REPUBLIC OF LITHUANIA official translation REPUBLIC OF LITHUANIA LAW LEGAL PROTECTION OF PERSONAL DATA June 11,
- No I-1374 Vilnius (As amended by March 12, 1998 No.VII-662) Article
- Relations Regulated by the Law and Its Purpose
- This Law shall regulate relations arising during the collection, recording, processing, storage, use and disclosure of data about natural persons to information systems or any other related or relatable processing of data (hereinafter - information systems). The purpose of the Law is to establish the rights of data subjects and the manner of protection of those rights, guarantees of the rights to data protection during processing of personal data in information systems.
- This Law shall protect personal data, including special personal data the processing or disclosure of which may cause harm to data subject or to the persons related to him. Article
- Definitions
- Personal data - data about a concrete or a natural person identifiable from the data, his business relations and findings about the person on the basis of the data;
- Processing of data - augmentation, alteration, deletion, correction and classification of data.
- Receiver of data - a natural or legal person to whom data is being disclosed, except cases when the data is obtained in reply to requests about a concrete data subject.
- Data file - a uniform, automatically managed collection of data about a natural person.
- Data subject - a natural person whose data is protected by this law.
- Data management - acquisition, collection, storing, processing, safe-keeping and disclosure of data.
- Disclosure of data - transmission of data (communication to another person) and its disclosure ( making personal data available).
- Data controller - a natural or legal person who, in a manner prescribed by the laws and other legal acts of the Republic of Lithuania, manages personal data, heads data management institutions and grants the right to data management institutions to use the data obtained under a data disclosure agreement. The data controller and the data management institution may be one and the same natural or legal person.
- Regulations of the information system - a document establishing the procedure of management and processing of personal data by a computerised information system or another person. The regulations must specify the data controller and the data managing institution, the prescribed data management object and objectives, the list, scope, procedure of collection and disclosure of data, data collectors and the requirements for data protection measures.”
- Special Categories of Data - personal data about the individual's racial, national and ethnic origin, political opinions, religious and other beliefs, party membership, previous convictions, health, pathological defects and sexual (private) life.
- Information system - a system of management and retrieval of documents needed for a specific activity of an institution and/or data, functioning with the help of information technology: computers, their programmes, data bases, data transmission networks, and statutory acts regulating their use.
- State Data Protection Inspectorate- - an institution which controls protection of the data of information systems and the legality of disclosure and use of the data.
- Third party - every natural or legal person who is not a data subject, a data controller, or a data managing institution, and who is not authorised by a data managing institution to process or manage personal data. Article
- Criteria for Lawful Management of Personal Data
- Personal data may be managed only if: 1) the data subject gives his consent in writing; 2) it is necessary for the performance of an agreement concluded by the data subject and a data controller; 3) a data controller must, under law, manage personal data; 4) efforts are made to secure the vital interests of the data subject or the lawful interests of the public without violating the fundamental rights and freedoms of the data subject.
- It shall be prohibited to manage special categories of personal data except where: 1) the data subject gives his consent in writing to manage his data; 2) the right to manage the data is granted to the controller of data by the authority of law and is related to labour relations; 3) there is a need to protect the vital interests of data subjects. These data may be collected only subject to a reasoned court decision and only pursuant to law; 4) the data is managed by a public body (a fund, association etc.,) for political, religious or trade-union aim and on condition that the managed data are related to the members of the body or to persons who have regular contact with it in connection with its purposes. These data may not be disclosed to a third party without a consent of the data subject; 5) the data subject made the data public if the data are needed in for the establishment of legal claims; Article
- Term of Personal Data Protection and its Storage
- Legal protection of personal data shall be effective throughout the life of the natural person, and subsequent to his death, for 75 years following the last record. The term of legal protection shall be calculated from January 1 following the year of the last record.
- The term for data storage shall be determined by the Department of Archives of Lithuania, and shall be controlled by the State Data Protection Inspectorate.
- Upon the expiry of the term of personal data storage, legal protection of personal data shall continue pursuant to the provisions of paragraph 1 of Article
- CHAPTER II MANAGEMENT OF PERSONAL DATA Article
- Personal Data Records and Data Controller
- Personal data shall be collected and stored in data records the security and management whereof is the responsibility of the data controller. Data management shall be subject to the regulations of the information system the object whereof is personal data. Personal data shall be managed only pursuant to the criteria of a legal management of personal data.
- Records of data shall be stored only for a specified purpose. Data which is not meant for storage or use must not be, collected, recorded, processed and stored. Data shall be collected, recorded, processed, stored and used only in accordance with the purpose of a data record prescribed by law or subject to the authorisation of the data subject, and in case of legal incompetence of the data subject - subject to the authorisation of his parents (adoptive parents) or guardians. Data controllers shall ensure the right of data subjects to give consent for the performance of the acts provided in this paragraph.
- Data controllers, except those who manage data collected by them for purposes of internal administration or data constituting a State or official secret, must register at the State Data Protection Inspectorate. Article
- The Data Subject’s Right of Access to Data
- The data subject shall be entitled to access his data concerning him and rectify them. He shall also be entitled to obtain information as to the source of the data, the purpose for which and when it was used, is being used or may be used.
- The data controller, upon receiving a duly motivated request, must communicate this information to the data subject free of charge, within ten days from the day of application. At the request of the data subject, the information shall be communicated in writing.
- The data shall not be provided to the data subject for access if: 1) this may endanger the security of the Republic of Lithuania, public order or may harm in any other way the interests of the Republic of Lithuania in cases specified by law; 2) the data is closely connected with the interests of a third party and their disclosure or communication might harm the latter, and for that reason the data must be kept secret if that does not contravene the law; 3) the data may harm the interests of the data subject himself.
- The restrictions provided for by this Law on the right of access to personal data and the procedure for the communication of the data shall be specified in the regulations of the information system.
- The refusal to communicate the requested data must be duly motivated and provided in writing. The refusal may be appealed against within thirty calendar days to the State Data Protection Inspectorate, and the reply of the State Data Protection Inspectorate may be appealed against to the court in a manner prescribed by law. Article
- Rectification, Destruction of and Restrictions on Personal Data
- If it is established that personal data are inaccurate or if their accuracy is contested or questionable, the data controller may rectify, destroy, mark or set aside such data from the accurate data, restricting their further processing. When the accuracy of data is contested, the data in documents, data records or other sources are marked with the inscription "contested data".
- Personal data shall be destroyed if: 1) they are inaccurate and if this is not against the prescribed manner of recording of data; 2) it is prohibited to record them; 3) they are not needed by the data controller in accordance with the functions he is performing, it does not have to be transferred for storage to the national archives and if this is in conformity with the provisions of the information system in which this data were used.
- The data may be destroyed only subject to the authorisation of the State Data Protection Inspectorate and the Department of Archives of Lithuania except in cases specified in subparagraphs 1 and 2 of paragraph 2, Article
- The personal data subject and other persons concerned to whom the data were communicated must be notified about the rectification and destruction of the data. Notification is not necessary if this does not affect the interests of the persons concerned.
- Instead of destruction, restrictions on the processing of data may be used provided: 1) the term set for the storage of data has not expired; 2) the destruction of documents may affect the interests of the persons concerned; 3) it is impossible to destroy the data because of a specific manner of its recording or because the destruction involves considerable expenses; 4) it is impossible to establish inaccuracy of the data when it is contested.
- The data with restrictions on its management may be used in a prescribed manner without the authorisation of its subject when this is necessary for scientific research and when it is not going to harm the data subject or third parties. In such a case the data shall be communicated without indicating the data subject (without providing data that would make it possible to identify a concrete person). Article
- Maintaining Confidentiality of Personal Data
- The data controller and the data receiver must have all the necessary facilities for ensuring confidentiality of personal data. The data must be protected from illegal recording, alteration, disclosure, dissemination, and destruction. A request provided for by law to obtain the data must be recorded in a manner prescribed by the regulations of the information system. Persons in the exercise of official functions pertaining to the organisation and collection of personal data shall give a written undertaking to protect confidentiality of personal data. Confidentiality of personal data must also be maintained by them after the termination of labour relations, throughout the whole period of legal protection of personal data unless the law provides otherwise.
- Personal data may be disclosed without the authorisation of the data subject if this is requested by: 1) entities of operational activities specified by the Law on Operational Activities; 2) the State Control; 3) institutions of prosecution service, courts, consular institutions and bodies co-ordinating them; 4) institutions of social insurance and health. Personal data shall be made available to those institutions provided they have appropriate data protection facilities; 5) institutions which, without specifying personal data subjects, carry out assignments of a general character in scientific research, economic and social planning and management effectiveness; 6) the Seimas Commission for Investigation of Economic Crimes and other institutions for purposes specified by law in a manner prescribed by this Law. Article
- Disclosure of Personal Data
- Personal data shall be disclosed under a personal data disclosure agreement between a data controller and a recipient in the form prescribed by the State Data Protection Inspectorate. The agreement must specify the purpose, conditions and manner of disclosure of personal data.
- Personal data may be disclosed to other managers and recipients of data only subject to a written consent of the data subject; in case of legal incompetence of the data subject - subject to a consent of his parents (adoptive parents) or guardians except in cases specified in paragraph 2 of Article 8 and in cases when disclosure is in conformity with the criteria of legitimate management of personal data.
- Responsibility for the correctness of personal data and legitimacy of the disclosure shall be borne by the data controller.
- Upon receipt of the data under a personal data disclosure agreement, the receiver may use it only for the purpose specified in the agreement. The data may be used for a different purpose only subject to an authorisation of the State Data Protection Inspectorate issued upon a request of the receiver of data and in accordance with the personal data disclosure agreement. The State Data Protection Inspectorate shall issue an authorisation to use personal data only in cases prescribed by law, when it is absolutely necessary or when the data subject gives his consent.
- Responsibility for the legality of use of personal data shall be borne by the receiver of data. Article
- Transmission of Personal Data to National Archives When personal data loses its practical value or when the data controller goes into liquidation, the latter must notify the State Data Protection Inspectorate and the Department of Archives of Lithuania. The Department of Archives of Lithuania shall adopt a decision on the subsequent storage of the data at the national archives or on its destruction. Article
- Communication of Personal Data to Foreign Countries
- Personal data may be communicated to foreign countries in a manner prescribed by law only subject to an authorisation of the State Data Protection Inspectorate and only if this does not infringe upon the rights of the data subject, also if the country to which the data is being communicated guarantees a proper legal protection of personal data.
- Without an authorisation of the State Data Protection Inspectorate, personal data may be communicated to foreign countries, in accordance with the guarantees laid down in paragraph 1 of this Article, pursuant to international agreements to which the Republic of Lithuania is a party. ` CHAPTER III LIABILITY Article
- Liability of Data Controllers and Individuals Data controllers and other individuals violating the requirements laid down in this Law shall be liable under law. Article
- Compensation for Material and Moral Damage
- The data subject shall be entitled to claim compensation for material damage caused during an improper storage, illegal alteration or other distortion, disclosure, dissemination of personal data or if the personal data has become inaccurate through the fault of the data controller. The data subject shall also be entitled to claim compensation for moral damage caused by such actions.
- The scope of material and moral damage shall be determined by the court. CHAPTER IV FINAL PROVISIONS Article
- Implementation of the Law
- Within half a year following the adoption of this Law, the Government of Lithuania or authorities designated by it shall adopt subordinate legislation necessary for the implementation of the norms of this Law or shall submit such draft legislation to the Seimas.
- By July 1, 1998, the Government of the Republic of Lithuania or authorities designated by it shall specify the procedure for obtaining consent of data subjects.
- By June 1, 1998, the Government of the Republic of Lithuania or authorities designated by it shall establish the procedure and plan for making information systems of personal data controllers on the State and local government levels legitimate. I promulgate this Law passed by the Seimas of the Republic of Lithuania PRESIDENT OF THE REPUBLIC ALGIRDAS BRAZAUSKAS