Compliance Updates
MGA: Update to the Incident Reporting Requirements
The Malta Gaming Authority would like to inform its licensees of updates made to the Incident Report mechanism available through the Licensee Portal The information hereunder outlines relevant guidance and procedures for the submission of an Incident Report through the updated reporting instrument entitled the ‘Technical – Information Security Incident’.
As mandated by Articles 37(2)(c) and (d) of the Gaming Authorisations and Compliance Directive (Directive 3 of 2018), “Licensees shall notify the Authority forthwith, and in any case no later than three (3) working days after, the following:
(c) Any breach of the licensee’s information security that adversely affects the confidentiality of information relating to players;
(d) Any breach of the licensee’s information security that precludes players from accessing their accounts for a period exceeding twelve (12) hours.”
In this regard, Licensees are obliged to submit an Incident Report in order to notify the Authority of the circumstances relating to an information security breach that meet the above specified criteria. Additionally, Licensees are advised to remain mindful of any further obligations emanating from the General Data Protection Regulation (EU/2016/679) and any relevant legislation.
The Technical – Information Security Incident option will be accessible through the “New/Change” dropdown menu via the Portal. Upon selection, users will be directed to the applicable sections of the ‘Technical – Information Security Incident’ where all compulsory fields and any relevant documentation must be submitted to the Authority.
Upon submission, the Incident Report shall undergo review by the Authority. Any missing information that may be identified by the Authority, shall be requested accordingly from the Licensee. It is imperative that any pending clarifications are addressed in a timely manner.
If no further clarifications are deemed necessary by the Authority, the Incident Report will be closed off accordingly, and any relevant documentation will be securely filed for record-keeping purposes.
Any Incident Reports left in ‘Draft’ form (i.e. opened but not effectively submitted) for a period of ninety (90) days shall be automatically discarded.
-
Compliance Updates5 days ago
Cucacao Gaming Authority – AML Policy
-
Asia7 days ago
Natural8 India welcomes 2025 in style with Natural8 India X APT Manila Classic 2025
-
eSports7 days ago
PandaScore launches innovative genAI-powered StoryBuilder product
-
Africa6 days ago
Soft2Bet takes its first steps into Africa with a multi-year Turnkey deal with media leader Channels TV
-
Cryptocurrency7 days ago
How Cryptocurrencies Are Reshaping the iGaming Landscape
-
Eastern Europe6 days ago
Conquering Challenges: TotoGaming in Romania – 1 Year in the Market
-
eSports6 days ago
Melbet and Eternal Fire have formed a new partnership
-
Interviews6 days ago
Oliver Niner on his new Head of B2B role at PandaScore