VDAI (Lithuania) - 3R-1029

From GDPRhub
VDAI - 3R-1029
[[File:|center|250px]]
Authority: VDAI (Lithuania)
Jurisdiction: Lithuania
Relevant Law: Article 33(1) GDPR
Article 34(1) GDPR
Type: Complaint
Outcome: Upheld
Started: 17.10.2024
Decided: 05.08.2025
Published:
Fine: n/a
Parties: The Lithuanian Border Police
National Case Number/Name: 3R-1029
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Lithuanian
Original Source: VDAI (in LT)
Initial Contributor: cci

The DPA reprimanded the Border Police over its failure to report a data breach to the DPA and the affected data subject. The DPA clarified that data breaches involving identification documents entail a high risk for data subjects.

English Summary

Facts

In September 2024 the border police (the controller) stopped and fined an individual (the data subject) for driving a non-registered vehicle. Two officers uploaded a description of the data subject’s administrative offence on the border police’s Signal group along with the subject’s identity card and driver’s license. A third officer from the Signal group then forwarded the data to an unauthorized third party via Messenger.

The controller later investigated the incident and sanctioned the officer responsible for the disclosure. The controller also considered that the breach was unlikely to result in a risk to the rights and freedoms of natural persons and, therefore, that it was not necessary to notify it to the DPA or the data subject.

In the meantime, the data subject learned about the breach and filed a complaint with the DPA.

The DPA investigated the complaint and found that controller’s data policies allowed and regulated the use of Signal for internal communications but did not allow the use of Messenger.

Holding

The DPA clarified that leaks of identification documents are generally considered to be high-risk situations because the data could enable identity theft or other illegal actions data subjects. For this reason, the DPA held that the controller should have notified the data breach to both the DPA and the data subject.

The DPA reprimanded the controller for having breached Articles 33(1) and 34(1) GDPR.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.

STATE DATA PROTECTION INSPECTORATE DECISION August 5, 2025. No. 3R-1029 (2.13-1.E) Vilnius The State Data Protection Inspectorate (hereinafter referred to as the Inspectorate) received on 17 October 2024 [DATA NOT PUBLISHED] (hereinafter referred to as the Applicant) a complaint dated 02 October 2024 (Inspection reg. No. 1R-6393 (2.13.Mr)) (hereinafter referred to as the Complaint). The complaint states that an officer of the State Border Guard Service under the Ministry of the Interior of the Republic of Lithuania (hereinafter referred to as the Complainant or the State Border Guard Service) [DATA NOT TO BE PUBLISHED] (hereinafter referred to as the Complainant's Officer), using the messaging app "Messenger", illegally sent copies of the Applicant's documents and other personal data related to the Applicant to a third party (copy of the driver's license, copy of the identity card; data of the vehicle driven by the Applicant; information about the administrative offense committed by the Applicant). In the Applicant's opinion, the VSAT officers illegally processed his personal data and requests an assessment of whether the GDPR was violated1 , ADTAÿ2 or other legal acts regulating the management of personal data. The Inspectorate, having examined the Applicant's complaint within its scope, within the scope of its competence, n u s t a t ÿ, The person complained about submitted an explanation to the Inspectorate (Inspection reg. No. 1R-7733 (2.13.Mr)) (hereinafter referred to as the Explanation), which acknowledged that the Applicant's personal data had been unlawfully disclosed to a third party. Due to this personal data security breach (hereinafter referred to as the ADSP), an investigation was conducted internal service inspection, and the Complainant's officer who committed the ADSP was given a service penalty. In addition, the Complainant indicated that he had taken additional measures to ensure greater protection of personal data: 1) to tighten control over the actions of subordinate officers when working with personal data; 2) to ensure that in the group environment created by the Signal program, information related to personal data would be kept to a minimum, only to the extent necessary to ensure official functions; 3) to additionally instruct the Complainant's officers that the collection and transfer of such category of information is possible only in case of official necessity, only in permitted ways and only to those employees who have the right to dispose of it. During the official inspection conducted by the complainant, it was found that on 07-09-2024, the vehicle driven by the Applicant was stopped by officers who determined that it was not registered in accordance with the procedure established by legal acts, for which the Applicant was issued an administrative fine. On the same day, an officer of the Vilnius Border Guard Unit (hereinafter referred to as the Vilnius Border Guard Unit) of the State Border Guard Service (hereinafter referred to as the Tvereÿius Border Guard Unit) of the State Border Guard Service (hereinafter referred to as the Tvereÿius Border Guard Unit) of the State Border Guard Service (hereinafter referred to as the Tvereÿius Border Guard Unit) of the State Border Guard Service (hereinafter referred to as the VSAT) issued a notice of administrative offense committed by the Applicant. 1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the GDPR) 2 Law of the Republic of Lithuania on the Legal Protection of Personal Data Machine uploaded the description and photos of his personal documents to the messaging app Signal, which is included in the list of software approved by the order of the Commander of the Complainant and is intended only for official purposes of the Tvereÿius Police Department and for ensuring official functions, in the group - "Tvereÿius Police Department". On 08-09-2024, an officer of the Complainant forwarded the Applicant's personal data from the messaging app "Signal" to [DATA NOT PUBLISHED] (hereinafter Third party) to another messaging app "Messenger" (the app is not on the list of permitted software approved by the order of the Complainant's commander). The Complainant stated that the Complainant's officer illegally disposed of the Applicant's personal data and transferred this data to the Third Party for selfish reasons, and such an action by the Complainant's officer is to be assessed as a gross violation of personal data security, therefore, by order of the Complainant's commander, the Complainant's officer was imposed a disciplinary sanction. In turn, the Complainant's data protection officer stated that an ADSP was committed, which was registered in the Complainant's personal data security violation log on 16-09-2024, and was given reg. No. 28 (3). A notification of a personal data security violation and a personal data security violation report were also prepared. In his Explanation, the Complainant indicates that, taking into account the nature of the violation (the violation was committed when transferring personal data to a Third Party), the severity (it was assessed as low due to the content of the personal data), the duration, the issue of material or non-material damage is not raised, the transferred data does not include a large amount of personal data and did not have a significant impact on the data subject, the data was not used, the principles of accessibility, integrity and integrity were not violated, . The Complainant noted that the Inspectorate was informed of the complaint by the applicant himself, and after it was determined that the risk was assessed as low, an internal inspection was initiated on the initiative of the data controller. Article 4(12) of the GDPR provides that a personal data breach (hereinafter referred to as a Personal data breach (PDB) – a breach of security leading to the accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to, personal data transmitted, stored or otherwise processed. The actions of the data controller following a PDB are set out in Articles 33 and 34 of the GDPR. In accordance with Article 33(5) of the GDPR, the data controller shall document all PDBs, including the facts relating to the PDB, its impact and the corrective actions taken. Article 4(1) of the GDPR states that personal data means any information relating to an identified or identifiable natural person (data subject); an identifiable natural person is one who can be identified, directly or indirectly, in particular by reference to an identifier such as a name, an identification number, location data and an online identifier or to one or more factors specific to the physical, physiological, genetic, mental, economic, cultural or social identity of that natural person. Taking into account the established circumstances, the Inspectorate decides that in the case under consideration there has been ADSP (as defined in Article 4(12) of the GDPR), during which the Applicant's personal data were disclosed to a Third Party by sending them via the messaging app "Messenger". Given that ADSP has occurred, the GDPR provisions governing the management of ADSP apply. In accordance with Article 33(1) of the GDPR, in the case of an ADSP, the controller shall notify the supervisory authority without undue delay and, where feasible, no later than 72 hours after having become aware of the ADSP, unless the ADSP is unlikely to result in a risk to the rights and freedoms of natural persons. If the ADSP is not notified to the supervisory authority within 72 hours, the notification shall include: reasons for the delay are attached. Article 34 of the GDPR provides that where the processing of personal data is likely to result in a high risk to the rights and freedoms of natural persons, the controller shall communicate the processing of personal data to the data subject without undue delay. Article 34(3) of the GDPR provides that the notification referred to in paragraph 1 to the data subject shall not be required if any of the conditions referred to in paragraph 3 are met: (a) the controller has implemented appropriate technical and organisational security measures and those measures have been applied to the personal data affected by the personal data breach, in particular measures ensuring that the personal data are unintelligible to a person not authorised to have access to the personal data, such as encryption measures; (b) the controller has subsequently taken measures ensuring that the high risk to the rights and freedoms of data subjects referred to in paragraph 1 is no longer likely to arise; (c) this would involve a disproportionate effort. In such a case, a public notice shall be made instead or a similar measure shall be used to inform data subjects in an equally effective manner. Point 85 of the GDPR preamble further states that the data controller is not obliged to inform the supervisory authority about the occurrence of an ADSP if the data controller can demonstrate, on the basis of the principle of accountability, that the ADSP is unlikely to result in a risk to the rights and freedoms of natural persons. Paragraph 75 of the GDPR preamble states that risks of varying likelihood and seriousness to the rights and freedoms of natural persons may arise from the processing of personal data, which could result in material or non-material damage , in particular where the processing may lead to discrimination, identity theft or fraud, financial loss, . The Complainant claims that, taking into account the nature and severity of the breach identified, the ADSP should not pose a risk to the rights and freedoms of the Applicant. It should be noted that, according to Articles 33 and 34 of the GDPR, the data controller must assess the impact of the ADSP on the rights and freedoms of data subjects, based on objective criteria, including the nature, scope, quantity of the personal data breached, the presence of special categories of data, the possibility of identifying the data subject and the possible consequences. In the case at hand, the Complainant indicated only a subjective assessment that the breach should not pose a risk to the data subject, but did not provide arguments substantiating his claims and evidence that would allow the conclusion that the ADSP that occurred could not or will not be able to occur in the future. pose a risk to the rights and freedoms of the Applicant. Therefore, it must be concluded that the assessment submitted by the complainant is of a declarative nature and does not prove that the risk of ADSP to the rights and freedoms of the Applicant was objectively and comprehensively assessed. It should be noted that both copies of the identity card and the driver's license sending to a third party may pose a serious risk to the rights and freedoms of the data subject, since these documents contain personal data such as name, surname, personal identification number, date of birth, photo, document number, expiration date, date of issue, citizenship, signature and other information related to the data subject. Personal documents containing the aforementioned personal data, which are considered high-risk identity verification tools, used to commit a relevant illegal act, for example, identity theft or other illegal actions against the data subject, therefore it should be assessed that the ADSP that occurred may undoubtedly pose a significant risk to the rights and freedoms of natural persons. Thus, the Complainant had to comply with the obligation provided for in Article 33(1) of the GDPR, i.e. to inform the Inspectorate without undue delay about the ADSP, and also, based on Article 34(1) of the GDPR, to notify the data subject about the ADSP that occurred, but did not do so. It should be noted that the circumstance indicated by the Complainant that the Inspectorate was informed about the ADSP that occurred by the Applicant himself does not exempt the data controller from the obligations provided for in Articles 33 and 34 of the GDPR. It should also be noted that Article 34(3) of the GDPR establishes conditions under which (at least one of them) notification to the data subject is not required, however, in the case under consideration, the Complainant did not prove (did not prove) the existence of at least one of these circumstances. Taking into account the above, the Inspectorate decides that the Complainant has improperly implemented the provisions of Article 33(1) and Article 34(1) of the GDPR, therefore the Applicant's complaint is recognized as justified. In accordance with Article 31(2)(1) of the GDPR, if the complaint or part thereof is recognized as justified, the Inspectorate shall provide the data controller and/or data processor with reasoned instructions, recommendations and/or apply other measures specified in Article 58(2) of the GDPR, Article 33 of the GDPR and other laws regulating the protection of personal data and/or privacy . When deciding on the application of enforcement measures, point 129 of the GDPR preamble shall be considered relevant, which states that each measure should be appropriate, necessary and proportionate to ensure compliance with the GDPR. When deciding on imposing sanctions on the Complainant, the Inspectorate takes into account that the violation is a one-time offense (the Inspectorate has no information that the Complainant has committed more personal data security violations of a similar nature and their seriousness). was not properly assessed), i.e. the violation is not systemic. Taking into account the above, a reprimand is issued to the Complainant in accordance with Article 58(2)(b) of the GDPR. The application of other sanctions, in the opinion of the Inspectorate, would not be proportionate in the case under consideration. The Inspectorate, in accordance with Article 31(1)(1) and (2)(1) of the Act on the Protection of Personal Data, GDPR Article 58(2)(b) and having regard to the above, n u s p r e n d ž i a: 1. To declare the applicant's complaint well-founded. 2. The person complained about for violation of Article 33(1) and Article 34(1) of the GDPR to issue a reprimand. 3. To inform the Applicant and the Respondent about the decision made. This decision may be appealed to the Regional Administrative Court (address: Žygimantÿ g. 2, Vilnius) within one month from the date of its delivery, in accordance with the procedure established by the Law on Administrative Procedure of the Republic of Lithuania. Director Dijana Šinkÿnienÿ