Performance Audit Reports

Protection of automatically processed personal data

December 11, 2013

2013-12-19

National Audit Office: there are gaps in personal data protection

Picture for National Audit Office: there are gaps in personal data protection

A number of unresolved legal, processing, supervision, information and methodological issues related to the protection of personal data have piled up over the past few years in Lithuania, like in many other EU countries. Therefore, the National Audit Office carried out an audit to assess the efficiency of the protection and supervision of automatically processed personal data.

“Auditors found a failure to fully ensure individual’s right to privacy in Lithuania. Not all requirements set for personal data protection in the law have been implemented in the public sector and the regulation of this area is lagging behind the progress in information and communication technology. In order to improve personal data protection policy, it should be based on internationally accepted principles and best practices, taking into account new technologies and operational risks and adjusting these measures to the existing legal regulation”, said Auditor Giedrė Švedienė summing up the audit results.

Although the Law on Legal Protection of Personal Data and its implementing legislation have been amended several times during the period 2008-2012, rapid development of information and communication technology continuously brings about issues of practical application of personal data protection, which are not addressed by the existing legislation. There is a lack of attention paid to the reduction of administrative burden of data managers, who have to fill out a complicated notification form and description prior to the processing of personal data. It is also necessary to improve the exchange of data in electronic form, because so far the personal identification number is the only data widely used for person's identification in the country. In addition, sanctions for violations in this area are applicable only to natural persons and penalties are small in comparison with other Baltic countries: up to LTL 2 thousand in Lithuania, up to LTL 5 thousand in Latvia, and up to LTL 110 thousand in Estonia.

After examining the implementation of personal data protection requirements by public sector data controllers and processors, the National Audit Office found that the majority (84 percent) of the audited institutions have been failing to comply with all such requirements. The data subject's right to privacy has been properly implemented only in about half (47 percent) of the audited institutions, meanwhile the remaining ones (53 percent) have not set forth ways for the implementation of the data subject’s rights and have not established specific actions and/or procedures in internal legal acts for the implementation of other personal data processing requirements, thus limiting the data subjects’ possibilities to check the implementation of their rights. The scope of personal data processing in some institutions was larger than indicated in the State Register of Personal Data Controllers. So it could happen that persons did not know what personal information was being collected and if they asked the State Data Protection Inspectorate (SDPI), they would have received information that does not comply with the personal data processing scope. Personal data protection issues would be addressed more efficiently if personal data processing requirements were harmonised with general safety requirements and monitoring devices for electronic information at the state level.

In addition, it was found that the public receives insufficient information about data protection. An analysis of the material published by the SDPI and its contents revealed that the number of publications about personal data protection prepared by the SDPI has been going down every year, so less relevant information that would be useful in protecting personal data is provided to the public. Auditors also established that electronic services developed by the SDPI before 2013 were unattractive and little used. In 2013 the SDPI improved its electronic services provided, however, not all the improvements are working smoothly.

The National Audit Office made recommendations to the Ministry of Justice and the SDPI to facilitate planning of the legal regulation of personal data protection and ensuring the protection of personal data, improving electronic service quality and availability to users.