← Lietuva

Official translation

Official translation Official translation REPUBLIC OF LITHUANIA L A W ON LEGAL PROTECTION OF PERSONAL DATA 11 June 1996, No. I-1374 New version 17 July 2000, No. VIII-1852 As last amended on 22 Januar

Article 5

, paragraph 2, subparagraph 4; 3)

Article 8

; 4)

Article 10

; 5) following the procedure set forth in the Law of the Republic of Lithuania on State and Official Secrets. Article

  1. Registration of Data Controllers
  2. Data controllers shall be registered in the State Register of Personal Data Controllers which shall be established and its regulations shall be approved by the Government.
  3. The State Register of Personal Data Controllers shall be administered by an institution authorised by the Government CHAPTER VI TRANSFER OF PERSONAL DATA TO DATA RECIPIENTS IN FOREIGN COUNTRIES Article
  4. Transfer of Personal Data to Data Recipients in Foreign Countries
  5. Personal data shall be transferred to data recipients in foreign countries upon receiving an authorisation from the institution authorised by the Government, except in the cases referred to in paragraphs 4 and 5 of this Article.
  6. The institution authorised by the Government shall issue an authorisation to transfer personal data to foreign countries, provided there is an adequate level of protection in these countries. The institution authorised by the Government shall assess the adequacy of the level of protection of personal data with account of the laws and other legislation in force in the foreign country to which the personal data are being transferred which ensure legal protection of personal data in accordance with the type of the data transferred, the methods, purposes and duration of the processing of data.
  7. The institution authorised by the Government shall grant an authorisation to transfer personal data to a foreign country which cannot guarantee adequate level of legal protection of personal data on condition that the data controller providing personal data specifies in the contract the requirements for the safeguards of personal data to the recipient of the data.
  8. Without an authorisation of the institution authorised by the Government personal data shall be transferred to a foreign country or an international law enforcement organisation only when: 1) the data subject has given consent to the transfer of the data; 2) the provision of personal data is necessary for the conclusion or performance of a contract between the data controller and a third party; 3) the personal data are necessary for the performance of a contract which has been concluded by the data subject as one of the parties to the contract; 4) the transfer of personal data is necessary in the interests of the State; 5) the data are necessary for a court hearing; 6) for the purpose of protecting the life of the data subject; 7) it is necessary for the prevention or investigation of criminal offences.
  9. Personal data may also be transferred without an authorisation of the institution authorised by the Government to foreign countries under international agreements to which the Republic of Lithuania is a party. CHAPTER VII MONITORING OF APPLICATION OF THIS LAW Article
  10. Supervisory Authority
  11. The implementation of the Law on Legal Protection of Personal Data, with the exception of its Article 8, shall be supervised and monitored by the an institution authorised by the Government. The institution authorised by the Government shall be a government institution financed from the State budget. It shall be accountable to the Government. The regulations of the institution authorised by the Government shall be approved by the Government.
  12. The institution authorised by the Government shall be guided by the Constitution of the Republic of Lithuania, laws, international agreements of the Republic of Lithuania, and, in discharging the functions established in this Law and taking decisions relating to the performance of the functions laid down in this Law, shall be independent: its rights may be restricted only by the law. The actions of the employees of the institution authorised by the Government relating to the performance of the functions laid down in this Law shall be appealed against only in the manner established by law. Article
  13. Functions of the Supervisory Authority The institution authorised by the Government shall: 1) administer the Register of Personal Data Controllers, make its data public and carry out supervision of the activities of the registered data controllers relating to the processing of personal data; 2) examine personal requests and complaints in cases provided by this Law in the manner set forth in the Law on Public Administration; 3) check the lawfulness of personal data processing and take decisions in respect of the violations of personal data processing; 4) grant authorisations to data controllers to disclose personal data to data recipients in foreign countries; 5) draw up and announce annual reports on its activities; 6) draw up methodological recommendations on the protection of personal data and submit them to data controllers; 7) provide assistance, following the procedure established by law, to the data subjects resident abroad; 8) provide information, in the cases established by law, to other states about the legislation of the Republic of Lithuania regulating protection of personal data and the practices of their administration. Article
  14. Rights of the Supervisory Authority
  15. The institution authorised by the Government shall be entitled: 1) to obtain free of charge all necessary information on the processing of personal data from data controllers, to access personal data that are being processed, and carry out inspections in places of processing of personal data in the cases provided by this Law; 2) to instruct data controllers on personal data processing and protection; 3) to draw up records about administrative offences in accordance with the procedure set forth in the Code of Administrative Offences; 4) to exchange information with personal data supervisory authorities in other countries to the extent that is necessary for the discharge of their duties; 5) to invite experts/consultants for examination of data processing or protection, as well as for drafting of documents on data protection; 6) to engage in legal proceedings where international and national law on personal data protection has been violated.
  16. The institution authorised by the Government shall not have the right to control the processing of personal data in courts.
  17. The employees of the institution authorised by the Government must keep secrecy of the personal data in respect of the confidential information to which they have access, and ensure its confidentiality, even after transfer to another position, leaving of the public service or after termination of their employment.
  18. When drawing up rules/codes of conduct related to the processing of personal data, the data controllers and other persons must submit them to the opinion of the institution authorised by the Government.
  19. The institution authorised by the Government must be notified if it is believed that the envisaged processing of personal data may threaten the rights of the data subject or may considerably damage the data (due to the type or volume of data, the number of data subjects, the purposes of data protection, the volume and frequency of disclosed data).
  20. In the cases specified in paragraph 5 of this Article, the institution authorised by the Government shall carry out a prior check and give an opinion about the intended processing of personal data. CHAPTER VIII LIABILITY Article
  21. Liability for Breaches of this Law Liability provided in the laws of the Republic of Lithuania shall apply to the data controllers, data processors and other persons who have violated this Law. Article
  22. Compensation for Material and Non-Material Damage
  23. Any person who has sustained damage as a result of unlawful processing of personal data or other acts or omissions by the data controller or data processor shall be entitled to claim compensation for material and non-material damage caused to him.
  24. The court shall determine the extent of material and non-material damage.
  25. The data controller, data processor or other person, after compensation for damage caused to the person, shall make a claim, in the manner established by law, for recovery of the loss sustained from the employee processing the data due to whose fault the loss occurred. I promulgate this Law passed by the Seimas of the Republic of Lithuania PRESIDENT OF THE REPUBLIC VALDAS ADAMKUS

🔗 Į oficialų šaltinį

DI paaiškinimas pagal oficialų įstatymo tekstą. Orientacinis, nepakeičia teisinės konsultacijos.