required to compile an internal data protection and data security regulation to execute the present
Act.
19. Conference of Internal Data Protection Officers
Section 25
(1) The purpose of the conference for internal data protection officers (hereinafter conference) is to
establish regular professional contacts between the Authority and internal data protection officers
with the aim of developing standard legal practices in regard to the application of legislation
relevant to the protection of personal data and accessing data of public interest.
(2) The president of the Authority convenes the conference as required; although, at least once a
year, and defines its agenda.
(3) The internal data protection officers of every organisation appointed by law, as a mandatory
requirement, are members of this conference.
(4) The internal data protection officers who do not have to be appointed by law may also be
members of this conference, in which regard these officers are entitled to register in the internal
data protection officer database managed by the Authority.
(5) The Authority manages an internal data protection officer database of conference members for
networking purposes. The name of the internal data protection officer, postal and email address, as
well as the organisation they represent is registered in this database.
(6) The Authority maintains the data defined in subsection (5) in the databases until the mandate of
the data protection officer expires or the Authority becomes aware of this.
CHAPTER 3
ACCESSING DATA OF PUBLIC INTEREST
20. General Rules Concerning Accessing Data of Public Interest
Section 26
(1) Bodies or individuals undertaking state or local government duties, as well as other duties
defined in the relevant legislation (hereinafter jointly referred to as body undertaking public duties)
must be ensured the opportunity to provide access to data of public interest and data public on
grounds of public interest to anyone requesting such data under their control, with the exception of
cases defined within the scope of the present Act.
(2) The name of the person undertaking tasks within the scope of responsibilities and authority of
the body undertaking public duties, as well as their scope of responsibilities, scope of work,
executive mandate and other personal data relevant to the provision of their responsibilities to
which access must be ensured by law qualify as data of public interest.
(3) Should it not otherwise be regulated by law, data of public interest implies data under the control
of bodies or individuals providing services which must, as a mandatory requirement, be used on the
grounds of the relevant legislation or the contract concluded with the state or the local government,
cannot be provided through other means, is relevant to their activities and which do not qualify as
personal data.
Section 27
(1) Access to data of public interest and data public on grounds of public interest cannot be ensured
should this data qualify as classified information on the grounds of the act on the protection of
classified information.
(2) Right to access data of public interest and data public on grounds of public interest may – by
specifying the type of data – be restricted by law