bodies under their supervision or some of these (hereinafter individual disclosure list).
(4) The Minister in charge of the direction of civil national security services and the Minister
competent for the direction of civil intelligence activities define the scope of data to be disclosed by
civil national security agencies, whilst the Minister for Defence defines the scope of data to be
disclosed by national defence agencies - after requesting the opinion of the Authority – within the
scope of a decree.
(5) Compiling and modifying the individual disclosure list – having requested the opinion of the
Authority - is designated to the scope of authority of the body in the case of bodies obliged to
disclose information operating as corporate bodies.
(6) The head of the organisation obliged to disclose information annually reviews the disclosure list
they issued in accordance with subsection (3) on the basis the data of data requests made in
connection with data of public interest not included in the disclosure list and adds items to this list
based on the high rate or volume of data requests made.
(7) Depending on the type of data to be disclosed, it is also possible to determine the frequency of
disclosure in these disclosure lists.
(8) The Authority is also entitled to make recommendations for compiling and contributing to
special and individual disclosure lists.
CHAPTER 5
NATIONAL AUTHORITY FOR DATA PROTECTION AND FREEDOM OF
INFORMATION
25. Legal Status of the Authority
Section 38
(1) The Authority shall be an autonomous state administration organ.
(2) The task of the Authority shall be to supervise and promote the enforcement of the right to the
protection of personal data, and of the right to access to data of public interest or to data public on
grounds of public interest.
(3) In the performance of its tasks pursuant to subsection (2) and to the provisions laid down in this
Act, the Authority
a) shall conduct investigations on the basis of reports;
b) may conduct ex officio data protection procedures;
c) may conduct ex officio procedures for the supervision of classified data;
d) may institute legal proceedings for infringements relating to access to data of public interest or to
data public on grounds of public interest;
e) may intervene in legal proceedings initiated by others;
f) shall keep a data protection register.
(4) In the performance of its tasks pursuant to subsection (2), the Authority
a) may put forward proposals for the making or amendment of rules of law affecting the processing
of personal data or affecting access to data of public interest or to data public on grounds of public
interest, and shall give an opinion on the draft rules of law affecting its tasks;
b) shall publish an annual report on its activities by 31 March of the calendar year and submit the
report to Parliament;
c) shall issue general recommendations and recommendations for specific controllers;