data processor and the activities they undertake in connection with control, in addition to the legal
grounds and recipients should the personal data of the data subject not be transferred.
(2) The controller keeps a record of data transferred to verify the legitimacy of the data transferral
and informs the data subject which file details the date on which the personal data they controlled
was sent, the legal grounds of this action and its recipients, the specific scope of the personal data
sent, as well as other data specified in legislation prescribing control.
(3) The Act prescribing control may restrict the duration of the obligation to safeguard data set out
in subsection (2) in the data transfer file, and therefore, the information notification period. Within
the scope of this restriction, a minimum period of five years applies in the case of personal data and
a minimum of 20 years in the case of special data.
(4) The controller shall provide clear information in writing within the shortest possible space of
time following the submission of the request; however, no later than within 30 days.
(5) Information specified in subsection (4) is provided free of charge, if the individual requesting
the information has not yet submitted a request for information to the controller in connection with
the same scope of data in the same year. The rate of reimbursement of costs may also be specified in
the contract concluded by the parties. Reimbursed costs that have already been paid must be
reimbursed in the event that the data was illegitimately controlled, or the request for information
leads to correction.
Section 16
(1) The controller is only entitled to deny a request for information in cases specified in Section 9
(1) and Section 19.
(2) Should a request for information be denied, the controller must notify the data subject of this in
writing by referring to the relevant section of the present Act on what grounds the request for
information was denied. Should a request for information be denied, the controller must inform the
data subject of the means available to facilitate legal redress in court and contact the National
Authority for Data Protection and Freedom of Information (hereinafter Authority) to seek help.
(3) The controller keeps the Authority informed about rejected requests each year up to 31 January
following the year under review.
Section 17
(1) The controller shall correct the personal data should the personal data not be authentic and the
controller has access to the authentic personal data.
(2) Personal data must be deleted should
a. its control be illegal;
b. it have been requested by the data subject in accordance with point c) of Section 14;
c. it be incomplete or incorrect – and this cannot be legitimately changed – on condition that
the law does not rule out deletion;
d. the objective of the control have ceased to exist or the period defined in the relevant
legislation for storing the data have expired;
e. it have been ordered by the court or the Authority.
(3) Deletion obligations do not apply to personal data which is recorded on a data carrier which
must be placed in the archives in accordance with legislation governing the preservation of archival
materials in cases specified in subsection (2)(d).
(4) Instead of deletion, the controller blocks the personal data should the data subject request this, or
in the event that the basis of the information available, deletion would presumably violate the
rightful interests of the data subject. Personal data blocked through such means may exclusively be
controlled while the control objective remains valid which barred the deletion of the personal data.