shall submit a change registration request to the Authority within a period of eight days of the occurrence of changes. Rules defined in subsections (1), (3) and (5) must be applied in the case of the change registration procedure on condition that the request must contain the data which changed. 36. Data Protection Audit Section 69 (1) The data protection audit is a service provided by the Authority designed to provide high standard data protection and data security on control operations carried out or planned through the evaluation of professional standards defined and published by the Authority. Planned control operations may be audited should the concept regarding data control enable this. (2) The Authority shall conduct a data protection audit pursuant to the request of the controller. The fee defined in the ministry decree must be paid to conduct the data protection audit. (3) The Authority shall register the outcomes of the data protection audit in an evaluation report compiled in connection with the audit. This evaluation report may put forth recommendations for the controller. The evaluation report is public, unless otherwise requested by the controller. (4) The data protection audit does not restrict the Authority from exercising the scopes of authority defined within the scope of the present Act. 37. Initiating Criminal, Infringement and Disciplinary Proceedings Section 70 (1) The Authority shall initiate criminal proceedings with the body authorised to launch such proceedings if the Authority suspects that an offence has been committed during the course of the procedure. The Authority shall initiate infringement or disciplinary proceedings with the body authorised to launch such proceedings if the Authority suspects that an infringement or disciplinary violation has been committed during the course of the procedure. (2) The body defined in subsection (1) shall notify the Authority of their position in connection with the launch of the procedure – unless otherwise regulated by law – within a period of 30 days and shall notify the Authority of its outcomes within a period of 30 days following its completion. 38. Data Control and Confidentiality Section 71 (1) The Authority is authorised to control - to the extent and duration required for conducting the procedure - any personal data during the procedure, as well as data classified by law as confidential information and linked to exercising their profession, which relate to the procedure and the control of which is required to efficiently conduct the procedure. (2) The Authority is entitled to use data acquired during the course of the investigation within the scope of its administrative proceedings. (3) The Authority may have access to data defined in Article 23 (2) of Act CXI of 2011 on the Commissioner of Fundamental Rights in accordance with the conditions set out in Article 23 (7) of Act CXI of 2011 on the Commissioner of Fundamental Rights. (4) Within the scope of the procedure conducted in connection with the control of classified information, the vice president, executive public officer and inspector of the Authority may also gain access to classified information without holding any user authorisation defined in the act on the protection of classified information, if they hold an appropriate level personal attestation of security clearance. (5) The president and vice president of the Authority, as well as individuals employed or contracted, or previously employed or contracted by the Authority - with the exception of providing data

Select target paragraph3