ficial translation REPUBLIC
LITHUANIA L A W ON LEGAL PROTECTION
PERSONAL DATA 21 January 2003, No. IX-1296 Vilnius Article 1. A New Version
the Law
the Republic
Lithuania on Legal Protection
Personal Data The Law
the Republic
Lithuania on Legal Protection
Personal Data shall be amended and set forth to read as follows: “REPUBLIC
LITHUANIA LAW ON LEGAL PROTECTION
PERSONAL DATA CHAPTER ONE GENERAL PROVISIONS Article 1. Purpose, Objectives and Scope
the Law 1. The purpose
this Law is protection
an individual’s right to privacy with regard to the processing
personal data. 2. This Law shall regulate relations arising in the course
the processing
personal data by automatic means, and during the processing
personal data by other than automatic means in filing systems: lists, card indexes, files, codes etc. The Law shall establish the rights
natural persons as data subjects, the procedure for the protection
these rights, the rights, duties and responsibility
legal and natural persons with regard to the processing
personal data. 3. This Law shall apply to the processing
personal data where: 1) personal data are processed in the course
its activities by a data controller who is established and operating on the territory
Lithuania; 2) personal data are processed by a data controller which is not established on the territory
the Republic
Lithuania but to which the laws
the Republic
Lithuania apply by virtue
international public law, including diplomatic missions and consular institutions; 3) personal data are processed by a data controller established and operating in a non-member state
the European Union, which makes use
automated personal data processing means established in the Republic
Lithuania, with the exception
cases where such means are used only for transit
data through the territory
the Republic
Lithuania and the territory
the European Union. In the case specified in this subparagraph, the data controller must have its representative - an established subsidiary or a representative
fice in the Republic
Lithuania to which the provisions
this Law in respect
the data controller shall apply. 4. This Law shall not apply if personal data are processed by a natural person in the course
a purely personal activity, unrelated to business or profession. 5. When personal data are processed for the purposes
State security or defence, this Law shall apply in so far as other laws do not provide otherwise. 6. Free movement
personal data shall in no way be restricted or prohibited when fulfilling the commitments
membership
the Republic
Lithuania in the European Union. 7. Under this Law, regulation
legal protection
personal data in the Republic
Lithuania shall be approximated with the acquis referred to in the appendix to this Law. Article
the implementation
this Law referred to in Articles 8 and 29 as well as state and municipal institutions and agencies shall not be regarded as recipients when they obtain personal data in response to a specific request for the purposes
discharging the functions
control provided for by law. 3. Disclosure
data - disclosure
personal data by transmission or making it available by any other means, with the exception
making it public in the mass media. 4. Processing
data - any operation, which is performed upon personal data such as collection, recording, accumulation, storage, classification, grouping, combination, alteration (supplementing or rectifying), disclosure, making available, use, logical and/or arithmetic operations, retrieval, dissemination, destruction or any other operation or a set
operations. 5. Processing
data by automatic means - operations performed upon personal data carried out in whole or in part by automated means. 6. Data processor - a legal or a natural person, not an employee
the data controller, processing personal data on behalf
the data controller. The data processor and/or the procedure
its appointment may be designated by laws or other legal acts. 7. Data controller - a legal or natural person which alone or jointly with others determines the purposes and means
the processing
personal data. Where the purposes
the processing
personal data are determined by laws or other legal acts, the data controller and/or the procedure for its appointment may be designated by laws or other legal acts. 8. Prior checking - an advance inspection
the procedures which are planned for the processing
personal data before they are started in the cases provided for in this Law. 9. Special categories
personal data - the data as to the racial or ethnic origin
a natural person, his political opinions, religious, philosophical or other beliefs, membership in a trade union, and data concerning his health, sex life and criminal convictions. 10. Filing system - any structured set
personal data arranged in accordance with specific criteria relating to the person, allowing for an easy access to personal data in the file. 11. Consent - any freely given specific and informed indication
his wishes by which the data subject signifies his agreement to the processing
personal data relating to him. His consent with regard to special categories
personal data must be expressed clearly - in a written form, its equivalent or any other form giving an unambiguous evidence
the data subject’s free will. 12. Direct marketing - an activity intended for
fering goods or services to individuals by post, telephone or any other direct means and/or inquiring their opinion about the
fered goods or services 13. Third party - a legal or natural person, with the exception
the data subject, the data controller, the data processor and the persons who have been assigned by the data controller or the data processor to process data. 14. Internal administration - activity which ensures an independent functioning
the data controller (structure administration, personnel management, management and use
materials and finances, and clerical work). 15. Public data file - a state register or any other data file which pursuant to laws and other legal acts is intended for the provision
information to the public and which may be lawfully used by the public. CHAPTER TWO PROCESSING
PERSONAL DATA Article 3. General Principles
Data Processing Personal data must be: 1) collected for specified and legitimate purposes determined before collecting personal data and are later processed in a way compatible with those purposes; 2) processed accurately, fairly and lawfully; 3) accurate, and, where necessary for the processing
personal data, kept up to date; inaccurate or incomplete data must be rectified, supplemented, destroyed or their further processing must be restricted. 4) identical, adequate and not excessive in relation to the purposes for which they are collected and processed; 5) kept in a form which permits identification
data subjects for no longer than is necessary for the purposes for which the data were collected and processed.
personal data processing principles set out in paragraphs 1 and 2
this Article. Article 4. Storage and Destruction
Personal Data Personal data shall not be stored longer than necessary for the purposes
data processing. Personal data shall be destroyed when no more needed for the purposes
their processing, with the exception
the data which must be transferred to State archives in cases established by law. . Article 5. Criteria for Lawful Processing
Personal Data 1. Personal data may be processed only if: 1) the data subject has given his consent; 2) a contract to which the data subject is party is being concluded or performed; 3) it is a legal obligation
the data controller under the laws to process personal data; 4) processing is necessary in order to protect the vital interests
the data subject; 5) processing is necessary for the performance
a task in the exercise
ficial authority vested in state and municipal institutions or a third party to whom the data are disclosed; 6) processing is necessary for the purposes
the legitimate interests pursued by the data controller or by a third party to whom the data are disclosed, except where such interests are overridden by the interests
the data subject. 2. It shall be prohibited to process special categories
personal data save in the following cases: 1) the data subject has given his consent; 2) such processing is necessary for the purposes
work or public service in the exercise
the rights and obligations
the data controller in the field
labour law in cases provided by law; 3) it is necessary to protect vital interests
the data subject or
any other person, where the data subject is unable to give his consent due to a physical disability or because he is s legally incapable; 4) processing is carried out in the course
the activities by a foundation, association or any other non-profit-seeking body for political, philosophical, religious or trade-union aim on condition that the processed data relate solely to the members
the body or to persons who have regular contact with it in connection with its purposes. This category
personal data may not be disclosed to a third party without the consent
the data subject; 5) the data have been made public by the data subject; 6) it is necessary, in cases provided by law, for the prevention and investigation
criminal
fences; 7) the data are necessary for a court hearing. 3. The data about a person’s health may also be processed for the purposes and in the manner specified by Article 10
this Law and the laws pertaining to health care. 4. Personal data relating to a person's record
conviction, criminal acts or security measures in the course
crime prevention or investigation also in other cases provided for by law may be processed only by a state institution or an agency following the procedure prescribed by law. Other natural or legal persons may process such data in cases specified by law provided that appropriate safeguards established by laws and other legal acts for the protection
the legitimate interests
the data subject have been implemented adequately. Detailed data about previous convictions may be processed only in accordance with the procedure set out in the Law on State Registers. Article 6. Forms
Personal Data Disclosure In the cases provided for by this Law personal data shall be disclosed under a personal data disclosure contract between the data controller and the data recipient in cases
multiple disclosure or under a request
the data recipient in cases
a single disclosure. The contract must specify the purposes for which the data will be used, the conditions
and the procedure for its use. The request must specify the intended use
the data. Article 7. Use
Personal Identification Number 1. The personal identification number is a unique sequence
digits assigned to a person in accordance with the procedure set forth in the Law on the Population Register. 2. The use
a personal identification number for the processing
personal data shall be conditional on the consent
the data subject. 3. The personal identification number may be used when processing personal data without the consent
the data subject only if: 1) such a right is stipulated in this Law and other laws; 2) for research or statistical purposes in cases specified in Articles 12 and 13
this Law; 3) in state registers and information systems provided that they have been
ficially approved under law; 4) it is used by legal persons involved in activities related to granting
loans, recovery
debts, insurance or leasing, health care and social insurance as well as in the activities
other institutions
social care, educational establishments, research and studies institutions, and when processing classified data in cases provided by law. Article 8. Reconciliation
Processing
Personal Data with Provision
Information to the Public The processing
personal data carried out for the purposes
providing information to the public or the purposes
artistic or literary expression as well as other purposes shall be supervised by the Inspector
Journalistic Ethics. His competencies shall be determined by the Law on Provision
Information to the Public. In these cases only the provisions
Articles 1, 2, 3, 4, 6, 7, 24, 33 and 34
this Law shall apply to the processing
personal data. Article 9. Processing
Personal Data for Purposes
Social Insurance and Social Care Providers
social services when performing their functions related to social insurance and other purposes
social care shall provide personal data to one another without the consent
the data subject. Article 10. Processing
Personal Data for Purposes
Health Care
personal data for purposes
medical research shall be governed by this Law and other laws. Article 11. Processing
Personal Data for Purposes
Elections, Referenda and Citizens' Legislative Initiative 1. Processing
personal data (name, surname, date
birth, personal identification number, the place
residence, nationality, number
the identification document) for purposes
elections, referenda, citizens' legislative initiative, political campaigns and financing
political parties shall be determined by this Law and other laws. 2. The information about the candidates, the votes received, the lists
members
the electoral committees, observers, representatives, members
initiative groups after the election, the announcement
the referendum results, as well as the lists
donors
political campaigns compiled on the basis
the statements and other documents submitted to the Central Electoral Committee by the candidates or their representatives and announced on an Internet web site may be revised after the announcement
the results
the election and the referenda for the purposes
correction
language mistakes or when the information on the Internet web site differs from the information provided in the statements and other documents at the time prescribed by legal acts. An Internet web site may not make public personal identification numbers
the candidates and any other persons, their nationality or numbers
their identification documents, the exact address (street, number
the house, number
the apartment)
their place
residence. Article 12. Processing
Personal Data for Purposes
Scientific Research 1. Personal data shall be processed in the course
scientific research on condition the data subject has given his consent. Without the consent
the data subject personal data may be processed only if the State Personal Data Protection Inspectorate which must carry out a prior checking has been duly notified.
scientific research may not be used for any other purposes. 4. In the cases where the research does not require data identifying a person, the data controller shall provide to the data recipient personal data from which identification
a person is not possible.
Personal Data for Statistical Purposes 1. Processing
personal data for statistical purposes shall be carrying out
statistical surveys, disclosure and keeping
their results. 2. Personal data collected for non-statistical purposes may be used, in the cases provided for by law, for the preparation
ficial statistical information.
personal data against the unlawful use for non-statistical purposes is ensured. 5. Special categories
personal data shall be collected for statistical purposes solely in the form, which does not permit direct or indirect identification
the data subject, except in the cases provided by law. Article 14. Processing
Personal Data for the Purposes
Direct Marketing 1. Personal data may be processed for the purposes
direct marketing only if the time period for the storage
personal data is set during the collection
the data. 2. Personal data may be processed for the purposes
direct marketing provided that the data subject has given his consent. Article 15. Processing
Personal Data in Telecommunications The processing
personal data in telecommunications shall be governed by the Law on Telecommunications and this Law. Article 16. Processing
Personal Data for the Purposes
Evaluation
a Person's Solvency and Management
His Debt 1. The data controllers shall have the right to process and disclose to third parties having the legitimate interests the data as well as the personal identification number
the data subjects who have failed to fulfil in a timely and proper manner their financial and/or property obligations (hereinafter "debtors") for the purposes
evaluation
the person's solvency and debt management, provided that all the data protection requirements set out in this Law and other legal acts are duly complied with. 2. The data controller shall have the right to disclose the debtors’ personal data and personal identification number to data controllers processing consolidated debtor files (hereinafter "consolidated files"). The data controller may process consolidated files with a view to disclosing such data to third parties having the legitimate interests so that they could evaluate solvency
the data subject and manage the debt only if he has duly notified, following the procedure set out in Article 26
this Law, the State Data Protection Inspectorate which must carry out a prior checking. 3. The data controller may disclose the debtors' personal data on condition he has sent a reminder in writing to the data subject about his default on the debt and where, within 18 calendar days
the date when the data controller sent/submitted to the data subject a reminder: 1) the debt was not settled and/or the deadline for the repayment was not extended; 2) the data subject did not contest the debt on compelling grounds. 4. The data controller may not process special categories
personal data. 5. Consolidated files may not be combined with personal data from the files
other personal data which were compiled and are processed for purposes other than evaluation
solvency and debt management. 6. The data controller who is processing consolidated files, upon receiving from the data controller referred to in paragraph 2
this Article the debtors’ data, must provide to each data subject the following information, except where the data subject already has such information: 1) the identity
himself (the data controller) and his representative if any, and his registered
fice; 2) the purposes
the processing
the data subject’s personal data; 3) the sources and type
the data subject’s personal data which have been collected, the recipient and the purposes for which the data are being disclosed, the data subject's right
access to his personal data and his right to request rectification
incorrect, inaccurate and incomplete personal data. 7. The data about the default
the data subject on a timely and proper fulfilment
his financial and/or property obligations may not be processed for a period longer than 10 years from the date
the settlement
the debt. Where the data subject repays his debt, data controllers must ensure that during the processing
the data about the data subject's default on a timely and proper fulfilment
his financial and/or property obligations the following information is specified: 1) settlement
the debt by the data subject; 2) the data
the debt settlement. 8. Banks and other credit institutions and financial undertakings engaged in credit and/or financial activities may disclose to each other the following data
the data subjects who have taken out loans from them, including leasing/financial leasing: the name, surname, personal identification number, the type
the loan, its amount and the deadline for the repayment
the loan in order to evaluate the solvency
the subjects. Banks and other credit institutions and financial undertakings engaged in credit and/or financial activities may apply to each other with a request to obtain the personal data referred to in this paragraph only when the data subject applies to these institutions for a loan, including leasing/financial leasing, and gives his consent that these institutions and undertakings obtain his data. The data
the data subjects may not be: 1) stored for a period longer than 2 working days
the receipt
such data; 2) combined with the other personal data. CHAPTER THREE RIGHTS
THE DATA SUBJECT Article 17. Rights
the Data Subject 1. The data subject, in accordance with the procedure provided by this Law, shall have the right: 1) to know/ be informed about the processing
his personal data; 2) to have access to his personal data and familiarise himself with the processing method; 3) to demand rectification or destruction
his personal data or restriction
further processing
his personal data, with the exception
storage, where the data are processed not in compliance with the provisions
this Law and other laws; 4) to object to the processing
his personal data. 2. The data controller must provide conditions for the data subject to exercise the rights specified in this Article, with the exception
cases provided by law when it is necessary to ensure: 1) state security or defence; 2) public order, the prevention, investigation, detection and prosecution
criminal
fences; 3) important economic or financial interests
the state; 4) prevention, investigation and detection
breaches
ficial or professional ethics; 5) protection
the rights and freedoms
the data subject or any other persons. 3. The data controller must give a reasoned refusal to grant the request
the data subject to exercise the rights granted by this Law to the data subject. Upon receiving a request from the data subject, the data controller must send a reply to him within 30 calendar days
the date
the data subject's application. Where the request
the data subject is in writing, the data controller must send him a written reply. 4. The data subject may appeal the acts/omissions
the data controller to the State Data Protection Inspectorate within 3 months
the receipt
the reply from the data controller or within 3 months
the date when the time period for giving a reply set out in paragraph 3
this Article expires. The acts/omissions
the State Data Protection Inspectorate may be appealed against in court in accordance with the procedure provided by law. Article 18. Informing the Data Subject about the Processing
Data Relating to Him 1. The data controller must provide to the data subject from whom data relating to himself are collected directly the following information, except where the data subject already has it: 1) the identity
the data controller and his representative if any, and his permanent place
residence where the data controller or his representative is a natural person, or other particulars, and the registered
fice where the data controller or its representative is a legal person; 2) the purposes
the processing
the data subject’s personal data; 3) any other additional information - the recipient
the data and for what purposes the data
the data subject are disclosed; what personal data the data subject is supposed to provide and the consequences
his failure to provide data, the right
the data subject to have access to his personal data and the right to request rectification
incorrect, incomplete and inaccurate personal data, necessary for ensuring a proper processing
personal data without violation
the data subject’s rights. 2. Where the data controller obtains personal data not from the data subject he must inform the data subject about it before the start
data processing or, if he intends to disclose the data to third parties, he must inform the data subject about it not later than by the moment when the data are disclosed for the first time, unless the laws or other legal acts determine the procedure for collection or disclosure
such data and the data recipients. In such cases the data controller must provide to the data subject the following information except where the data subject already has such information: 1) the identity
himself (the data controller) and his representative if any, his permanent place
residence where the data controller or his representative is a natural person, or other particulars and the registered
fice where the data controller or its representative is a legal person; 2) the purposes
the processing or the intended processing
the personal data
the data subject; 3) any other additional information (the sources and type
his personal data which is being collected or will be collected; the recipient
the data subject’s personal data and the purposes
the disclosure; the right
the data subject to have access to his personal data and his right to request rectification
incorrect, incomplete and inaccurate personal data) to the extent it is necessary to ensure a fair processing
personal data without violating the rights
the data subject. 3. When the data controller collects or intends to collect personal data from the data subject and processes or intends to process the data for the purposes
direct marketing, before disclosing the data
the data subject he must inform the data subject about the recipient
the personal data and the purposes for which the data will be disclosed. 4. Paragraph 2
this Article shall not be applicable to the processing
personal data for the statistical or research purposes where the provision
such information is impossible or involves unnecessary difficulties owing to a large number
data recipients, the outdated character
the data and excessively large expenses or where the procedure for collecting and disclosing data are established by law. The data controller must duly notify the State Data Protection Inspectorate about it following the procedure set out in Article 26
this Law. Article 19. Data Subject’s Right
Access to his Personal Data 1. Upon submitting to the data controller or the data processor a document certifying his identity, the data subject shall be entitled to obtain information on the source and type
his personal data that has been collected, the purposes
processing, and the recipient to whom the data are disclosed. 2. Upon receiving an enquiry from the data subject concerning the processing
his data, the data controller must make a reply whether the personal data relating to him are processed, and provide to the data subject the requested data within 30 calendar days
the date
the receipt
the data subject’s enquiry. On request such information must be provided to the data subject in writing. Once a calendar year the data controller shall provide such information to the data subject free
charge. When such information is disclosed for a fee, the amount
the fee shall not exceed the expenses
the disclosure
the data. The procedure
compensation
the expenses
disclosure
the data shall be determined by the Government. Article 20. The Data Subject’s Right to Request Rectification, Destruction
His Personal Data or Restriction
Further Processing
His Personal Data 1. Where the data subject, after access to his personal data, finds that his data are incorrect, incomplete and inaccurate and applies to the data controller, the latter must check the personal data without delay and, at the request
the data subject, oral or written or in any other form, immediately rectify the incorrect, incomplete and inaccurate personal data and/or restrict further processing
such personal data except its keeping. 2. Where the data subject, after access to his personal data, considers that his data are processed unlawfully and unfairly and applies to the data controller, the latter must check without delay and free
charge the lawfulness and fairness
the processing
personal data and, at the data subject’s request in writing, immediately destroy the personal data collected unlawfully and unfairly or restrict further processing
such personal data except its keeping. 3. When, upon the request
the data subject, further processing
his personal data is restricted, the personal data further processing
which has been restricted must be kept until their rectification or destruction either at the request
the data subject or upon expiry
the period
their keeping. Any other actions
processing
such personal data may be performed solely: 1) for the purposes
giving proof
the circumstances due to which further processing
the data was restricted; 2) where the data subject gives his consent for the further processing
his personal data; 3) where the rights or legitimate interests
third parties have to be protected. 4. The data controller must immediately notify the data subject
the performed or not performed rectification, destruction
the personal data or restriction
their further processing in response to the application
the data subject. 5. Personal data shall be rectified and destroyed or their further processing shall be restricted in response to the application
the data subject and on the basis
documents confirming his identity and his personal data. 6. If the data controller questions the correctness
the personal data submitted by the data subject, he must restrict further processing
such personal data, check the data and update them. The contested personal data may be used solely for checking their correctness. 7. The data controller must inform forthwith data recipients
the personal data rectified or destroyed and
the restriction
further processing at the request
the data subject except where providing such information might be impossible or too difficult due to an excessively large number
the data subjects, the period covered by the data and unreasonably high costs. If such is the case, the State Data Protection Inspectorate must be immediately notified. . Article 21. Data Subject’s Right to Withhold His Consent to the Processing
His Personal Data 1. In the cases referred to in paragraph 1
this Law, and when the data are being processed or are about to be processed for the purposes
direct marketing, the data controller must inform the data subject about his right to object to the processing
his personal data. 2. In the cases specified in paragraph 1
this Law, the data subject shall have the right to object (in writing, orally or in any other form) to the processing
his personal data. Where the objection
the data subject is legally motivated, the data controller must immediately and free
charge restrict any other further processing
personal data except in the cases set out by law, and duly notify the data recipients. 3. The data subject shall have the right to object to the processing
his personal data without giving the motives for such objection where the data are processed or are about to be processed for the purposes
direct marketing. In this case the data controller must immediately and free
charge restrict any further processing
personal data except in the cases provided for by law and must duly notify the recipients
the data. 4. At the request
the data subject, the data controller must notify the data subject about the cessation
the processing
his personal data or his refusal to cease the processing
the data subject’s personal data. Article 22. Evaluation
Personal Aspects by Automated Means 1. No decision may be taken in respect
the data subject’s personal aspects (his creditworthiness, reliability, performance at work) where such aspects were evaluated only by automated means and where such a decision might produce legal effects concerning the data subject or affect him in any other way, with the exception
the following cases: 1) the decision is taken following the procedure established by law, where laws provide for measures for the protection
the legitimate interests
the data subject; 2) the decision is taken when concluding a contract or performing it provided that the request
the data subject to conclude a contract and perform it has been granted; 3) the decision is taken when concluding a contract or performing it provided that appropriate measures have been implemented for the protection
the legitimate interests
the data subject, e.g., a procedure has been provided allowing the data subject to put his point
view. 2. Before undertaking the evaluation
the personal aspects
the data subject by automated means, the data controller must provide conditions for the data subject to be informed about the evaluation criteria and principles determined by the data controller. 3. Where, following the evaluation
the personal aspects
the data subject by the data controller by automated means, the data subject objects to such an evaluation he shall be entitled to put his point
view about the evaluation
his personal aspects. The data controller must take into account the point
view
the data subject and, as necessary, repeat the evaluation by non-automated means. Article 23. Service to the Data Subject in Exercising His Right
Access to His Personal Data 1. The State Data Protection Inspectorate shall assist the data subject in exercising his right
access to his personal data. 2. When applying to the State Data Protection Inspectorate and after producing his identity document, the data subject shall have the right to request the State Data Protection Inspectorate to collect his personal data or information on the processing
his personal data from registered data controllers and to make the collected data or information available to him. 3. When providing to the data subject the service referred to in paragraph 2
this Article, the State Data Protection Inspectorate shall not have the right to collect data which is classified information under the Law
the Republic
Lithuania on State and
ficial Secrets. 4. The service specified in paragraph 2
this Article shall be provided to the data for a certain fee. The amount
the fee shall not exceed the expenses
data collection and provision
the service. The procedure for payment for the service shall be determined by the Government. CHAPTER FOUR SECURITY
DATA Article 24. Security
Data 1. The data controller and data processor must implement appropriate organisational and technical measures intended for the protection
personal data against any accidental or unlawful destruction, alteration, disclosure as well as against any other unlawful processing. These measures must ensure a level
security appropriate to the nature
the data to be protected and the risks represented by the processing and must be specified in a written document or its equivalent (data processing regulations approved by the data controller, a contract concluded by the data controller and the data processor etc.). 2. The data controller shall himself process personal data and/or shall authorise the data processor to do so. If the data controller authorises the data processor to process personal data, he must choose a processor providing guarantees in respect
adequate technical and organisational data protection measures and ensuring compliance with those measures.
the data controller, the data processor and their representatives who are processing personal data must keep confidentiality
personal data if these personal data are not intended for public disclosure. This obligation shall continue after leaving the public service, transfer to another position or upon termination
employment or contractual relations. CHAPTER FIVE REGISTRATION
DATA CONTROLLERS Article 25. Notification
Data Processing 1. Personal data may be processed by automated means subject to notification by the data controller or his representative
the State Data Protection Inspectorate (pursuant to paragraph 3
this Law) in accordance with the procedure established by the Government, except when personal data are processed: 1) for the purposes
internal administration; 2) processing is carried out in the course
the activities by a foundation, association or any other non-profit-seeking body for political, philosophical or trade union aim on condition that the processed data relate solely to the members
the body or to persons who have regular contact with it in connection with its purposes; 3) in the cases specified in Article 8
this Law; 4) in the cases specified in Article 10
this Law; 5) following the procedure set forth in the Law
the Republic
Lithuania on State and
ficial Secrets. Article
personal data save in the cases specified in Article 10 and paragraph 2
this Law; 2) where the data controller intends to process public data files unless the laws and other legal acts specify the procedure for disclosure
the data; 3) where the data controller
the information systems
state registers or state and municipal institutions authorises the data processor to process personal data save the cases where the laws and other legal acts provide for the right
the data controller to authorise a specific data processor to process personal data or where the data processor is a legal entity established by the data controller; 4) in the cases specified in paragraph 1
, paragraph 2
and paragraph 4
this Law. 2. The data controller must, two months before the intended commencement
the data processing operations, notify the State Data Protection Inspectorate, in accordance with the procedure specified by the State Data Protection Inspectorate, about the cases referred to in paragraph 1
this Article. Such data processing operations may be carried out only if an authorisation has been granted by the State Data Protection Inspectorate. Within two months
the receipt
the notification, the State Data Protection Inspectorate must carry out prior checking according to the procedure determined by the State Data Protection Inspectorate and grant or refuse to grant an authorisation to the data controller to carry out data processing operations. A decision
the State Data Protection Inspectorate not to grant an authorisation to the data controller to undertake data processing operations may be appealed against following the procedure prescribed by law. If, within two months
the date
the receipt
the notification specified in this paragraph, the State Data Protection Inspectorate fails to take a decision in respect
granting or refusal to grant an authorisation it shall be regarded that the data controller has been granted an authorisation to carry out data processing operations about which a notification had been made. Article 27. Registration
Data Controllers 1. Data controllers shall be registered in the State Register
Personal Data Controllers. 2. The State Register
Personal Data Controllers shall be administered by the State Data Protection Inspectorate. CHAPTER SIX TRANSFER
PERSONAL DATA TO DATA RECIPIENTS IN THIRD COUNTRIES Article 28. Transfer
Personal Data to Data Recipients in Third Countries 1. Transfer
personal data to recipients in foreign countries shall be subject to an authorisation from the State Data Protection Inspectorate, except in the cases referred to in paragraph 4
this Article. 2. The State Data Protection Inspectorate shall grant an authorisation for transfer
personal data to foreign countries, provided that there is an adequate level
personal data protection in these countries. The level
legal protection
personal data shall be assessed in the light
all circumstances surrounding a data transfer operation, by giving particular consideration to the laws and other legal acts in force in the country
destination providing legal protection
personal data, the nature
the data, the proposed processing operations, purposes
processing, its duration and safeguards which shall be observed in the third country in question. 3. The State Data Protection Inspectorate may grant an authorisation to transfer personal data to a third country which cannot guarantee an adequate level
legal protection
personal data on condition that the data controller has established adequate safeguards for the protection
an individual’s right to privacy as well for protection and exercise
the other rights
the data subject. Such safeguards must be stipulated in the contract on the transfer
personal data to a third country. 4. Without an authorisation
the State Data Protection Inspectorate personal data shall be transferred to a third country or an international law enforcement organisationonly if: 1) the data subject has given his consent to the transfer
the data; 2) the transfer
personal data is necessary for the conclusion or performance
a contract between the data controller and a third party concluded in the interests
the data subject; 3) the transfer
personal data is necessary for the performance
a contract between the data controller and the data subject or the implementation
pre-contractual measures taken in response to the data subject’s request; 4) the transfer
personal data is necessary or legally required in the public interest or for the purpose
legal proceedings; 5) the transfer is necessary in order to protect the vital interests
the data subject; 6) the transfer is necessary for the prevention or investigation
criminal
fences; 7) the data are transferred from a public data file following the procedure prescribed by laws and other legal acts. CHAPTER SEVEN MONITORING
APPLICATION
THIS LAW Article
the Law on Legal Protection
Personal Data, with the exception
The State Data Protection Inspectorate shall be a government institution financed from the state budget. It shall be accountable to the Government. The regulations
the State Data Protection Inspectorate shall be approved by the Government. 2. The major objectives
the State Data Protection Inspectorate shall be supervision
the activities
data controllers when processing personal data, monitoring the legality
processing
personal data, prevention
breaches in data processing and ensuring protection
the rights
the data subject. 3. The State Data Protection Inspectorate shall have no right to monitor processing
personal data in courts. Article 30. Legal Basis ands Principals
the Activities
the State Data Protection Inspectorate 1. In its activities the State Data Protection Inspectorate shall be guided by the Constitution
the Republic
Lithuania, international agreements to which the Republic
Lithuania is a party, this Law and other legal acts. 2. The activities
the State Data Protection Inspectorate shall be based on the principles
lawfulness, impartiality, openness and professionalism in the discharge
its functions. When discharging the functions provided by this Law and making its decisions related to the discharge
the functions set out for it in this Law, the State Data Protection Inspectorate shall be independent; its rights may be limited only by law. 3. State and municipal institutions and agencies, members
the Seimas and other
ficials, political parties, political and public organisations, other legal and natural persons shall have no right to exert any kind
political, economic, psychological or social pressure on the employees
the State Data Protection Inspectorat or tamper with them in any other way. Interference with the activities
the State Data Protection Inspectorate shall render the infringing party liable in accordance with law. Article 31. Functions
the State Data Protection Inspectorate The State Data Protection Inspectorate shall: 1) administer the Register
Personal Data Controllers, make its data public and carry out supervision
the activities
the registered data controllers relating to the processing
personal data; 2) examine personal requests and complaints in cases provided by this Law in the manner set forth in the Law on Public Administration; 3) check the lawfulness
personal data processing and take decisions in respect
the breaches
personal data processing; 4) grant authorisations to data controllers to disclose personal data to data recipients in third countries; 5) draw up and announce annual reports on its activities; 6) provide assistance to data controllers and draw up methodological recommendations on the protection
personal data and make them public on the internet; 7) following the procedure established by law, provide assistance to data subjects residing abroad; 8) provide information, in the cases established by law, to other states about the legislation
the Republic
Lithuania regulating protection
personal data and the practices
its administration; 9) carry out prior checking in the cases established by this Law and submit its conclusions to the data controller about the intended data processing; 10) implement the provisions
the Convention for the Protection
Individuals with Regard to Automatic Processing
Personal Data (ETS No. 108); 11) make recommendations to the Seimas, the Government, other state and municipal institutions and agencies relating to drafting, amendment and repeal
laws or other legal acts where the provisions
laws or other legal acts are related to the questions falling within the competence
the State Data Protection Inspectorate; 12) assess the personal data processing regulations submitted by data controllers; 13) perform other functions set out in this Law and other legal acts. Article 32. Rights
the State Data Protection Inspectorate 1. The State Data Protection Inspectorate shall be empowered: 1) to obtain free
charge from state and municipal institutions and agencies, other legal and natural persons all necessary information, copies and transcripts
documents, copies
data and get access to all data and documents necessary for discharging all the functions
supervision
personal data processing; 2) to obtain access, subject to a prior notice in writing, to the premises
the supervised person, including the premises which are leased or used on any other basis, or to the territory where the documents and equipment used for the personal data processing are kept. Access to the territory
the legal person, his buildings and premises, including the buildings and premises which are leased or used on any other basis shall be permitted only during the
fice hours
the legal person under supervision. Access to residential premises, including the premises which are leased or used on any other basis
a natural person under supervision, where documents and equipment relating to the personal data processing are kept shall be permitted only upon producing a court order warranting entry into the residential premises; 3) to take part in the sessions
the Seimas, meetings
the Government and other state institutions when issues relating to the personal data protection are being deliberated; 4) to summon experts/consultants, form work groups for examination
data processing or data protection, as well as for drafting
documents on data protection and for making decisions on other issues within the competence
the State Data Protection Inspectorate; 5) to make recommendations and give instructions to data controllers with regard to personal data processing and protection; 6) to draw up records about administrative
fences in accordance with the procedure set out in the Code
Administrative
fences 7) to exchange information with personal data supervisory authorities in other countries and international organisations to the extent necessary for the discharge
their duties; 8) to take part in legal proceedings involving violations
international and national law on personal data protection; 9) to exercise other rights provided by law and other legal acts. CHAPTER EIGHT LIABILITY Article 33. Liability for Breaches
this Law Breaches
this Law shall render data controllers, data processors and other persons liable under the laws the Republic
Lithuania. Article
unlawful processing
personal data or any other acts or omissions by the data controller, the data processor or any other persons in violation
the provisions
this Law shall be entitled to claim compensation for pecuniary and non-pecuniary damage caused to him. 2. The extent
pecuniary and non-pecuniary damage shall be determined by court. Annex
the Law
the Republic
Lithuania on Protection
Personal Data The Law
the Republic
Lithuania on Legal Protection
Personal Data has been approximated with Directive 95/46/EC
the European Parliament and
the Council
24 October 1995 on the protection
individuals with regard to the processing
personal data and on the free movement
such data.” Article
paragraph 3
this Law shall enter into force upon Lithuania’s accession to the European Union. 3. Article 23
this Law shall enter into force on 1 April
this Law shall apply only to the transfer
personal data to the countries which are non-member states
the European Union. Article 3. Implementation
the Law 1. Within three months from entry
this Law into force, the Government shall submit to the Seimas draft laws amending the laws relating to the implementation
this Law. 2. By 1 July 2003 the Government shall approve the legal acts necessary for the implementation
this Law. 3. The data controllers who, upon entry
this Law into force, continue the data processing operations in the cases specified in Article 26
the date
entry
this Law into force. The notification made by the data controllers shall not suspend or revoke the data processing operations unless the State Data Protection Inspectorate decides otherwise. I promulgate this Law passed by the Seimas
the Republic
Lithuania PRESIDENT
THE REPUBLIC VALDAS ADAMKUS
DI paaiškinimas pagal oficialų įstatymo tekstą. Orientacinis, nepakeičia teisinės konsultacijos.