Cyber Security and Data Protection 21 Content of notification (1) The notification referred to in section 20 shall state, at least— (a) the date of notification and the law or regulatory instrument permitting the automatic processing of data; (b) the surname, first names and complete address or the name and registered offices of the controller and of his or her representative, if any; (c) the denomination of the automatic processing; (d) the purpose or the set of related purposes of the automatic processing; (e) the categories of data being processed and a detailed description of the sensitive data being processed; (f) a description of the category or categories of the data subjects; (g) the safeguards that must be linked to the disclosure of the data to third parties; (h) the manner in which the data subjects are informed, the service providing for the exercise of the right to access and the measures taken to facilitate the exercise of that right; (i) the inter-related processing planned or any other form of linking with other processing; (j) the period of time after the expiration of which the data may no longer be stored, used or disclosed; (k) a general description containing a preliminary assessment of whether the security measures provided for pursuant to section 13 above are adequate; (l) the recourse to a data processor, if any; (m) the transfers of data to a third country as planned by the data controller. (2) The Authority may prescribe other information which shall be mentioned in the notification. (3) Where the Authority is of the opinion that the processing or transfer of data by a data controller entails specific risks to the privacy rights of data subjects, he or she may inspect and assess the security and organisational measures prior to the commencement of the processing or transfer. 5 10 15 20 25 30 (4) The Authority may, during working hours, carry out further inspection and assessment of the security and organisational measures employed by a data controller subject to reasonable notification to the data controller of the Authority’s intended inspection and assessment. 22 Authorisation 35 (1) The Authority shall establish the categories of data processing which represent specific risks to the fundamental rights of the data subject and which require specific authorisation from the Authority. (2) Such authorisation shall only be provided following receipt of notification from the data controller or from the data protection officer pursuant to sections 15 and 16. 23 40 Openness of Processing (1) The Authority shall keep a register of all automatic processing operations of data. (2) Any entry in the register referred to in subsection (1) must include the information mentioned in section 16(1). 14 45

Select target paragraph3