2 - Any attempt to commit the administrative offences provided for in Articles 37 and 38 shall always be liable to punishment. 1 – The chairman of the CNPD is responsible for the application of the fines provided for in this Act, subject to prior deliberation by the Commission. 2 – After being approved by the chairman the deliberation of the CNPD shall be enforceable if it is not challenged within the statutory period. The sums collected as a result of the application of fines shall be divided equally between the State and the CNPD. (a) omits notification or the application for authorisation referred to in Articles 27 and 28; (b) provides false information in the notification or in applications for authorisation for the processing of personal data or makes alterations in the latter which are not permitted by the legalisation instrument; (c) misappropriates or uses personal data in a form incompatible with the purpose of the collection or with the legalisation instrument; (d) promotes or carries out an illegal combination of personal data; (e) fails to comply with the obligations provided for in this Act or in other data protection legislation when the time limit fixed by the CNPD for complying with them has expired; (f) continues to allow access to open data transmission networks to controllers who fail to comply with the provisions of this Act after notification by the CNPD not to do so, shall be liable to up to one year’s imprisonment or a fine of up to 120 days. 2 – The penalty shall be increased to double the maxima in the case of the personal data referred to in Articles 7 and 8. 1 – Any person who without due authorisation gains access by any means to personal data prohibited to him shall be liable to up to one year’s imprisonment or a fine of up to 120 days. (a) is achieved by means of violating technical security rules; (b) allows the agent or third parties to obtain knowledge of the personal data; (c) provides the agent or third parties with a benefit or material advantage. 3 – In the case of 1 criminal proceedings are dependent upon a complaint. 1 – Any person who without due authorisation erases, destroys, damages, deletes or changes personal data, making them unusable or affecting their capacity for use, shall be liable to up to two years’ imprisonment or a fine of up to 240 days. 18/20

Select target paragraph3