0A4F4F9BD490A749D5437F821CF06DF1
Protection of Natural Persons Against the Processing of Personal Data and the Free Circulation of such Data Act of 2018 (Law 125 (1))
http://www.dataprotection.gov.cy/dataprotection/dataprotection.nsf/all/DE97F6F59835A03AC22582DD003D895E/$file/Νόμος%20125(Ι)_2018.pdf?openelement
http://leaux.net/URLS/ConvertAPI Text Files/12D722804C89FAF3D0CAE59D0D49D557.en.txt
Examining the file media/Synopses/12D722804C89FAF3D0CAE59D0D49D557.html:
This file was generated: 2020-07-14 08:18:45
Indicators in focus are typically shown highlighted in yellow; |
Peer Indicators (that share the same Vulnerability association) are shown highlighted in pink; |
"Outside" Indicators (those that do NOT share the same Vulnerability association) are shown highlighted in green; |
Trigger Words/Phrases are shown highlighted in gray. |
Link to Orphaned Trigger Words (Appendix (Indicator List, Indicator Peers, Trigger Words, Type/Vulnerability/Indicator Overlay)
Applicable Type / Vulnerability / Indicator Overlay for this Input
Political / criminal
Searching for indicator criminal:
(return to top)
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
p.000830: processing of such data requires the separate consent of the data subject.
p.000830: Combining filing systems
p.000830: public authorities or bodies.
p.000830: 10 .- (1) The combination of large-scale filing systems of two or more public authorities or bodies,
p.000830: is permitted only for reasons of public interest, and provided that the provisions of points (c) or (e) thereof are met
p.000830: paragraph (1) of Rule 6 or points (g), (h) or (i) of Rule 9 (2).
p.000830: (2) Where the combination concerns specific categories of personal data or data which
p.000830: relate to criminal convictions and offenses or will be carried out using the coupon number
p.000830: ID or other generic ID, an assessment is required
p.000830: impact and prior consultation with the Commissioner.
p.000830: (3) The impact assessment referred to in paragraph (2) shall be carried out jointly by the public authorities, or
p.000830: entities that are going to combine their filing systems and include those provided in the
p.000830: paragraph (7) of Rule 35 of the Rules of Procedure and, where appropriate, a description of those provided for in the Rules
p.000830: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000830: (4) The Commissioner may authorize the combination of filing systems provided for in this Article.
p.000830: and impose on the public authorities or bodies that are to
p.000831: 831
p.000831: combine their filing systems, terms and conditions for such combination.
p.000831: PART III
p.000831: LIMITATIONS ON RIGHTS AND OBLIGATIONS
p.000831: Restriction of rights.
p.000831: 11 .- (1) Subject to the provisions of Rule 23 (1), the controller
p.000831: may apply measures to limit, in whole or in part, the Articles 12, 18, 19 and 20
p.000831: of the Rights Regulation:
p.000831: Provided that, if the restriction of rights relates to a processing operation entrusted to the processor, the
p.000831: the measures referred to in paragraph (1) shall apply subject to the provisions of Rule 28 of the Rules of Procedure.
p.000831: (2) The implementation of the measures referred to in (1) requires an impact assessment and prior
p.000831: consulting the Commissioner.
p.000831: (3) The impact assessment referred to in subsection (2) shall include those provided for in paragraph (2) of
p.000831: Rule 23, paragraph (7) of Rule 35 information and, where appropriate, a description thereof
...
p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
p.000836: (d) in the exercise of its powers of investigation to seize documents or electronic equipment
p.000836: under a search warrant pursuant to the provisions of the Criminal Procedure Law;
p.000836: (e) in addition to the corrections provided for in Article 58 (2) of the Rules of Procedure
p.000836: powers, require the Cyprus Quality Promotion Organization as it withdraws accreditation
p.000836: a certification body, when it finds that the certification requirements are no longer met or no longer met, or
p.000836: insofar as the actions of the certification body are in breach of the provisions of this Regulation and of this Regulation
p.000836: Law;
p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
p.000838: (2) In the event of failure to pay the administrative fine referred to in (1), this
p.000838: is collected as a civil debt due to the Republic.
p.000838: (3) Administrative fine imposed on a public authority or public body for activities not related to
p.000838: speculative in nature, may not exceed two hundred thousand euros (€ 200,000).
p.000838: Offenses and penalties.
p.000838: 33.- (1) Commits a criminal offense-
p.000838: (a) The controller or processor who does not keep the record of activities that
p.000838: provided for in Rule 30 of the Rules of Procedure or does not update this file or refuses to place the file in
p.000838: Commissioner at his request or provide the Commissioner with false, inaccurate, incomplete or misleading information
p.000838: about this file,
p.000838: (b) a controller or processor who does not cooperate with the Commissioner, in accordance with
p.000838: by the provisions of Rule 31 of the Rules of Procedure,
p.000838: (c) a controller who does not notify the Commissioner of a breach of personal data
p.000838: in accordance with the provisions of Rule 33 (1),
p.000838: (d) perform the processing which does not promptly inform the controller of
p.000838: violation of personal data in accordance with the provisions of Article 33 (2)
p.000838: Regulation,
p.000838: (e) a controller who does not report a breach of personal data
p.000838: the data subject, in accordance with the provisions of Rule 34 of the Rules of Procedure,
p.000838: (f) a controller who does not conduct an impact assessment in breach of the provisions of paragraph
p.000838: (1) Rule 35 of this Regulation or Rule 13 of this Law,
p.000838: (g) the controller or processor who blocks the data controller from
p.000838: carrying out his duties, in particular those relating to working with the Commissioner,
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
...
Health / Mentally Disabled
Searching for indicator disability:
(return to top)
p.000833: is performed by the controller or the processor on the basis of the requirements of
p.000833: Article 49 of the Derogation Regulation for special situations requires an impact assessment to be carried out and
p.000833: prior consultation with the Commissioner.
p.000833: (2) The impact assessment referred to in paragraph (1) shall include those provided for in paragraph (7) of the
p.000833: Rule 35 information, and, where appropriate, a description of those provided for in the Articles
p.000833: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000833: (3) Without prejudice to Rule 49 of the Rules of Procedure, the Commissioner may, for serious public reasons,
p.000833: interest, to impose on the controller or processor explicit restrictions on
p.000833: transmission of those referred to in subparagraph
p.000833: (1) Specific categories of personal data.
p.000833: PART VIII
p.000833: PERSONAL DATA PROTECTION COMMITTEE
p.000833: His appointment, qualifications and term of office
p.000833: Commissioner.
p.000833: 19 .- (1) The Personal Data Protection Commissioner is appointed by the Council of Ministers, after
p.000833: recommendation of the Minister.
p.000833: (2) A person who is qualified to be a High Court Judge shall be appointed as a Commissioner.
p.000833: (3) The term of office of the Commissioner shall be six (6) years and may be renewed for a further
p.000833: service.
p.000833: (4) Subject to the provisions of Rule 53 (4) and Rule 20 thereof
p.000833: of this Act, the Commissioner may not be dismissed during his / her term of office only for reasons
p.000833: mental or physical disability or disability that render him unable to perform his duties.
p.000834: 834
p.000834: (5) The Commissioner is designated as a supervisory authority for the purposes of the Rules of Procedure and is responsible for monitoring the
p.000834: implementation of the provisions of the Rules of Procedure and this Law in the Republic and other regulations which
p.000834: relate to the processing of personal data.
p.000834: Deduction from office
p.000834: of the Commissioner.
p.000834: 20 .- (1) The Commissioner shall be removed from office if, during his term of office: -
p.000834: (a) Perform an act incompatible with his duties or carry on any profession incompatible
p.000834: to his property, whether it is profitable or not, or,
p.000834: (b) convicted of the offense provided for in subsection (3) of section 21 of this Law.
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
...
Social / Access to Social Goods
Searching for indicator access:
(return to top)
p.000829: against the processing of personal data and for the free movement of data
p.000829: and repealing Directive 95/46 / EC (General Data Protection Regulation) ";
p.000829: Official
p.000829: EU Journal: L.218, 13.8.2008,
p.000829: p.
p.000829: "Regulation (EC) No 765/2008" means the European Union Act entitled
p.000829: "Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 laying down detailed rules for the
p.000829: accreditation and market surveillance requirements for and marketing of products
p.000829: Regulation (EEC) No. Council Regulation (EC) No 339/93 ";
p.000829: 156 (I) of 2002
p.000829: 10 (I) of 2010
p.000829: 57 (I) of 2011
p.000829: 69 (I) of 2012
p.000829: 120 (I) of 2012.
p.000829: "Cyprus Quality Promotion Organization" means the Cyprus Quality Promotion Organization, designated as
p.000829: the national accreditation body under its Accreditation, Standardization and Technical Provisions
p.000829: Law Information;
p.000829: Official
p.000829: EU Journal: 241,
p.000829: 17.9.2015, p
p.000829: "Directive (EU) 2015/1535" means the European Union act entitled "Directive (EU) 2015/1535"
p.000829: European Parliament and Council of 9 September 2015 establishing an information procedure
p.000829: in the field of technical specifications and rules on information society services (codified
p.000829: text)"·
p.000829: "Business group" means a controlling undertaking and the undertakings controlled by it;
p.000829: "Personal data breach" means the breach of security that results in accidental or
p.000829: unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data
p.000829: characters that were transmitted, stored or otherwise processed;
p.000829: "Consent" of the data subject means any indication of will, free, specific, explicit and
p.000829: fully aware, with which the data subject demonstrates agreement, statement or clear affirmation
p.000829: action to process personal data relating to it;
p.000829: 'Filing system' means any structured set of personal data which
p.000829: are accessible on the basis of specific criteria, whether aggregated or decentralized
p.000829: either distributed on a functional or geographical basis;
p.000829: 'Controller' means the natural or legal person, public authority, agency or other entity which, alone or
p.000829: together with others, determine the purpose and manner of processing personal data ∙
p.000829: where the purposes and manner of such processing are determined by Union or Republic law, the person responsible shall
p.000829: processing or the specific criteria for his appointment may be provided for by Union law or
p.000829: the law of the Republic;
p.000829: 'Information society service' means a service within the meaning of Article 1 (1)
p.000829: point (b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;
p.000829: "Minister" means the Minister of Justice and Public Order.
p.000829: (2) Any terms contained in this Law and not specifically defined herein shall have the meaning assigned thereto.
p.000829: in these terms by the Rules of Procedure.
p.000829: Field of application.
p.000829: 3. The provisions of this Law shall apply to the Republic in accordance with the provisions of Articles 2 and 3 thereof
...
p.000835: inform the complainant in writing of its progress and outcome within thirty (30) days of its submission
p.000835: Complaint:
p.000835: Provided that, where the complaint is found to be unfounded or does not fall within its remit
p.000835: Commissioner, he shall notify the complainant in writing within thirty (30) days of the submission of the complaint;
p.000835: (c) inform, where appropriate, the data subject, the controller where appropriate;
p.000835: and the executor for the time limits provided for in Rules 60 to 66 of the Rules of Procedure;
p.000835: (d) may not consider or terminate a complaint for reasons of public interest and shall notify it
p.000835: the data subject, within a reasonable time, the reasons for not examining or for
p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
p.000835: perform the processing designated by the data protection officer as provided for in Article 14 hereof
p.000835: Law.
p.000835: Additional powers of the Commissioner.
p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
p.000836: (d) in the exercise of its powers of investigation to seize documents or electronic equipment
p.000836: under a search warrant pursuant to the provisions of the Criminal Procedure Law;
p.000836: (e) in addition to the corrections provided for in Article 58 (2) of the Rules of Procedure
p.000836: powers, require the Cyprus Quality Promotion Organization as it withdraws accreditation
p.000836: a certification body, when it finds that the certification requirements are no longer met or no longer met, or
...
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
p.000838: (2) In the event of failure to pay the administrative fine referred to in (1), this
p.000838: is collected as a civil debt due to the Republic.
p.000838: (3) Administrative fine imposed on a public authority or public body for activities not related to
p.000838: speculative in nature, may not exceed two hundred thousand euros (€ 200,000).
p.000838: Offenses and penalties.
p.000838: 33.- (1) Commits a criminal offense-
p.000838: (a) The controller or processor who does not keep the record of activities that
p.000838: provided for in Rule 30 of the Rules of Procedure or does not update this file or refuses to place the file in
p.000838: Commissioner at his request or provide the Commissioner with false, inaccurate, incomplete or misleading information
p.000838: about this file,
p.000838: (b) a controller or processor who does not cooperate with the Commissioner, in accordance with
p.000838: by the provisions of Rule 31 of the Rules of Procedure,
p.000838: (c) a controller who does not notify the Commissioner of a breach of personal data
p.000838: in accordance with the provisions of Rule 33 (1),
p.000838: (d) perform the processing which does not promptly inform the controller of
p.000838: violation of personal data in accordance with the provisions of Article 33 (2)
p.000838: Regulation,
p.000838: (e) a controller who does not report a breach of personal data
p.000838: the data subject, in accordance with the provisions of Rule 34 of the Rules of Procedure,
p.000838: (f) a controller who does not conduct an impact assessment in breach of the provisions of paragraph
p.000838: (1) Rule 35 of this Regulation or Rule 13 of this Law,
p.000838: (g) the controller or processor who blocks the data controller from
p.000838: carrying out his duties, in particular those relating to working with the Commissioner,
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the restrictions imposed by the Commissioner under the provisions of the Articles
p.000838: 17 or 18 of this Law,
p.000838: (k) a person who unlawfully interferes with any data archiving system
p.000838: personal or knowingly acquiring or removing, altering, damaging, destroying, processing,
p.000838: exploits in any way, transmits, communicates, makes them accessible to unauthorized persons, or
p.000838: allows such persons to access such data, for profit or non-profit purposes,
p.000838: (l) the controller or performer of the processing which prevents or impedes the exercise
p.000838: the powers of the Commissioner provided for in Rule 58 of this Rules of Procedure and Rule 17 of this Law,
p.000839: 839
p.000839: (m) controller or processor who fails to comply with the provisions of the Rules of Procedure
p.000839: and of this Law in carrying out a processing act which is not an offense under
p.000839: the provisions of this Article,
p.000839: (n) a public authority or public body combining large archive systems
p.000839: scale in violation of the provisions of section 10 of this Law.
p.000839: (2) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (a) to (l) of subparagraph (1) shall be subject to a prison sentence not exceeding one year.
p.000839: three (3) years or a fine not exceeding thirty thousand euros (€ 30,000) or both.
p.000839: (3) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (m) and (n) of subparagraph (1), subject to a prison sentence not exceeding
p.000839: one (1) year or a fine not exceeding ten thousand euros (€ 10,000) or both.
p.000839: (4) Where a person is convicted of committing any of the offenses which
p.000839: refer to paragraphs (g) to (j) of subparagraph (1), which infringes the interests of the Republic or causes
p.000839: danger to the unhindered operation of the Government or threatening national security is subject to a prison sentence which
p.000839: does not exceed five (5) years or a fine not exceeding fifty thousand euros (€ 50,000) or
p.000839: these two sentences.
...
Social / Age
Searching for indicator age:
(return to top)
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
p.000830: is permitted and legal when made for the purpose of publishing or issuing a decision
p.000830: any court or when necessary for the purposes of the administration of justice.
p.000830: Processing based on the decision of the Council of Ministers.
p.000830: 7. The processing of personal data entrusted by the Council of Ministers to
p.000830: a public authority or body for the performance of a duty performed in the public interest or for the performance of a public interest
p.000830: power is carried out legally and legally in a clear, precise and transparent manner with respect to the subject
p.000830: data, in accordance with the provisions of point (a) of paragraph (1) of Article 5, and
p.000830: point (e) of Rule 6 (1).
p.000830: Special offer
p.000830: community services
p.000830: of information to a child.
p.000830: 8 .- (1) Where the provision of information society services directly to a child is based on
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
p.000830: processing of such data requires the separate consent of the data subject.
p.000830: Combining filing systems
p.000830: public authorities or bodies.
p.000830: 10 .- (1) The combination of large-scale filing systems of two or more public authorities or bodies,
p.000830: is permitted only for reasons of public interest, and provided that the provisions of points (c) or (e) thereof are met
p.000830: paragraph (1) of Rule 6 or points (g), (h) or (i) of Rule 9 (2).
p.000830: (2) Where the combination concerns specific categories of personal data or data which
p.000830: relate to criminal convictions and offenses or will be carried out using the coupon number
p.000830: ID or other generic ID, an assessment is required
p.000830: impact and prior consultation with the Commissioner.
p.000830: (3) The impact assessment referred to in paragraph (2) shall be carried out jointly by the public authorities, or
p.000830: entities that are going to combine their filing systems and include those provided in the
...
Social / Child
Searching for indicator child:
(return to top)
p.000829: Democracy is the Minister of Justice and Public Order.
p.000830: 830
p.000830: PART II
p.000830: LEGALITY OF CERTAIN PROCESSING ACTS
p.000830: Editing data from
p.000830: courts and the House of Representatives
p.000830: Representatives.
p.000830: 5. Without prejudice to the provisions of Rule 6 (e) (6),
p.000830: personal data is allowed and legal when it is performed-
p.000830: (a) By the courts within their jurisdiction for the purposes of its award
p.000830: justice, including the processing of personal data necessary for the purpose of publication
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
p.000830: is permitted and legal when made for the purpose of publishing or issuing a decision
p.000830: any court or when necessary for the purposes of the administration of justice.
p.000830: Processing based on the decision of the Council of Ministers.
p.000830: 7. The processing of personal data entrusted by the Council of Ministers to
p.000830: a public authority or body for the performance of a duty performed in the public interest or for the performance of a public interest
p.000830: power is carried out legally and legally in a clear, precise and transparent manner with respect to the subject
p.000830: data, in accordance with the provisions of point (a) of paragraph (1) of Article 5, and
p.000830: point (e) of Rule 6 (1).
p.000830: Special offer
p.000830: community services
p.000830: of information to a child.
p.000830: 8 .- (1) Where the provision of information society services directly to a child is based on
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
p.000830: processing of such data requires the separate consent of the data subject.
p.000830: Combining filing systems
p.000830: public authorities or bodies.
p.000830: 10 .- (1) The combination of large-scale filing systems of two or more public authorities or bodies,
p.000830: is permitted only for reasons of public interest, and provided that the provisions of points (c) or (e) thereof are met
p.000830: paragraph (1) of Rule 6 or points (g), (h) or (i) of Rule 9 (2).
p.000830: (2) Where the combination concerns specific categories of personal data or data which
p.000830: relate to criminal convictions and offenses or will be carried out using the coupon number
p.000830: ID or other generic ID, an assessment is required
p.000830: impact and prior consultation with the Commissioner.
p.000830: (3) The impact assessment referred to in paragraph (2) shall be carried out jointly by the public authorities, or
p.000830: entities that are going to combine their filing systems and include those provided in the
p.000830: paragraph (7) of Rule 35 of the Rules of Procedure and, where appropriate, a description of those provided for in the Rules
p.000830: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000830: (4) The Commissioner may authorize the combination of filing systems provided for in this Article.
p.000830: and impose on the public authorities or bodies that are to
p.000831: 831
...
Social / Incarcerated
Searching for indicator prison:
(return to top)
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the restrictions imposed by the Commissioner under the provisions of the Articles
p.000838: 17 or 18 of this Law,
p.000838: (k) a person who unlawfully interferes with any data archiving system
p.000838: personal or knowingly acquiring or removing, altering, damaging, destroying, processing,
p.000838: exploits in any way, transmits, communicates, makes them accessible to unauthorized persons, or
p.000838: allows such persons to access such data, for profit or non-profit purposes,
p.000838: (l) the controller or performer of the processing which prevents or impedes the exercise
p.000838: the powers of the Commissioner provided for in Rule 58 of this Rules of Procedure and Rule 17 of this Law,
p.000839: 839
p.000839: (m) controller or processor who fails to comply with the provisions of the Rules of Procedure
p.000839: and of this Law in carrying out a processing act which is not an offense under
p.000839: the provisions of this Article,
p.000839: (n) a public authority or public body combining large archive systems
p.000839: scale in violation of the provisions of section 10 of this Law.
p.000839: (2) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (a) to (l) of subparagraph (1) shall be subject to a prison sentence not exceeding one year.
p.000839: three (3) years or a fine not exceeding thirty thousand euros (€ 30,000) or both.
p.000839: (3) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (m) and (n) of subparagraph (1), subject to a prison sentence not exceeding
p.000839: one (1) year or a fine not exceeding ten thousand euros (€ 10,000) or both.
p.000839: (4) Where a person is convicted of committing any of the offenses which
p.000839: refer to paragraphs (g) to (j) of subparagraph (1), which infringes the interests of the Republic or causes
p.000839: danger to the unhindered operation of the Government or threatening national security is subject to a prison sentence which
p.000839: does not exceed five (5) years or a fine not exceeding fifty thousand euros (€ 50,000) or
p.000839: these two sentences.
p.000839: (5) For the purposes of applying the provisions of this Article;
p.000839: (a) If the controller or processor is a business or group of undertakings, legal liability
p.000839: bears the person designated as the supreme executive body or body of the undertaking or group of undertakings,
p.000839: (b) if the controller or processor is a public authority or public body;
p.000839: the head or the person in charge of the effective administration of the public authority or
p.000839: public body.
p.000839: PART XI
p.000839: FINAL PROVISIONS
p.000839: Regulations. 34. The Council of Ministers, on the recommendation of the Commissioner, may
p.000839: to issue Regulations for the effective implementation of the provisions of this Regulation and this Law.
p.000839: International
p.000839: cooperation.
p.000839: 35 .- (1) In the absence of an appropriate legal measure by the Commission binding on the Member States, the Commissioner may
p.000839: Recommends to the Minister the conclusion of agreements with third countries or international organizations to fulfill the objectives
p.000839: referred to in Rule 50 of the Rules of Procedure.
p.000839: (2) The Commissioner may conclude, establish and sign memorandums of understanding with corresponding authorities in other countries.
p.000839: or with international organizations.
p.000839: Abolition of law.
p.000839: 138 (I) of 2001
p.000839: 37 (I) of 2003
p.000839: 105 (I) of 2012.
p.000839: 36. With the entry into force of the provisions of this Law on the Processing of Personal Data
...
Social / Marital Status
Searching for indicator single:
(return to top)
p.000828: of a person who has been inherited or acquired, in particular as a result of a biological sample analysis of that person
p.000828: natural person and which provide unique information about the physiology or health of that natural person
p.000828: face;
p.000828: "Personal data" means any information relating to an identified or identifiable natural
p.000828: person ('data subject'). The identifiable natural person is one whose identity
p.000828: can be ascertained, directly or indirectly, in particular by reference to an identity such as a name, a number
p.000828: ID, location data, online ID, or one or more factors
p.000828: specific to the physical, physiological, genetic, psychological, economic, cultural or social
p.000828: the identity of that natural person;
p.000828: "Binding corporate rules" means their personal data protection policies
p.000828: followed by a controller or processor established in the territory of a State
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
p.000828: (a) the processing of personal data carried out in the course of the activities of various parties;
p.000828: establishments in more than one Member State responsible for processing or processing in the Union where
p.000828: the controller or processor is established in more than one Member State, or
p.000828: (b) the processing of personal data carried out in the course of one's activities
p.000828: a single installation controller or processor in the Union but which affects or
p.000828: may substantially affect data subjects in more than one Member State;
p.000828: "International organization" means the organization and its subordinate bodies governed by
p.000828: public international law or any other body established by or on the basis of an agreement between two or
p.000828: more countries;
p.000828: 'Representative' means a natural or legal person established in the Union, designated in writing by the person responsible;
p.000828: processor or performer of the processing under Rule 27 of the Rules of Procedure and represent the person responsible
p.000828: processor or performer of the processing of their respective obligations under the Rules of Procedure and
p.000828: this Law;
p.000828: 'Perform the processing' means the natural or legal person, or a public authority, or service or other body which
p.000828: processes personal data on behalf of the controller;
p.000828: 'Processing' means any operation or series of operations performed with or without the use of automated means;
p.000828: in personal data or in personal data sets, such as collection, h
p.000828: registration, organization, structure, storage, customization or modification, recovery, search
p.000828: information, use, disclosure, dissemination or any other form of distribution, association or combination;
p.000828: restriction, deletion or destruction;
p.000828: 'Commissioner' means the Commissioner for Personal Data Protection who is appointed under
p.000828: provisions of section 19 of this Law;
p.000828: 'Enterprise' means any natural or legal person carrying on an economic activity, irrespective of
...
Social / Police Officer
Searching for indicator officer:
(return to top)
p.000831: measures referred to in subparagraph (1) and to inform the subject referred to in subparagraph (4) of
p.000831: data.
p.000831: Exemption from liability for infringement notice.
p.000831: 12 .- (1) The controller may be relieved, in whole or in part, of the responsibility for notifying a breach
p.000831: personal data to the data subject, for one or more of those referred to
p.000831: for the purposes of Rule 23 (1).
p.000831: (2) An exemption from the liability referred to in (1) requires an assessment to be carried out.
p.000831: impact and prior consultation with the Commissioner.
p.000831: (3) The impact assessment referred to in paragraph (2) shall include those provided for in paragraph (2) of
p.000831: Rule 23 and Rule 35 (7) information.
p.000831: (4) The Commissioner may impose on the controller the terms and conditions for the purpose referred to in the subparagraph.
p.000831: (1) Release of liability for communication.
p.000831: PART IV
p.000831: IMPACT ASSESSMENT OF LEGISLATIVE MEASURES
p.000831: Carry out an impact assessment after the adoption of legislative or regulatory measures.
p.000831: 13 .- (1) Before the enactment of a law or Regulations issued by law providing for a specific
p.000831: an operation or series of processing operations, an impact assessment and prior is required
p.000831: consulting the Commissioner.
p.000831: (2) The provisions of subparagraph (1) shall not apply if the Commissioner considers that the
p.000831: was made while drafting a law or regulations issued by law is satisfactory and not
p.000831: an additional impact assessment is required prior to the implementation of the operation concerned, or
p.000831: a series of processing operations, which they provide.
p.000832: 832
p.000832: PART V
p.000832: DATA PROTECTION OFFICER
p.000832: Definition
p.000832: data protection officer.
p.000832: 14 .- (1) The data protection officer shall be appointed in accordance with Rule 37 of the Rules of Procedure.
p.000832: (2) The Commissioner may draw up and make public a list of processing operations and cases in
p.000832: which require the designation of a data protection officer, in addition to those provided for in paragraph (1) of the
p.000832: Rule 37 acts.
p.000832: (3) The Commissioner may publish on his office's website a list of controllers
p.000832: and perform the processing they have designated data protection officer and data
p.000832: contact, if the controller and the processor wish to be included in the
p.000832: list it.
p.000832: Obligation of the Data Protection Officer
p.000832: for compliance
p.000832: of privacy or of
p.000832: confidentiality.
p.000832: 15 .- (1) Subject to the provisions of any law regulating matters of professional secrecy or
p.000832: In the performance of his duties, the Data Protection Officer is bound by the obligation
p.000832: privacy or confidentiality.
p.000832: (2) Data protection officer's confidentiality or confidentiality,
p.000832: affects the provisions of Rule 58 (1) and Rule (a) and (b) thereof
p.000832: section 25 of this Act the powers of control of the Commissioner.
p.000832: PART VI
p.000832: ACCREDITATION ACCREDITATION BODY
p.000832: Accreditation of certification bodies.
p.000832: 16 .- (1) Subject to Rule 43 of the Rules of Procedure, accreditation bodies shall be accredited.
p.000832: by the Cyprus Quality Promotion Organization.
p.000832: (2) Submitted to the Cyprus Quality Promotion Organization for accreditation of a certification body.
p.000832: the positive opinion of the Commissioner, that the applicant for certification of body fulfills the provisions of points (a), (b), and (e) of
p.000832: Rule 43 (2).
p.000832: (3) The Cyprus Quality Promotion Agency shall revoke accreditation of accreditation body if
p.000832: certification requirements are no longer fulfilled or are not fulfilled or if the actions of the certification body
p.000832: violate the provisions of the Rules of Procedure or this Law.
p.000832: (4) The Commissioner may request the Cyprus Quality Promotion Organization to revoke it
p.000832: accreditation of a certification body if the Commissioner finds that the certification requirements are not met
p.000832: or are no longer fulfilled or if the actions of the certification body are in breach of the provisions of the Regulation or of
p.000832: of this Law.
p.000832: (5) In case the Cyprus Quality Promotion Organization does not revoke the accreditation body
p.000832: certification according to points (3) and (4), the Commissioner complains to the Cyprus Quality Promotion Organization
p.000832: European Commission.
p.000833: 833
p.000833: PART VII
p.000833: TRANSFER OF SPECIAL CATEGORIES OF DATA IN THIRD COUNTRY OR IN INTERNATIONAL ORGANIZATION
...
p.000835: make a case under the provisions of this subparagraph with the lead supervisory authority and
p.000835: supervisory authorities concerned.
p.000835: (4) The Commissioner has no jurisdiction to review processing acts performed by the courts of the Republic
p.000835: within their jurisdiction.
p.000835: Additional tasks
p.000835: Commissioner.
p.000835: 24. Subject to the provisions of Rule 57 of the Rules of Procedure and in addition to the duties which
p.000835: as provided in this Article, the Commissioner shall perform the following tasks:
p.000835: (a) It may publish, on the Office's website, how to file complaints; and
p.000835: applications;
p.000835: (b) consider a complaint and, where possible, depending on the nature and type of complaint;
p.000835: inform the complainant in writing of its progress and outcome within thirty (30) days of its submission
p.000835: Complaint:
p.000835: Provided that, where the complaint is found to be unfounded or does not fall within its remit
p.000835: Commissioner, he shall notify the complainant in writing within thirty (30) days of the submission of the complaint;
p.000835: (c) inform, where appropriate, the data subject, the controller where appropriate;
p.000835: and the executor for the time limits provided for in Rules 60 to 66 of the Rules of Procedure;
p.000835: (d) may not consider or terminate a complaint for reasons of public interest and shall notify it
p.000835: the data subject, within a reasonable time, the reasons for not examining or for
p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
p.000835: perform the processing designated by the data protection officer as provided for in Article 14 hereof
p.000835: Law.
p.000835: Additional powers of the Commissioner.
p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
...
Searching for indicator police:
(return to top)
p.000827: Tuesday, July 31, 2018
p.000827: 827
p.000827: On the Protection of Individuals with regard to the Processing of Personal Data and the
p.000827: Free Release of these Data Law of 2018 is published with publication in the Official Gazette of Cyprus
p.000827: Democracy in accordance with Article 52 of the Constitution.
p.000827: No. 125 (I) of 2018
p.000827: LAW ON PROTECTION OF NATURAL PERSONS AGAINST PERSONAL DATA PROCESSING AND PROTECTION
p.000827: FOR FREE MOVEMENT OF THESE DATA
p.000827: Preamble. Official newspaper
p.000827: OJ: L.119, 4.5.2016, p. 1.
p.000827: For the purpose of effective implementation of certain provisions of the European Union Act entitled
p.000827: 'Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of the
p.000827: natural persons against the processing of personal data and for the free movement of such data
p.000827: including the repeal of Directive 95/46 / EC (General Data Protection Regulation) ",
p.000827: The House of Representatives votes as follows:
p.000827: PART I.
p.000827: general provisions
p.000827: Short title.
p.000827: 1. This Law shall be referred to as the Protection of Individuals against it
p.000827: Processing of Personal Data and the Free Movement of such Data
p.000827: of 2018.
p.000827: Interpretation. 2 .- (1) In this Law, unless its text or the text of the Rules of Procedure
p.000827: a different concept emerges;
p.000828: 828
p.000828: "Police" means the Cyprus Police;
p.000828: 'Biometric data' means personal data derived from a specific technique
p.000828: treatment associated with physical, biological or behavioral characteristics of the natural person and which
p.000828: permit or confirm the unambiguous identification of such natural person, such as facial images, or
p.000828: fingerprint data;
p.000828: "Genetic data" means personal data relating to the genetic characteristics of the natural
p.000828: of a person who has been inherited or acquired, in particular as a result of a biological sample analysis of that person
p.000828: natural person and which provide unique information about the physiology or health of that natural person
p.000828: face;
p.000828: "Personal data" means any information relating to an identified or identifiable natural
p.000828: person ('data subject'). The identifiable natural person is one whose identity
p.000828: can be ascertained, directly or indirectly, in particular by reference to an identity such as a name, a number
p.000828: ID, location data, online ID, or one or more factors
p.000828: specific to the physical, physiological, genetic, psychological, economic, cultural or social
p.000828: the identity of that natural person;
p.000828: "Binding corporate rules" means their personal data protection policies
p.000828: followed by a controller or processor established in the territory of a State
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
...
p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
p.000835: perform the processing designated by the data protection officer as provided for in Article 14 hereof
p.000835: Law.
p.000835: Additional powers of the Commissioner.
p.000835: 25. Subject to the provisions of Rule 58 of the Rules of Procedure and in addition to the powers conferred thereto
p.000835: as provided in that Article, the Commissioner shall exercise the following powers:
p.000835: (a) Subject to the provisions of points (a) and (e) of Rule 58 (1),
p.000835: access to all personal data and all information necessary for its execution
p.000835: duties and the exercise of his powers, without being able to oppose any secrecy,
p.000835: except for legal confidentiality;
p.000835: (b) subject to the provisions of Rule 58 (1) (f), to enter,
p.000835: without necessarily preceding any briefing by the controller or processor or
p.000835: their representative, in any office, business premises or means of transport, excluding dwellings;
p.000835: (c) for the exercise of the provisions of Rule 58 (a) and
p.000835: this article of control powers may be assisted by an expert and / or the Police;
p.000836: 836
p.000836: Cap.155.
p.000836: 93 of 1972
p.000836: 2 of 1975
p.000836: 12 of 1975
p.000836: 41 of 1978
p.000836: 162 of 1989
p.000836: 142 of 1991
p.000836: 9 (I) of 1992
p.000836: 10 (I) of 1996
p.000836: 89 (I) of 1997
p.000836: 54 (I) of 1998
p.000836: 96 (I) of 1998
p.000836: 14 (I) of 2001
p.000836: 185 (I) of 2003
p.000836: 219 (I) of 2004
p.000836: 57 (I) of 2007
p.000836: 9 (I) of 2009
p.000836: 111 (I) of 2011
p.000836: 165 (I) of 2011
p.000836: 7 (I) of 2012
p.000836: 21 (I) of 2012
p.000836: 160 (I) of 2012
p.000836: 23 (I) of 2013
p.000836: 16 (I) of 2014
p.000836: 42 (I) of 2014
p.000836: 186 (I) of 2014.
p.000836: (d) in the exercise of its powers of investigation to seize documents or electronic equipment
p.000836: under a search warrant pursuant to the provisions of the Criminal Procedure Law;
p.000836: (e) in addition to the corrections provided for in Article 58 (2) of the Rules of Procedure
p.000836: powers, require the Cyprus Quality Promotion Organization as it withdraws accreditation
p.000836: a certification body, when it finds that the certification requirements are no longer met or no longer met, or
p.000836: insofar as the actions of the certification body are in breach of the provisions of this Regulation and of this Regulation
p.000836: Law;
p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
...
Social / Property Ownership
Searching for indicator property:
(return to top)
p.000833: transmission of those referred to in subparagraph
p.000833: (1) Specific categories of personal data.
p.000833: PART VIII
p.000833: PERSONAL DATA PROTECTION COMMITTEE
p.000833: His appointment, qualifications and term of office
p.000833: Commissioner.
p.000833: 19 .- (1) The Personal Data Protection Commissioner is appointed by the Council of Ministers, after
p.000833: recommendation of the Minister.
p.000833: (2) A person who is qualified to be a High Court Judge shall be appointed as a Commissioner.
p.000833: (3) The term of office of the Commissioner shall be six (6) years and may be renewed for a further
p.000833: service.
p.000833: (4) Subject to the provisions of Rule 53 (4) and Rule 20 thereof
p.000833: of this Act, the Commissioner may not be dismissed during his / her term of office only for reasons
p.000833: mental or physical disability or disability that render him unable to perform his duties.
p.000834: 834
p.000834: (5) The Commissioner is designated as a supervisory authority for the purposes of the Rules of Procedure and is responsible for monitoring the
p.000834: implementation of the provisions of the Rules of Procedure and this Law in the Republic and other regulations which
p.000834: relate to the processing of personal data.
p.000834: Deduction from office
p.000834: of the Commissioner.
p.000834: 20 .- (1) The Commissioner shall be removed from office if, during his term of office: -
p.000834: (a) Perform an act incompatible with his duties or carry on any profession incompatible
p.000834: to his property, whether it is profitable or not, or,
p.000834: (b) convicted of the offense provided for in subsection (3) of section 21 of this Law.
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
p.000834: (d) upon expiry of his term of office, he shall refrain from any act incompatible with them
p.000834: its powers, duties and powers and does not carry out any incompatible profession, profitable or not,
p.000834: for a period of two (2) years.
p.000834: (3) Where the Commissioner, in breach of the provisions of the Rules of Procedure and this Law,
p.000834: any manner of personal information or data that is accessible to him because of his location; or
p.000834: allows another person to know about them, commits an offense and, if convicted, is subject to a penalty
p.000834: to imprisonment not exceeding three (3) years or to a fine not exceeding thirty thousand euros
p.000834: (€ 30,000) or both.
p.000834: Office
p.000834: Commissioner.
...
Social / Trade Union Membership
Searching for indicator union:
(return to top)
p.000827: N. 125 (I) / 2018
p.000827: OFFICIAL NEWSPAPER
p.000827: OF THE CYPRUS REPUBLIC
p.000827: ANNEX FIRST
p.000827: LEGISLATION - PART I.
p.000827: Number 4670
p.000827: Tuesday, July 31, 2018
p.000827: 827
p.000827: On the Protection of Individuals with regard to the Processing of Personal Data and the
p.000827: Free Release of these Data Law of 2018 is published with publication in the Official Gazette of Cyprus
p.000827: Democracy in accordance with Article 52 of the Constitution.
p.000827: No. 125 (I) of 2018
p.000827: LAW ON PROTECTION OF NATURAL PERSONS AGAINST PERSONAL DATA PROCESSING AND PROTECTION
p.000827: FOR FREE MOVEMENT OF THESE DATA
p.000827: Preamble. Official newspaper
p.000827: OJ: L.119, 4.5.2016, p. 1.
p.000827: For the purpose of effective implementation of certain provisions of the European Union Act entitled
p.000827: 'Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of the
p.000827: natural persons against the processing of personal data and for the free movement of such data
p.000827: including the repeal of Directive 95/46 / EC (General Data Protection Regulation) ",
p.000827: The House of Representatives votes as follows:
p.000827: PART I.
p.000827: general provisions
p.000827: Short title.
p.000827: 1. This Law shall be referred to as the Protection of Individuals against it
p.000827: Processing of Personal Data and the Free Movement of such Data
p.000827: of 2018.
p.000827: Interpretation. 2 .- (1) In this Law, unless its text or the text of the Rules of Procedure
p.000827: a different concept emerges;
p.000828: 828
p.000828: "Police" means the Cyprus Police;
p.000828: 'Biometric data' means personal data derived from a specific technique
p.000828: treatment associated with physical, biological or behavioral characteristics of the natural person and which
p.000828: permit or confirm the unambiguous identification of such natural person, such as facial images, or
p.000828: fingerprint data;
p.000828: "Genetic data" means personal data relating to the genetic characteristics of the natural
p.000828: of a person who has been inherited or acquired, in particular as a result of a biological sample analysis of that person
p.000828: natural person and which provide unique information about the physiology or health of that natural person
p.000828: face;
p.000828: "Personal data" means any information relating to an identified or identifiable natural
p.000828: person ('data subject'). The identifiable natural person is one whose identity
p.000828: can be ascertained, directly or indirectly, in particular by reference to an identity such as a name, a number
p.000828: ID, location data, online ID, or one or more factors
p.000828: specific to the physical, physiological, genetic, psychological, economic, cultural or social
p.000828: the identity of that natural person;
p.000828: "Binding corporate rules" means their personal data protection policies
p.000828: followed by a controller or processor established in the territory of a State
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
p.000828: (a) the processing of personal data carried out in the course of the activities of various parties;
p.000828: establishments in more than one Member State responsible for processing or processing in the Union where
p.000828: the controller or processor is established in more than one Member State, or
p.000828: (b) the processing of personal data carried out in the course of one's activities
p.000828: a single installation controller or processor in the Union but which affects or
p.000828: may substantially affect data subjects in more than one Member State;
p.000828: "International organization" means the organization and its subordinate bodies governed by
p.000828: public international law or any other body established by or on the basis of an agreement between two or
p.000828: more countries;
p.000828: 'Representative' means a natural or legal person established in the Union, designated in writing by the person responsible;
p.000828: processor or performer of the processing under Rule 27 of the Rules of Procedure and represent the person responsible
p.000828: processor or performer of the processing of their respective obligations under the Rules of Procedure and
p.000828: this Law;
p.000828: 'Perform the processing' means the natural or legal person, or a public authority, or service or other body which
p.000828: processes personal data on behalf of the controller;
p.000828: 'Processing' means any operation or series of operations performed with or without the use of automated means;
p.000828: in personal data or in personal data sets, such as collection, h
p.000828: registration, organization, structure, storage, customization or modification, recovery, search
p.000828: information, use, disclosure, dissemination or any other form of distribution, association or combination;
p.000828: restriction, deletion or destruction;
p.000828: 'Commissioner' means the Commissioner for Personal Data Protection who is appointed under
p.000828: provisions of section 19 of this Law;
p.000828: 'Enterprise' means any natural or legal person carrying on an economic activity, irrespective of
p.000828: its legal form, including its own companies or companies
p.000829: 829
p.000829: associations regularly engaged in economic activity;
p.000829: "Supervisory authority" means the Commissioner, who is appointed pursuant to the provisions of section 19 of this Law,
p.000829: application of the provisions of Rule 51 of the Rules of Procedure;
p.000829: "Regulation" means the European Union act entitled "Regulation (EU) No. Of 2016/679
p.000829: European Parliament and of the Council of 27 April 2016 on the protection of individuals
p.000829: against the processing of personal data and for the free movement of data
p.000829: and repealing Directive 95/46 / EC (General Data Protection Regulation) ";
p.000829: Official
p.000829: EU Journal: L.218, 13.8.2008,
p.000829: p.
p.000829: "Regulation (EC) No 765/2008" means the European Union Act entitled
p.000829: "Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 laying down detailed rules for the
p.000829: accreditation and market surveillance requirements for and marketing of products
p.000829: Regulation (EEC) No. Council Regulation (EC) No 339/93 ";
p.000829: 156 (I) of 2002
p.000829: 10 (I) of 2010
p.000829: 57 (I) of 2011
p.000829: 69 (I) of 2012
p.000829: 120 (I) of 2012.
p.000829: "Cyprus Quality Promotion Organization" means the Cyprus Quality Promotion Organization, designated as
p.000829: the national accreditation body under its Accreditation, Standardization and Technical Provisions
p.000829: Law Information;
p.000829: Official
p.000829: EU Journal: 241,
p.000829: 17.9.2015, p
p.000829: "Directive (EU) 2015/1535" means the European Union act entitled "Directive (EU) 2015/1535"
p.000829: European Parliament and Council of 9 September 2015 establishing an information procedure
p.000829: in the field of technical specifications and rules on information society services (codified
p.000829: text)"·
p.000829: "Business group" means a controlling undertaking and the undertakings controlled by it;
p.000829: "Personal data breach" means the breach of security that results in accidental or
p.000829: unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data
p.000829: characters that were transmitted, stored or otherwise processed;
p.000829: "Consent" of the data subject means any indication of will, free, specific, explicit and
p.000829: fully aware, with which the data subject demonstrates agreement, statement or clear affirmation
p.000829: action to process personal data relating to it;
p.000829: 'Filing system' means any structured set of personal data which
p.000829: are accessible on the basis of specific criteria, whether aggregated or decentralized
p.000829: either distributed on a functional or geographical basis;
p.000829: 'Controller' means the natural or legal person, public authority, agency or other entity which, alone or
p.000829: together with others, determine the purpose and manner of processing personal data ∙
p.000829: where the purposes and manner of such processing are determined by Union or Republic law, the person responsible shall
p.000829: processing or the specific criteria for his appointment may be provided for by Union law or
p.000829: the law of the Republic;
p.000829: 'Information society service' means a service within the meaning of Article 1 (1)
p.000829: point (b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;
p.000829: "Minister" means the Minister of Justice and Public Order.
p.000829: (2) Any terms contained in this Law and not specifically defined herein shall have the meaning assigned thereto.
p.000829: in these terms by the Rules of Procedure.
p.000829: Field of application.
p.000829: 3. The provisions of this Law shall apply to the Republic in accordance with the provisions of Articles 2 and 3 thereof
p.000829: Regulation.
p.000829: Competent authority. 4. Competent authority for the application of the provisions of the Rules of Procedure and this Law to
p.000829: Democracy is the Minister of Justice and Public Order.
p.000830: 830
p.000830: PART II
p.000830: LEGALITY OF CERTAIN PROCESSING ACTS
p.000830: Editing data from
p.000830: courts and the House of Representatives
p.000830: Representatives.
p.000830: 5. Without prejudice to the provisions of Rule 6 (e) (6),
p.000830: personal data is allowed and legal when it is performed-
p.000830: (a) By the courts within their jurisdiction for the purposes of its award
p.000830: justice, including the processing of personal data necessary for the purpose of publication
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
...
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
...
Social / employees
Searching for indicator employees:
(return to top)
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
p.000834: (d) upon expiry of his term of office, he shall refrain from any act incompatible with them
p.000834: its powers, duties and powers and does not carry out any incompatible profession, profitable or not,
p.000834: for a period of two (2) years.
p.000834: (3) Where the Commissioner, in breach of the provisions of the Rules of Procedure and this Law,
p.000834: any manner of personal information or data that is accessible to him because of his location; or
p.000834: allows another person to know about them, commits an offense and, if convicted, is subject to a penalty
p.000834: to imprisonment not exceeding three (3) years or to a fine not exceeding thirty thousand euros
p.000834: (€ 30,000) or both.
p.000834: Office
p.000834: Commissioner.
p.000834: 22. The Commissioner holds an office which may be staffed by permanent, temporary or indefinite-term public servants.
p.000834: employees:
p.000834: Provided that the Commissioner participates in the selection process of his Office staff and the staff is administered
p.000834: exclusively by him:
p.000834: It is further understood that the staff of the Office of the Commissioner are responsible for maintaining confidentiality or confidentiality.
p.000834: even after the end of their service.
p.000834: Duties and powers of the Commissioner.
p.000834: 23 .- (1) The Commissioner shall perform the tasks assigned to him and shall exercise the powers conferred on him by the Commission.
p.000834: of the Rules of Procedure, this Law and any other law.
p.000835: 835
p.000835: (2) The Commissioner, without prejudice to the principle of hierarchy, may authorize in writing any of his officers.
p.000835: An office which he holds responsible as he exercises such duties and powers
p.000835: subject to the conditions, exceptions and reservations, which the Commissioner shall specify in its delegation.
p.000835: (3) The Commissioner may, at his discretion, make a case concerning the execution of the
p.000835: of his duties or in the exercise of his powers:
p.000835: Provided that, if the case concerns cross-border treatment, the Commissioner shall consult his intention to
p.000835: make a case under the provisions of this subparagraph with the lead supervisory authority and
p.000835: supervisory authorities concerned.
p.000835: (4) The Commissioner has no jurisdiction to review processing acts performed by the courts of the Republic
p.000835: within their jurisdiction.
p.000835: Additional tasks
p.000835: Commissioner.
p.000835: 24. Subject to the provisions of Rule 57 of the Rules of Procedure and in addition to the duties which
p.000835: as provided in this Article, the Commissioner shall perform the following tasks:
p.000835: (a) It may publish, on the Office's website, how to file complaints; and
...
p.000836: Law;
p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
...
Social / philosophical differences/differences of opinion
Searching for indicator opinion:
(return to top)
p.000832: Rule 37 acts.
p.000832: (3) The Commissioner may publish on his office's website a list of controllers
p.000832: and perform the processing they have designated data protection officer and data
p.000832: contact, if the controller and the processor wish to be included in the
p.000832: list it.
p.000832: Obligation of the Data Protection Officer
p.000832: for compliance
p.000832: of privacy or of
p.000832: confidentiality.
p.000832: 15 .- (1) Subject to the provisions of any law regulating matters of professional secrecy or
p.000832: In the performance of his duties, the Data Protection Officer is bound by the obligation
p.000832: privacy or confidentiality.
p.000832: (2) Data protection officer's confidentiality or confidentiality,
p.000832: affects the provisions of Rule 58 (1) and Rule (a) and (b) thereof
p.000832: section 25 of this Act the powers of control of the Commissioner.
p.000832: PART VI
p.000832: ACCREDITATION ACCREDITATION BODY
p.000832: Accreditation of certification bodies.
p.000832: 16 .- (1) Subject to Rule 43 of the Rules of Procedure, accreditation bodies shall be accredited.
p.000832: by the Cyprus Quality Promotion Organization.
p.000832: (2) Submitted to the Cyprus Quality Promotion Organization for accreditation of a certification body.
p.000832: the positive opinion of the Commissioner, that the applicant for certification of body fulfills the provisions of points (a), (b), and (e) of
p.000832: Rule 43 (2).
p.000832: (3) The Cyprus Quality Promotion Agency shall revoke accreditation of accreditation body if
p.000832: certification requirements are no longer fulfilled or are not fulfilled or if the actions of the certification body
p.000832: violate the provisions of the Rules of Procedure or this Law.
p.000832: (4) The Commissioner may request the Cyprus Quality Promotion Organization to revoke it
p.000832: accreditation of a certification body if the Commissioner finds that the certification requirements are not met
p.000832: or are no longer fulfilled or if the actions of the certification body are in breach of the provisions of the Regulation or of
p.000832: of this Law.
p.000832: (5) In case the Cyprus Quality Promotion Organization does not revoke the accreditation body
p.000832: certification according to points (3) and (4), the Commissioner complains to the Cyprus Quality Promotion Organization
p.000832: European Commission.
p.000833: 833
p.000833: PART VII
p.000833: TRANSFER OF SPECIAL CATEGORIES OF DATA IN THIRD COUNTRY OR IN INTERNATIONAL ORGANIZATION
p.000833: Transmission of specific categories of personal data on the basis of appropriate guarantees or binding corporate
p.000833: rules.
p.000833: 17 .- (1) Where the controller or performer intends to transmit specific categories of data
p.000833: personal status in a third country or international organization, on the basis of the rules laid down in Rule 46 of the Rules of Procedure
p.000833: appropriate guarantees or on the basis of the binding corporate rules provided for in Rule 47,
p.000833: the controller or processor informs the Commissioner of his intention before transmitting
p.000833: of this data.
...
General/Other / Relationship to Authority
Searching for indicator authority:
(return to top)
p.000828: member for transfers or transfers of personal data to a controller or
p.000828: performing processing in one or more third countries within a group of undertakings or group
p.000828: companies operating a joint economic activity;
p.000828: "Democracy" means the Republic of Cyprus;
p.000828: 'Cross-border processing' means-
p.000828: (a) the processing of personal data carried out in the course of the activities of various parties;
p.000828: establishments in more than one Member State responsible for processing or processing in the Union where
p.000828: the controller or processor is established in more than one Member State, or
p.000828: (b) the processing of personal data carried out in the course of one's activities
p.000828: a single installation controller or processor in the Union but which affects or
p.000828: may substantially affect data subjects in more than one Member State;
p.000828: "International organization" means the organization and its subordinate bodies governed by
p.000828: public international law or any other body established by or on the basis of an agreement between two or
p.000828: more countries;
p.000828: 'Representative' means a natural or legal person established in the Union, designated in writing by the person responsible;
p.000828: processor or performer of the processing under Rule 27 of the Rules of Procedure and represent the person responsible
p.000828: processor or performer of the processing of their respective obligations under the Rules of Procedure and
p.000828: this Law;
p.000828: 'Perform the processing' means the natural or legal person, or a public authority, or service or other body which
p.000828: processes personal data on behalf of the controller;
p.000828: 'Processing' means any operation or series of operations performed with or without the use of automated means;
p.000828: in personal data or in personal data sets, such as collection, h
p.000828: registration, organization, structure, storage, customization or modification, recovery, search
p.000828: information, use, disclosure, dissemination or any other form of distribution, association or combination;
p.000828: restriction, deletion or destruction;
p.000828: 'Commissioner' means the Commissioner for Personal Data Protection who is appointed under
p.000828: provisions of section 19 of this Law;
p.000828: 'Enterprise' means any natural or legal person carrying on an economic activity, irrespective of
p.000828: its legal form, including its own companies or companies
p.000829: 829
p.000829: associations regularly engaged in economic activity;
p.000829: "Supervisory authority" means the Commissioner, who is appointed pursuant to the provisions of section 19 of this Law,
p.000829: application of the provisions of Rule 51 of the Rules of Procedure;
p.000829: "Regulation" means the European Union act entitled "Regulation (EU) No. Of 2016/679
p.000829: European Parliament and of the Council of 27 April 2016 on the protection of individuals
p.000829: against the processing of personal data and for the free movement of data
p.000829: and repealing Directive 95/46 / EC (General Data Protection Regulation) ";
p.000829: Official
p.000829: EU Journal: L.218, 13.8.2008,
p.000829: p.
p.000829: "Regulation (EC) No 765/2008" means the European Union Act entitled
p.000829: "Regulation (EC) No 765/2008 of the European Parliament and of the Council of 9 July 2008 laying down detailed rules for the
p.000829: accreditation and market surveillance requirements for and marketing of products
p.000829: Regulation (EEC) No. Council Regulation (EC) No 339/93 ";
p.000829: 156 (I) of 2002
p.000829: 10 (I) of 2010
p.000829: 57 (I) of 2011
p.000829: 69 (I) of 2012
p.000829: 120 (I) of 2012.
p.000829: "Cyprus Quality Promotion Organization" means the Cyprus Quality Promotion Organization, designated as
p.000829: the national accreditation body under its Accreditation, Standardization and Technical Provisions
p.000829: Law Information;
p.000829: Official
p.000829: EU Journal: 241,
p.000829: 17.9.2015, p
p.000829: "Directive (EU) 2015/1535" means the European Union act entitled "Directive (EU) 2015/1535"
p.000829: European Parliament and Council of 9 September 2015 establishing an information procedure
p.000829: in the field of technical specifications and rules on information society services (codified
p.000829: text)"·
p.000829: "Business group" means a controlling undertaking and the undertakings controlled by it;
p.000829: "Personal data breach" means the breach of security that results in accidental or
p.000829: unlawful destruction, loss, alteration, unauthorized disclosure or access to personal data
p.000829: characters that were transmitted, stored or otherwise processed;
p.000829: "Consent" of the data subject means any indication of will, free, specific, explicit and
p.000829: fully aware, with which the data subject demonstrates agreement, statement or clear affirmation
p.000829: action to process personal data relating to it;
p.000829: 'Filing system' means any structured set of personal data which
p.000829: are accessible on the basis of specific criteria, whether aggregated or decentralized
p.000829: either distributed on a functional or geographical basis;
p.000829: 'Controller' means the natural or legal person, public authority, agency or other entity which, alone or
p.000829: together with others, determine the purpose and manner of processing personal data ∙
p.000829: where the purposes and manner of such processing are determined by Union or Republic law, the person responsible shall
p.000829: processing or the specific criteria for his appointment may be provided for by Union law or
p.000829: the law of the Republic;
p.000829: 'Information society service' means a service within the meaning of Article 1 (1)
p.000829: point (b) of Directive (EU) 2015/1535 of the European Parliament and of the Council;
p.000829: "Minister" means the Minister of Justice and Public Order.
p.000829: (2) Any terms contained in this Law and not specifically defined herein shall have the meaning assigned thereto.
p.000829: in these terms by the Rules of Procedure.
p.000829: Field of application.
p.000829: 3. The provisions of this Law shall apply to the Republic in accordance with the provisions of Articles 2 and 3 thereof
p.000829: Regulation.
p.000829: Competent authority. 4. Competent authority for the application of the provisions of the Rules of Procedure and this Law to
p.000829: Democracy is the Minister of Justice and Public Order.
p.000830: 830
p.000830: PART II
p.000830: LEGALITY OF CERTAIN PROCESSING ACTS
p.000830: Editing data from
p.000830: courts and the House of Representatives
p.000830: Representatives.
p.000830: 5. Without prejudice to the provisions of Rule 6 (e) (6),
p.000830: personal data is allowed and legal when it is performed-
p.000830: (a) By the courts within their jurisdiction for the purposes of its award
p.000830: justice, including the processing of personal data necessary for the purpose of publication
p.000830: or of any court ruling, and
p.000830: (b) by the House of Representatives within its powers.
p.000830: Publication or judgment of a court.
p.000830: 6. The processing of the specific categories of personal data provided for in Rule 9 of the Regulation
p.000830: is permitted and legal when made for the purpose of publishing or issuing a decision
p.000830: any court or when necessary for the purposes of the administration of justice.
p.000830: Processing based on the decision of the Council of Ministers.
p.000830: 7. The processing of personal data entrusted by the Council of Ministers to
p.000830: a public authority or body for the performance of a duty performed in the public interest or for the performance of a public interest
p.000830: power is carried out legally and legally in a clear, precise and transparent manner with respect to the subject
p.000830: data, in accordance with the provisions of point (a) of paragraph (1) of Article 5, and
p.000830: point (e) of Rule 6 (1).
p.000830: Special offer
p.000830: community services
p.000830: of information to a child.
p.000830: 8 .- (1) Where the provision of information society services directly to a child is based on
p.000830: consent of the child the processing of personal data is legal if the child is at least
p.000830: fourteen (14) years.
p.000830: (2) For a child under the age of fourteen (14), the treatment referred to in subsection (1)
p.000830: personal data is lawful with the consent provided or approved by
p.000830: person who has parental responsibility for the child.
p.000830: Processing of genetic and biometric data.
p.000830: 9 .- (1) The processing of genetic and biometric data for health and life insurance purposes is prohibited.
p.000830: (2) Without prejudice to Rule 5 (b) (1), when processing
p.000830: genetic and biometric data is based on the data subject's consent for further
...
p.000832: or are no longer fulfilled or if the actions of the certification body are in breach of the provisions of the Regulation or of
p.000832: of this Law.
p.000832: (5) In case the Cyprus Quality Promotion Organization does not revoke the accreditation body
p.000832: certification according to points (3) and (4), the Commissioner complains to the Cyprus Quality Promotion Organization
p.000832: European Commission.
p.000833: 833
p.000833: PART VII
p.000833: TRANSFER OF SPECIAL CATEGORIES OF DATA IN THIRD COUNTRY OR IN INTERNATIONAL ORGANIZATION
p.000833: Transmission of specific categories of personal data on the basis of appropriate guarantees or binding corporate
p.000833: rules.
p.000833: 17 .- (1) Where the controller or performer intends to transmit specific categories of data
p.000833: personal status in a third country or international organization, on the basis of the rules laid down in Rule 46 of the Rules of Procedure
p.000833: appropriate guarantees or on the basis of the binding corporate rules provided for in Rule 47,
p.000833: the controller or processor informs the Commissioner of his intention before transmitting
p.000833: of this data.
p.000833: (2) Without prejudice to Rule 46 and 47 of the Rules of Procedure, the Commissioner may, for serious reasons,
p.000833: in the public interest, to impose on the controller or the controller explicit
p.000833: restrictions on the transmission of specific categories of personal data referred to in (1).
p.000833: (3) Where appropriate guarantees or binding corporate rules referred to in
p.000833: subparagraph (1) were approved by the European Commission or within the framework of Article 63 thereof
p.000833: The Commissioner shall consult the aforementioned entities referred to in paragraph (2)
p.000833: limitations, where appropriate, with the Commission, the Council, the lead authority and other authorities concerned,
p.000833: before imposing them.
p.000833: Transmission of specific categories of personal data on the basis of derogations for special situations.
p.000833: 18 .- (1) The transmission of specific categories of personal data to a third country or to an international organization which
p.000833: is performed by the controller or the processor on the basis of the requirements of
p.000833: Article 49 of the Derogation Regulation for special situations requires an impact assessment to be carried out and
p.000833: prior consultation with the Commissioner.
p.000833: (2) The impact assessment referred to in paragraph (1) shall include those provided for in paragraph (7) of the
p.000833: Rule 35 information, and, where appropriate, a description of those provided for in the Articles
p.000833: 24, 25, 28 and 32 of the Regulation on technical and organizational security measures.
p.000833: (3) Without prejudice to Rule 49 of the Rules of Procedure, the Commissioner may, for serious public reasons,
p.000833: interest, to impose on the controller or processor explicit restrictions on
p.000833: transmission of those referred to in subparagraph
p.000833: (1) Specific categories of personal data.
p.000833: PART VIII
p.000833: PERSONAL DATA PROTECTION COMMITTEE
p.000833: His appointment, qualifications and term of office
p.000833: Commissioner.
p.000833: 19 .- (1) The Personal Data Protection Commissioner is appointed by the Council of Ministers, after
p.000833: recommendation of the Minister.
p.000833: (2) A person who is qualified to be a High Court Judge shall be appointed as a Commissioner.
p.000833: (3) The term of office of the Commissioner shall be six (6) years and may be renewed for a further
p.000833: service.
p.000833: (4) Subject to the provisions of Rule 53 (4) and Rule 20 thereof
p.000833: of this Act, the Commissioner may not be dismissed during his / her term of office only for reasons
p.000833: mental or physical disability or disability that render him unable to perform his duties.
p.000834: 834
p.000834: (5) The Commissioner is designated as a supervisory authority for the purposes of the Rules of Procedure and is responsible for monitoring the
p.000834: implementation of the provisions of the Rules of Procedure and this Law in the Republic and other regulations which
p.000834: relate to the processing of personal data.
p.000834: Deduction from office
p.000834: of the Commissioner.
p.000834: 20 .- (1) The Commissioner shall be removed from office if, during his term of office: -
p.000834: (a) Perform an act incompatible with his duties or carry on any profession incompatible
p.000834: to his property, whether it is profitable or not, or,
p.000834: (b) convicted of the offense provided for in subsection (3) of section 21 of this Law.
p.000834: (2) The Council of Ministers shall publish its notification in accordance with the provisions of subsection (1).
p.000834: from the office of Commissioner, as well as the date of its entry into force, in its Official Journal
p.000834: Republic.
p.000834: Obligations and rights of the Commissioner.
p.000834: 21 .- (1) The Commissioner shall be paid compensation, the amount of which shall be fixed by the Council of Ministers.
p.000834: (2) The Commissioner-
p.000834: (a) In exercising his powers, duties and powers, he obeys his conscience and
p.000834: provisions of the Rules of Procedure and this Law,
p.000834: (b) during his term of office and upon termination, shall be bound by his or her confidentiality;
p.000834: confidentiality.
p.000834: (c) may testify before any court or witness
p.000834: data concerning the application of the provisions of the Rules of Procedure and this Law, as well as others
p.000834: settings concerning the processing of personal data,
p.000834: (d) upon expiry of his term of office, he shall refrain from any act incompatible with them
p.000834: its powers, duties and powers and does not carry out any incompatible profession, profitable or not,
...
p.000834: allows another person to know about them, commits an offense and, if convicted, is subject to a penalty
p.000834: to imprisonment not exceeding three (3) years or to a fine not exceeding thirty thousand euros
p.000834: (€ 30,000) or both.
p.000834: Office
p.000834: Commissioner.
p.000834: 22. The Commissioner holds an office which may be staffed by permanent, temporary or indefinite-term public servants.
p.000834: employees:
p.000834: Provided that the Commissioner participates in the selection process of his Office staff and the staff is administered
p.000834: exclusively by him:
p.000834: It is further understood that the staff of the Office of the Commissioner are responsible for maintaining confidentiality or confidentiality.
p.000834: even after the end of their service.
p.000834: Duties and powers of the Commissioner.
p.000834: 23 .- (1) The Commissioner shall perform the tasks assigned to him and shall exercise the powers conferred on him by the Commission.
p.000834: of the Rules of Procedure, this Law and any other law.
p.000835: 835
p.000835: (2) The Commissioner, without prejudice to the principle of hierarchy, may authorize in writing any of his officers.
p.000835: An office which he holds responsible as he exercises such duties and powers
p.000835: subject to the conditions, exceptions and reservations, which the Commissioner shall specify in its delegation.
p.000835: (3) The Commissioner may, at his discretion, make a case concerning the execution of the
p.000835: of his duties or in the exercise of his powers:
p.000835: Provided that, if the case concerns cross-border treatment, the Commissioner shall consult his intention to
p.000835: make a case under the provisions of this subparagraph with the lead supervisory authority and
p.000835: supervisory authorities concerned.
p.000835: (4) The Commissioner has no jurisdiction to review processing acts performed by the courts of the Republic
p.000835: within their jurisdiction.
p.000835: Additional tasks
p.000835: Commissioner.
p.000835: 24. Subject to the provisions of Rule 57 of the Rules of Procedure and in addition to the duties which
p.000835: as provided in this Article, the Commissioner shall perform the following tasks:
p.000835: (a) It may publish, on the Office's website, how to file complaints; and
p.000835: applications;
p.000835: (b) consider a complaint and, where possible, depending on the nature and type of complaint;
p.000835: inform the complainant in writing of its progress and outcome within thirty (30) days of its submission
p.000835: Complaint:
p.000835: Provided that, where the complaint is found to be unfounded or does not fall within its remit
p.000835: Commissioner, he shall notify the complainant in writing within thirty (30) days of the submission of the complaint;
p.000835: (c) inform, where appropriate, the data subject, the controller where appropriate;
p.000835: and the executor for the time limits provided for in Rules 60 to 66 of the Rules of Procedure;
p.000835: (d) may not consider or terminate a complaint for reasons of public interest and shall notify it
p.000835: the data subject, within a reasonable time, the reasons for not examining or for
p.000835: interruption of the examination of the complaint;
p.000835: (e) may draw up and make public the list of processing operations and cases which
p.000835: require the designation of a data protection officer in accordance with the provisions of Article 14 hereof
p.000835: Law; and
p.000835: (f) may publish on its Office's website the list of controllers; and
...
p.000836: (f) report the Cyprus Quality Promotion Organization to the European Commission if
p.000836: Cyprus Quality Promotion Organization does not revoke accreditation body accreditation according to
p.000836: paragraphs (3) and (4) of article 16 of this Law;
p.000836: (g) in addition to the authorizations provided for in Article 58 (3) of the Rules of Procedure
p.000836: and advisory powers-
p.000836: (i) allow the combination of filing systems as provided for in section 10 of this Law, and
p.000836: imposes terms and conditions for its implementation,
p.000836: (ii) impose terms and conditions on the application of the measures provided for in section 11 of this Law.
p.000836: restriction of rights,
p.000836: (iii) impose terms and conditions on the discharge provided for in section 12 of this Law
p.000836: infringement notice,
p.000836: (iv) impose explicit restrictions on the transmission of Articles 17 and 18 of the Convention;
p.000836: this Law specific categories of personal data, and
p.000836: (v) to recommend to the Minister the conclusion of agreements with other countries and to conclude, draft and
p.000836: signs the memorandums of understanding provided for in section 35 of this Law;
p.000836: (h) in accordance with the provisions of Rule 58 (5) of the Rules of Procedure, to notify
p.000836: Attorney General of the Republic and / or the Police of any violation of his / her provisions
p.000836: Regulation or this Law, which may constitute a criminal offense under the provisions of this article
p.000836: 33 of this Law; and
p.000837: 837
p.000837: (i) to delegate the powers provided for in section 27 of this Law to its members or employees;
p.000837: a seconding supervisory authority involved in joint operations in the Republic.
p.000837: Annual Report of the Commissioner.
p.000837: 26. The Commissioner submits an annual activity report to the President of the Republic and to the President of the House of Representatives.
p.000837: Representatives, which is published by posting on the website of his Office.
p.000837: Joint ventures.
p.000837: 27 .- (1) Subject to the provisions of Rule 62 of the Rules of Procedure, the Commissioner may participate in joint operations
p.000837: with supervisory authorities of other Member States.
p.000837: (2) When a Joint Undertaking is held in the Republic, the Commissioner may delegate powers, including
p.000837: powers of inquiry, to members or officials of the seconding supervisory authority participating in the joint
p.000837: business.
p.000837: Resort
p.000837: against decisions of the Commissioner.
p.000837: 28. Every natural or legal person has the right to appeal against a decision of the Commissioner before him
p.000837: Administrative Court.
p.000837: PART IX
p.000837: SPECIAL CASES OF PERSONAL DATA PROCESSING
p.000837: Processing and freedom of expression and information.
p.000837: 39 of 1962.
p.000837: 29 .- (1) The processing of personal data or special categories of personal data or
p.000837: personal data relating to criminal convictions and offenses committed for
p.000837: for journalistic or academic purposes or for the purposes of artistic or literary expression is lawful, provided that
p.000837: these objectives are commensurate with the objective pursued and respect the essence of rights such as these.
p.000837: are set out in the Charter of Fundamental Rights of the European Union in the European Convention on Human Rights
p.000837: Rights and Fundamental Freedoms (ECHR), ratified by the European Convention on Human Rights
p.000837: the protection of Human Rights (Ratification) Law, and in Part II of the Constitution.
p.000837: (2) The provisions of Rules 14 and 15 of the Rules of Procedure shall apply insofar as they do not affect it
p.000837: the right to freedom of expression and information and journalistic confidentiality.
p.000837: Editing and public access to official documents.
p.000837: 184 (I) of 2017.
p.000837: 30. Personal data in official documents held by a public authority or body for fulfillment
p.000837: a duty performed in the public interest shall be disclosed, in accordance with its provisions.
p.000837: on the Right of Access to Public Sector Law Documents.
p.000837: Safeguards and derogations regarding processing
p.000837: for purposes of filing in the public interest; or
p.000837: for scientific or historical research purposes or for statistical purposes.
p.000837: 31. Processing performed by the controller or performing the processing for purposes
p.000837: filing for the public interest or for the purposes of scientific or historical research or for statistical purposes
p.000837: excludes the use of personal data for decision making, which produces legal effects
p.000837: against the data subject or affect it significantly in a similar manner.
p.000838: 838
p.000838: PART X
p.000838: ADMINISTRATIVE PENALTIES AND OFFENSES
p.000838: Administrative fines.
p.000838: 32 .- (1) Subject to Rule 83 of the Rules of Procedure, the Commissioner shall impose an administrative fine.
p.000838: (2) In the event of failure to pay the administrative fine referred to in (1), this
p.000838: is collected as a civil debt due to the Republic.
p.000838: (3) Administrative fine imposed on a public authority or public body for activities not related to
p.000838: speculative in nature, may not exceed two hundred thousand euros (€ 200,000).
p.000838: Offenses and penalties.
p.000838: 33.- (1) Commits a criminal offense-
p.000838: (a) The controller or processor who does not keep the record of activities that
p.000838: provided for in Rule 30 of the Rules of Procedure or does not update this file or refuses to place the file in
p.000838: Commissioner at his request or provide the Commissioner with false, inaccurate, incomplete or misleading information
p.000838: about this file,
p.000838: (b) a controller or processor who does not cooperate with the Commissioner, in accordance with
p.000838: by the provisions of Rule 31 of the Rules of Procedure,
p.000838: (c) a controller who does not notify the Commissioner of a breach of personal data
p.000838: in accordance with the provisions of Rule 33 (1),
p.000838: (d) perform the processing which does not promptly inform the controller of
p.000838: violation of personal data in accordance with the provisions of Article 33 (2)
p.000838: Regulation,
p.000838: (e) a controller who does not report a breach of personal data
p.000838: the data subject, in accordance with the provisions of Rule 34 of the Rules of Procedure,
p.000838: (f) a controller who does not conduct an impact assessment in breach of the provisions of paragraph
p.000838: (1) Rule 35 of this Regulation or Rule 13 of this Law,
p.000838: (g) the controller or processor who blocks the data controller from
p.000838: carrying out his duties, in particular those relating to working with the Commissioner,
p.000838: (h) a certification body granting or not withdrawing certification in accordance with Article 42 thereof
p.000838: Regulation,
p.000838: (i) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the provisions of Chapter V of the Rules of Procedure,
p.000838: (j) the controller or processor who transmits personal data to
p.000838: third country or international organization in breach of the restrictions imposed by the Commissioner under the provisions of the Articles
p.000838: 17 or 18 of this Law,
p.000838: (k) a person who unlawfully interferes with any data archiving system
p.000838: personal or knowingly acquiring or removing, altering, damaging, destroying, processing,
p.000838: exploits in any way, transmits, communicates, makes them accessible to unauthorized persons, or
p.000838: allows such persons to access such data, for profit or non-profit purposes,
p.000838: (l) the controller or performer of the processing which prevents or impedes the exercise
p.000838: the powers of the Commissioner provided for in Rule 58 of this Rules of Procedure and Rule 17 of this Law,
p.000839: 839
p.000839: (m) controller or processor who fails to comply with the provisions of the Rules of Procedure
p.000839: and of this Law in carrying out a processing act which is not an offense under
p.000839: the provisions of this Article,
p.000839: (n) a public authority or public body combining large archive systems
p.000839: scale in violation of the provisions of section 10 of this Law.
p.000839: (2) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (a) to (l) of subparagraph (1) shall be subject to a prison sentence not exceeding one year.
p.000839: three (3) years or a fine not exceeding thirty thousand euros (€ 30,000) or both.
p.000839: (3) If a person is convicted of committing any of the offenses which
p.000839: referred to in paragraphs (m) and (n) of subparagraph (1), subject to a prison sentence not exceeding
p.000839: one (1) year or a fine not exceeding ten thousand euros (€ 10,000) or both.
p.000839: (4) Where a person is convicted of committing any of the offenses which
p.000839: refer to paragraphs (g) to (j) of subparagraph (1), which infringes the interests of the Republic or causes
p.000839: danger to the unhindered operation of the Government or threatening national security is subject to a prison sentence which
p.000839: does not exceed five (5) years or a fine not exceeding fifty thousand euros (€ 50,000) or
p.000839: these two sentences.
p.000839: (5) For the purposes of applying the provisions of this Article;
p.000839: (a) If the controller or processor is a business or group of undertakings, legal liability
p.000839: bears the person designated as the supreme executive body or body of the undertaking or group of undertakings,
p.000839: (b) if the controller or processor is a public authority or public body;
p.000839: the head or the person in charge of the effective administration of the public authority or
p.000839: public body.
p.000839: PART XI
p.000839: FINAL PROVISIONS
p.000839: Regulations. 34. The Council of Ministers, on the recommendation of the Commissioner, may
p.000839: to issue Regulations for the effective implementation of the provisions of this Regulation and this Law.
p.000839: International
p.000839: cooperation.
p.000839: 35 .- (1) In the absence of an appropriate legal measure by the Commission binding on the Member States, the Commissioner may
p.000839: Recommends to the Minister the conclusion of agreements with third countries or international organizations to fulfill the objectives
p.000839: referred to in Rule 50 of the Rules of Procedure.
p.000839: (2) The Commissioner may conclude, establish and sign memorandums of understanding with corresponding authorities in other countries.
p.000839: or with international organizations.
p.000839: Abolition of law.
p.000839: 138 (I) of 2001
p.000839: 37 (I) of 2003
p.000839: 105 (I) of 2012.
p.000839: 36. With the entry into force of the provisions of this Law on the Processing of Personal Data
p.000839: Character (Protection of Individuals) Laws 2001 to 2012 are repealed.
p.000840: 840
p.000840: PART XII
p.000840: TRANSITIONAL PROVISIONS
p.000840: Transitional provisions.
p.000840: 37 .- (1) The appointment of the Commissioner made by the Council of Ministers pursuant to Decision no. 79,538,
p.000840: valid for four (4) years, dated 28.9.2015, until the expiry of his / her term of office.
p.000840: (2) Acts adopted by the Commissioner under the provisions of the repeal on Data Processing
p.000840: Personnel (Protection of Person) Law shall remain in force until expiry or replacement.
p.000840: (3) Until the Cyprus Quality Promotion Organization successfully submits its peer review
...
Orphaned Trigger Words
Appendix
Indicator List
Indicator | Vulnerability |
access | Access to Social Goods |
age | Age |
authority | Relationship to Authority |
child | Child |
criminal | criminal |
disability | Mentally Disabled |
employees | employees |
officer | Police Officer |
opinion | philosophical differences/differences of opinion |
police | Police Officer |
prison | Incarcerated |
property | Property Ownership |
single | Marital Status |
union | Trade Union Membership |
Indicator Peers (Indicators in Same Vulnerability)
Indicator | Peers |
officer | ['police'] |
police | ['officer'] |
Trigger Words
consent
cultural
justice
protection
Applicable Type / Vulnerability / Indicator Overlay for this Input