“It is important to distinguish two things”: the Registrų centras’s message after the data theft

According to statements from Eltai regarding the Registrų centras (RC), it is important to clearly distinguish between two separate categories of information. The first relates to the public details surrounding an ongoing pre-trial investigation into a potential criminal act, a matter that falls outside the direct competence of the center. The second category pertains specifically to the personal data of the affected individuals—the data subjects—whose private information was disclosed as a result of the incident, a responsibility governed by the General Data Protection Regulation (GDPR).

The state enterprise emphasized its legal obligation to ensure that all persons whose personal data was compromised receive proper notification. Due to the sheer volume of residents potentially impacted by the data leak, the RC initiated the development of a specialized technical solution to manage and disseminate these alerts. This complex process, the center noted, required a significant allocation of time.

Furthermore, the RC provided a detailed timeline outlining the chronology of events. This chronology specified precisely when the enterprise became aware of the data breach and subsequently when it received authorization to inform the affected residents about the compromised data. This careful delineation of timelines and responsibilities underscores the regulatory adherence required when managing sensitive personal data.

The center’s communication serves to clarify the scope of its role, separating its data protection duties from external criminal proceedings.

Topics: #data #important #distinguish

Leave a Reply

Your email address will not be published. Required fields are marked *