data processor and the activities they undertake in connection with control, in addition to the legal grounds and recipients should the personal data of the data subject not be transferred. (2) The controller keeps a record of data transferred to verify the legitimacy of the data transferral and informs the data subject which file details the date on which the personal data they controlled was sent, the legal grounds of this action and its recipients, the specific scope of the personal data sent, as well as other data specified in legislation prescribing control. (3) The Act prescribing control may restrict the duration of the obligation to safeguard data set out in subsection (2) in the data transfer file, and therefore, the information notification period. Within the scope of this restriction, a minimum period of five years applies in the case of personal data and a minimum of 20 years in the case of special data. (4) The controller shall provide clear information in writing within the shortest possible space of time following the submission of the request; however, no later than within 30 days. (5) Information specified in subsection (4) is provided free of charge, if the individual requesting the information has not yet submitted a request for information to the controller in connection with the same scope of data in the same year. The rate of reimbursement of costs may also be specified in the contract concluded by the parties. Reimbursed costs that have already been paid must be reimbursed in the event that the data was illegitimately controlled, or the request for information leads to correction. Section 16 (1) The controller is only entitled to deny a request for information in cases specified in Section 9 (1) and Section 19. (2) Should a request for information be denied, the controller must notify the data subject of this in writing by referring to the relevant section of the present Act on what grounds the request for information was denied. Should a request for information be denied, the controller must inform the data subject of the means available to facilitate legal redress in court and contact the National Authority for Data Protection and Freedom of Information (hereinafter Authority) to seek help. (3) The controller keeps the Authority informed about rejected requests each year up to 31 January following the year under review. Section 17 (1) The controller shall correct the personal data should the personal data not be authentic and the controller has access to the authentic personal data. (2) Personal data must be deleted should a. its control be illegal; b. it have been requested by the data subject in accordance with point c) of Section 14; c. it be incomplete or incorrect – and this cannot be legitimately changed – on condition that the law does not rule out deletion; d. the objective of the control have ceased to exist or the period defined in the relevant legislation for storing the data have expired; e. it have been ordered by the court or the Authority. (3) Deletion obligations do not apply to personal data which is recorded on a data carrier which must be placed in the archives in accordance with legislation governing the preservation of archival materials in cases specified in subsection (2)(d). (4) Instead of deletion, the controller blocks the personal data should the data subject request this, or in the event that the basis of the information available, deletion would presumably violate the rightful interests of the data subject. Personal data blocked through such means may exclusively be controlled while the control objective remains valid which barred the deletion of the personal data.

Select target paragraph3