13
Mandatory notification of processing that is particularly sensitive as regards integrity
Section 41
The Government may issue regulations providing that such processing of personal data as
involves particular risks for improper intrusion of personal integrity shall be notified for
preliminary examination, three weeks in advance, to the supervisory authority in accordance
with Section 36. If the Government has issued such regulations, the exemption from the
obligation to give notification under Section 37 does not apply.
Information to the public about processing that has not been notified
Section 42
The controller of personal data shall, to everybody who requests it, expeditiously and in an
appropriate manner provide information about such automated or other processing of personal
data that have not been notified to the supervisory authority. The information shall comprise
that which a notification under Section 36, first paragraph, would have comprised. However,
the controller of personal data is not responsible to provide information subject to secrecy or
information about which security measures have been taken. In that connection, a controller of
personal data who is not an authority may, in a case corresponding to those referred to in the
Secrecy Act (1980:100), refuse to provide information.
The powers of the supervisory authority
Section 43
The supervisory authority is entitled for its supervision to obtain on request
a) access to the personal data that is processed,
b) information about and documentation of the processing of personal data and security of
this processing, and
c) access to those premises linked to the processing of personal data.
Section 44
If the supervisory authority cannot, pursuant to a request under Section 43, obtain sufficient
information in order to conclude that the processing of personal data is lawful, the authority
may prohibit, subject to a default fine, the controller of personal data to process personal data
in any other manner than by storing them.
Section 45
If the supervisory authority concludes that personal data is processed or may be processed in
an unlawful manner, the authority shall by a reminder or similar procedure endeavour to attain
rectification. If it is not possible to obtain rectification in any other manner or if the matter is
urgent, the authority may prohibit, subject to a default fine, the controller of personal data to
continue processing the personal data in any other manner than by storing them.
If the controller of personal data does not voluntary comply with the decision concerning
security measures under Section 32 that has entered into final legal force, the supervisory
authority may prescribe a default fine.