b) order for the blocking, erasure, destruction or suspension of the unlawful processing of personal data; c) issue instructions prior to the data processing and ensure their publication; 2. In cases of recurring or intentional serious infringement of law by a controller or processor, especially in cases of recurring failure to carry out the Commissioner’s recommendations, he acts in compliance with article 39 herein and may report the case publicly in accordance with his duties or report it to the Assembly and the Council of Ministers. 2.1 In case the violation consists in a crime, it makes the respective report. Article 31 Responsibilities 1. The Commissioner is in charge of: a) giving opinions on legal and secondary draft acts related to personal data, as well as projects required to be implemented by the controller alone or jointly with others; a/1) giving recommendations for the implementation of the obligations deriving from the law on protection of personal data and assures publication thereof; b) authorizing in special cases the use of personal data for purposes not designated during the phase of their collection by observing the principles of article 5 of this law; c) authorizing the international transfer of personal data in compliance to article 9 herein; ç) issuing guidelines that regulate the length of retention of personal data according to their purpose in the activity of specific sectors; d) ensuring the right to information and the exercise of the right to rectify and update data; 34 dh) authorizing the use of sensitive data in compliance with Article 7 point 2 letter ‘c’ herein; e) checking the processing of data in conformity with the law, ex officio or upon request of a person when such a processing is exempted of the right to information and to inform the person that the check is carried out and whether the process is lawful or not; ë) addressing of complaints the data subject related to the protection of his/her rights and freedoms, for processing of personal data and informing him/her on the settlement of the complaint submitted; f) issuing guidelines on security measures in the activity of specific sectors, g) overseeing the execution of penalties; gj) encourage the controller to draft the of codes of ethics and their assessment; h) the publication and explanation of the rights related to the data protection and the periodic publication of his activities; i) cooperating with the supervisory authorities on the personal data of foreign states regarding the protection of individuals who reside in those states; j) representing the supervisory authority in the field of personal data protection in the national and international events; k) exercising other legal obligations. 2. The Commissioner shall create a register to document all notifications and authorizations that he performs in exercise of his powers in the field of personal data protection. 3. The Commissioner shall submit an annual report to the Assembly and reports in front of the Assembly when asked to do so. In addition he may ask to the Assembly to be heard for issues that he deems to be important. 35

Select target paragraph3