, Gibraltar Regulatory Authority annual report staffing.

Collective Redress And Class ActionsRed

No Gibraltar-specific collective-redress or class-action mechanism for data protection claims was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar data protection class action, Gibraltar collective redress data protection.

Private Right Of ActionRed

No Gibraltar-specific private right of action for data protection breaches (distinct from GRA enforcement) was located.

Absence provenance: Not located in this pass.. Searched: Gibraltar private right of action data protection, Gibraltar Supreme Court data protection claim.

Recent Developments 180DRed

No Gibraltar-specific data-protection legislative, guidance, or case-law development within the last 180 days (i.e., since approximately February 2026) was located; UK-EU adequacy renewal activity in late 2025/2026 pertains to the UK's own adequacy status rather than a confirmed Gibraltar-specific instrument.

Absence provenance: No GI-specific development within the last 180 days was confirmed in this research pass.. Searched: Gibraltar data protection news 2026, GRA press release 2026, Gibraltar GDPR amendment 2026.

Category narrative68 words

The GRA has demonstrated active investigatory and fining powers, evidenced by two separate fines against the Royal Gibraltar Police (£5,000 in 2020 and £10,000 in 2022) for DPA 2004/GDPR breaches, and has published enforcement-activity and breach-notification reports. No Gibraltar-specific collective-redress, class-action, or private-right-of-action mechanism was located, and no distinctly Gibraltar-specific development within the last 180 days was confirmed (recent EU-UK adequacy renewal activity is UK-specific rather than GI-specific).

Periodic update · new data 2026-09-21

Enforcement & Redress

Gibraltar's data protection enforcement regime follows the GDPR-standard fine tier structure: the highest tier of Gibraltar GDPR fines, under Article 83(5), reaches up to EUR 17.5 million or, for an undertaking, a percentage-of-turnover equivalent. This is assessed at Probable confidence, sourced via secondary legal summary rather than independently confirmed against the GRA's own enforcement decisions this cycle.

No GI-specific enforcement decision — fines, notices, or other regulator actions from the GRA's Information Rights Division — was located this cycle. The enforcement framework itself remains stable and unchanged; what is absent is any case-level activity to report against it.

Outlook

The absence of a located enforcement decision this cycle should be read as a research gap rather than a confirmed no-enforcement finding. The clearest development to watch for is any GRA decision applying the Article 83(5) fine tier, or any case testing the newly re-based adequacy mechanism described under Cross-Border & Adequacy.

1 further periodic run re-emitted the standing brief unchanged and is not shown.

Sources and claims (2)
  1. ConfirmedOneTrust DataGuidance — The GRA fined the Royal Gibraltar Police £5,000 in August 2020 for unlawful disclosure of personal data, and £10,000 in April 2022 for multiple further breaches of the DPA 2004 and GDPR, demonstrating active use of its investigatory and fining powers.observed
  2. ConfirmedOneTrust DataGuidance — GRA published, on 2 June 2020, reports on investigations and enforcement covering deletion of personal data, unlawful disclosure to third parties, unlawful processing, failure to respond to subject access requests, unlawful CCTV installation, and unsolicited email marketing, alongside a breach-notification report on unlawful CCTV footage disclosure.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

Blocking. 1 failing check(s).

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okFAIL
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct31.25
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Gibraltar
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 27 claim(s) (27 category placement(s)), 24 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (37 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 82Enforcement & Redresscollective redress and class actions
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator identity, core instruments, breach-notification duties, security-measures guidance, and enforcement activity (regulator_and_framework, controller_processor_duties, enforcement_and_redress) are well-evidenced via T1 (ICO/EDPB) and T3 (DataGuidance news coverage of GRA decisions/guidance) sources. Cross_border_and_adequacy is partially T1-grounded (ICO adequacy list, EDPB UK adequacy opinion) but the EU-side adequacy status specific to Gibraltar remains unconfirmed. Lawful_processing_and_special_data, data_subject_rights, and sectoral_watch rely on a mix of confirmed GRA guidance (T3) and inferred GDPR-mirroring (Probable confidence). Adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance, and children_and_vulnerable_groups had very limited Gibraltar-specific primary or secondary sourcing; most sub-modules in these three carry absent_field_provenance rather than fabricated claims.

Unresolved questions (5):

  • Has the European Commission issued (or is it considering) an adequacy decision specifically for Gibraltar, distinct from the UK's own EU adequacy decisions?
  • What are Gibraltar's DPO-appointment thresholds under the DPA 2004, if any diverge from GDPR Arts 37-39?
  • Does Gibraltar require controller registration/notification/filing with the GRA, and if so under what fee schedule?
  • Is there a Gibraltar-specific cookie-consent enforcement record or guidance distinct from the Communications (Personal Data and Privacy) Regulations 2006?
  • What data-protection developments, if any, has the GRA issued in the last 180 days (since February 2026)?

Escalate to primary-source review: yes