We use cookies to personalise content and ads, to provide social media features and to analyse our traffic. We also share information about your use of our site with our social media, advertising and analytics partners. Read More

Log in


Date last updated:  24 May 2021
The Malta Institute of Accountants (“MIA”) believes the privacy and confidentiality of an individual’s personal information is important. We provide the following updated privacy notice (the “Privacy Notice”) in order to demonstrate our firm commitment to privacy.
References to “data controller”, “data subject”, “personal data”, “process”, “processed”, “processing” and “Data Protection Officer” in this Privacy Notice have the meanings set out in, and will be interpreted in accordance with applicable laws, including but not limited to the General Data Protection Regulation (EU) 2016/679 and the Data Protection Act, Chapter 586 of the Laws of Malta and subsidiary legislation thereto, as may be amended from time to time.


The Malta Institute of Accountants (hereinafter referred to as the “MIA” “we”, “us” or “our” in this Privacy Notice) is an approved accountancy body in accordance with the requirements of the Accountancy Profession Act and of the relevant Legal Notices, having its address at Level 1, Tower Business Centre, Tower Street, Swatar, BKR4013, Malta.
If you have any questions about this Privacy Notice, including concerns about your personal data or our data collection practices, please feel free to contact us by post on the above-mentioned address or contact the MIA’s Data Protection Officer, Maria Mifsud Farrugia by phone on (+356) 2258 1900 or by email at mmfarrugia@miamalta.org.


The term “personal data” refers to all personally identifiable information about the participant which includes all the information provided to us in the Continuing Professional Education (CPE) registration form and all information which may arise that can be identified with an individual personally, including information of third party’s provided to us by a company or other corporate entity registering on behalf of a participant(s).
The personal data that the MIA collects about the participant is the data voluntarily provided to us for CPE registration purposes and Sponsorship.
The MIA collects personal information to fulfil its role as a professional representative body. As we perform various different functions and activities to service the needs of its members, registered students and other non-member users, the personal information requested and collected will vary depending on your group.
We typically collect the following categories of data:
(a) Identification Data and other Contact Data: such as name(s), surname(s), identity card number, date and place of birth, nationality, residential address, and e-mail address, telephone numbers or any similar contact information available;
(b) Student/Professional/Other User Data: such as student or employment details, educational qualifications, work history, current employment and position;
(c) Registration Data on courses and other events: such as information connected to training, CPE records, attendance records for CPE courses and events and subscription information with respect to journals, reports and newsletters issued by the MIA;
(d) Regulatory Data: such as certificates, or information requests received from legal bodies, such as the Accountancy Board, government authorities or regulators; or
(e) Transaction Data and Transaction Information: bank account and credit card details or details of payments, statements, incoming and outgoing payments.
We only collect information, including personal data that we believe to be relevant and required for the MIA to carry out its functions and activities and to conduct its business as required by law and regulatory obligations.


Where you provide us with personally identifiable information relating to other people, such as your directors, officers, employees, advisors or other related persons, you shall be solely responsible for making sure that the provision of such data by you to the MIA fully complies with applicable data protection law and the relevant person in regard to whom the data relates has been provided with the necessary information at law regarding the MIA’s processing of the personal data and where necessary you will obtain their consent to our use of their information.
Any information notices, consents or other applicable requirements that may be required to be fulfilled for the provision of third party data to us shall be borne solely by you and you hereby fully indemnify the MIA and shall render the MIA completely harmless against all costs, damages or liability of whatsoever nature resulting from any claims or litigation (instituted or threatened) by any third party against the MIA as a result of the provision of any third party personal data by you to the MIA.


Typically, the MIA will process your personal data for the following purposes:
(a) registering you as a user of the Institute’s services;
(b) creating and providing access to an online account via our website;
(c) registering you to attend a CPE training course or other event organised by us and maintaining records of CPE declarations;
(d) registering you as a speaker;
(e) registering you as a sponsor;
(f) communicating with you about your account, including process payments or registration fees;
(g) providing you with, products, services, or information you have requested from us or which are offered by MIA and/or its business partners;
(h) keeping you updated and providing notices or advertisements, circulars, agendas that are consistent with MIA’s organisational purpose;
(i) to request your participation in MIA or third-party surveys or other initiatives;
(j) monitoring your performance on CPE courses and assist you in the tracking of your progress; or
(k) providing marketing information about the MIA’s services as well as news, events, and other information connected thereto.


The use for which your personal information is requested and collected will vary depending on your group. Typically the MIA will collect personal data in the manners outlined below:
(a) by email, by written correspondence, on hard copy forms (such event registration forms, sponsorship forms and speakers image release forms);
(b) when you post a query, submission, complaint, request registration, effect a payment transaction or otherwise make contact with us;
(c) when you contact us voluntarily in other circumstances such as when seeking to attend an MIA organised or sponsored event or function; or
(d) electronic systems such as registration of an event through your MIA account and online registration forms.
Generally, you would have provided your personal data to the MIA directly. However, in some instances, we may collect personal data about you from third party sources, such as your employer.


From time-to-time MIA may require to contact you about promotional offers, marketing as well as information in relation to the products and services provided by third parties (“Marketing”).
Marketing will be carried out primarily through the circulation of e-mails. Other means of communication may also be used, however the MIA shall always seek your prior consent.
You may withdraw consent to the processing of personal data for Marketing purposes at any time by sending us an e-mail on: info@miamalta.org. Alternatively, you may unsubscribe to such communications by clicking the “Unsubscribe” link contained in the footer of any Marketing email you will receive from us. However, please note that by withdrawing your consent for Marketing communication does not affect the lawfulness of the processing of personal data based on such consent prior to its withdrawal.


The Institute’s legal basis for processing personal data provided will vary from activity to activity. In some instances, processing may have more than one lawful basis. The following information below summarises the basis on which we process personal information.
(a) for the purpose of effecting the registration form concluded with the MIA (completing the registration form or any amendments) for participating in a CPE course or event;
(b) for the purposes of performing our contract with you, such as our sponsorship, joint collaboration agreements, or in anticipation of you becoming a general user of the Institute;
(c) where we have a legitimate interest in using it, such as, day to day operational and business purposes, including, maintaining our membership database or for the purposes of managing our contracts and relationships with our members, students, non-member users, suppliers, or service providers;
(d) for compliance with our legal or regulatory obligations, including, enabling members to attain their CPE requirements to maintain their professional competence by providing information about courses and events, ongoing monitoring and certification or regulatory reporting obligations; and
(e) if we need and you have given your consent to use of your personal data for a particular purpose, including Marketing consent.


The recipients of the personal data are:
(a) selected individuals within the Institute;
(b) MIA’s Subsidiaries/Affiliates/Partners;
(c) MIA’s Investigating Committee, Disciplinary Committee and Appeals Board;
(d) Governmental bodies including the Accountancy Board;
(e) third parties/subcontractors to whom disclosure is required for the performance of the registration including IT service providers, the provider of our members’ management system and website hosting and management and cloud storage services;
(f) professional advisors including auditors, legal advisors if necessary, to establish, exercise or defend MIA legal rights and obtain advice in connection with the running of the operation. Personal data may be shared with these advisors as necessary in connection with the services they have been engaged to provide;
(g) payment gateways (such as Paypal);
(h) online conferencing platforms (such as Zoom);
(i) third parties to whom disclosure may be required as a result of legal obligations imposed on the MIA.
The MIA’s recipients of personal data are mainly located within the EU. However, please note that we do transfer some personal data to entities located outside of the EEA, including to entities located in the United States. Prior to transferring personal data outside the EAA, we ensure that appropriate transfer safeguards, as set out in Chapter V of the GDPR, are implemented. The safeguards that we typically implement are the Standard Contractual Clauses. These are pre-determined sets of contracts approved by the European Commission which require the parties signing the contracts to adhere to an adequate level of data protection. You may request more information on the way in which we transfer personal data outside of the EEA by contacting our Data Protection Officer via email at mmfarrugia@miamalta.org and by telephone at 22581900. The entities located outside the EEA that we transfer personal data to include:
  • Wild Apricot Inc. – used as our membership management platform;
  • Microsoft Inc. – used for cloud storage;
  • Zoom Video Communications Inc. – used for online conferencing;


The processing of personal data is not a statutory requirement: it is a requirement in order to complete the registration form. Failure to provide personal data impedes us from being in a position to conclude your registration.


Your personal data will not be used for any automated decision-making or profiling.


Information will be retained for no longer than is necessary for the purpose for which it was obtained by us, or as required or permitted for legal and regulatory purposes, and for legitimate business purposes. In certain circumstances, where required by law or applicable regulations or where the Institute deems it necessary for our legitimate business, regulatory and / or legal purposes, we may hold the data for a longer or shorter period.


For as long as we hold personal data about an individual, that individual may (where applicable):
(a) request access to and rectification of personal data where incomplete or inaccurate;
(b) request erasure of his personal data;
(c) request restriction of processing of his personal data;
(d) object to the processing of his personal data;
(e) request provision of his personal data in a structured, commonly used and machine-readable format; and
(f) request transmission to himself or another controller indicated by the individual.
Please note that your rights are not absolute.


MIA and its Data Protection Officer may be contacted on complaints regarding the processing of personal data at the details indicated above. A right to lodge a complaint with the Office of the Information and Data Protection Commissioner in Malta (www.idpc.gov.mt) is also in place.


Recent News

Contact Us

Suite 4, Level 1, Tower Business Centre, Tower Street, Swatar, BKR 4013, Malta 

E-mail: info@miamalta.org

Tel. +356 2258 1900