3382
GOVERNMENT GAZETTE
individuals with regard to the processing of personal data,
including on the basis of information received from another
public authority,
(i) monitor relevant developments, insofar as they
have an impact on the protection of personal data, in
particular developments in information and communication
technologies and commercial practices,
(j) contribute to the activities of the EDPB.
2. In exercising its powers, the Authority shall file without
further action any requests, questions or complaints which
are manifestly vague, unfounded or understated, or are
submitted abusively or anonymously. The Authority shall
inform the data subjects and the applicants of its actions.
Without prejudice to the time limits set out in the GDPR, the
priority for examining requests, questions and complaints
shall be assessed by the Authority on the basis of the
relevance and general interest of the matter.
Article 14
Activity report
The Authority shall draw up each year a report on the
performance of its tasks during the previous calendar
year. The report shall be submitted by the President of the
Authority to the President of the Parliament and the Prime
Minister, and shall be published in the Government Gazette
under the responsibility of the Authority, which may give
further publicity to the report.
Article 15
Investigative and corrective powers
1. In addition to the powers laid down in Article 58 of the
GDPR, the Authority shall conduct, ex officio or following
a complaint, investigations and audits relating to the
compliance with this Law during which the technological
infrastructure and other automated or non-automated
means supporting the processing of personal data are
subject to controls. In carrying out such investigations and
inspections, the Authority shall have the power to obtain,
from the controller and the processor, access to all personal
data processed and to all information necessary for the
purposes of such audits and the performance of its tasks,
and no type of confidentiality may be relied upon against it.
The Authority shall, by way of exception, not have access
to data identifying associates or staff employed in entities
contained in records held for national security purposes or
for the purpose of investigating particularly serious crimes.
2. The audits shall be carried out by a member or
members of the Authority, or employees of the Secretariat's
department of scientific staff who are specially authorised
to that effect by the President of the Authority. The
President and the members of the Authority, as well as the
Secretariat’s specially mandated officials shall be deemed
as special investigating officers having all the rights
provided for in the Code of Criminal Procedure. They shall
be entitled to carry out a preliminary investigation, even
without an order by the Public Prosecutor, in case of an act
caught in flagrante delicto, or a misdemeanor, or if there is
a risk as a result of any delay. The public authorities shall
assist the Authority in carrying out the audit.
3. The President of the Authority may grant the power
A’ 137/29.08.2019
to carry out audits to members and staff of a supervisory
authority of another Member State of the European Union
(‘seconding supervisory authority’) in the framework of joint
operations carried out under Article 62 of the GDPR and
Article 79 of this Law.
4. The Authority shall, for the purposes of this Law:
(a) issue warnings to a controller or processor that
intended processing operations are likely to infringe
provisions of this Law;
(b) order the controller or processor to comply with the
provisions of this Law in a specified manner and within a
specified period, in particular by ordering the rectification or
erasure of personal data;
(c) order and impose a temporary or definitive limitation,
or even a ban on the processing of personal data;
(d) order and impose that documents, filing systems,
equipment or means for processing personal data be
delivered to it, as well as their content in the case provided
for in subparagraph (c) of this paragraph;
(e) seize documents, information, filing systems for each
piece of equipment and means of personal data breach,
and their content which becomes known to the Authority
in the exercise of its supervisory powers. The Authority
shall be the sequestrator of the above material until a
decision has been reached by the competent judicial and
prosecutorial authorities.
5. In addition to the corrective powers provided for in
Article 58(2) of the GDPR, the Authority shall order the
controller or processor, or a recipient, or a third party, to
discontinue the processing of personal data or to return or
lock (block) the relevant data or to destroy the filing system
or the relevant data.
6. The Authority shall impose the administrative penalties
provided for in Article 83 of the GDPR and Article 39 hereof.
7. The Authority shall impose the administrative penalties
provided for in Article 82.
8. Where the protection of the individual against the
processing of personal data concerning him or her requires
immediate decision-making, the President may, at the
request of the person concerned or ex officio, issue a
temporary order for immediate temporary limitation, in
whole or in part, of the processing or the operation of the
file. The order shall apply until the Authority reaches its final
decision.
9. In order to ensure compliance with the provisions of
the GDPR, this Law and other regulations relating to the
protection of the data subject with regard to the processing
of personal data, the Authority, without prejudice to Chapter
VII of the GDPR, shall adopt administrative regulatory acts
to regulate specific, technical and detailed matters referred
to in those acts.
10. The regulatory acts of the Authority, which shall not
be published in the Government Gazette, shall be published
on the Authority’s website.
Article 16
Rights and obligations of the members of the
Authority
1. In performing their tasks, the President and the
members of the Authority shall be subject to their