b) order for the blocking, erasure, destruction or suspension of the unlawful processing of personal data;
c) issue instructions prior to the data processing and
ensure their publication;
2. In cases of recurring or intentional serious infringement of law by a controller or processor, especially in cases
of recurring failure to carry out the Commissioner’s recommendations, he acts in compliance with article 39 herein and
may report the case publicly in accordance with his duties
or report it to the Assembly and the Council of Ministers.
2.1 In case the violation consists in a crime, it makes
the respective report.
Article 31
Responsibilities
1. The Commissioner is in charge of:
a) giving opinions on legal and secondary draft acts related to personal data, as well as projects required to be
implemented by the controller alone or jointly with others;
a/1) giving recommendations for the implementation
of the obligations deriving from the law on protection of
personal data and assures publication thereof;
b) authorizing in special cases the use of personal
data for purposes not designated during the phase of their
collection by observing the principles of article 5 of this law;
c) authorizing the international transfer of personal data
in compliance to article 9 herein;
ç) issuing guidelines that regulate the length of retention
of personal data according to their purpose in the activity of
specific sectors;
d) ensuring the right to information and the exercise of
the right to rectify and update data;
34
dh) authorizing the use of sensitive data in compliance
with Article 7 point 2 letter ‘c’ herein;
e) checking the processing of data in conformity with
the law, ex officio or upon request of a person when such
a processing is exempted of the right to information and to
inform the person that the check is carried out and whether
the process is lawful or not;
ë) addressing of complaints the data subject related to
the protection of his/her rights and freedoms, for processing
of personal data and informing him/her on the settlement of
the complaint submitted;
f) issuing guidelines on security measures in the activity
of specific sectors,
g) overseeing the execution of penalties;
gj) encourage the controller to draft the of codes of
ethics and their assessment;
h) the publication and explanation of the rights related
to the data protection and the periodic publication of his
activities;
i) cooperating with the supervisory authorities on the
personal data of foreign states regarding the protection of
individuals who reside in those states;
j) representing the supervisory authority in the field of
personal data protection in the national and international
events;
k) exercising other legal obligations.
2. The Commissioner shall create a register to document
all notifications and authorizations that he performs in
exercise of his powers in the field of personal data protection.
3. The Commissioner shall submit an annual report to
the Assembly and reports in front of the Assembly when
asked to do so. In addition he may ask to the Assembly to
be heard for issues that he deems to be important.
35