5 Official translation GOVERNMENT OF THE REPUBLIC OF LITHUANIA RESOLUTION NO. 952 On Data Protection in The State and Munisicipal Information Systems 4 September 1997 Vilnius In order to ensure the data reliability and protection against unauthorised use, pursuant to the Law on Public Registers, Law on Legal Protection of Personal Data and taking into consideration that information systems are under constant development, the Government of the Republic of Lithuania h a s r e s o l v e d:
- To approve the General Requirements for Data Protection (attached thereto).
- To instruct t the Ministry of Informatics and Communications: 2.
- every year by 20 January to provide in the information appendix of “Valstybės žinios” the following: 2.1.
- the list of public registers registered by the Public Register Service, other information systems and their data ; 2.1.
- the list of State Managers of Personal Data registered by the State Data Protection Inspectorate; 2.
- together with the Ministry of Justice to prepare draft amendments to the Administrative Code and Criminal Code of the Republic of Lithuania as regards the administrative and criminal responsibility in the field of data protection and authorisations to investigate the cases of such violations and to submit them to the Government of the Republic of Lithuania by 31 December 1997; 2.
- by 20 October 1997, together with the Ministry of Public Administration Reforms and Local Authorities to work out a plan for legalisation of international documents on information security and European Standards according to the Lithuanian standards, to announce it in the bulletin of the Lithuanian Standardisation Department and to organise its implementation.
- By 30 November 1997, to instruct the Data Managers of state information systems to prepare special requirements for data protection measures, to submit their implementation plan to the Ministry of Informatics and Communications and appoint persons for data security.
- To provide that paragraph 8 of the General Requirements for Data Protection approved by this Resolution shall come into force from 1 January
- Prime Minister Gediminas Vagnorius Minister of Communications Algis Žvaliauskas Approved by Government of the Republic Resolution No 952 of 4 September 1997 GENERAL REQUIREMENTS FOR DATA PROTECTION
- As used in these Requirements: 1.
- information system shall mean a system for managing and retrieval of data and/or documents necessary for the operation of certain institution(s) which use information technologies: hardware, software, databases, data transfer networks and comply with the legal acts that regulate their use; 1.
- secret and top secret data shall mean data which are specified in the Law on State Secrets and their Protection of the Republic of Lithuania, also in the legal acts specifying the official secrets; 1.
- confidential data shall mean data not covered by paragraphs 1.2 of these Requirements and that can be supplied and opened following the procedure established by laws, other legal acts or legal agreements; 1.
- public data shall mean data not covered by the paragraphs 1.2 and 1.3; 1.
- level of data protection shall mean relative variable which is set by the data manager who determines data category and risk factors; 1.
- violation of data shall mean any action which may cause or has caused undesirable impact on data, information system, ownership and data subject; 1.
- impact level of data infringement shall mean relative variable set by the data manager for the assessment of damage caused by infringement of data and possible consequences; 1.
- data manager shall mean a legal entity who according to the procedure established by laws and other legal acts controls data managing offices and determines the purposes and means of the institutions managing data. In the case of Public Registers this notion corresponds to the notion of the institution in charge of register keeping; 1.
- data managing office shall mean public institution which keeps a public register or personal database, or other databases of the state or municipal information systems in accordance with the procedure established by laws or other legal acts. Data manager and data managing office may be the same legal entity; 1.
- data recipient shall mean legal or natural person to whom data are disclosed; 1.11 . network operator shall mean a legal person responsible for the functioning of the network and for data supply to the users; 1.
- data group shall mean logically related data elements complying with the standards for information classification, encrypting and contents description.
- These requirements shall apply to the databases that are administered by the keepers of public registers, personal data managers, the managers of other state and municipal information systems and data managing office. Secret and top secret data are managed and disclosed in accordance with the procedure established by laws. The procedure for non-disclosure of data constituting state secret in state and municipal institutions shall be established by the subjects of state secrets and shall give instructions to that effect to data managers.
- Data manager and data managing office shall be responsible for data reliability, lawfulness of data administration, lawfulness of disclosure of confidential data and data protection against unauthorised use unless the laws and other legal acts provide otherwise.
- Network operator together with the data manager shall be responsible for communication of data via computer networks.
- Data manager governed on the basis of the recommended standards that comply with the international standards ISO 11442, ISO/IEC TR 13335-1, ISO/TR 13569, or other recommendations shall set special requirements for data protection measures by determining: 5.
- groups of processed data (hereinafter referred to as “data”) 5.
- data categories (public, confidential, secret or top secret); 5.
- level of data protection; 5.
- risk factors of infringement of data: 5.4.
- unintentional internal and external subjective factors (mistakes and errors made while processing data, deletion of files, incorrect determination of the route while transmitting data, physical disturbances: due to power supply, computer or server viruses that damage data, and etc.); 5.4.
- deliberate subjective factors (unauthorised break into the system from the outside, deliberate infringement of legal acts, theft, etc.); 5.4.
- force majeure ; 5.
- consequences of the infringement of data (damage to or loss of property, etc.) and the level of possible data damage according to the risk factors.
- Data manager shall be governed by the recommended Lithuanian standards complying with the ISO/IEC standards of international standards “Information technology. Security technique” or other recommendations and shall establish the following procedure for the implementation of data security and the following necessary measures: 6.
- security of hardware, software, databases, premises (copying of information, uninterrupted power supply, anti-virus software, digital signature, data coding, security system for the network, keeping of records of network operations, etc.); data encrypting should be co-ordinated observing the procedure established for the state secrets if it is included in the list of state secrets; 6.
- procedure for fixing of data damages and restoration of damaged data; 6.
- techniques for control of data security and data supply; 6.
- procedure for data supply; 6.
- authorisations and rights for all data managing offices and data processors.
- Data manager shall appoint a person responsible for data protection, who organises protection of data in all data managing offices and provide State Data Protection Inspectorate and the subjects of state secrets with conditions necessary for carry out checks.
- If the information system of the public register, personal data manager or other state or municipal information system is not legalised, its development is not completed or it is not yet approved and if the laws and other legal acts do not provide for the disclosure of data to specific users, data manager has the right to apply to the State Data Protection Inspectorate for temporary permit to transfer data which may not be available to the public, to other data managers and users. This permit is the basis for the lawful disclosure of data in different forms and via computer network of public institutions. A temporary permit may be issued only after the level of protection is assessed.
- Data manager shall be concerned with the improvement of data protection system, shall review the instructions and other documents related to data protection , shall update them, and, if there are changes related to the data protection, shall submit, each year by 31 January, the reports in the prescribed form to the State Data Protection Inspectorate on data protection measures.
- Data manager shall provide data to other data managers or recipient of data in accordance with the procedure established by laws upon the agreement between parties under the contract the form of which is prescribed by the State Data Protection Inspectorate.
- Databases shall be liquidated or reorganised according to the procedure established by laws and other legal acts. where data may not be disclosed to the public The procedure for the liquidation or reorganisation must be agreed with the State Data Protection Inspectorate and where data are secret or top secret – with the State Security Department of the Republic of Lithuania.