REPUBLIC OF LITHUANIA REPUBLIC OF LITHUANIA LAW ON LEGAL PROTECTION OF PERSONAL DATA Article
- Relations Regulated by the Law and Its Purpose
- This Law shall regulate relations arising during the acquisition, collection, processing, storing, using and communicating data about natural persons by means of state computerised information systems, public registers included (hereinafter - information systems). The purpose of the Law is to establish the rights of data subjects and the manner of protection of those rights, guarantees of the rights to data protection during management of personal data in information systems.
- This Law shall not apply to relations regulated by other laws. Article
- Definitions
- Personal data - data about a concrete or a natural person identifiable from the data, his business relations and findings about the person on the basis of the data;
- Data processing - augmentation, alteration, deletion, correction and classification of data.
- Receiver of data - a natural or legal person to whom data is being communicated.
- Data record - a uniform, automatically managed collection of data about a natural person.
- Data subject - a person whose data is protected by this Law.
- Data management - acquisition, collection, storing, processing, safe-keeping and communication of data.
- Communication of data - transmission of data (communication to another person) and its disclosure ( providing conditions for accessing personal data).
- Data manager - a natural or legal person who lawfully manages the data.
- Regulations of the information system - regulations of the computerised information system ( public register) approved by the Government which must specify the data manager (the managing institution), the object and objectives of managing, the list, scope, procedure of collection and communication of data, the data collectors etc.
- Special personal data - personal data about the individual’s racial, national and ethnic origin, political opinions, religious and other beliefs, party membership, previous convictions, health, pathological defects and sexual (private) life.
- State computerised information system - a system of the documents needed for a specific activity and/or data management and search system functioning with the help of information technology: computers, their programmes, data bases, data transmission networks, and statutory acts regulating their use.
- State Data Protection Inspectorate- - an institution which controls the protection of the data of information systems and the lawfulness of communication and use of the data. Article
- Personal Data as the Object of Legal Protection This Law shall protect special and other personal data ( hereinafter - personal data) the disclosure or communication whereof to other persons may cause harm to the data subject or persons related to him. Article
- Term of Personal Data Protection and Its Storage
- Legal protection of personal data shall be effective throughout the life of the natural person, and subsequent to his death, for 75 years following the last record. The term of legal protection shall be calculated from January 1 following the year of the last record.
- The term for data storage shall be determined by the Department of Archives of Lithuania, and shall be controlled by the State Data Protection Inspectorate.
- At the expiry of the term of personal data storage, legal protection of personal data shall be effective pursuant to the provisions of Article 4
(1). Chapter II MANAGEMENT OF PERSONAL DATA Article
- Personal Data Records and Data Manager
- Personal data shall be collected and stored in data records the security and management whereof is the responsibility of the data manager. Data management shall be regulated by the provisions of the information system the object whereof is personal data, approved in a manner prescribed by the Government.
- Records of data shall be stored only for a definite purpose. Data which is not meant for storage or use may not be acquired, collected, processed and stored. Data shall be acquired, collected, processed, stored and used only in accordance with the purpose of a data record or subject to the permission of the data subject; in case of legal incompetence of the data subject - subject to the authorisation of his parents (adoptive parents) or guardians.
- Data managers shall be registered at the State Data Protection Inspectorate. Article
- The Right of the Data Subject to Access his Data
- The data subject shall be entitled to access his data and to rectify it. He shall also be entitled to get information from what sources and for what purpose the data has been obtained, when it has been used, is being used or might be used.
- The data manager, upon receiving a duly justified application, must communicate this information to the data subject free of charge, within ten days from the day of application. At the request of the person, the information shall be communicated in writing.
- The data shall not be provided to the data subject for access if: 1) this might endanger the security , public order of the Republic of Lithuania or might harm the interests of the Republic of Lithuania in cases specified by law; 2) the data is closely connected with the interests of a third party and its disclosure or communication might harm the latter, and for that reason the data must be kept secret if that does not contravene the law; 3) the data may harm the interests of the subject himself.
- The restrictions provided for by this Law on the right to access personal data and the procedure for the communication of the data shall be specified in the regulations of the information system.
- The refusal to communicate the requested data must be duly justified and provided in writing. The refusal may be appealed against within thirty calendar days to the State Data Protection Inspectorate, and the reply of the State Data Protection Inspectorate may be appealed against to the court in a manner prescribed by law. Article
- Rectification, Destruction of and Restrictions on Personal Data
- If it has been established that personal data is incorrect or its correctness is contested or questionable, the data manager may rectify, delete, mark or set aside such data from the correct data, limiting its further processing. When the correctness of data is contested, the data in documents, data records or other sources is marked by the inscription “contested data”.
- Personal data shall be destroyed if: 1) it is incorrect and this is not against the prescribed manner of collection of data; 2) it is prohibited to collect it; 3) it is not needed by the manager of the data according to the functions he is performing, it does not have to be transferred for storage at the national archives and if this is in conformity with the provisions of the information system in which this data was used.
- The data may be destroyed only subject to the authorisation of the State Data Protection Inspectorate and the Department of Archives of Lithuania.
- The personal data subject and other persons concerned to whom the data was communicated should be notified about the rectification and destruction of the data. Notification is not necessary if this does not affect the interests of the persons concerned.
- Instead of destruction, restrictions on the processing of the data may be used if: 1) the time set for the storage of the data has not expired; 2) the destruction of documents may affect the interests of the persons concerned; 3) it is impossible to destroy the data because of a specific manner of their collection or because the destruction involves considerable expenses; 4) after the data has been contested, it is impossible to establish that it erroneous.
- The data with restrictions on its processing may be used in a prescribed manner without the authorisation of its subject when this is necessary for scientific research and when it is not going to harm the data subject or a third party. In such a case the data shall be communicated without indicating its subject ( without providing data that would make it possible to identify a concrete person). Article
- Secrecy of Personal Data
- The manager of data must have all the necessary facilities for ensuring the secrecy of the personal data. The data must be protected from illegal collection, amending, communication, disclosure, and destruction. The request provided for in laws to obtain the data must be recorded in a manner prescribed by the regulations of the information system. Persons performing their official functions pertaining to the processing and communication of personal data shall be obligated in writing against their written acknowledgement to keep the secret of personal data. The secret of personal data must also be kept by them following the expiry of labour relations, throughout the whole period of legal protection of personal data unless the law provides otherwise.
- Personal data may be communicated without the authorisation of the data subject if this is requested by; 1) state control and security institutions; 2) institutions of inquiry, investigation, prosecution and the court; 3) institutions carrying out assignments of a generalised character in scientific research, economic and social planning and management effectiveness, without specifying the personal data subjects (anonymous data); 4) other state institutions in cases provided for by law. Article
- Communication of Personal Data to Other Managers of Data
- Personal data shall be communicated to other managers of data under a personal data communication agreement in the form prescribed by the State Data Protection Inspectorate between the communicating manager of data and the receiving manager of data. The agreement must state the purpose, conditions and manner or communication of personal data.
- Personal data may be communicated to other managers of data only upon receipt of a written consent of their subject; in case of the legal incompetence of the data subject - upon receipt of the consent of his parents (foster parents) or guardians.
- Personal data may be communicated without a prior consent of their subject if the communicating party communicates it to another manager of data in the course of performing his official duties established by law (regulations), while the receiver of the data has a right under law to receive such data and the data subject has no legal ground to object to such communication.
- Responsibility for the correctness of personal data and lawfulness of its communication shall be borne by the communicating manager.
- The receiver may use the obtained data only for the purpose specified in the agreement. The personal data may be used for a different purpose only subject to an authorisation of the State Data Protection Inspectorate. The State Data Protection Inspectorate shall issue an authorisation to use personal data only in cases established by law if this is deemed necessary or if the data subject gives his consent.
- Responsibility for a lawful use of personal data shall be borne by the receiving manager of data. Article
- Communication of Personal Data to National Archives When the personal data loses its practical value or the manager of data goes into liquidation, the latter must notify the State Data Protection Inspectorate and the Department of Archives of Lithuania. The Department of Archives of Lithuania shall adopt a decision on the subsequent storage of the data at the national archives or on its destruction. Article
- Communication of Personal data to Foreign Countries
- Personal data may be communicated to foreign countries in a manner prescribed by law only subject to an authorisation of the State Data Protection Inspectorate and if this does not infringe upon the rights of the data subject, also if the country to which the data is being communicated guarantees a proper legal protection of personal data.
- Personal data may be communicated to foreign countries without an authorisation of the State Data Protection Inspectorate, in accordance with the guarantees laid down in paragraph 1 of this Article, pursuant to international agreements to which the Republic of Lithuania is a party. Chapter III LIABILITY Article
- Liability of Managers of Data and Persons Managers of data and other persons violating the requirements laid down in this Law shall be liable under law. Article
- Material and Moral Damages
- The data subject shall be entitled to claim compensation for material damage caused during an improper storage, illegal alteration or other distortion, communication, disclosure of personal data or if the personal data has become incorrect through the fault of the manager of data. The data subject shall also be entitled to claim compensation for a moral damage caused by such actions.
- The scope of material and moral damage shall be determined by the court. Chapter IV Final PROVISIONS Article
- Implementation of the Law Within half a year following the adoption of this Law, the Government shall adopt subordinate legislation necessary for the implementation of the norms of this Law or shall submit such draft statutory acts to the Seimas. I promulgate this Law passed by the Seimas of the Republic of Lithuania. Algirdas Brazauskas President of the Republic Vilnius June 11, 1996 No I-1374