LTschema gdpri-v2trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC
Last updated · 10 categories · 51
claims · 39 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
51Claimsbaseline..claims[]
13Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No red categories; 12 sub-modules are flagged red.
Jurisdiction brief
Standing brief, as of 25 August 2026.
Lead Signal
Lithuania's data-protection enforcement cadence is escalating even as the underlying legal framework remains stable. The State Data Protection Inspectorate's record EUR 2,385,276 fine against Vinted UAB, imposed in July 2024 for transparency and accountability violations including deficient handling of erasure requests and undisclosed shadow banning, was upheld by the Regional Administrative Court in May 2025. That confirmation on appeal removes the uncertainty that typically attaches to a first-instance fine and establishes the decision as a settled benchmark for how the VDAI expects controllers to handle data-subject erasure requests and transparency obligations going forward.
Other Developments
Breach reporting patterns. The VDAI's H1 2026 report identifies human error as the cause of 48 percent of reported personal data breaches in Lithuania, a finding that points controllers toward process and training gaps as the dominant breach vector rather than external attack or technical failure.
Breach-notification duty confirmed. Data controllers in Lithuania must notify the VDAI of personal data breaches within 72 hours, a standing GDPR-derived duty that continues to anchor the controller/processor compliance baseline.
Cross-border transfer mechanics clarified. The VDAI has clarified that Standard Contractual Clauses are optional in nature and apply specifically to data controller-processor relationships, a clarification assessed with moderate confidence from a single guidance source rather than a binding regulatory instrument.
Cross-Monitor Connections
The erasure-handling and shadow-banning findings underlying the Vinted decision touch consumer-facing digital-platform practices that may also be of interest to the artificial-intelligence monitor to the extent algorithmic ranking or account-visibility decisions were implicated, though that algorithmic dimension is not re-analysed here. The forthcoming EU cross-border GDPR enforcement cooperation regulation, applicable from April 2027, is a structural development relevant to any monitor tracking EU-level regulatory-cooperation architecture, including financial-integrity's own tracking of the parallel AMLA supervisory-cooperation build-out; the two are separate instruments but part of the same broader EU trend toward centralised, cooperative enforcement mechanisms.
Outlook
Watch for further decisions applying the erasure-handling and transparency standard established by the Vinted case, and for whether the human-error-driven breach pattern identified in the H1 2026 report prompts any enforcement or guidance response from the VDAI. The EU cross-border GDPR enforcement cooperation regulation, applicable from April 2027, remains a multi-year horizon item rather than a near-term operational change, but its eventual application will alter how VDAI cooperates with counterpart authorities on cross-border cases.
trust tier: ai_unverified
Standing brief, as of 25 August 2026.
Regulatory Status
Lithuania's data-protection framework remains anchored in GDPR with the VDAI as supervisory authority, but this cycle is defined by an escalating enforcement cadence rather than framework change. The Regional Administrative Court's May 2025 confirmation of the VDAI's EUR 2,385,276 fine against Vinted UAB, for transparency violations including deficient erasure-request handling, establishes a settled enforcement benchmark. The 72-hour breach-notification duty for controllers remains confirmed and operative, while the VDAI's H1 2026 breach report identifies human error as the cause of 48 percent of reported breaches. On cross-border transfers, the VDAI has clarified that SCCs are optional and specific to controller-processor relationships, and a new EU cross-border enforcement cooperation regulation will apply from April 2027.
Outlook
Watch for further enforcement decisions building on the Vinted erasure-handling standard, for any guidance response to the human-error breach pattern, and for preparatory developments ahead of the April 2027 cross-border enforcement cooperation regulation's application.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Comprehensive, mature GDPR-aligned framework with an active, EDPB-participating supervisory authority and no material derogation gaps identified.
Primary frameworkGeneral Data Protection Regulation (EU) 2016/679, as implemented by Law No XIII-1426 of 30 June 2018 amending Law No I-1374 (Law on Legal Protection of Personal Data)
Traffic-light rationale — GreenComprehensive, mature GDPR-aligned framework with an active, EDPB-participating supervisory authority and no material derogation gaps identified.
Sub-modules (5)
Regulator And AuthorityGreen
VDAI is the single national supervisory authority under GDPR Art. 51, participating in the EDPB.
Claims (1):
<cite index="6-1,6-2">The State Data Protection Inspectorate, located at L. Sapiegos str. 17, 10312 Vilnius, Lithuania, is listed as the national supervisory authority with contact reachable via ada@ada.lt.</cite>
Act And InstrumentsGreen
GDPR is directly applicable; national implementation is via Law No XIII-1426/2018 amending the Law on Legal Protection of Personal Data.
Claims (1):
<cite index="1-1">Lithuania implemented the GDPR through Law No XIII-1426 of 30 June 2018 amending Law No I-1374, together with the General Data Protection Regulation (Regulation (EU) 2016/679).</cite>
Material ScopeGreen
Material scope follows GDPR: covers processing by private-sector and most public-sector bodies.
Claims (1):
<cite index="67-8">The GDPR ensures protection of natural persons where their data is processed by the private sector and by most public-sector entities.</cite>
Territorial ScopeGreen
GDPR extraterritorial reach applies: non-EU established entities offering goods/services to, or monitoring, Lithuania-based data subjects are in scope.
Claims (1):
<cite index="67-31">Non-EU established companies must apply the same GDPR rules with regard to the offering of goods or services and the monitoring of the behaviour of persons living in the EU.</cite>
Regulator Registration And FilingAmber
No general notification regime; controllers/processors must communicate DPO contact details to VDAI where a DPO is appointed.
Claims (1):
<cite index="1-7,1-8">Article 37 GDPR obliges controllers and processors meeting DPO thresholds to designate a DPO, publish the DPO's contact details, and communicate them to the relevant supervisory authority.</cite>
Category narrative41 words
Lithuania is an EU Member State fully subject to the GDPR, supervised by the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, 'VDAI'), and implementing GDPR via a national amending law to the pre-existing Law on Legal Protection of Personal Data.
Sources and claims (5)
ConfirmedEDPB — <cite index="6-1,6-2">The State Data Protection Inspectorate, located at L. Sapiegos str. 17, 10312 Vilnius, Lithuania, is listed as the national supervisory authority with contact reachable via ada@ada.lt.</cite>observed
ConfirmedDataGuidance — <cite index="1-1">Lithuania implemented the GDPR through Law No XIII-1426 of 30 June 2018 amending Law No I-1374, together with the General Data Protection Regulation (Regulation (EU) 2016/679).</cite>observed
ConfirmedEUR-Lex — <cite index="67-8">The GDPR ensures protection of natural persons where their data is processed by the private sector and by most public-sector entities.</cite>observed
ConfirmedEUR-Lex — <cite index="67-31">Non-EU established companies must apply the same GDPR rules with regard to the offering of goods or services and the monitoring of the behaviour of persons living in the EU.</cite>observed
ConfirmedDataGuidance — <cite index="1-7,1-8">Article 37 GDPR obliges controllers and processors meeting DPO thresholds to designate a DPO, publish the DPO's contact details, and communicate them to the relevant supervisory authority.</cite>observed
Traffic-light rationale — GreenNo national derogation weakening GDPR standards identified; VDAI enforcement activity on biometric data confirms an active special-categories regime.
Sub-modules (4)
Lawful BasesGreen
Standard GDPR Art. 6(1) bases apply (consent, contract, legal obligation, vital interests, public task, legitimate interests).
Claims (1):
<cite index="69-6">Data controllers can only process personal data lawfully where one of the enumerated legal bases in Article 6 GDPR applies, such as consent, contract, legal obligation, public interest, or legitimate interests.</cite>
Consent ThresholdsGreen
Consent must be freely given, specific, informed and unambiguous per Art. 7 GDPR.
Claims (1):
<cite index="69-9">Where consent is used as a legal basis, controllers must ensure the consent is freely given, informed, specific and unambiguous.</cite>
Special CategoriesAmber
VDAI has prioritised biometric-data enforcement (including in sports contexts) and issued recommendations on criminal-record data processing by employers.
Claims (2):
<cite index="1-3">Areas of focus for VDAI have included biometric data, as indicated by its thorough review of the use of biometric data in sports.</cite>
<cite index="1-26">VDAI's Recommendation outlines when and how employers in Lithuania can process criminal record data.</cite>
Pseudonymisation And AnonymisationGreen
GDPR promotes pseudonymisation and encryption as risk-mitigation techniques; no LT-specific safe-harbour beyond the Regulation was identified.
Claims (1):
<cite index="67-35">To limit the risks of data processing, use of pseudonyms (replacing identifying fields with artificial identifiers) and encryption is promoted.</cite>
Category narrative28 words
Lawful bases and consent standards follow GDPR Art. 6/7 directly. VDAI has issued sector guidance on special-category data (biometric, criminal-record) reflecting active supervisory focus on Art. 9/10 categories.
Sources and claims (5)
ConfirmedEDPB — <cite index="69-6">Data controllers can only process personal data lawfully where one of the enumerated legal bases in Article 6 GDPR applies, such as consent, contract, legal obligation, public interest, or legitimate interests.</cite>observed
ConfirmedEDPB — <cite index="69-9">Where consent is used as a legal basis, controllers must ensure the consent is freely given, informed, specific and unambiguous.</cite>observed
ProbableDataGuidance — <cite index="1-3">Areas of focus for VDAI have included biometric data, as indicated by its thorough review of the use of biometric data in sports.</cite>observed
ProbableDataGuidance — <cite index="1-26">VDAI's Recommendation outlines when and how employers in Lithuania can process criminal record data.</cite>observed
ConfirmedEUR-Lex — <cite index="67-35">To limit the risks of data processing, use of pseudonyms (replacing identifying fields with artificial identifiers) and encryption is promoted.</cite>observed
Traffic-light rationale — GreenRights framework is directly GDPR-derived and actively enforced; no LT-specific narrowing identified.
Sub-modules (5)
Access RightAmber
VDAI found Vinted failed to properly evidence action taken on access requests.
Claims (1):
<cite index="32-4">The Lithuanian SA found that the company also failed to demonstrate that it had taken or refused to act in accordance with the applicant's request for the right of access.</cite>
Rectification And ErasureAmber
VDAI enforcement covers both erasure-request handling (Vinted) and data-accuracy/rectification duties (Vilnius Municipality).
Claims (2):
<cite index="32-1">Lithuanian SA found the company, in response to erasure requests, stated it would not act on a specific request because the applicant did not identify a specific reason under Article 17(1) GDPR and failed to identify all purposes of continued processing.</cite>
<cite index="17-4">A fine was imposed for infringements of Articles 5(1)(d) and 5(1)(f) GDPR for failure to implement appropriate technical and organisational measures ensuring accuracy of processed personal data.</cite>
<cite index="28-11">Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person or important public interest.</cite>
Data PortabilityGreen
Standard Art. 20 portability right applies without LT-specific modification.
Claims (1):
<cite index="67-5,67-6">Data subjects have easier access to their data and a right to data portability, allowing personal data to be transferred more easily between service providers.</cite>
Deadlines And Response WindowsGreen
Controllers must respond within the GDPR's one-month (extendable by two months) statutory deadline.
Claims (1):
<cite index="89-6">Article 12(3) of the GDPR provides that organizations need to respond to data subject requests without undue delay and in any event within one month of receipt of the request.</cite>
Category narrative25 words
Data subject rights follow GDPR Arts. 15-22 directly. VDAI enforcement against Vinted (access/erasure) and against Vilnius Municipality (accuracy/rectification) demonstrates active application of these rights domestically.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (6)
ConfirmedEDPB / VDAI — <cite index="32-4">The Lithuanian SA found that the company also failed to demonstrate that it had taken or refused to act in accordance with the applicant's request for the right of access.</cite>observed
ConfirmedEDPB / VDAI — <cite index="32-1">Lithuanian SA found the company, in response to erasure requests, stated it would not act on a specific request because the applicant did not identify a specific reason under Article 17(1) GDPR and failed to identify all purposes of continued processing.</cite>observed
ConfirmedEDPB / VDAI — <cite index="17-4">A fine was imposed for infringements of Articles 5(1)(d) and 5(1)(f) GDPR for failure to implement appropriate technical and organisational measures ensuring accuracy of processed personal data.</cite>observed
ConfirmedEUR-Lex — <cite index="28-11">Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person or important public interest.</cite>observed
ConfirmedEUR-Lex — <cite index="67-5,67-6">Data subjects have easier access to their data and a right to data portability, allowing personal data to be transferred more easily between service providers.</cite>observed
ConfirmedIAPP — <cite index="89-6">Article 12(3) of the GDPR provides that organizations need to respond to data subject requests without undue delay and in any event within one month of receipt of the request.</cite>observed
Traffic-light rationale — GreenCore duties are directly GDPR-derived and actively supervised; retention/disposal sub-module lacks a confirmed LT-specific instrument.
Sub-modules (7)
Accountability And DpiaAmber
VDAI adopted a national DPIA list under Art. 35(4), reviewed and partly revised following EDPB Opinion 13/2018.
Claims (2):
<cite index="91-1">Lithuania's SA adopted a list of the kind of processing operations which are subject to the requirement for a Data Protection Impact Assessment under Article 35(4) GDPR, per EDPB Opinion 13/2018.</cite>
<cite index="94-6">DPIA is mandatory for processing of genetic data only while evaluating the data subject's features or scoring, including profiling and forecasting, following revision of the initial blacklist.</cite>
Dpo RequirementsAmber
Art. 37 DPO designation applies; VDAI inspections have identified DPO role-conflict issues in practice.
Claims (1):
<cite index="33-10">VDAI's inspection results reveal DPO role conflicts and emphasize the need for GDPR compliance audits.</cite>
Ropa RequirementsGreen
VDAI has published guidance/recommendations on records of processing activities.
Claims (1):
<cite index="12-7">In 2018-19, Lithuania's DPA released numerous guidelines and recommendations including recommendations for the records of processing activities.</cite>
Joint Controller ArrangementsGreen
Standard Art. 26 joint-controller allocation-of-responsibility rule applies.
Claims (1):
<cite index="61-15,61-16">Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers and must transparently determine their respective responsibilities by mutual arrangement.</cite>
Security MeasuresAmber
VDAI has fined controllers for inadequate technical/organisational security measures under Art. 32.
Claims (1):
<cite index="4-5">VDAI considered that the Center for Registers had not implemented adequate technical and organisational measures, acting in contravention of Article 32 GDPR.</cite>
<cite index="83-5">In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.</cite>
<cite index="41-5">VDAI reports 116 data breaches in early 2025, mostly due to human error and cyber incidents, affecting 168,822 individuals.</cite>
Retention And DisposalRed
No LT sector-specific retention/disposal statute beyond the GDPR storage-limitation principle was located in this research pass.
Accountability, DPIA, DPO, ROPA, joint-controller, security and breach-notification duties follow GDPR directly. VDAI has published a national DPIA 'blacklist' under Art. 35(4), and has fined controllers for security failures (Art. 32). Retention/disposal rules are governed by the general storage-limitation principle; no LT sector-specific retention statute was identified.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (8)
ConfirmedEDPB — <cite index="91-1">Lithuania's SA adopted a list of the kind of processing operations which are subject to the requirement for a Data Protection Impact Assessment under Article 35(4) GDPR, per EDPB Opinion 13/2018.</cite>observed
ConfirmedIAPP — <cite index="94-6">DPIA is mandatory for processing of genetic data only while evaluating the data subject's features or scoring, including profiling and forecasting, following revision of the initial blacklist.</cite>observed
ProbableDataGuidance — <cite index="33-10">VDAI's inspection results reveal DPO role conflicts and emphasize the need for GDPR compliance audits.</cite>observed
ProbableIAPP — <cite index="12-7">In 2018-19, Lithuania's DPA released numerous guidelines and recommendations including recommendations for the records of processing activities.</cite>observed
ConfirmedEUR-Lex — <cite index="61-15,61-16">Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers and must transparently determine their respective responsibilities by mutual arrangement.</cite>observed
ConfirmedDataGuidance — <cite index="4-5">VDAI considered that the Center for Registers had not implemented adequate technical and organisational measures, acting in contravention of Article 32 GDPR.</cite>observed
ConfirmedEUR-Lex — <cite index="83-5">In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.</cite>observed
ConfirmedDataGuidance — <cite index="41-5">VDAI reports 116 data breaches in early 2025, mostly due to human error and cyber incidents, affecting 168,822 individuals.</cite>observed
Traffic-light rationale — AmberFramework is sound (GDPR Chapter V) but LT-specific TIA practice and confirmation of any localisation rules could not be fully verified in this pass.
Sub-modules (6)
Transfer MechanismsGreen
VDAI guidance recommends SCCs or BCRs as the operative transfer mechanisms for third-country transfers.
Claims (1):
<cite index="80-3">VDAI recommended that Lithuanian companies ensure the lawfulness of data transfers by determining the types of personal data transferred and assessing available bases such as Standard Contractual Clauses or Binding Corporate Rules.</cite>
Adequacy ReceivedGreen
Adequacy determinations are adopted at EU level and apply uniformly across Member States; Lithuania does not issue separate national adequacy findings.
Claims (1):
Adequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.
Adequacy GrantedGreen
Adequacy decisions regarding third countries are an EU Commission competence, not a Lithuanian national act.
Claims (1):
Adequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.
Sccs And BcrsGreen
VDAI has issued guidance clarifying the optional nature of the EU SCCs for controller-processor relationships.
Claims (1):
<cite index="11-21">Lithuania's VDAI clarifies the use of EU SCCs, highlighting their optional nature and specific applicability to data controller-processor relationships.</cite>
Transfer Impact AssessmentAmber
VDAI's Brexit FAQ recommended Lithuanian companies assess transfer bases irrespective of any adequacy decision, consistent with post-Schrems II TIA practice.
Claims (1):
<cite index="80-2,80-3">VDAI highlighted that upon expiry of the Brexit transitional period, Lithuanian companies should implement mechanisms ensuring lawfulness of transfers to the UK as a third country, regardless of any adequacy decision.</cite>
Data LocalisationRed
No general LT-specific data-localisation mandate was identified in this research pass beyond GDPR Chapter V.
As an EU Member State, Lithuania relies on GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, derogations); adequacy decisions are an EU-level competence and not issued/received bilaterally by Lithuania. VDAI has issued practical guidance (e.g. on Brexit-related transfers and SCC use) but no LT-specific data-localisation mandate was found.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (4)
ProbableDataGuidance — <cite index="80-3">VDAI recommended that Lithuanian companies ensure the lawfulness of data transfers by determining the types of personal data transferred and assessing available bases such as Standard Contractual Clauses or Binding Corporate Rules.</cite>observed
ConfirmedEUR-Lex — Adequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.observed
ProbableDataGuidance — <cite index="11-21">Lithuania's VDAI clarifies the use of EU SCCs, highlighting their optional nature and specific applicability to data controller-processor relationships.</cite>observed
ProbableDataGuidance — <cite index="80-2,80-3">VDAI highlighted that upon expiry of the Brexit transitional period, Lithuanian companies should implement mechanisms ensuring lawfulness of transfers to the UK as a third country, regardless of any adequacy decision.</cite>observed
Traffic-light rationale — AmberCore sectors (telecoms, employment, health, credit) are covered by guidance or investigation; education and insurance sub-modules show a coverage gap.
Sub-modules (7)
Financial Sector OverlayAmber
VDAI opened an investigation into fintech Revolut over a data breach affecting over 50,000 customers.
Claims (1):
<cite index="1-14">VDAI investigates Revolut for a data breach affecting over 50,000 customers, assessing GDPR violations.</cite>
Health Sector OverlayGreen
VDAI issued FAQs on employer collection of employee health data under the Civil Service Law and GDPR Art. 5.
Claims (1):
<cite index="5-4">Employers must ensure health data collection is necessary, use less intrusive means, and process data according to GDPR Article 5.</cite>
Telecoms And EprivacyGreen
ePrivacy obligations are transposed via the Law on Electronic Communications No. IX-2135 alongside GDPR.
Claims (1):
<cite index="78-1">In addition to Law No XIII-1426 and the GDPR, the Law on Electronic Communications of 15 April 2004, No. IX-2135, as amended, applies to e-marketing in Lithuania.</cite>
Employment DataGreen
VDAI published three separate guides addressing employee, business, and public-sector employment data protection.
Claims (1):
<cite index="3-3">VDAI published three guides: one for employees, one for businesses, and one for the public sector, all in the context of employment relations.</cite>
Credit And ScoringGreen
VDAI issued a recommendation on the processing of debtors' personal data covering lawful grounds and limits on data subject rights.
Claims (1):
<cite index="2-4">The VDAI recommendation on debtors' data outlines data processing principles, lawful grounds, and roles of parties, emphasizing that data subject rights do not affect debtors' contractual obligations.</cite>
EducationRed
No LT-specific education-sector data-protection instrument was identified beyond general GDPR application (illustrated indirectly by the children's-camp consent case).
Sectoral overlays are thin in Lithuania beyond GDPR: telecoms/eprivacy is transposed via the Law on Electronic Communications; VDAI has issued employment and health-sector guidance; a fintech (Revolut) breach investigation illustrates financial-sector overlap. No LT-specific education or insurance-sector DP rules were found.
Sources and claims (5)
ProbableDataGuidance — <cite index="1-14">VDAI investigates Revolut for a data breach affecting over 50,000 customers, assessing GDPR violations.</cite>observed
ConfirmedDataGuidance — <cite index="5-4">Employers must ensure health data collection is necessary, use less intrusive means, and process data according to GDPR Article 5.</cite>observed
ConfirmedDataGuidance — <cite index="78-1">In addition to Law No XIII-1426 and the GDPR, the Law on Electronic Communications of 15 April 2004, No. IX-2135, as amended, applies to e-marketing in Lithuania.</cite>observed
ConfirmedDataGuidance — <cite index="3-3">VDAI published three guides: one for employees, one for businesses, and one for the public sector, all in the context of employment relations.</cite>observed
ProbableDataGuidance — <cite index="2-4">The VDAI recommendation on debtors' data outlines data processing principles, lawful grounds, and roles of parties, emphasizing that data subject rights do not affect debtors' contractual obligations.</cite>observed
Traffic-light rationale — AmberCookie and direct-marketing rules are covered; opt-out-signal and clean-room concepts are not applicable/found under the EU framework.
Sub-modules (6)
Cookies And TrackersGreen
VDAI has issued cookie-compliance guidance emphasising user-friendly consent design.
Claims (1):
<cite index="1-21">Lithuania's VDAI outlines cookie practices for compliance with GDPR and user-friendly design.</cite>
Dark PatternsAmber
VDAI's Vinted decision found 'shadow blocking' practices unlawful for violating fairness and transparency principles, functioning as a dark-pattern precedent.
Claims (1):
<cite index="32-2,32-3">The company unlawfully, in violation of the principles of fairness and transparency, processed personal data in the context of 'shadow blocking', i.e. processing intended to make a user leave the platform without being aware of it.</cite>
Opt Out SignalsRed
No LT-specific Global Privacy Control/DAA-equivalent opt-out signal regime was identified; not a feature of the EU consent-based model.
The CPRA 'sale'/'share' construct has no direct EU/LT analogue; GDPR consent and legitimate-interest rules govern comparable adtech processing instead.
VDAI guidance addresses direct marketing scope and consent/third-party-data requirements, including in the public sector.
Claims (1):
<cite index="9-4,9-5">VDAI guidance clarifies that direct marketing includes inquiries about opinions on goods or services, including via post, telephone, or other direct means to subscribers or users of electronic communications services.</cite>
Category narrative37 words
Cookie consent and direct-marketing rules follow GDPR/ePrivacy transposition. VDAI's Vinted enforcement establishes a precedent against non-transparent 'shadow blocking' practices analogous to dark patterns. No CPRA-style 'sale/share' concept or GPC-equivalent opt-out signal regime exists in this EU jurisdiction.
Sources and claims (3)
ProbableDataGuidance — <cite index="1-21">Lithuania's VDAI outlines cookie practices for compliance with GDPR and user-friendly design.</cite>observed
ConfirmedEDPB / VDAI — <cite index="32-2,32-3">The company unlawfully, in violation of the principles of fairness and transparency, processed personal data in the context of 'shadow blocking', i.e. processing intended to make a user leave the platform without being aware of it.</cite>observed
ConfirmedDataGuidance — <cite index="9-4,9-5">VDAI guidance clarifies that direct marketing includes inquiries about opinions on goods or services, including via post, telephone, or other direct means to subscribers or users of electronic communications services.</cite>observed
Biometric/genetic governance is documented; ADM-transparency and state-surveillance-carveout sub-modules rely on general GDPR text without LT-specific enforcement examples.
Primary frameworkGDPR Arts. 9, 22, 35; VDAI DPIA Order of 14 March 2019
Traffic-light rationale — AmberBiometric/genetic governance is documented; ADM-transparency and state-surveillance-carveout sub-modules rely on general GDPR text without LT-specific enforcement examples.
Sub-modules (6)
Profiling RestrictionsAmber
DPIA is required for genetic-data processing used for profiling/scoring/forecasting individuals.
Claims (1):
<cite index="94-6">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>
Automated Decision Making TransparencyRed
No LT-specific Art. 22 ADM enforcement precedent was located in this research pass; GDPR Art. 22 applies directly as EU law.
VDAI has publicly warned about AI tool risk (DeepSeek) and issued FAQ guidance for organisations starting AI system deployments.
Claims (2):
<cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or to think carefully about how they use it, citing insufficient information about its privacy practices.</cite>
<cite index="66-8">VDAI's FAQ guides organizations on starting with AI systems, emphasizing GDPR compliance and expert involvement.</cite>
Biometric RegimeAmber
Lithuania's DPIA list treats standalone biometric-identification processing as a DPIA trigger; VDAI fined a sports-club operator for unlawful biometric processing.
Claims (2):
<cite index="95-7,95-8">Lithuania's SA list stated that biometric-data processing on its own would create the obligation to perform a DPIA; the EDPB requested amendment so that biometric processing to uniquely identify a person requires a DPIA only in conjunction with at least one other criterion.</cite>
<cite index="1-13">Praktiškas was fined €6,000 for GDPR violations related to biometric data processing at its sports clubs.</cite>
Genetic DataGreen
Genetic-data DPIA obligation was narrowed to profiling/scoring contexts after EDPB review of the initial 2018 list.
Claims (1):
<cite index="94-6">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>
State Surveillance CarveoutsGreen
GDPR permits Member State law to restrict certain data-subject rights and obligations for criminal-law-enforcement and public-security purposes.
Claims (1):
<cite index="83-11">Union or Member State law may restrict the scope of certain GDPR obligations and rights where necessary to safeguard the prevention, investigation, detection or prosecution of criminal offences, public security, or other important objectives of general public interest.</cite>
Category narrative42 words
Lithuania's DPIA 'blacklist' treats biometric- and genetic-data processing as DPIA triggers (partially revised after EDPB opinion). VDAI has fined a biometric-data controller and issued a public AI-risk warning regarding DeepSeek. No LT-specific Art. 22 ADM enforcement precedent was located in this pass.
Sources and claims (6)
ConfirmedIAPP — <cite index="94-6">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>observed
ConfirmedIAPP — <cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or to think carefully about how they use it, citing insufficient information about its privacy practices.</cite>observed
ProbableDataGuidance — <cite index="66-8">VDAI's FAQ guides organizations on starting with AI systems, emphasizing GDPR compliance and expert involvement.</cite>observed
UncertainIAPP — <cite index="95-7,95-8">Lithuania's SA list stated that biometric-data processing on its own would create the obligation to perform a DPIA; the EDPB requested amendment so that biometric processing to uniquely identify a person requires a DPIA only in conjunction with at least one other criterion.</cite>observed
ConfirmedDataGuidance — <cite index="1-13">Praktiškas was fined €6,000 for GDPR violations related to biometric data processing at its sports clubs.</cite>observed
ConfirmedEUR-Lex — <cite index="83-11">Union or Member State law may restrict the scope of certain GDPR obligations and rights where necessary to safeguard the prevention, investigation, detection or prosecution of criminal offences, public security, or other important objectives of general public interest.</cite>observed
Core Art. 8 framework applies but the exact Lithuanian national age-of-consent derogation (if any) could not be confirmed; education-settings and dependent-adults sub-modules lack dedicated LT instruments.
Traffic-light rationale — AmberCore Art. 8 framework applies but the exact Lithuanian national age-of-consent derogation (if any) could not be confirmed; education-settings and dependent-adults sub-modules lack dedicated LT instruments.
Sub-modules (5)
Age VerificationAmber
Controllers must make reasonable efforts to verify parental-responsibility-holder consent for children below the applicable age threshold.
Claims (1):
<cite index="61-8">The controller shall, taking into account available technologies, make reasonable efforts to verify that consent has been given or authorised by the holder of parental responsibility over the child.</cite>
Parental ConsentAmber
GDPR Art. 8 defaults to 16 as the age at which a child may consent to information-society services directly; Member States may lower this to no less than 13. No LT-specific derogation was confirmed in this pass.
Claims (1):
<cite index="69-2,69-3">Children aged 16 and above are considered able to give their own consent; for children below 16, the organisation must request consent from that child's legal guardian or parent, absent a lower national threshold.</cite>
Minor Profiling BansAmber
VDAI found a children's-camp organiser's consent mechanism for processing children's image data did not meet GDPR consent conditions (freely given, specific, revocable).
Claims (1):
<cite index="45-13,45-14">The organisation's processing of children's image data without GDPR-compliant consent, including failure to allow free choice or withdrawal without detriment, infringed the principle of lawfulness and the conditions of consent under Articles 5(1)(a), 6 and 7 GDPR.</cite>
Education SettingsRed
No dedicated LT education-sector children's-data instrument was identified beyond the general consent enforcement precedent noted above.
GDPR Art. 8 sets a default digital-consent age of 16 with Member State discretion to lower to no less than 13; no confirmed Lithuanian national derogation was found in this research pass, so the GDPR default is presumed to apply. VDAI enforcement against a children's-camp operator illustrates active supervision of consent for minors' image data.
Sources and claims (3)
ConfirmedEUR-Lex — <cite index="61-8">The controller shall, taking into account available technologies, make reasonable efforts to verify that consent has been given or authorised by the holder of parental responsibility over the child.</cite>observed
UncertainEDPB — <cite index="69-2,69-3">Children aged 16 and above are considered able to give their own consent; for children below 16, the organisation must request consent from that child's legal guardian or parent, absent a lower national threshold.</cite>observed
ConfirmedEDPB / VDAI — <cite index="45-13,45-14">The organisation's processing of children's image data without GDPR-compliant consent, including failure to allow free choice or withdrawal without detriment, infringed the principle of lawfulness and the conditions of consent under Articles 5(1)(a), 6 and 7 GDPR.</cite>observed
Traffic-light rationale — GreenEnforcement powers and recent activity are well evidenced; funding/capacity and collective-redress sub-modules lack confirmed LT-specific detail.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
VDAI can impose fines up to the GDPR statutory maxima of €20 million or 4% of global annual turnover, whichever is higher.
Claims (1):
<cite index="102-1">A supervisory authority can impose fines that go up to a maximum of 20 million or 4% of total worldwide annual turnover in the previous financial year for breaches such as unlawful processing or breaches of data subject rights.</cite>
Enforcement Activity IndexAmber
Notable 2021-2024 fines include Vinted (€2.38M, 2024), Vilnius Municipality (€15,000, 2021) and State Enterprise Centre of Registers (€15,000, 2021).
Claims (3):
<cite index="32-10">In fining Vinted, the Lithuanian SA relied on EDPB Guidelines 04/2022 on calculation of administrative fines, taking into account the cross-border scope of processing, the large number of data subjects affected, and the duration of the infringements.</cite>
<cite index="17-2">A fine in the amount of EUR 15,000 was imposed on Vilnius City Municipality Administration for improperly processed personal data of the parents of an adopted child.</cite>
<cite index="4-1">VDAI fined the State Enterprise Center for Registers €15,000 for implementing inadequate technical and organisational measures for data security.</cite>
Regulator Funding And CapacityRed
No confirmed data on VDAI's budget or headcount was located in this research pass.
GDPR Art. 80 permits representative actions by not-for-profit bodies on behalf of data subjects; no LT-specific implementing detail was confirmed in this pass.
VDAI decisions are subject to judicial appeal, evidencing an available private right of action/judicial remedy route.
Claims (1):
<cite index="17-16">The decision of the SDPI is not effective and may be appealed against to the court.</cite>
Recent Developments 180DAmber
Within the last 180 days, VDAI's public warning regarding DeepSeek's data practices reflects the most notable documented development.
Claims (1):
<cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or think carefully about how they use it, citing insufficient information about its privacy practices.</cite>
Category narrative63 words
VDAI actively exercises GDPR Art. 83 fining powers, with a notable escalation to a €2.38M fine against Vinted in 2024 alongside multiple smaller fines (Vilnius Municipality, State Enterprise Centre of Registers, Praktiškas). Judicial appeal of VDAI decisions is available. Regulator funding/capacity data and collective-redress mechanisms were not confirmed in this pass; the most recent notable development is VDAI's 2026 public warning on DeepSeek.
No new data since the standing brief. 1 periodic run re-emitted it unchanged.
Sources and claims (6)
ConfirmedEDPB — <cite index="102-1">A supervisory authority can impose fines that go up to a maximum of 20 million or 4% of total worldwide annual turnover in the previous financial year for breaches such as unlawful processing or breaches of data subject rights.</cite>observed
ConfirmedEDPB / VDAI — <cite index="32-10">In fining Vinted, the Lithuanian SA relied on EDPB Guidelines 04/2022 on calculation of administrative fines, taking into account the cross-border scope of processing, the large number of data subjects affected, and the duration of the infringements.</cite>observed
ConfirmedEDPB / VDAI — <cite index="17-2">A fine in the amount of EUR 15,000 was imposed on Vilnius City Municipality Administration for improperly processed personal data of the parents of an adopted child.</cite>observed
ConfirmedDataGuidance — <cite index="4-1">VDAI fined the State Enterprise Center for Registers €15,000 for implementing inadequate technical and organisational measures for data security.</cite>observed
ConfirmedEDPB / VDAI — <cite index="17-16">The decision of the SDPI is not effective and may be appealed against to the court.</cite>observed
ConfirmedIAPP — <cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or think carefully about how they use it, citing insufficient information about its privacy practices.</cite>observed
No categories match.
Filters combine as OR inside a group and AND across
groups.
Publication gate
No failing checks.
schema_valid
pass
min_t1_per_instrument_met
n/a — no subject in this jurisdiction
min_quoted_text_present
waived — floor 0%
translation_provenance_recorded
n/a — no subject in this jurisdiction
egress_verified
pass
source_tier_integrity_ok
pass
jurisdiction_source_floor_met
pass
tier_a_b_national_primary_pct
46.88
aggregator_only_jurisdiction_count
0
manual_override
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Lithuania
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
no reviewer on record
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 51 claim(s) (51 category placement(s)), 39 source(s) in the cumulative register.
Regulator identity, GDPR/national-law framework, lawful bases, breach notification, DPIA list, and enforcement-activity modules rest on T1 (EUR-Lex, EDPB official registers/news, VDAI order text) and T2 (EDPB-published national-authority decisions) sources with high confidence. Sectoral overlays (telecoms/eprivacy, employment, health, credit) and adtech/dark-pattern findings rely primarily on T3 secondary commentary (DataGuidance, IAPP, CNIL) summarizing official VDAI/EDPB actions, which is treated as Probable/Confirmed depending on corroboration. Education, insurance, dependent-adults, opt-out-signal, clean-room, cross-context-advertising, data-localisation, regulator-funding, and collective-redress sub-modules returned no LT-specific instrument in this pass and are marked red with explicit absent_field_provenance. The exact Lithuanian national derogation (if any) on the GDPR Art. 8 child-consent age threshold could not be confirmed and is flagged Uncertain.
Unresolved questions (6):
Has Lithuania enacted a national derogation lowering the GDPR Article 8 default digital-consent age below 16 (as permitted down to 13)?
Was VDAI's 2019 DPIA 'blacklist' formally amended to align with the EDPB's request to limit standalone biometric- and genetic-data DPIA triggers to combination-with-other-criteria cases, and if so, on what date?
What is VDAI's current annual budget and staffing/headcount, relevant to assessing regulator capacity?
Does Lithuania have any implementing detail for GDPR Article 80 representative/collective-redress actions beyond the general Regulation text?
Is there a dedicated Lithuanian education-sector or insurance-sector data-protection instrument not surfaced by this research pass?
What was the final outcome/status of the VDAI investigation into Revolut's data breach affecting over 50,000 customers?