shall submit a change registration request to the Authority within a period of eight days of the
occurrence of changes. Rules defined in subsections (1), (3) and (5) must be applied in the case of
the change registration procedure on condition that the request must contain the data which
changed.
36. Data Protection Audit
Section 69
(1) The data protection audit is a service provided by the Authority designed to provide high
standard data protection and data security on control operations carried out or planned through the
evaluation of professional standards defined and published by the Authority. Planned control
operations may be audited should the concept regarding data control enable this.
(2) The Authority shall conduct a data protection audit pursuant to the request of the controller. The
fee defined in the ministry decree must be paid to conduct the data protection audit.
(3) The Authority shall register the outcomes of the data protection audit in an evaluation report
compiled in connection with the audit. This evaluation report may put forth recommendations for
the controller. The evaluation report is public, unless otherwise requested by the controller.
(4) The data protection audit does not restrict the Authority from exercising the scopes of authority
defined within the scope of the present Act.
37. Initiating Criminal, Infringement and Disciplinary Proceedings
Section 70
(1) The Authority shall initiate criminal proceedings with the body authorised to launch such
proceedings if the Authority suspects that an offence has been committed during the course of the
procedure. The Authority shall initiate infringement or disciplinary proceedings with the body
authorised to launch such proceedings if the Authority suspects that an infringement or disciplinary
violation has been committed during the course of the procedure.
(2) The body defined in subsection (1) shall notify the Authority of their position in connection with
the launch of the procedure – unless otherwise regulated by law – within a period of 30 days and
shall notify the Authority of its outcomes within a period of 30 days following its completion.
38. Data Control and Confidentiality
Section 71
(1) The Authority is authorised to control - to the extent and duration required for conducting the
procedure - any personal data during the procedure, as well as data classified by law as confidential
information and linked to exercising their profession, which relate to the procedure and the control
of which is required to efficiently conduct the procedure.
(2) The Authority is entitled to use data acquired during the course of the investigation within the
scope of its administrative proceedings.
(3) The Authority may have access to data defined in Article 23 (2) of Act CXI of 2011 on the
Commissioner of Fundamental Rights in accordance with the conditions set out in Article 23 (7) of
Act CXI of 2011 on the Commissioner of Fundamental Rights.
(4) Within the scope of the procedure conducted in connection with the control of classified
information, the vice president, executive public officer and inspector of the Authority may also
gain access to classified information without holding any user authorisation defined in the act on the
protection of classified information, if they hold an appropriate level personal attestation of security
clearance.
(5) The president and vice president of the Authority, as well as individuals employed or contracted,
or previously employed or contracted by the Authority - with the exception of providing data