Cyber Security and Data Protection
21
Content of notification
(1) The notification referred to in section 20 shall state, at least—
(a) the date of notification and the law or regulatory instrument permitting
the automatic processing of data;
(b) the surname, first names and complete address or the name and registered
offices of the controller and of his or her representative, if any;
(c) the denomination of the automatic processing;
(d) the purpose or the set of related purposes of the automatic processing;
(e) the categories of data being processed and a detailed description of the
sensitive data being processed;
(f) a description of the category or categories of the data subjects;
(g) the safeguards that must be linked to the disclosure of the data to third
parties;
(h) the manner in which the data subjects are informed, the service providing
for the exercise of the right to access and the measures taken to facilitate
the exercise of that right;
(i) the inter-related processing planned or any other form of linking with
other processing;
(j) the period of time after the expiration of which the data may no longer
be stored, used or disclosed;
(k) a general description containing a preliminary assessment of whether the
security measures provided for pursuant to section 13 above are adequate;
(l) the recourse to a data processor, if any;
(m) the transfers of data to a third country as planned by the data controller.
(2) The Authority may prescribe other information which shall be mentioned
in the notification.
(3) Where the Authority is of the opinion that the processing or transfer of
data by a data controller entails specific risks to the privacy rights of data subjects, he
or she may inspect and assess the security and organisational measures prior to the
commencement of the processing or transfer.
5
10
15
20
25
30
(4) The Authority may, during working hours, carry out further inspection and
assessment of the security and organisational measures employed by a data controller
subject to reasonable notification to the data controller of the Authority’s intended
inspection and assessment.
22
Authorisation
35
(1) The Authority shall establish the categories of data processing which
represent specific risks to the fundamental rights of the data subject and which require
specific authorisation from the Authority.
(2) Such authorisation shall only be provided following receipt of notification
from the data controller or from the data protection officer pursuant to sections 15 and
16.
23
40
Openness of Processing
(1) The Authority shall keep a register of all automatic processing operations
of data.
(2) Any entry in the register referred to in subsection (1) must include the
information mentioned in section 16(1).
14
45