Privacy notice
This notice explains what personal data ImportaMT collects, why, and what you can do about it. The controller is the Malta Competition and Consumer Affairs Authority.
What we collect
Your email address and telephone number; the contact name you give; the trader details you declare, including legal name, VAT number, EORI number where held and registered address; the product details and declared intended use; the documents you upload; payment metadata from our payment processor; and technical records of access, including IP address and user agent.
What we do not collect
No identity document, photograph or biometric is ever requested. The portal performs no identity proofing and must not appear to.
Why we process it
To carry out a public task: assessing pre-import compliance documentation and issuing decisions under the Authority's statutory functions. Payment data is processed to perform a contract. Access logs are kept to meet our accountability and audit obligations.
Who sees it
The verifier assigned to your request, who attests no conflict of interest before documents are shown; the Committee and secretariat, for oversight and sampling; and system administrators, who can see metadata and state history but not your documents. Customs officers see outcome and metadata only, never documents.
What is published
Only the field set the Committee has approved for public view — by default the scheme identity, the receipt reference, the current status, the decision date and the approved product matching fields. Trader identity and the recorded acts are not published by default.
Mailbox control is the assurance level
Because there is no password, anyone who can read the mailbox an application was made from can see that application. This is the same assurance level as a password-reset flow anywhere, and it is stated here plainly rather than left implied.
Where it is held
Within the EU. Documents are held in private storage, encrypted at rest, reachable only through short-lived signed links issued after a server-side permission check. Uploads are virus scanned before a verifier can see them.
How long we keep it
Documents are deleted when a draft or unpaid request expires after 60 days of inactivity. Decision records and the audit log are retained under the Authority's retention schedule, and no application path deletes audit entries early.
Your rights
You may request access, rectification, erasure where applicable, restriction, and portability, and you may object to processing. Signing in to your applications self-serves much of the access right. Contact the Authority's Data Protection Officer to exercise any of them, or to complain to the Information and Data Protection Commissioner.
Email
Transactional email is sent in the language you choose and contains no tracking pixels. Validity reminders carry a one-click unsubscribe; unsubscribing stops reminders only and never suppresses email about an application in flight.
- Version
- 1.0
- Effective
- 1 September 2026
- Languages
- English · Malti
Contact the MCCAA, or the Authority’s Data Protection Officer for anything in the privacy notice.