(a) the controller of the file and his representative, if any; (b) the categories of personal data processed; (c) the purposes of the data and the categories of body to whom they might be disclosed; (d) the form of exercising the right of access and rectification.; (e) any combinations of personal data processing; (f) proposed transfers of data to third countries. 2 – Any change in the information referred to in 1 shall be subject to the procedures provided for in Articles 27 and 28. 1 – When personal data processing is not covered by a legal provision and must be authorised or notified it shall be set down in a CNPD register open to consultation by any person. 2 – The register shall contain the information listed in Article 29 (a) to (d) and (i). 3 – A controller not subject to notification shall make available at least the information referred to in Article 30 (1) in an appropriate form to any person on request. 4 – This Article does not apply to processing whose sole purpose is the keeping of a register which according to laws or regulations is intended to provide information to the public and which is open to consultation either by the public in general or by any person who can provide proof of a legitimate interest. 5 – All the opinions and authorisations drawn up or granted under this Act, particularly the authorisations provided for in Article 7 (2) and Article 9 (2), must be published by the CNPD in its annual report. 1 – The CNPD shall encourage the drawing up of codes of conduct intended to contribute to the proper implementation of the provisions in this Act, taking account of the specific features of the various sectors. 2 – Trade associations and other bodies representing other categories of controllers which have drawn up draft codes of conduct shall be able to submit them to the opinion of the CNPD. 3 – The CNPD may declare whether the drafts are in accordance with the laws and regulations in force in the area of personal data protection. Without prejudice to the right to submit a complaint to the CNPD, according to the law any individual may have recourse to administrative and legal means to guarantee compliance with legal provisions in the area of personal data protection. 16/20

Select target paragraph3