The new Malta Business Wallet & CDR Regulations

The Malta Business Wallet

Sammut Azzopardi were honoured to be present for the official launch of the Malta Business Wallet, which took place on the 14th of May 2026 during an inaugural ceremony hosted at the Malta Business Registry, in the presence of the Minister for the Economy, Hon. Silvio Schembri.

The Malta Business Wallet is a new digital tool designed to help businesses securely organise and manage key documentation in one centralised platform. It is intended to streamline the secure sharing of corporate and compliance-related information between businesses, their representatives, and authorised third parties, while remaining voluntary in nature.

A key distinctive feature of the Malta Business Wallet is the introduction of the right to selective disclosure. This allows users who upload data and documentation onto the platform to retain full control over how their information is shared, enabling them to choose which entities may access their data and to grant access only to specific documents. This approach strengthens transparency and user autonomy, while ensuring that information is shared strictly on a need-to-know basis.

The need for such a tool arises from the increasing demand for more efficient and modern public services, particularly in a business environment where compliance requirements can be time-consuming and repetitive. By simplifying processes and reducing bureaucracy, the Malta Business Wallet supports a more business-friendly ecosystem while also aligning Malta with evolving EU digitalisation initiatives and future European frameworks focused on interoperability, transparency, and the easier exchange of verified information.

The new CRD Regulations

The Malta Business Wallet was introduced as part of a broader package of reforms aimed at strengthening Malta’s digital infrastructure for businesses. This initiative is also backed by a new legislative framework: The Companies Act (Central Data Repository) Regulations 2026, published through Legal Notice 151 of 2026, which provides the necessary legal basis to support its implementation and ensure that the platform can be effectively used as an official tool for the secure management and sharing of business information.

The Regulations establish a secure digital repository to be administered by the Registrar of Companies under the Malta Business Registry. 

Importantly, the regulations make clear that the repository does not replace existing due diligence or compliance obligations under anti-money laundering and other applicable laws, but rather provides an additional digital mechanism through which information may be exchanged securely and efficiently. 

Through the Malta Business Wallet, the central data repository  functions as a secure digital platform allowing users to upload, store, retrieve, amend and selectively share information with authorised relying parties. 

Users may include company officers, partners in commercial partnerships, legal representatives, and subject persons acting on behalf of clients, while relying parties may include competent authorities, anti-money laundering subject persons, and other authorised entities approved by the Registrar. 

Competent authorities are also permitted to access data for the prevention, investigation and prosecution of money laundering, terrorism financing and other serious crimes.    

The regulations further outline the types of information that may be hosted on the repository. These include identity documents, proof of residential or service addresses, documentary evidence relating to the appointment of subject persons, and any additional information the Registrar may prescribe where necessary for compliance purposes. 

The framework also introduces safeguards relating to data protection, access logging, verification procedures, retention periods and biometric verification. Data containing personal information would generally be retained for five years, extendable to ten years in cases linked to financial crime investigations or other legal obligations. 

The regulations also establish penalties for fraudulent use of the repository, including fines of up to €50,000 and imprisonment of up to three years. 

Facebook
Twitter
LinkedIn

Other articles of interest