Official translation Official translation GOVERNMENT OF THE REPUBLIC OF LITHUANIA Resolution No. 349 REGARDING THE ESTABLISHMENT OF THE STATE REGISTER OF PERSONAL DATA CONTROLLERS AND APPROVAL OF THE REGISTER REGULATIONS 27 March 2000 Vilnius Based on paragraph 3 of Article 5 of the Law of the Republic of Lithuania on Legal Protection of Personal Data (Žin., 1996, No. 63-1479; 1998, No. 31-819) and the Law of the Republic of Lithuania on State Registers (Žin., 1996, No. 86-2043), the Government of the Republic of Lithuania has resolved:
- to establish the State Register of Personal Data Controllers;
- to approve the Regulations of the State Register of Personal Data Controllers (appended). Prime Minister Andrius Kubilius Minister of Public Administration Reforms and Local Government Affairs Jonas Rudalevičius APPROVED by Resolution No. 349 of 27 March 2000 of the Government of the Republic of Lithuania REGULATIONS OF STATE REGISTER OF PERSONAL DATA CONTROLLERS I. GENERAL PROVISIONS
- The Regulations of the State Register of Personal Data Controllers (hereinafter referred to as the Register) shall regulate the purpose and the objects of the Register, also the rights and duties of the agency controlling the Register, and the management, reorganisation and liquidation of the Register.
- The purpose of the Register is to collect, accumulate, process, systematise, store, use and disclose the data of the Register.
- The object of the Register shall be the personal data controllers of the Republic of Lithuania .
- The Register shall be kept in accordance with the Law of the Republic of Lithuania on State Registers (Žin., 1996, No. 86-2043), the Law of the Republic of Lithuania on Legal Protection of Personal Data (Žin., 1996, No. 63-1479), these Regulations and other legal acts regulating the keeping of state registers and management of personal data.
- The Register is not the principal Register of the State and shall be managed with the help of automatic equipment.
- Personal data controllers shall be registered free of charge. II. REGISTER MANAGING AGENCY
- The agency managing the Register shall be the State Data Protection Inspectorate under the Ministry of Public Administration and Local Government Reforms (hereinafter referred to as the Register Agency).
- The Register Agency shall perform the following functions: 8.
- shall collect from the personal data controllers registration data specified in these Regulations; 8.
- shall register personal data controllers and manage the data base of the Register; 8.
- shall ensure correspondence of the data entered in the Register with the data in the submitted documents; 8.
- by making use of the data in the registers of other states, shall check the registration data presented by the personal data controllers; 8.
- shall disclose the Register data to data recipients: legal or natural persons also enterprises without the rights of a legal person; 8.
- shall accumulate, update, amend, or transfer the data of the Register to the Register Data Archives; 8.
- shall guarantee the protection of the Register data base and Register Data Archives; 8.
- shall keep the archives of documents presented for registration, guarantee their protection; 8.
- shall organise technical servicing and maintenance of the Register data base; 8.
- shall organise technical equipment and software modernisation of the Register.
- The employees of the Register Agency who take part in the processing of registration documents must keep the secret of the documents confidential for the time period specified by laws and other legal acts.
- The Register Agency shall have the right to: 10.
- obtain from the personal data controllers registration data required for the Register, manage and disclose the said data; 10.
- demand that personal data controllers correct the false or inaccurate registration data in the manner laid down by these Regulations; 10.
- submit certified Register data excerpts; 10.
- select, according to the procedure laid down in laws and other legal acts, entities responsible for designing, technical servicing and maintenance of the data base.
- The Register Agency shall be responsible for: ] 11.
- correspondence of the Register data in the submitted registration documents; 11.
- protection of the documents submitted by personal data controllers; 11.
- protection of the Register data base; 11.
- ensuring that the Register data base is functional. III. REGISTRATION DATA
- The registration number assigned to the personal data controller upon his registration by the Register Agency shall be the identification code of the personal data controller, comprised of the letter indicating the time period of personal data processing and the sequence of four digits constituting the current number of registration in the Register.
- The registration data shall comprise the following data: 13.
- the identification code of the personal data controller; 13.
- the dates of registration of the personal data controller and his removal from the Register; 13.
- the address of the personal data controller; 13.
- the name or personal name and surname of the personal data controller; 13.
- legal basis of personal data processing (the date, number and title of the legal act/acts authorising the processing of personal data); 13.
- purpose of personal data processing; 13.
- means of personal data processing (automated, non-automated); 13.
- groups of personal data processed by the personal data controller; also the additionally marked groups of special category of personal data; 13.
- sources of personal data; 13.
- the name and surname, workplace and office phone and fax numbers as well as e-mail address of the representative for data protection; 13.
- the list of data processing agencies (processors) operating under the command of the personal data controller; 13.
- entities specified by the personal data controller, which provide information (address, name, telephone number/numbers) to which the person may apply in order to find out where and according to what procedure he may access his personal data, rectify the data, also restrict or grant the right to disclose his personal data; 13.
- the number and the date of the document establishing the requirements for the data protection means; 13.
- a general description, according to the requirements laid down by the Register Agency, of the security measures taken to protect the data by the personal data controller and every data processing agency (data processor). IV. THE PROCEDURE OF OBJECT REGISTARION
- Registration data shall be submitted to the Register by personal data controllers who, pursuant to the Law of the Republic of Lithuania on Legal Protection of Personal Data, must be registered with the Register Agency.
- The personal data controller shall submit the registration data to the Register Agency, filling out the application wherein the controller shall specify the registration data set forth in subparagraphs 13.3 and 13.4 and the time period of personal data processing, should temporary data processing be envisaged; he shall also submit a copy of the document identified in subparagraph 13.3 or, if there is a common document intended for a group of personal data controllers, give a reference to the said document.
- The Register Agency shall consider the application within 30 calendar days from the receipt thereof, shall check the accuracy of the submitted registration data and the chief executive of the Agency (or the person authorised by him) shall take a decision regarding the registration of the personal data controller. The decision may be appealed in accordance with the procedure established by the laws of the Republic of Lithuania.
- If the registration data submitted by the personal data controller conflict with legitimate data processing or do not meet the general requirements for data protection, the Register Agency shall request updating or supplementing the data. Upon receiving updated information or supplementary documents, the Register Agency shall consider the application within 15 calendar days from the receipt of the updated information or supplementary documents.
- Having considered the application, the Register Agency shall enter the registration data in the Register data base and shall issue the personal data controller’s registration certificate or shall notify the personal data controller in writing of the refusal to register, indicating the reasons for refusal. The certificate of the personal data controller shall be sent to the personal data controller by post (by a registered letter) or shall be issued, upon signature, to the person authorised by the personal data controller - the person responsible for data protection. A copy of the certificate shall be kept at the Register Agency. If the personal data controller indicates that the personal data is processed on a temporary basis, the Register Agency shall issue a temporary registration certificate.
- Upon establishing that false registration data were indicated in the documents submitted for registration, the Register Agency shall forthwith notify the personal data controller thereof and demand the mistake be immediately rectified. Having rectified the mistake the Register Agency shall notify the users of the Register data thereof.
- The personal data controller shall have the right to access, free of charge, the registration data submitted by him and kept in the Register, also to demand the rectification of erroneous or supplementing of incomplete registration data. Having received the personal data controller’s request for the rectification or supplementing of the submitted registration data, the Register Agency must, within 10 calendar days, consider the request and notify the personal data controller in writing of the taken decision.
- In case of changes occurring in the registration data, the personal data controllers must within 15 calendar days submit the changed registration data to the Register Agency. The Register Agency shall expeditiously transfer the changed data to the Register Data Archives.
- If, through the fault of the Register Agency, the registration data entered in the register data base do not correspond with those given in the documents, the Register Agency shall without delay rectify the mistake and notify the users of the Register data thereof.
- The Register Agency shall cancel the registration of the data submitted by the personal data controllers if: 23.
- there are legal grounds to terminate the activities of the personal data controller; 23.
- the registration data of the personal data controller entered in the Register have not been updated for over a 2-year period and the Register Agency has warned the personal data controller thereof. If the personal data controller fails to respond within 30 calendar days, the Register Agency shall cancel the registration.
- In the cases provided for in paragraph 23 the Register Agency shall forthwith remove the registration data from the Register data base and transfer the data to the Register Data Archives. The Register Agency must announce in the media about the cancellation of registration.
- Upon agreement with the Lithuanian Archives Department under the Government of the Republic of Lithuania, the Register Agency shall set the time period for the storing of the Register data and for the keeping of Register Data Archives.
- The registration of the personal data controllers shall be started in the manner laid down in these Regulations after the register becomes legally operational in accordance with the procedure established by the Government of the Republic of Lithuania. The data of registration of the personal data controllers submitted before the Register becomes operational shall be transferred to the Register data base. V. INTERACTION WITH OTHER REGISTERS
- To ensure the functioning of the Register, the following data of other State Registers shall be made use of: 27.
- of the registers for the registration of legal persons - the code, name and address of the legal person or the enterprise without the rights of a legal person; 27.
- of the Population Register - the code, name, surname, residence address of the natural person; 27.
- of the Register of Territorial Administrative Units, Residential Localities and Streets - the name of residential localities, streets; 27.
- of the Register of Laws and other Legal Acts - the number of the legal act, the date of coming into force, the date of invalidation or suspension of validity, the name of the institution which passed the legal act.
- The state registers shall exchange information free of charge, unless otherwise established by other legal acts.
- Wishing to update the registration data, the Register Agency shall have the right, without concluding a contract for the disclosure of data, file individual inquiries with the register management agencies of other states. VI. USE OF REGISTER DATA
- All the data contained in the Register shall be public. The data specified in subparagraphs 13.1-13.12 shall be publicised on the computer network of government institutions and through other means of provision of information to the public. The registration data and documents specified in subparagraphs 13.13 and 13.14 shall be provided free of charge upon the request of public and local authorities. VII. TRANSFER OF THE REGISTER DATA TO DATA RECIPIENTS IN FOREIGN COUNTRIES
- The registration data specified in subparagraphs 13.1.-13.12 as well as consolidated date concerning the personal data protection measures used in the Republic of Lithuania may be transferred by the Register Agency to foreign countries through the international computer network or other means only in the cases provided for by laws, other legal acts of the Republic of Lithuania and legal agreements with foreign states to which the Republic of Lithuania is a party. VIII. PROTECTION OF THE REGISTER DATA
- The protection of the Register data shall be organised by the Register Agency. In order to ensure the protection of the Register data base from damaging or destruction, the Register Agency shall select safeguards taking account of the following risks of data damaging: 32.
- insufficient maintenance of the Register safeguards; 32.
- improper maintenance of data media; 32.
- improper use of software and hardware; 32.
- malfunction of hardware or software; 32.
- mistakes or slips of data processing; 32.
- file erasure; 32.
- inaccurate indication of the path for data transmission; 32.
- staff turnover; 32.
- violations of house regulations and non-compliance with job instructions; 32.
- interruptions in the electricity supply; 32.
- voltage and currency fluctuations; 32.
- computer viruses; 32.
- breaking in into office premises; 32.
- hacking into computer systems; 32.
- use of unlicensed software; 32.
- violation of consumer rights; 32.
- theft; 32.
- lightning, fire, flood or other water damage. IX. LIABILITY
- Violation of these Regulations shall incur liability under the laws of the Republic of Lithuania. X. FUNDING OF REGISTRATION
- The Register shall be financed with the funds from the State Budget of the Republic of Lithuania, allotted to the State Data Protection Inspectorate under the Ministry of Administrative Reforms and Local Authorities Affairs for the implementation of the Data Protection Control Programme. XI. REORGANISATION AND LIQUIDATION OF THE REGISTER
- The reorganisation and liquidation of the Register shall be governed by the legal acts of the Republic of Lithuania.
- The data of the Register under liquidation shall be transferred to another register, State Archives or shall be destroyed in accordance with the procedure laid down by legal acts of the Republic of Lithuania .