2 - Any attempt to commit the administrative offences provided for in Articles 37 and 38
shall always be liable to punishment.
1 – The chairman of the CNPD is responsible for the application of the fines provided for
in this Act, subject to prior deliberation by the Commission.
2 – After being approved by the chairman the deliberation of the CNPD shall be
enforceable if it is not challenged within the statutory period.
The sums collected as a result of the application of fines shall be divided equally between
the State and the CNPD.
(a) omits notification or the application for authorisation referred to in Articles 27 and 28;
(b) provides false information in the notification or in applications for authorisation for
the processing of personal data or makes alterations in the latter which are not permitted
by the legalisation instrument;
(c) misappropriates or uses personal data in a form incompatible with the purpose of the
collection or with the legalisation instrument;
(d) promotes or carries out an illegal combination of personal data;
(e) fails to comply with the obligations provided for in this Act or in other data protection
legislation when the time limit fixed by the CNPD for complying with them has expired;
(f) continues to allow access to open data transmission networks to controllers who fail to
comply with the provisions of this Act after notification by the CNPD not to do so,
shall be liable to up to one year’s imprisonment or a fine of up to 120 days.
2 – The penalty shall be increased to double the maxima in the case of the personal data
referred to in Articles 7 and 8.
1 – Any person who without due authorisation gains access by any means to personal data
prohibited to him shall be liable to up to one year’s imprisonment or a fine of up to 120
days.
(a) is achieved by means of violating technical security rules;
(b) allows the agent or third parties to obtain knowledge of the personal data;
(c) provides the agent or third parties with a benefit or material advantage.
3 – In the case of 1 criminal proceedings are dependent upon a complaint.
1 – Any person who without due authorisation erases, destroys, damages, deletes or
changes personal data, making them unusable or affecting their capacity for use, shall be
liable to up to two years’ imprisonment or a fine of up to 240 days.
18/20