Informacinis privatumas Lietuvos teismų sistemos veikloje kaip vienas iš konstitucinės teisės į privataus gyvenimo apsaugą aspektų
| Date |
|---|
2026 |
Asmens duomenų apsaugos koncepcija siejama su Lietuvos Respublikos Konstitucijos 22 str. nustatyta teise į žmogaus privataus gyvenimo neliečiamumą. Nacionalinėje teisėje asmens duomenų apsaugos doktrina kildinama iš šios teisės, Europos Sąjungos teisės sistemoje šios teisės atskirtos: teisė į privatų ir šeimos gyvenimą nustatyta Chartijos 7 str., o Chartijos 8 str. 1 d. įtvirtinta teisė į asmens duomenų apsaugą. Informacinis privatumas yra asmens duomenų apsaugos doktrinos sudedamoji dalis. Tvarkant asmens duomenis imta plačiai naudotis sparčiai modernėjančiomis informacinėmis technologijomis. Asmens duomenų valdytojai ir tvarkytojai pagal savo veiklos sritį ėmė kurti taisykles, kurios numatytų duomenų apsaugos technines ir organizacines priemones, siekdami užtikrinti 2016 m. balandžio 27 d. Europos Parlamento ir Tarybos reglamento (ES) 2016/679 dėl fizinių asmenų apsaugos tvarkant asmens duomenis ir dėl laisvo tokių duomenų judėjimo ir kuriuo panaikinama Direktyva 95/46/EB (Bendrasis duomenų apsaugos reglamentas) (OJ L 119, 2016-05-04) (toliau – Reglamentas arba BDAR), nuostatas. Lietuvos įstatymų leidėjas neparengė teisės principų, kurių pagrindu turėtų būti kuriamas asmens duomenų tvarkymo teisinis mechanizmas. Taisyklių sukurtą rezultatų legitimumą pirmiausia reikėtų vertinti atsižvelgiant į Konstitucinio Teismo formuojamą žmogaus privataus neliečiamumo principo doktriną. Po to atliekama patikra su Chartijos 8 str. numatytomis asmens duomenų tvarkymo garantijomis. Panašus aiškinimas pateikiamas generalinio advokato P. Cruz Villalón išvadoje sujungtose bylose C-293/12 ir C-594/12 (žr. 63–66 p.). Tačiau, kaip parodė taisyklių taikymo rezultatas, kuriant asmens duomenų apsaugos tvarkas dažnai perrašomos Reglamento nuostatos, o jų aiškinimas atliekamas formaliai, stengiantis nenukrypti nuo teisės akto nuostatų. Asmens duomenų tvarkymo teismuose taisyklių kūrimo paskata taip pat buvo Reglamentas. Kalbant apie teismuose tvarkomus asmens duomenis, pastebėtina, kad šią veiklą reguliuojančios taisyklės yra sudėtinė teismų vykdomo teisingumo dalis. Tai svarbus aspektas, keičiantis bendras asmens duomenų apsaugos taisykles. Kita vertus, Europos Sąjungos Teisingumo Teismas 2023 m. kovo 2 d. sprendime byloje Norra Stockholm Bygg C 268/21 pabrėžė, kad vadovaudamas bylos procesui nacionalinis teismas turi imtis papildomų duomenų apsaugos priemonių, kaip antai BDAR 4 str. 5 p. apibrėžto pseudonimų davimo duomenų subjektų vardams ir pavardėms ar bet kurios kitos priemonės, mažinančios teisės į duomenų apsaugą suvaržymą. Tai rodo, kad teisingumo vykdymo misija negalima pateisinti laisvo viešuose teismo posėdžiuose nagrinėjamų bylų asmens duomenų naudojimo. Atsižvelgiant į tai buvo pasirinktas tyrimo tikslas – atskleisti, ar paieškų variklių valdytojas (teismai) imasi priemonių, kad draudžiama platinti informacija apie žmogaus asmeninį gyvenimą nebūtų atskleista, o ją atskleidus, ar yra veiksmingas būdas pažeidimams pašalinti. Teismai neturėtų spręsti, neinformavę duomenų subjekto apie jo duomenų panaudojimą, ar asmens duomenų panaudojimas nepažeidžia asmens teisių ir laisvių. Pastebėtina, kad Lietuvoje dėl teisės būti pamirštam, siekiant asmens duomenų apsaugos, buvo pradėti keli teismo procesai, tačiau tokia teisė neįgyvendinta. Suprantama, teisės būti pamirštam sąvoka turi daug aspektų, ji vis dar kuriama ir, nors jos taikymas praktikoje įgijo tam tikrų skiriamųjų bruožų, teismuose dėl aukšto įrodinėjimo standarto labai sudėtinga šią teisę įgyvendinti.
The concept of personal data protection is linked to the right to privacy established in Article 22 of the Constitution of the Republic of Lithuania. While in national law the doctrine of personal data protection derives from this right, in the European Union legal system these rights are separate: the right to private and family life is established in Article 7 of the Charter, while the right to personal data protection is enshrined in Article 8(1) of the Charter. Information privacy is an integral part of the doctrine of personal data protection. Rapidly modernizing information technologies are widely used in the processing of personal data. Depending on their field of activity, personal data controllers and processors have begun to develop rules that provide for technical and organizational measures for data protection in order to ensure compliance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 Regulation (EU) 201 The Lithuanian legislature has not developed legal principles on which the rules for the processing of personal data should be based. The legitimacy of the results obtained with the help of the rules should first be assessed in light of the doctrine of the principle of personal privacy developed by the Constitutional Court. This is followed by a check against the guarantees for the processing of personal data provided for in Article 8 of the Charter. A similar interpretation is given in the opinion of Advocate General P. Cruz Villalón in joined cases C-293/12 and C-594/12 (see paragraphs 63-66). However, as the result of the application of the rules has shown, when developing procedures for the protection of personal data, the provisions of the GDPR are often rewritten and interpreted formally, in an effort not to deviate from the provisions of the law. The GDPR also provided impetus for the development of rules on the processing of personal data in courts. With regard to personal data processed by courts, it should be noted that the rules governing this activity are an integral part of the administration of justice by courts. This is an important aspect of the change in the general rules on personal data protection. On the other hand, in its judgment of 2 March 2023 in the case of Norra Stockholm Bygg, C-268/21, the Court of Justice of the European Union emphasized that, in conducting the proceedings, the national court must take additional data protection measures, such as pseudonymising the names and surnames of data subjects as defined in Article 4(5) of the GDPR, or any other measure designed to reduce the restriction of the right to data protection. This shows that the mission of administering justice cannot justify the free use of personal data in cases heard in public court hearings. Furthermore, courts should not decide whether the use of personal data violates the rights and freedoms of individuals without informing the data subject about the use of their data. It should be noted that several court proceedings have been initiated in Lithuania regarding the right to be forgotten for the purpose of personal data protection, but this right has not been implemented. Understandably, the concept of the right to be forgotten has many aspects, it is still being developed, and although its application in practice has acquired certain distinctive features, the high standard of proof required in courts makes it very difficult to implement this right.