(4) Where the data controller has not already communicated the personal data breach to the data subject, the Commission may require it to do so. 56. (1) Prior Security Check Where the Commission is of the opinion that the processing or transfer of data by a controller or processor may entail a specific risk to the privacy rights of data subjects, it may inspect and assess the security measures taken under Article 26 sub-Articles (4), (5) and (6) of this Proclamation prior to the beginning of the processing or transfer. The Commission may, at any reasonable time during working hours, carry out further inspection and assessment of the security measures imposed on a data controller or data processor under Article 26 sub-Article (4), (5) and (6) of this Proclamation. (2) 57. Record of Processing Operations (1) Every data controller and data processor shall maintain, including logging, a record of all processing operations under his responsibility. (2) The record shall set out: (a) the name and contact details of the data controller or data processor, and, where applicable, his representative and any data protection officer; (b) the purpose of the processing; (c) a description of the categories of data subjects and of personal data; (d) a description of the categories of recipients to whom personal data have been or will be disclosed, including recipients in other countries; (e) any transfers of data to another country, and the suitable safeguards; (f) where possible, the envisaged time limits for the erasure of the different categories of data; and (g) the description of the mechanisms on data security. (3) The data controller or data processor shall, on request, make the record available to the Commission. (4) In case of logging, (a) Data controllers and data processors shall keep logs of personal data processing activities including reading; (b) Logs recording reading, disclosure and transmission shall enable to ascertain the reasoning for conduct of the specified activities, the date and time thereof and the information about the person who read, disclosed or transmitted the personal data, and the names of the recipients of such personal data; (c) Logs may be used for verification of legality of personal data processing activities, internal monitoring, ensuring integrity and security of personal data and for criminal proceedings; (d) Information on logs shall be made available to the Commission; (e) The Commission shall establish the retention periods of logs. 58. Data Protection Impact Assessment 25

Select target paragraph3