a) At the proposal of the NSAPDP control departments;
b) At the proposal of the NSAPDP president or vice-president through a written
resolution;
c) At the proposal of other departments within the NSAPDP;
d) Following the transmission of personal data breach notifications;
e) For the verification of data and information regarding the processing of personal
data, obtained by the NSAPDP from sources other than the ones that are the
subject of a complaint, including those based on notifications or information
received from another supervisory authority or from another public authority;
f) For international cooperation, as well as for cooperation with the other supervisory authorities in the Member States, in the field of personal data protection,
including in the framework of joint operations and mutual assistance.
What is interesting is that when you file a personal data privacy violation
notification to an authority (because you have a legal obligation to do it in certain
cases), the authority may use the information you send to initiate an investigation
against you. In fact, in some situations, it would be the equivalent of a selfdenouncement.
Is the investigation limited to a complaint/ex officio? The answer to this question
is no. The NSAPDP may initiate an investigation based on clues/complaints, but it
may verify any other aspect related to personal data protection. This means that even
if the subject of the complaint is unfounded, they may find other irregularities to
sanction companies.
In field investigations, the NSAPDP control staff carries out the following
activities: going to the headquarters/domicile/office or other locations where the
audited entity operates; presenting the badge and power of attorney, according to the
situation, to the representatives of the audited entity who will ensure the involvement
of the persons who are to provide relevant information about the controlled field. The
persons designated by the controlled entity/The Data Protection Officer take(s) part
in the carrying out of the control, by providing the information and documents
requested by the control team, and they sign the resulting control papers; in the cases
provided by the law, presenting the legal authorization issued by the President of the
Bucharest Court of Appeal or by a judge delegated by it; requesting the registration
of the travel order and of the power of attorney, if applicable; entering the data
provided in art. 3 par. (2) of the Law no. 252/2003
10 on program counters into the
program counter of the audited entity, if applicable; presenting the objectives of the
investigation; verifying all aspects related to the subject of the investigation by
requesting any information related to the control objectives; verifying any document,
equipment or data storage medium necessary to carry out the investigation; removing the documents, in a certified copy made by the controlled entity, or the relevant
documentation related to the aim of the control and attaching them to the verification/sanctioning report; drawing up the verification/sanctioning report, by
10 See Law no. 252 of 10 June 2003 on the Single Control Register Published in the Official Gazette
no 429 from 18 June 2003.
290
E. Lazar and D. N. Costescu
Précédent

- 293/540

Suivant