0A4F4F9BD490A749D5437F821CF06DF1

Protection of Natural Persons Against the Processing of Personal Data and the Free Circulation of such Data Act of 2018 (Law 125 (1))

http://www.dataprotection.gov.cy/dataprotection/dataprotection.nsf/all/DE97F6F59835A03AC22582DD003D895E/$file/Νόμος%20125(Ι)_2018.pdf?openelement

http://leaux.net/URLS/ConvertAPI Text Files/12D722804C89FAF3D0CAE59D0D49D557.en.txt

Examining the file media/Synopses/12D722804C89FAF3D0CAE59D0D49D557.html:

This file was generated: 2020-07-14 08:18:45

Indicators in focus are typically shown highlighted in yellow; Peer Indicators (that share the same Vulnerability association) are shown highlighted in pink; "Outside" Indicators (those that do NOT share the same Vulnerability association) are shown highlighted in green; Trigger Words/Phrases are shown highlighted in gray.

Link to Orphaned Trigger Words (Appendix (Indicator List, Indicator Peers, Trigger Words, Type/Vulnerability/Indicator Overlay)


Applicable Type / Vulnerability / Indicator Overlay for this Input

Vulnerability TypeVulnerabilityIndicator# Matches
Politicalcriminalcriminal5
HealthMentally Disableddisability2
SocialAccess to Social Goodsaccess5
SocialAgeage1
SocialChildchild6
SocialIncarceratedprison3
SocialMarital Statussingle1
SocialPolice Officerofficer10
SocialPolice Officerpolice4
SocialProperty Ownershipproperty1
SocialTrade Union Membershipunion10
Socialemployeesemployees2
Socialphilosophical differences/differences of opinionopinion1
General/OtherRelationship to Authorityauthority16

Political / criminal

Searching for indicator criminal:

(return to top)
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
p.000830: processing of such data requires the separate consent of the data subject.
p.000830: Combining filing systems
p.000830: public authorities or bodies.
p.000830: 10 .- (1) The combination of large-scale filing systems of two or more public authorities or bodies,
p.000830: is permitted only for reasons of public interest, and provided that the provisions of points (c) or (e) thereof are met
p.000830: paragraph (1) of Rule 6 or points (g), (h) or (i) of Rule 9 (2).
p.000830: (2) Where the combination concerns specific categories of personal data or data which
p.000830: relate to criminal convictions and offenses or will be carried out using the coupon number
p.000830: ID or other generic ID, an assessment is required
p.000830: impact and prior consultation with the Commissioner.
p.000830: (3) The impact assessment referred to in paragraph (2) shall be carried out jointly by the public authorities, or
p.000830: entities that are going to combine their filing systems and include those provided in the
p.000830: paragraph (7) of Rule 35 of the Rules of Procedure and, where appropriate, a description of those provided for in the Rules
p.000830: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000830: (4) The Commissioner may authorize the combination of filing systems provided for in this Article.
p.000830: and impose on the public authorities or bodies that are to
p.000831: 831
p.000831: combine their filing systems, terms and conditions for such combination.
p.000831: PART III
p.000831: LIMITATIONS ON RIGHTS AND OBLIGATIONS
p.000831: Restriction of rights.
p.000831: 11 .- (1) Subject to the provisions of Rule 23 (1), the controller
p.000831: may apply measures to limit, in whole or in part, the Articles 12, 18, 19 and 20
p.000831: of the Rights Regulation:
p.000831: Provided that, if the restriction of rights relates to a processing operation entrusted to the processor, the
p.000831: the measures referred to in paragraph (1) shall apply subject to the provisions of Rule 28 of the Rules of Procedure.
p.000831: (2) The implementation of the measures referred to in (1) requires an impact assessment and prior
p.000831: consulting the Commissioner.
p.000831: (3) The impact assessment referred to in subsection (2) shall include those provided for in paragraph (2) of
p.000831: Rule 23, paragraph (7) of Rule 35 information and, where appropriate, a description thereof
...

p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
p.000836: (d) in the exercise of its powers of investigation to seize documents or electronic equipment
p.000836: under a search warrant pursuant to the provisions of the Criminal Procedure Law;
p.000836: (e) in addition to the corrections provided for in Article 58 (2) of the Rules of Procedure
p.000836: powers, require the Cyprus Quality Promotion Organization as it withdraws accreditation
p.000836: a certification body, when it finds that the certification requirements are no longer met or no longer met, or
p.000836: insofar as the actions of the certification body are in breach of the provisions of this Regulation and of this Regulation
p.000836: Law;
p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
p.000838: (2) In the event of failure to pay the administrative fine referred to in (1), this
p.000838: is collected as a civil debt due to the Republic.
p.000838: (3) Administrative fine imposed on a public authority or public body for activities not related to
p.000838: speculative in nature, may not exceed two hundred thousand euros (€ 200,000).
p.000838: Offenses and penalties.
p.000838: 33.- (1) Commits a criminal offense-
p.000838: (a) The controller or processor who does not keep the record of activities that
p.000838: provided for in Rule 30 of the Rules of Procedure or does not update this file or refuses to place the file in
p.000838: Commissioner at his request or provide the Commissioner with false, inaccurate, incomplete or misleading information
p.000838: about this file,
p.000838: (b) a controller or processor who does not cooperate with the Commissioner, in accordance with
p.000838: by the provisions of Rule 31 of the Rules of Procedure,
p.000838: (c) a controller who does not notify the Commissioner of a breach of personal data
p.000838: in accordance with the provisions of Rule 33 (1),
p.000838: (d) perform the processing which does not promptly inform the controller of
p.000838: violation of personal data in accordance with the provisions of Article 33 (2)
p.000838: Regulation,
p.000838: (e) a controller who does not report a breach of personal data
p.000838: the data subject, in accordance with the provisions of Rule 34 of the Rules of Procedure,
p.000838: (f) a controller who does not conduct an impact assessment in breach of the provisions of paragraph
p.000838: (1) Rule 35 of this Regulation or Rule 13 of this Law,
p.000838: (g) the controller or processor who blocks the data controller from
p.000838: carrying out his duties, in particular those relating to working with the Commissioner,
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
...

Health / Mentally Disabled

Searching for indicator disability:

(return to top)
p.000833: is performed by the controller or the processor on the basis of the requirements of
p.000833: Article 49 of the Derogation Regulation for special situations requires an impact assessment to be carried out and
p.000833: prior consultation with the Commissioner.
p.000833: (2) The impact assessment referred to in paragraph (1) shall include those provided for in paragraph (7) of the
p.000833: Rule 35 information, and, where appropriate, a description of those provided for in the Articles
p.000833: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000833: (3) Without prejudice to Rule 49 of the Rules of Procedure, the Commissioner may, for serious public reasons,
p.000833: interest, to impose on the controller or processor explicit restrictions on
p.000833: transmission of those referred to in subparagraph
p.000833: (1) Specific categories of personal data.
p.000833: PART VIII
p.000833: PERSONAL DATA PROTECTION COMMITTEE
p.000833: His appointment, qualifications and term of office
p.000833: Commissioner.
p.000833: 19 .- (1) The Personal Data Protection Commissioner is appointed by the Council of Ministers, after
p.000833: recommendation of the Minister.
p.000833: (2) A person who is qualified to be a High Court Judge shall be appointed as a Commissioner.
p.000833: (3) The term of office of the Commissioner shall be six (6) years and may be renewed for a further
p.000833: service.
p.000833: (4) Subject to the provisions of Rule 53 (4) and Rule 20 thereof
p.000833: of this Act, the Commissioner may not be dismissed during his / her term of office only for reasons
p.000833: mental or physical disability or disability that render him unable to perform his duties.
p.000834: 834
p.000834: (5) The Commissioner is designated as a supervisory authority for the purposes of the Rules of Procedure and is responsible for monitoring the
p.000834: implementation of the provisions of the Rules of Procedure and this Law in the Republic and other regulations which
p.000834: relate to the processing of personal data.
p.000834: Deduction from office
p.000834: of the Commissioner.
p.000834: 20 .- (1) The Commissioner shall be removed from office if, during his term of office: -
p.000834: (a) Perform an act incompatible with his duties or carry on any profession incompatible
p.000834: to his property, whether it is profitable or not, or,
p.000834: (b) convicted of the offense provided for in subsection (3) of section 21 of this Law.
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
...

Social / Access to Social Goods

Searching for indicator access:

(return to top)
p.000829: against the processing of personal data and for the free movement of data
p.000829: and repealing Directive 95/46 / EC (General Data Protection Regulation) ";
p.000829: Official
p.000829: EU Journal: L.218, 13.8.2008,
p.000829: p.
p.000829: "Regulation (EC) No 765/2008" means the European Union Act entitled
p.000829: "Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 laying down detailed rules for the
p.000829: accreditation and market surveillance requirements for and marketing of products
p.000829: Regulation (EEC) No. Council Regulation (EC) No 339/93 ";
p.000829: 156 (I) of 2002
p.000829: 10 (I) of 2010
p.000829: 57 (I) of 2011
p.000829: 69 (I) of 2012
p.000829: 120 (I) of 2012.
p.000829: "Cyprus Quality Promotion Organization" means the Cyprus Quality Promotion Organization, designated as
p.000829: the national accreditation body under its Accreditation, Standardization and Technical Provisions
p.000829: Law Information;
p.000829: Official
p.000829: EU Journal: 241,
p.000829: 17.9.2015, p
p.000829: "Directive (EU) 2015/1535" means the European Union act entitled "Directive (EU) 2015/1535"
p.000829: European Parliament and Council of 9 September 2015 establishing an information procedure
p.000829: in the field of technical specifications and rules on information society services (codified
p.000829: text)"·
p.000829: "Business group" means a controlling undertaking and the undertakings controlled by it;
p.000829: "Personal data breach" means the breach of security that results in accidental or
p.000829: unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data
p.000829: characters that were transmitted, stored or otherwise processed;
p.000829: "Consent" of the data subject means any indication of will, free, specific, explicit and
p.000829: fully aware, with which the data subject demonstrates agreement, statement or clear affirmation
p.000829: action to process personal data relating to it;
p.000829: 'Filing system' means any structured set of personal data which
p.000829: are accessible on the basis of specific criteria, whether aggregated or decentralized
p.000829: either distributed on a functional or geographical basis;
p.000829: 'Controller' means the natural or legal person, public authority, agency or other entity which, alone or
p.000829: together with others, determine the purpose and manner of processing personal data ∙
p.000829: where the purposes and manner of such processing are determined by Union or Republic law, the person responsible shall
p.000829: processing or the specific criteria for his appointment may be provided for by Union law or
p.000829: the law of the Republic;
p.000829: 'Information society service' means a service within the meaning of Article 1 (1)
p.000829: point (b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;
p.000829: "Minister" means the Minister of Justice and Public Order.
p.000829: (2) Any terms contained in this Law and not specifically defined herein shall have the meaning assigned thereto.
p.000829: in these terms by the Rules of Procedure.
p.000829: Field of application.
p.000829: 3. The provisions of this Law shall apply to the Republic in accordance with the provisions of Articles 2 and 3 thereof
...

p.000835: inform the complainant in writing of its progress and outcome within thirty (30) days of its submission
p.000835: Complaint:
p.000835: Provided that, where the complaint is found to be unfounded or does not fall within its remit
p.000835: Commissioner, he shall notify the complainant in writing within thirty (30) days of the submission of the complaint;
p.000835: (c) inform, where appropriate, the data subject, the controller where appropriate;
p.000835: and the executor for the time limits provided for in Rules 60 to 66 of the Rules of Procedure;
p.000835: (d) may not consider or terminate a complaint for reasons of public interest and shall notify it
p.000835: the data subject, within a reasonable time, the reasons for not examining or for
p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
p.000835: perform the processing designated by the data protection officer as provided for in Article 14 hereof
p.000835: Law.
p.000835: Additional powers of the Commissioner.
p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
p.000836: (d) in the exercise of its powers of investigation to seize documents or electronic equipment
p.000836: under a search warrant pursuant to the provisions of the Criminal Procedure Law;
p.000836: (e) in addition to the corrections provided for in Article 58 (2) of the Rules of Procedure
p.000836: powers, require the Cyprus Quality Promotion Organization as it withdraws accreditation
p.000836: a certification body, when it finds that the certification requirements are no longer met or no longer met, or
...

p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
p.000838: (2) In the event of failure to pay the administrative fine referred to in (1), this
p.000838: is collected as a civil debt due to the Republic.
p.000838: (3) Administrative fine imposed on a public authority or public body for activities not related to
p.000838: speculative in nature, may not exceed two hundred thousand euros (€ 200,000).
p.000838: Offenses and penalties.
p.000838: 33.- (1) Commits a criminal offense-
p.000838: (a) The controller or processor who does not keep the record of activities that
p.000838: provided for in Rule 30 of the Rules of Procedure or does not update this file or refuses to place the file in
p.000838: Commissioner at his request or provide the Commissioner with false, inaccurate, incomplete or misleading information
p.000838: about this file,
p.000838: (b) a controller or processor who does not cooperate with the Commissioner, in accordance with
p.000838: by the provisions of Rule 31 of the Rules of Procedure,
p.000838: (c) a controller who does not notify the Commissioner of a breach of personal data
p.000838: in accordance with the provisions of Rule 33 (1),
p.000838: (d) perform the processing which does not promptly inform the controller of
p.000838: violation of personal data in accordance with the provisions of Article 33 (2)
p.000838: Regulation,
p.000838: (e) a controller who does not report a breach of personal data
p.000838: the data subject, in accordance with the provisions of Rule 34 of the Rules of Procedure,
p.000838: (f) a controller who does not conduct an impact assessment in breach of the provisions of paragraph
p.000838: (1) Rule 35 of this Regulation or Rule 13 of this Law,
p.000838: (g) the controller or processor who blocks the data controller from
p.000838: carrying out his duties, in particular those relating to working with the Commissioner,
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the restrictions imposed by the Commissioner under the provisions of the Articles
p.000838: 17 or 18 of this Law,
p.000838: (k) a person who unlawfully interferes with any data archiving system
p.000838: personal or knowingly acquiring or removing, altering, damaging, destroying, processing,
p.000838: exploits in any way, transmits, communicates, makes them accessible to unauthorized persons, or
p.000838: allows such persons to access such data, for profit or non-profit purposes,
p.000838: (l) the controller or performer of the processing which prevents or impedes the exercise
p.000838: the powers of the Commissioner provided for in Rule 58 of this Rules of Procedure and Rule 17 of this Law,
p.000839: 839
p.000839: (m) controller or processor who fails to comply with the provisions of the Rules of Procedure
p.000839: and of this Law in carrying out a processing act which is not an offense under
p.000839: the provisions of this Article,
p.000839: (n) a public authority or public body combining large archive systems
p.000839: scale in violation of the provisions of section 10 of this Law.
p.000839: (2) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (a) to (l) of subparagraph (1) shall be subject to a prison sentence not exceeding one year.
p.000839: three (3) years or a fine not exceeding thirty thousand euros (€ 30,000) or both.
p.000839: (3) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (m) and (n) of subparagraph (1), subject to a prison sentence not exceeding
p.000839: one (1) year or a fine not exceeding ten thousand euros (€ 10,000) or both.
p.000839: (4) Where a person is convicted of committing any of the offenses which
p.000839: refer to paragraphs (g) to (j) of subparagraph (1), which infringes the interests of the Republic or causes
p.000839: danger to the unhindered operation of the Government or threatening national security is subject to a prison sentence which
p.000839: does not exceed five (5) years or a fine not exceeding fifty thousand euros (€ 50,000) or
p.000839: these two sentences.
...

Social / Age

Searching for indicator age:

(return to top)
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
p.000830: is permitted and legal when made for the purpose of publishing or issuing a decision
p.000830: any court or when necessary for the purposes of the administration of justice.
p.000830: Processing based on the decision of the Council of Ministers.
p.000830: 7. The processing of personal data entrusted by the Council of Ministers to
p.000830: a public authority or body for the performance of a duty performed in the public interest or for the performance of a public interest
p.000830: power is carried out legally and legally in a clear, precise and transparent manner with respect to the subject
p.000830: data, in accordance with the provisions of point (a) of paragraph (1) of Article 5, and
p.000830: point (e) of Rule 6 (1).
p.000830: Special offer
p.000830: community services
p.000830: of information to a child.
p.000830: 8 .- (1) Where the provision of information society services directly to a child is based on
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
p.000830: processing of such data requires the separate consent of the data subject.
p.000830: Combining filing systems
p.000830: public authorities or bodies.
p.000830: 10 .- (1) The combination of large-scale filing systems of two or more public authorities or bodies,
p.000830: is permitted only for reasons of public interest, and provided that the provisions of points (c) or (e) thereof are met
p.000830: paragraph (1) of Rule 6 or points (g), (h) or (i) of Rule 9 (2).
p.000830: (2) Where the combination concerns specific categories of personal data or data which
p.000830: relate to criminal convictions and offenses or will be carried out using the coupon number
p.000830: ID or other generic ID, an assessment is required
p.000830: impact and prior consultation with the Commissioner.
p.000830: (3) The impact assessment referred to in paragraph (2) shall be carried out jointly by the public authorities, or
p.000830: entities that are going to combine their filing systems and include those provided in the
...

Social / Child

Searching for indicator child:

(return to top)
p.000829: Democracy is the Minister of Justice and Public Order.
p.000830: 830
p.000830: PART II
p.000830: LEGALITY OF CERTAIN PROCESSING ACTS
p.000830: Editing data from
p.000830: courts and the House of Representatives
p.000830: Representatives.
p.000830: 5. Without prejudice to the provisions of Rule 6 (e) (6),
p.000830: personal data is allowed and legal when it is performed-
p.000830: (a) By the courts within their jurisdiction for the purposes of its award
p.000830: justice, including the processing of personal data necessary for the purpose of publication
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
p.000830: is permitted and legal when made for the purpose of publishing or issuing a decision
p.000830: any court or when necessary for the purposes of the administration of justice.
p.000830: Processing based on the decision of the Council of Ministers.
p.000830: 7. The processing of personal data entrusted by the Council of Ministers to
p.000830: a public authority or body for the performance of a duty performed in the public interest or for the performance of a public interest
p.000830: power is carried out legally and legally in a clear, precise and transparent manner with respect to the subject
p.000830: data, in accordance with the provisions of point (a) of paragraph (1) of Article 5, and
p.000830: point (e) of Rule 6 (1).
p.000830: Special offer
p.000830: community services
p.000830: of information to a child.
p.000830: 8 .- (1) Where the provision of information society services directly to a child is based on
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
p.000830: processing of such data requires the separate consent of the data subject.
p.000830: Combining filing systems
p.000830: public authorities or bodies.
p.000830: 10 .- (1) The combination of large-scale filing systems of two or more public authorities or bodies,
p.000830: is permitted only for reasons of public interest, and provided that the provisions of points (c) or (e) thereof are met
p.000830: paragraph (1) of Rule 6 or points (g), (h) or (i) of Rule 9 (2).
p.000830: (2) Where the combination concerns specific categories of personal data or data which
p.000830: relate to criminal convictions and offenses or will be carried out using the coupon number
p.000830: ID or other generic ID, an assessment is required
p.000830: impact and prior consultation with the Commissioner.
p.000830: (3) The impact assessment referred to in paragraph (2) shall be carried out jointly by the public authorities, or
p.000830: entities that are going to combine their filing systems and include those provided in the
p.000830: paragraph (7) of Rule 35 of the Rules of Procedure and, where appropriate, a description of those provided for in the Rules
p.000830: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000830: (4) The Commissioner may authorize the combination of filing systems provided for in this Article.
p.000830: and impose on the public authorities or bodies that are to
p.000831: 831
...

Social / Incarcerated

Searching for indicator prison:

(return to top)
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the restrictions imposed by the Commissioner under the provisions of the Articles
p.000838: 17 or 18 of this Law,
p.000838: (k) a person who unlawfully interferes with any data archiving system
p.000838: personal or knowingly acquiring or removing, altering, damaging, destroying, processing,
p.000838: exploits in any way, transmits, communicates, makes them accessible to unauthorized persons, or
p.000838: allows such persons to access such data, for profit or non-profit purposes,
p.000838: (l) the controller or performer of the processing which prevents or impedes the exercise
p.000838: the powers of the Commissioner provided for in Rule 58 of this Rules of Procedure and Rule 17 of this Law,
p.000839: 839
p.000839: (m) controller or processor who fails to comply with the provisions of the Rules of Procedure
p.000839: and of this Law in carrying out a processing act which is not an offense under
p.000839: the provisions of this Article,
p.000839: (n) a public authority or public body combining large archive systems
p.000839: scale in violation of the provisions of section 10 of this Law.
p.000839: (2) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (a) to (l) of subparagraph (1) shall be subject to a prison sentence not exceeding one year.
p.000839: three (3) years or a fine not exceeding thirty thousand euros (€ 30,000) or both.
p.000839: (3) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (m) and (n) of subparagraph (1), subject to a prison sentence not exceeding
p.000839: one (1) year or a fine not exceeding ten thousand euros (€ 10,000) or both.
p.000839: (4) Where a person is convicted of committing any of the offenses which
p.000839: refer to paragraphs (g) to (j) of subparagraph (1), which infringes the interests of the Republic or causes
p.000839: danger to the unhindered operation of the Government or threatening national security is subject to a prison sentence which
p.000839: does not exceed five (5) years or a fine not exceeding fifty thousand euros (€ 50,000) or
p.000839: these two sentences.
p.000839: (5) For the purposes of applying the provisions of this Article;
p.000839: (a) If the controller or processor is a business or group of undertakings, legal liability
p.000839: bears the person designated as the supreme executive body or body of the undertaking or group of undertakings,
p.000839: (b) if the controller or processor is a public authority or public body;
p.000839: the head or the person in charge of the effective administration of the public authority or
p.000839: public body.
p.000839: PART XI
p.000839: FINAL PROVISIONS
p.000839: Regulations. 34. The Council of Ministers, on the recommendation of the Commissioner, may
p.000839: to issue Regulations for the effective implementation of the provisions of this Regulation and this Law.
p.000839: International
p.000839: cooperation.
p.000839: 35 .- (1) In the absence of an appropriate legal measure by the Commission binding on the Member States, the Commissioner may
p.000839: Recommends to the Minister the conclusion of agreements with third countries or international organizations to fulfill the objectives
p.000839: referred to in Rule 50 of the Rules of Procedure.
p.000839: (2) The Commissioner may conclude, establish and sign memorandums of understanding with corresponding authorities in other countries.
p.000839: or with international organizations.
p.000839: Abolition of law.
p.000839: 138 (I) of 2001
p.000839: 37 (I) of 2003
p.000839: 105 (I) of 2012.
p.000839: 36. With the entry into force of the provisions of this Law on the Processing of Personal Data
...

Social / Marital Status

Searching for indicator single:

(return to top)
p.000828: of a person who has been inherited or acquired, in particular as a result of a biological sample analysis of that person
p.000828: natural person and which provide unique information about the physiology or health of that natural person
p.000828: face;
p.000828: "Personal data" means any information relating to an identified or identifiable natural
p.000828: person ('data subject'). The identifiable natural person is one whose identity
p.000828: can be ascertained, directly or indirectly, in particular by reference to an identity such as a name, a number
p.000828: ID, location data, online ID, or one or more factors
p.000828: specific to the physical, physiological, genetic, psychological, economic, cultural or social
p.000828: the identity of that natural person;
p.000828: "Binding corporate rules" means their personal data protection policies
p.000828: followed by a controller or processor established in the territory of a State
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
p.000828: (a) the processing of personal data carried out in the course of the activities of various parties;
p.000828: establishments in more than one Member State responsible for processing or processing in the Union where
p.000828: the controller or processor is established in more than one Member State, or
p.000828: (b) the processing of personal data carried out in the course of one's activities
p.000828: a single installation controller or processor in the Union but which affects or
p.000828: may substantially affect data subjects in more than one Member State;
p.000828: "International organization" means the organization and its subordinate bodies governed by
p.000828: public international law or any other body established by or on the basis of an agreement between two or
p.000828: more countries;
p.000828: 'Representative' means a natural or legal person established in the Union, designated in writing by the person responsible;
p.000828: processor or performer of the processing under Rule 27 of the Rules of Procedure and represent the person responsible
p.000828: processor or performer of the processing of their respective obligations under the Rules of Procedure and
p.000828: this Law;
p.000828: 'Perform the processing' means the natural or legal person, or a public authority, or service or other body which
p.000828: processes personal data on behalf of the controller;
p.000828: 'Processing' means any operation or series of operations performed with or without the use of automated means;
p.000828: in personal data or in personal data sets, such as collection, h
p.000828: registration, organization, structure, storage, customization or modification, recovery, search
p.000828: information, use, disclosure, dissemination or any other form of distribution, association or combination;
p.000828: restriction, deletion or destruction;
p.000828: 'Commissioner' means the Commissioner for Personal Data Protection who is appointed under
p.000828: provisions of section 19 of this Law;
p.000828: 'Enterprise' means any natural or legal person carrying on an economic activity, irrespective of
...

Social / Police Officer

Searching for indicator officer:

(return to top)
p.000831: measures referred to in subparagraph (1) and to inform the subject referred to in subparagraph (4) of
p.000831: data.
p.000831: Exemption from liability for infringement notice.
p.000831: 12 .- (1) The controller may be relieved, in whole or in part, of the responsibility for notifying a breach
p.000831: personal data to the data subject, for one or more of those referred to
p.000831: for the purposes of Rule 23 (1).
p.000831: (2) An exemption from the liability referred to in (1) requires an assessment to be carried out.
p.000831: impact and prior consultation with the Commissioner.
p.000831: (3) The impact assessment referred to in paragraph (2) shall include those provided for in paragraph (2) of
p.000831: Rule 23 and Rule 35 (7) information.
p.000831: (4) The Commissioner may impose on the controller the terms and conditions for the purpose referred to in the subparagraph.
p.000831: (1) Release of liability for communication.
p.000831: PART IV
p.000831: IMPACT ASSESSMENT OF LEGISLATIVE MEASURES
p.000831: Carry out an impact assessment after the adoption of legislative or regulatory measures.
p.000831: 13 .- (1) Before the enactment of a law or Regulations issued by law providing for a specific
p.000831: an operation or series of processing operations, an impact assessment and prior is required
p.000831: consulting the Commissioner.
p.000831: (2) The provisions of subparagraph (1) shall not apply if the Commissioner considers that the
p.000831: was made while drafting a law or regulations issued by law is satisfactory and not
p.000831: an additional impact assessment is required prior to the implementation of the operation concerned, or
p.000831: a series of processing operations, which they provide.
p.000832: 832
p.000832: PART V
p.000832: DATA PROTECTION OFFICER
p.000832: Definition
p.000832: data protection officer.
p.000832: 14 .- (1) The data protection officer shall be appointed in accordance with Rule 37 of the Rules of Procedure.
p.000832: (2) The Commissioner may draw up and make public a list of processing operations and cases in
p.000832: which require the designation of a data protection officer, in addition to those provided for in paragraph (1) of the
p.000832: Rule 37 acts.
p.000832: (3) The Commissioner may publish on his office's website a list of controllers
p.000832: and perform the processing they have designated data protection officer and data
p.000832: contact, if the controller and the processor wish to be included in the
p.000832: list it.
p.000832: Obligation of the Data Protection Officer
p.000832: for compliance
p.000832: of privacy or of
p.000832: confidentiality.
p.000832: 15 .- (1) Subject to the provisions of any law regulating matters of professional secrecy or
p.000832: In the performance of his duties, the Data Protection Officer is bound by the obligation
p.000832: privacy or confidentiality.
p.000832: (2) Data protection officer's confidentiality or confidentiality,
p.000832: affects the provisions of Rule 58 (1) and Rule (a) and (b) thereof
p.000832: section 25 of this Act the powers of control of the Commissioner.
p.000832: PART VI
p.000832: ACCREDITATION ACCREDITATION BODY
p.000832: Accreditation of certification bodies.
p.000832: 16 .- (1) Subject to Rule 43 of the Rules of Procedure, accreditation bodies shall be accredited.
p.000832: by the Cyprus Quality Promotion Organization.
p.000832: (2) Submitted to the Cyprus Quality Promotion Organization for accreditation of a certification body.
p.000832: the positive opinion of the Commissioner, that the applicant for certification of body fulfills the provisions of points (a), (b), and (e) of
p.000832: Rule 43 (2).
p.000832: (3) The Cyprus Quality Promotion Agency shall revoke accreditation of accreditation body if
p.000832: certification requirements are no longer fulfilled or are not fulfilled or if the actions of the certification body
p.000832: violate the provisions of the Rules of Procedure or this Law.
p.000832: (4) The Commissioner may request the Cyprus Quality Promotion Organization to revoke it
p.000832: accreditation of a certification body if the Commissioner finds that the certification requirements are not met
p.000832: or are no longer fulfilled or if the actions of the certification body are in breach of the provisions of the Regulation or of
p.000832: of this Law.
p.000832: (5) In case the Cyprus Quality Promotion Organization does not revoke the accreditation body
p.000832: certification according to points (3) and (4), the Commissioner complains to the Cyprus Quality Promotion Organization
p.000832: European Commission.
p.000833: 833
p.000833: PART VII
p.000833: TRANSFER OF SPECIAL CATEGORIES OF DATA IN THIRD COUNTRY OR IN INTERNATIONAL ORGANIZATION
...

p.000835: make a case under the provisions of this subparagraph with the lead supervisory authority and
p.000835: supervisory authorities concerned.
p.000835: (4) The Commissioner has no jurisdiction to review processing acts performed by the courts of the Republic
p.000835: within their jurisdiction.
p.000835: Additional tasks
p.000835: Commissioner.
p.000835: 24. Subject to the provisions of Rule 57 of the Rules of Procedure and in addition to the duties which
p.000835: as provided in this Article, the Commissioner shall perform the following tasks:
p.000835: (a) It may publish, on the Office's website, how to file complaints; and
p.000835: applications;
p.000835: (b) consider a complaint and, where possible, depending on the nature and type of complaint;
p.000835: inform the complainant in writing of its progress and outcome within thirty (30) days of its submission
p.000835: Complaint:
p.000835: Provided that, where the complaint is found to be unfounded or does not fall within its remit
p.000835: Commissioner, he shall notify the complainant in writing within thirty (30) days of the submission of the complaint;
p.000835: (c) inform, where appropriate, the data subject, the controller where appropriate;
p.000835: and the executor for the time limits provided for in Rules 60 to 66 of the Rules of Procedure;
p.000835: (d) may not consider or terminate a complaint for reasons of public interest and shall notify it
p.000835: the data subject, within a reasonable time, the reasons for not examining or for
p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
p.000835: perform the processing designated by the data protection officer as provided for in Article 14 hereof
p.000835: Law.
p.000835: Additional powers of the Commissioner.
p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
...

Searching for indicator police:

(return to top)
p.000827: Tuesday, July 31, 2018
p.000827: 827
p.000827: On the Protection of Individuals with regard to the Processing of Personal Data and the
p.000827: Free Release of these Data Law of 2018 is published with publication in the Official Gazette of Cyprus
p.000827: Democracy in accordance with Article 52 of the Constitution.
p.000827: No. 125 (I) of 2018
p.000827: LAW ON PROTECTION OF NATURAL PERSONS AGAINST PERSONAL DATA PROCESSING AND PROTECTION
p.000827: FOR FREE MOVEMENT OF THESE DATA
p.000827: Preamble. Official newspaper
p.000827: OJ: L.119, 4.5.2016, p. 1.
p.000827: For the purpose of effective implementation of certain provisions of the European Union Act entitled
p.000827: 'Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of the
p.000827: natural persons against the processing of personal data and for the free movement of such data
p.000827: including the repeal of Directive 95/46 / EC (General Data Protection Regulation) ",
p.000827: The House of Representatives votes as follows:
p.000827: PART I.
p.000827: general provisions
p.000827: Short title.
p.000827: 1. This Law shall be referred to as the Protection of Individuals against it
p.000827: Processing of Personal Data and the Free Movement of such Data
p.000827: of 2018.
p.000827: Interpretation. 2 .- (1) In this Law, unless its text or the text of the Rules of Procedure
p.000827: a different concept emerges;
p.000828: 828
p.000828: "Police" means the Cyprus Police;
p.000828: 'Biometric data' means personal data derived from a specific technique
p.000828: treatment associated with physical, biological or behavioral characteristics of the natural person and which
p.000828: permit or confirm the unambiguous identification of such natural person, such as facial images, or
p.000828: fingerprint data;
p.000828: "Genetic data" means personal data relating to the genetic characteristics of the natural
p.000828: of a person who has been inherited or acquired, in particular as a result of a biological sample analysis of that person
p.000828: natural person and which provide unique information about the physiology or health of that natural person
p.000828: face;
p.000828: "Personal data" means any information relating to an identified or identifiable natural
p.000828: person ('data subject'). The identifiable natural person is one whose identity
p.000828: can be ascertained, directly or indirectly, in particular by reference to an identity such as a name, a number
p.000828: ID, location data, online ID, or one or more factors
p.000828: specific to the physical, physiological, genetic, psychological, economic, cultural or social
p.000828: the identity of that natural person;
p.000828: "Binding corporate rules" means their personal data protection policies
p.000828: followed by a controller or processor established in the territory of a State
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
...

p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
p.000835: perform the processing designated by the data protection officer as provided for in Article 14 hereof
p.000835: Law.
p.000835: Additional powers of the Commissioner.
p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
p.000836: (d) in the exercise of its powers of investigation to seize documents or electronic equipment
p.000836: under a search warrant pursuant to the provisions of the Criminal Procedure Law;
p.000836: (e) in addition to the corrections provided for in Article 58 (2) of the Rules of Procedure
p.000836: powers, require the Cyprus Quality Promotion Organization as it withdraws accreditation
p.000836: a certification body, when it finds that the certification requirements are no longer met or no longer met, or
p.000836: insofar as the actions of the certification body are in breach of the provisions of this Regulation and of this Regulation
p.000836: Law;
p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
...

Social / Property Ownership

Searching for indicator property:

(return to top)
p.000833: transmission of those referred to in subparagraph
p.000833: (1) Specific categories of personal data.
p.000833: PART VIII
p.000833: PERSONAL DATA PROTECTION COMMITTEE
p.000833: His appointment, qualifications and term of office
p.000833: Commissioner.
p.000833: 19 .- (1) The Personal Data Protection Commissioner is appointed by the Council of Ministers, after
p.000833: recommendation of the Minister.
p.000833: (2) A person who is qualified to be a High Court Judge shall be appointed as a Commissioner.
p.000833: (3) The term of office of the Commissioner shall be six (6) years and may be renewed for a further
p.000833: service.
p.000833: (4) Subject to the provisions of Rule 53 (4) and Rule 20 thereof
p.000833: of this Act, the Commissioner may not be dismissed during his / her term of office only for reasons
p.000833: mental or physical disability or disability that render him unable to perform his duties.
p.000834: 834
p.000834: (5) The Commissioner is designated as a supervisory authority for the purposes of the Rules of Procedure and is responsible for monitoring the
p.000834: implementation of the provisions of the Rules of Procedure and this Law in the Republic and other regulations which
p.000834: relate to the processing of personal data.
p.000834: Deduction from office
p.000834: of the Commissioner.
p.000834: 20 .- (1) The Commissioner shall be removed from office if, during his term of office: -
p.000834: (a) Perform an act incompatible with his duties or carry on any profession incompatible
p.000834: to his property, whether it is profitable or not, or,
p.000834: (b) convicted of the offense provided for in subsection (3) of section 21 of this Law.
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
p.000834: (d) upon expiry of his term of office, he shall refrain from any act incompatible with them
p.000834: its powers, duties and powers and does not carry out any incompatible profession, profitable or not,
p.000834: for a period of two (2) years.
p.000834: (3) Where the Commissioner, in breach of the provisions of the Rules of Procedure and this Law,
p.000834: any manner of personal information or data that is accessible to him because of his location; or
p.000834: allows another person to know about them, commits an offense and, if convicted, is subject to a penalty
p.000834: to imprisonment not exceeding three (3) years or to a fine not exceeding thirty thousand euros
p.000834: (€ 30,000) or both.
p.000834: Office
p.000834: Commissioner.
...

Social / Trade Union Membership

Searching for indicator union:

(return to top)
p.000827: N. 125 (I) / 2018
p.000827: OFFICIAL NEWSPAPER
p.000827: OF THE CYPRUS REPUBLIC
p.000827: ANNEX FIRST
p.000827: LEGISLATION - PART I.
p.000827: Number 4670
p.000827: Tuesday, July 31, 2018
p.000827: 827
p.000827: On the Protection of Individuals with regard to the Processing of Personal Data and the
p.000827: Free Release of these Data Law of 2018 is published with publication in the Official Gazette of Cyprus
p.000827: Democracy in accordance with Article 52 of the Constitution.
p.000827: No. 125 (I) of 2018
p.000827: LAW ON PROTECTION OF NATURAL PERSONS AGAINST PERSONAL DATA PROCESSING AND PROTECTION
p.000827: FOR FREE MOVEMENT OF THESE DATA
p.000827: Preamble. Official newspaper
p.000827: OJ: L.119, 4.5.2016, p. 1.
p.000827: For the purpose of effective implementation of certain provisions of the European Union Act entitled
p.000827: 'Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of the
p.000827: natural persons against the processing of personal data and for the free movement of such data
p.000827: including the repeal of Directive 95/46 / EC (General Data Protection Regulation) ",
p.000827: The House of Representatives votes as follows:
p.000827: PART I.
p.000827: general provisions
p.000827: Short title.
p.000827: 1. This Law shall be referred to as the Protection of Individuals against it
p.000827: Processing of Personal Data and the Free Movement of such Data
p.000827: of 2018.
p.000827: Interpretation. 2 .- (1) In this Law, unless its text or the text of the Rules of Procedure
p.000827: a different concept emerges;
p.000828: 828
p.000828: "Police" means the Cyprus Police;
p.000828: 'Biometric data' means personal data derived from a specific technique
p.000828: treatment associated with physical, biological or behavioral characteristics of the natural person and which
p.000828: permit or confirm the unambiguous identification of such natural person, such as facial images, or
p.000828: fingerprint data;
p.000828: "Genetic data" means personal data relating to the genetic characteristics of the natural
p.000828: of a person who has been inherited or acquired, in particular as a result of a biological sample analysis of that person
p.000828: natural person and which provide unique information about the physiology or health of that natural person
p.000828: face;
p.000828: "Personal data" means any information relating to an identified or identifiable natural
p.000828: person ('data subject'). The identifiable natural person is one whose identity
p.000828: can be ascertained, directly or indirectly, in particular by reference to an identity such as a name, a number
p.000828: ID, location data, online ID, or one or more factors
p.000828: specific to the physical, physiological, genetic, psychological, economic, cultural or social
p.000828: the identity of that natural person;
p.000828: "Binding corporate rules" means their personal data protection policies
p.000828: followed by a controller or processor established in the territory of a State
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
p.000828: (a) the processing of personal data carried out in the course of the activities of various parties;
p.000828: establishments in more than one Member State responsible for processing or processing in the Union where
p.000828: the controller or processor is established in more than one Member State, or
p.000828: (b) the processing of personal data carried out in the course of one's activities
p.000828: a single installation controller or processor in the Union but which affects or
p.000828: may substantially affect data subjects in more than one Member State;
p.000828: "International organization" means the organization and its subordinate bodies governed by
p.000828: public international law or any other body established by or on the basis of an agreement between two or
p.000828: more countries;
p.000828: 'Representative' means a natural or legal person established in the Union, designated in writing by the person responsible;
p.000828: processor or performer of the processing under Rule 27 of the Rules of Procedure and represent the person responsible
p.000828: processor or performer of the processing of their respective obligations under the Rules of Procedure and
p.000828: this Law;
p.000828: 'Perform the processing' means the natural or legal person, or a public authority, or service or other body which
p.000828: processes personal data on behalf of the controller;
p.000828: 'Processing' means any operation or series of operations performed with or without the use of automated means;
p.000828: in personal data or in personal data sets, such as collection, h
p.000828: registration, organization, structure, storage, customization or modification, recovery, search
p.000828: information, use, disclosure, dissemination or any other form of distribution, association or combination;
p.000828: restriction, deletion or destruction;
p.000828: 'Commissioner' means the Commissioner for Personal Data Protection who is appointed under
p.000828: provisions of section 19 of this Law;
p.000828: 'Enterprise' means any natural or legal person carrying on an economic activity, irrespective of
p.000828: its legal form, including its own companies or companies
p.000829: 829
p.000829: associations regularly engaged in economic activity;
p.000829: "Supervisory authority" means the Commissioner, who is appointed pursuant to the provisions of section 19 of this Law,
p.000829: application of the provisions of Rule 51 of the Rules of Procedure;
p.000829: "Regulation" means the European Union act entitled "Regulation (EU) No. Of 2016/679
p.000829: European Parliament and of the Council of 27 April 2016 on the protection of individuals
p.000829: against the processing of personal data and for the free movement of data
p.000829: and repealing Directive 95/46 / EC (General Data Protection Regulation) ";
p.000829: Official
p.000829: EU Journal: L.218, 13.8.2008,
p.000829: p.
p.000829: "Regulation (EC) No 765/2008" means the European Union Act entitled
p.000829: "Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 laying down detailed rules for the
p.000829: accreditation and market surveillance requirements for and marketing of products
p.000829: Regulation (EEC) No. Council Regulation (EC) No 339/93 ";
p.000829: 156 (I) of 2002
p.000829: 10 (I) of 2010
p.000829: 57 (I) of 2011
p.000829: 69 (I) of 2012
p.000829: 120 (I) of 2012.
p.000829: "Cyprus Quality Promotion Organization" means the Cyprus Quality Promotion Organization, designated as
p.000829: the national accreditation body under its Accreditation, Standardization and Technical Provisions
p.000829: Law Information;
p.000829: Official
p.000829: EU Journal: 241,
p.000829: 17.9.2015, p
p.000829: "Directive (EU) 2015/1535" means the European Union act entitled "Directive (EU) 2015/1535"
p.000829: European Parliament and Council of 9 September 2015 establishing an information procedure
p.000829: in the field of technical specifications and rules on information society services (codified
p.000829: text)"·
p.000829: "Business group" means a controlling undertaking and the undertakings controlled by it;
p.000829: "Personal data breach" means the breach of security that results in accidental or
p.000829: unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data
p.000829: characters that were transmitted, stored or otherwise processed;
p.000829: "Consent" of the data subject means any indication of will, free, specific, explicit and
p.000829: fully aware, with which the data subject demonstrates agreement, statement or clear affirmation
p.000829: action to process personal data relating to it;
p.000829: 'Filing system' means any structured set of personal data which
p.000829: are accessible on the basis of specific criteria, whether aggregated or decentralized
p.000829: either distributed on a functional or geographical basis;
p.000829: 'Controller' means the natural or legal person, public authority, agency or other entity which, alone or
p.000829: together with others, determine the purpose and manner of processing personal data ∙
p.000829: where the purposes and manner of such processing are determined by Union or Republic law, the person responsible shall
p.000829: processing or the specific criteria for his appointment may be provided for by Union law or
p.000829: the law of the Republic;
p.000829: 'Information society service' means a service within the meaning of Article 1 (1)
p.000829: point (b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;
p.000829: "Minister" means the Minister of Justice and Public Order.
p.000829: (2) Any terms contained in this Law and not specifically defined herein shall have the meaning assigned thereto.
p.000829: in these terms by the Rules of Procedure.
p.000829: Field of application.
p.000829: 3. The provisions of this Law shall apply to the Republic in accordance with the provisions of Articles 2 and 3 thereof
p.000829: Regulation.
p.000829: Competent authority. 4. Competent authority for the application of the provisions of the Rules of Procedure and this Law to
p.000829: Democracy is the Minister of Justice and Public Order.
p.000830: 830
p.000830: PART II
p.000830: LEGALITY OF CERTAIN PROCESSING ACTS
p.000830: Editing data from
p.000830: courts and the House of Representatives
p.000830: Representatives.
p.000830: 5. Without prejudice to the provisions of Rule 6 (e) (6),
p.000830: personal data is allowed and legal when it is performed-
p.000830: (a) By the courts within their jurisdiction for the purposes of its award
p.000830: justice, including the processing of personal data necessary for the purpose of publication
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
...

p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
...

Social / employees

Searching for indicator employees:

(return to top)
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
p.000834: (d) upon expiry of his term of office, he shall refrain from any act incompatible with them
p.000834: its powers, duties and powers and does not carry out any incompatible profession, profitable or not,
p.000834: for a period of two (2) years.
p.000834: (3) Where the Commissioner, in breach of the provisions of the Rules of Procedure and this Law,
p.000834: any manner of personal information or data that is accessible to him because of his location; or
p.000834: allows another person to know about them, commits an offense and, if convicted, is subject to a penalty
p.000834: to imprisonment not exceeding three (3) years or to a fine not exceeding thirty thousand euros
p.000834: (€ 30,000) or both.
p.000834: Office
p.000834: Commissioner.
p.000834: 22. The Commissioner holds an office which may be staffed by permanent, temporary or indefinite-term public servants.
p.000834: employees:
p.000834: Provided that the Commissioner participates in the selection process of his Office staff and the staff is administered
p.000834: exclusively by him:
p.000834: It is further understood that the staff of the Office of the Commissioner are responsible for maintaining confidentiality or confidentiality.
p.000834: even after the end of their service.
p.000834: Duties and powers of the Commissioner.
p.000834: 23 .- (1) The Commissioner shall perform the tasks assigned to him and shall exercise the powers conferred on him by the Commission.
p.000834: of the Rules of Procedure, this Law and any other law.
p.000835: 835
p.000835: (2) The Commissioner, without prejudice to the principle of hierarchy, may authorize in writing any of his officers.
p.000835: An office which he holds responsible as he exercises such duties and powers
p.000835: subject to the conditions, exceptions and reservations, which the Commissioner shall specify in its delegation.
p.000835: (3) The Commissioner may, at his discretion, make a case concerning the execution of the
p.000835: of his duties or in the exercise of his powers:
p.000835: Provided that, if the case concerns cross-border treatment, the Commissioner shall consult his intention to
p.000835: make a case under the provisions of this subparagraph with the lead supervisory authority and
p.000835: supervisory authorities concerned.
p.000835: (4) The Commissioner has no jurisdiction to review processing acts performed by the courts of the Republic
p.000835: within their jurisdiction.
p.000835: Additional tasks
p.000835: Commissioner.
p.000835: 24. Subject to the provisions of Rule 57 of the Rules of Procedure and in addition to the duties which
p.000835: as provided in this Article, the Commissioner shall perform the following tasks:
p.000835: (a) It may publish, on the Office's website, how to file complaints; and
...

p.000836: Law;
p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
...

Social / philosophical differences/differences of opinion

Searching for indicator opinion:

(return to top)
p.000832: Rule 37 acts.
p.000832: (3) The Commissioner may publish on his office's website a list of controllers
p.000832: and perform the processing they have designated data protection officer and data
p.000832: contact, if the controller and the processor wish to be included in the
p.000832: list it.
p.000832: Obligation of the Data Protection Officer
p.000832: for compliance
p.000832: of privacy or of
p.000832: confidentiality.
p.000832: 15 .- (1) Subject to the provisions of any law regulating matters of professional secrecy or
p.000832: In the performance of his duties, the Data Protection Officer is bound by the obligation
p.000832: privacy or confidentiality.
p.000832: (2) Data protection officer's confidentiality or confidentiality,
p.000832: affects the provisions of Rule 58 (1) and Rule (a) and (b) thereof
p.000832: section 25 of this Act the powers of control of the Commissioner.
p.000832: PART VI
p.000832: ACCREDITATION ACCREDITATION BODY
p.000832: Accreditation of certification bodies.
p.000832: 16 .- (1) Subject to Rule 43 of the Rules of Procedure, accreditation bodies shall be accredited.
p.000832: by the Cyprus Quality Promotion Organization.
p.000832: (2) Submitted to the Cyprus Quality Promotion Organization for accreditation of a certification body.
p.000832: the positive opinion of the Commissioner, that the applicant for certification of body fulfills the provisions of points (a), (b), and (e) of
p.000832: Rule 43 (2).
p.000832: (3) The Cyprus Quality Promotion Agency shall revoke accreditation of accreditation body if
p.000832: certification requirements are no longer fulfilled or are not fulfilled or if the actions of the certification body
p.000832: violate the provisions of the Rules of Procedure or this Law.
p.000832: (4) The Commissioner may request the Cyprus Quality Promotion Organization to revoke it
p.000832: accreditation of a certification body if the Commissioner finds that the certification requirements are not met
p.000832: or are no longer fulfilled or if the actions of the certification body are in breach of the provisions of the Regulation or of
p.000832: of this Law.
p.000832: (5) In case the Cyprus Quality Promotion Organization does not revoke the accreditation body
p.000832: certification according to points (3) and (4), the Commissioner complains to the Cyprus Quality Promotion Organization
p.000832: European Commission.
p.000833: 833
p.000833: PART VII
p.000833: TRANSFER OF SPECIAL CATEGORIES OF DATA IN THIRD COUNTRY OR IN INTERNATIONAL ORGANIZATION
p.000833: Transmission of specific categories of personal data on the basis of appropriate guarantees or binding corporate
p.000833: rules.
p.000833: 17 .- (1) Where the controller or performer intends to transmit specific categories of data
p.000833: personal status in a third country or international organization, on the basis of the rules laid down in Rule 46 of the Rules of Procedure
p.000833: appropriate guarantees or on the basis of the binding corporate rules provided for in Rule 47,
p.000833: the controller or processor informs the Commissioner of his intention before transmitting
p.000833: of this data.
...

General/Other / Relationship to Authority

Searching for indicator authority:

(return to top)
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
p.000828: (a) the processing of personal data carried out in the course of the activities of various parties;
p.000828: establishments in more than one Member State responsible for processing or processing in the Union where
p.000828: the controller or processor is established in more than one Member State, or
p.000828: (b) the processing of personal data carried out in the course of one's activities
p.000828: a single installation controller or processor in the Union but which affects or
p.000828: may substantially affect data subjects in more than one Member State;
p.000828: "International organization" means the organization and its subordinate bodies governed by
p.000828: public international law or any other body established by or on the basis of an agreement between two or
p.000828: more countries;
p.000828: 'Representative' means a natural or legal person established in the Union, designated in writing by the person responsible;
p.000828: processor or performer of the processing under Rule 27 of the Rules of Procedure and represent the person responsible
p.000828: processor or performer of the processing of their respective obligations under the Rules of Procedure and
p.000828: this Law;
p.000828: 'Perform the processing' means the natural or legal person, or a public authority, or service or other body which
p.000828: processes personal data on behalf of the controller;
p.000828: 'Processing' means any operation or series of operations performed with or without the use of automated means;
p.000828: in personal data or in personal data sets, such as collection, h
p.000828: registration, organization, structure, storage, customization or modification, recovery, search
p.000828: information, use, disclosure, dissemination or any other form of distribution, association or combination;
p.000828: restriction, deletion or destruction;
p.000828: 'Commissioner' means the Commissioner for Personal Data Protection who is appointed under
p.000828: provisions of section 19 of this Law;
p.000828: 'Enterprise' means any natural or legal person carrying on an economic activity, irrespective of
p.000828: its legal form, including its own companies or companies
p.000829: 829
p.000829: associations regularly engaged in economic activity;
p.000829: "Supervisory authority" means the Commissioner, who is appointed pursuant to the provisions of section 19 of this Law,
p.000829: application of the provisions of Rule 51 of the Rules of Procedure;
p.000829: "Regulation" means the European Union act entitled "Regulation (EU) No. Of 2016/679
p.000829: European Parliament and of the Council of 27 April 2016 on the protection of individuals
p.000829: against the processing of personal data and for the free movement of data
p.000829: and repealing Directive 95/46 / EC (General Data Protection Regulation) ";
p.000829: Official
p.000829: EU Journal: L.218, 13.8.2008,
p.000829: p.
p.000829: "Regulation (EC) No 765/2008" means the European Union Act entitled
p.000829: "Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 laying down detailed rules for the
p.000829: accreditation and market surveillance requirements for and marketing of products
p.000829: Regulation (EEC) No. Council Regulation (EC) No 339/93 ";
p.000829: 156 (I) of 2002
p.000829: 10 (I) of 2010
p.000829: 57 (I) of 2011
p.000829: 69 (I) of 2012
p.000829: 120 (I) of 2012.
p.000829: "Cyprus Quality Promotion Organization" means the Cyprus Quality Promotion Organization, designated as
p.000829: the national accreditation body under its Accreditation, Standardization and Technical Provisions
p.000829: Law Information;
p.000829: Official
p.000829: EU Journal: 241,
p.000829: 17.9.2015, p
p.000829: "Directive (EU) 2015/1535" means the European Union act entitled "Directive (EU) 2015/1535"
p.000829: European Parliament and Council of 9 September 2015 establishing an information procedure
p.000829: in the field of technical specifications and rules on information society services (codified
p.000829: text)"·
p.000829: "Business group" means a controlling undertaking and the undertakings controlled by it;
p.000829: "Personal data breach" means the breach of security that results in accidental or
p.000829: unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data
p.000829: characters that were transmitted, stored or otherwise processed;
p.000829: "Consent" of the data subject means any indication of will, free, specific, explicit and
p.000829: fully aware, with which the data subject demonstrates agreement, statement or clear affirmation
p.000829: action to process personal data relating to it;
p.000829: 'Filing system' means any structured set of personal data which
p.000829: are accessible on the basis of specific criteria, whether aggregated or decentralized
p.000829: either distributed on a functional or geographical basis;
p.000829: 'Controller' means the natural or legal person, public authority, agency or other entity which, alone or
p.000829: together with others, determine the purpose and manner of processing personal data ∙
p.000829: where the purposes and manner of such processing are determined by Union or Republic law, the person responsible shall
p.000829: processing or the specific criteria for his appointment may be provided for by Union law or
p.000829: the law of the Republic;
p.000829: 'Information society service' means a service within the meaning of Article 1 (1)
p.000829: point (b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;
p.000829: "Minister" means the Minister of Justice and Public Order.
p.000829: (2) Any terms contained in this Law and not specifically defined herein shall have the meaning assigned thereto.
p.000829: in these terms by the Rules of Procedure.
p.000829: Field of application.
p.000829: 3. The provisions of this Law shall apply to the Republic in accordance with the provisions of Articles 2 and 3 thereof
p.000829: Regulation.
p.000829: Competent authority. 4. Competent authority for the application of the provisions of the Rules of Procedure and this Law to
p.000829: Democracy is the Minister of Justice and Public Order.
p.000830: 830
p.000830: PART II
p.000830: LEGALITY OF CERTAIN PROCESSING ACTS
p.000830: Editing data from
p.000830: courts and the House of Representatives
p.000830: Representatives.
p.000830: 5. Without prejudice to the provisions of Rule 6 (e) (6),
p.000830: personal data is allowed and legal when it is performed-
p.000830: (a) By the courts within their jurisdiction for the purposes of its award
p.000830: justice, including the processing of personal data necessary for the purpose of publication
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
p.000830: is permitted and legal when made for the purpose of publishing or issuing a decision
p.000830: any court or when necessary for the purposes of the administration of justice.
p.000830: Processing based on the decision of the Council of Ministers.
p.000830: 7. The processing of personal data entrusted by the Council of Ministers to
p.000830: a public authority or body for the performance of a duty performed in the public interest or for the performance of a public interest
p.000830: power is carried out legally and legally in a clear, precise and transparent manner with respect to the subject
p.000830: data, in accordance with the provisions of point (a) of paragraph (1) of Article 5, and
p.000830: point (e) of Rule 6 (1).
p.000830: Special offer
p.000830: community services
p.000830: of information to a child.
p.000830: 8 .- (1) Where the provision of information society services directly to a child is based on
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
...

p.000832: or are no longer fulfilled or if the actions of the certification body are in breach of the provisions of the Regulation or of
p.000832: of this Law.
p.000832: (5) In case the Cyprus Quality Promotion Organization does not revoke the accreditation body
p.000832: certification according to points (3) and (4), the Commissioner complains to the Cyprus Quality Promotion Organization
p.000832: European Commission.
p.000833: 833
p.000833: PART VII
p.000833: TRANSFER OF SPECIAL CATEGORIES OF DATA IN THIRD COUNTRY OR IN INTERNATIONAL ORGANIZATION
p.000833: Transmission of specific categories of personal data on the basis of appropriate guarantees or binding corporate
p.000833: rules.
p.000833: 17 .- (1) Where the controller or performer intends to transmit specific categories of data
p.000833: personal status in a third country or international organization, on the basis of the rules laid down in Rule 46 of the Rules of Procedure
p.000833: appropriate guarantees or on the basis of the binding corporate rules provided for in Rule 47,
p.000833: the controller or processor informs the Commissioner of his intention before transmitting
p.000833: of this data.
p.000833: (2) Without prejudice to Rule 46 and 47 of the Rules of Procedure, the Commissioner may, for serious reasons,
p.000833: in the public interest, to impose on the controller or the controller explicit
p.000833: restrictions on the transmission of specific categories of personal data referred to in (1).
p.000833: (3) Where appropriate guarantees or binding corporate rules referred to in
p.000833: subparagraph (1) were approved by the European Commission or within the framework of Article 63 thereof
p.000833: The Commissioner shall consult the aforementioned entities referred to in paragraph (2)
p.000833: limitations, where appropriate, with the Commission, the Council, the lead authority and other authorities concerned,
p.000833: before imposing them.
p.000833: Transmission of specific categories of personal data on the basis of derogations for special situations.
p.000833: 18 .- (1) The transmission of specific categories of personal data to a third country or to an international organization which
p.000833: is performed by the controller or the processor on the basis of the requirements of
p.000833: Article 49 of the Derogation Regulation for special situations requires an impact assessment to be carried out and
p.000833: prior consultation with the Commissioner.
p.000833: (2) The impact assessment referred to in paragraph (1) shall include those provided for in paragraph (7) of the
p.000833: Rule 35 information, and, where appropriate, a description of those provided for in the Articles
p.000833: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000833: (3) Without prejudice to Rule 49 of the Rules of Procedure, the Commissioner may, for serious public reasons,
p.000833: interest, to impose on the controller or processor explicit restrictions on
p.000833: transmission of those referred to in subparagraph
p.000833: (1) Specific categories of personal data.
p.000833: PART VIII
p.000833: PERSONAL DATA PROTECTION COMMITTEE
p.000833: His appointment, qualifications and term of office
p.000833: Commissioner.
p.000833: 19 .- (1) The Personal Data Protection Commissioner is appointed by the Council of Ministers, after
p.000833: recommendation of the Minister.
p.000833: (2) A person who is qualified to be a High Court Judge shall be appointed as a Commissioner.
p.000833: (3) The term of office of the Commissioner shall be six (6) years and may be renewed for a further
p.000833: service.
p.000833: (4) Subject to the provisions of Rule 53 (4) and Rule 20 thereof
p.000833: of this Act, the Commissioner may not be dismissed during his / her term of office only for reasons
p.000833: mental or physical disability or disability that render him unable to perform his duties.
p.000834: 834
p.000834: (5) The Commissioner is designated as a supervisory authority for the purposes of the Rules of Procedure and is responsible for monitoring the
p.000834: implementation of the provisions of the Rules of Procedure and this Law in the Republic and other regulations which
p.000834: relate to the processing of personal data.
p.000834: Deduction from office
p.000834: of the Commissioner.
p.000834: 20 .- (1) The Commissioner shall be removed from office if, during his term of office: -
p.000834: (a) Perform an act incompatible with his duties or carry on any profession incompatible
p.000834: to his property, whether it is profitable or not, or,
p.000834: (b) convicted of the offense provided for in subsection (3) of section 21 of this Law.
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
p.000834: (d) upon expiry of his term of office, he shall refrain from any act incompatible with them
p.000834: its powers, duties and powers and does not carry out any incompatible profession, profitable or not,
...

p.000834: allows another person to know about them, commits an offense and, if convicted, is subject to a penalty
p.000834: to imprisonment not exceeding three (3) years or to a fine not exceeding thirty thousand euros
p.000834: (€ 30,000) or both.
p.000834: Office
p.000834: Commissioner.
p.000834: 22. The Commissioner holds an office which may be staffed by permanent, temporary or indefinite-term public servants.
p.000834: employees:
p.000834: Provided that the Commissioner participates in the selection process of his Office staff and the staff is administered
p.000834: exclusively by him:
p.000834: It is further understood that the staff of the Office of the Commissioner are responsible for maintaining confidentiality or confidentiality.
p.000834: even after the end of their service.
p.000834: Duties and powers of the Commissioner.
p.000834: 23 .- (1) The Commissioner shall perform the tasks assigned to him and shall exercise the powers conferred on him by the Commission.
p.000834: of the Rules of Procedure, this Law and any other law.
p.000835: 835
p.000835: (2) The Commissioner, without prejudice to the principle of hierarchy, may authorize in writing any of his officers.
p.000835: An office which he holds responsible as he exercises such duties and powers
p.000835: subject to the conditions, exceptions and reservations, which the Commissioner shall specify in its delegation.
p.000835: (3) The Commissioner may, at his discretion, make a case concerning the execution of the
p.000835: of his duties or in the exercise of his powers:
p.000835: Provided that, if the case concerns cross-border treatment, the Commissioner shall consult his intention to
p.000835: make a case under the provisions of this subparagraph with the lead supervisory authority and
p.000835: supervisory authorities concerned.
p.000835: (4) The Commissioner has no jurisdiction to review processing acts performed by the courts of the Republic
p.000835: within their jurisdiction.
p.000835: Additional tasks
p.000835: Commissioner.
p.000835: 24. Subject to the provisions of Rule 57 of the Rules of Procedure and in addition to the duties which
p.000835: as provided in this Article, the Commissioner shall perform the following tasks:
p.000835: (a) It may publish, on the Office's website, how to file complaints; and
p.000835: applications;
p.000835: (b) consider a complaint and, where possible, depending on the nature and type of complaint;
p.000835: inform the complainant in writing of its progress and outcome within thirty (30) days of its submission
p.000835: Complaint:
p.000835: Provided that, where the complaint is found to be unfounded or does not fall within its remit
p.000835: Commissioner, he shall notify the complainant in writing within thirty (30) days of the submission of the complaint;
p.000835: (c) inform, where appropriate, the data subject, the controller where appropriate;
p.000835: and the executor for the time limits provided for in Rules 60 to 66 of the Rules of Procedure;
p.000835: (d) may not consider or terminate a complaint for reasons of public interest and shall notify it
p.000835: the data subject, within a reasonable time, the reasons for not examining or for
p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
...

p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
p.000838: (2) In the event of failure to pay the administrative fine referred to in (1), this
p.000838: is collected as a civil debt due to the Republic.
p.000838: (3) Administrative fine imposed on a public authority or public body for activities not related to
p.000838: speculative in nature, may not exceed two hundred thousand euros (€ 200,000).
p.000838: Offenses and penalties.
p.000838: 33.- (1) Commits a criminal offense-
p.000838: (a) The controller or processor who does not keep the record of activities that
p.000838: provided for in Rule 30 of the Rules of Procedure or does not update this file or refuses to place the file in
p.000838: Commissioner at his request or provide the Commissioner with false, inaccurate, incomplete or misleading information
p.000838: about this file,
p.000838: (b) a controller or processor who does not cooperate with the Commissioner, in accordance with
p.000838: by the provisions of Rule 31 of the Rules of Procedure,
p.000838: (c) a controller who does not notify the Commissioner of a breach of personal data
p.000838: in accordance with the provisions of Rule 33 (1),
p.000838: (d) perform the processing which does not promptly inform the controller of
p.000838: violation of personal data in accordance with the provisions of Article 33 (2)
p.000838: Regulation,
p.000838: (e) a controller who does not report a breach of personal data
p.000838: the data subject, in accordance with the provisions of Rule 34 of the Rules of Procedure,
p.000838: (f) a controller who does not conduct an impact assessment in breach of the provisions of paragraph
p.000838: (1) Rule 35 of this Regulation or Rule 13 of this Law,
p.000838: (g) the controller or processor who blocks the data controller from
p.000838: carrying out his duties, in particular those relating to working with the Commissioner,
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the restrictions imposed by the Commissioner under the provisions of the Articles
p.000838: 17 or 18 of this Law,
p.000838: (k) a person who unlawfully interferes with any data archiving system
p.000838: personal or knowingly acquiring or removing, altering, damaging, destroying, processing,
p.000838: exploits in any way, transmits, communicates, makes them accessible to unauthorized persons, or
p.000838: allows such persons to access such data, for profit or non-profit purposes,
p.000838: (l) the controller or performer of the processing which prevents or impedes the exercise
p.000838: the powers of the Commissioner provided for in Rule 58 of this Rules of Procedure and Rule 17 of this Law,
p.000839: 839
p.000839: (m) controller or processor who fails to comply with the provisions of the Rules of Procedure
p.000839: and of this Law in carrying out a processing act which is not an offense under
p.000839: the provisions of this Article,
p.000839: (n) a public authority or public body combining large archive systems
p.000839: scale in violation of the provisions of section 10 of this Law.
p.000839: (2) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (a) to (l) of subparagraph (1) shall be subject to a prison sentence not exceeding one year.
p.000839: three (3) years or a fine not exceeding thirty thousand euros (€ 30,000) or both.
p.000839: (3) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (m) and (n) of subparagraph (1), subject to a prison sentence not exceeding
p.000839: one (1) year or a fine not exceeding ten thousand euros (€ 10,000) or both.
p.000839: (4) Where a person is convicted of committing any of the offenses which
p.000839: refer to paragraphs (g) to (j) of subparagraph (1), which infringes the interests of the Republic or causes
p.000839: danger to the unhindered operation of the Government or threatening national security is subject to a prison sentence which
p.000839: does not exceed five (5) years or a fine not exceeding fifty thousand euros (€ 50,000) or
p.000839: these two sentences.
p.000839: (5) For the purposes of applying the provisions of this Article;
p.000839: (a) If the controller or processor is a business or group of undertakings, legal liability
p.000839: bears the person designated as the supreme executive body or body of the undertaking or group of undertakings,
p.000839: (b) if the controller or processor is a public authority or public body;
p.000839: the head or the person in charge of the effective administration of the public authority or
p.000839: public body.
p.000839: PART XI
p.000839: FINAL PROVISIONS
p.000839: Regulations. 34. The Council of Ministers, on the recommendation of the Commissioner, may
p.000839: to issue Regulations for the effective implementation of the provisions of this Regulation and this Law.
p.000839: International
p.000839: cooperation.
p.000839: 35 .- (1) In the absence of an appropriate legal measure by the Commission binding on the Member States, the Commissioner may
p.000839: Recommends to the Minister the conclusion of agreements with third countries or international organizations to fulfill the objectives
p.000839: referred to in Rule 50 of the Rules of Procedure.
p.000839: (2) The Commissioner may conclude, establish and sign memorandums of understanding with corresponding authorities in other countries.
p.000839: or with international organizations.
p.000839: Abolition of law.
p.000839: 138 (I) of 2001
p.000839: 37 (I) of 2003
p.000839: 105 (I) of 2012.
p.000839: 36. With the entry into force of the provisions of this Law on the Processing of Personal Data
p.000839: Character (Protection of Individuals) Laws 2001 to 2012 are repealed.
p.000840: 840
p.000840: PART XII
p.000840: TRANSITIONAL PROVISIONS
p.000840: Transitional provisions.
p.000840: 37 .- (1) The appointment of the Commissioner made by the Council of Ministers pursuant to Decision no. 79,538,
p.000840: valid for four (4) years, dated 28.9.2015, until the expiry of his / her term of office.
p.000840: (2) Acts adopted by the Commissioner under the provisions of the repeal on Data Processing
p.000840: Personnel (Protection of Person) Law shall remain in force until expiry or replacement.
p.000840: (3) Until the Cyprus Quality Promotion Organization successfully submits its peer review
...


Orphaned Trigger Words



Appendix

Indicator List

IndicatorVulnerability
accessAccess to Social Goods
ageAge
authorityRelationship to Authority
childChild
criminalcriminal
disabilityMentally Disabled
employeesemployees
officerPolice Officer
opinionphilosophical differences/differences of opinion
policePolice Officer
prisonIncarcerated
propertyProperty Ownership
singleMarital Status
unionTrade Union Membership

Indicator Peers (Indicators in Same Vulnerability)

IndicatorPeers
officer['police']
police['officer']

Trigger Words

consent

cultural

justice

protection


Applicable Type / Vulnerability / Indicator Overlay for this Input

Vulnerability TypeVulnerabilityIndicator# Matches
Politicalcriminalcriminal5
HealthMentally Disableddisability2
SocialAccess to Social Goodsaccess5
SocialAgeage1
SocialChildchild6
SocialIncarceratedprison3
SocialMarital Statussingle1
SocialPolice Officerofficer10
SocialPolice Officerpolice4
SocialProperty Ownershipproperty1
SocialTrade Union Membershipunion10
Socialemployeesemployees2
Socialphilosophical differences/differences of opinionopinion1
General/OtherRelationship to Authorityauthority16