🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
LT v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing28 sources retrieved model claude-sonnet-5 · 2026-08-05

Lithuania

LT schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 51 claims · 39 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
51Claimsbaseline..claims[]
13Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 12 sub-modules are flagged red.

Jurisdiction brief

Standing brief, as of 25 August 2026.

Lead Signal

Lithuania's data-protection enforcement cadence is escalating even as the underlying legal framework remains stable. The State Data Protection Inspectorate's record EUR 2,385,276 fine against Vinted UAB, imposed in July 2024 for transparency and accountability violations including deficient handling of erasure requests and undisclosed shadow banning, was upheld by the Regional Administrative Court in May 2025. That confirmation on appeal removes the uncertainty that typically attaches to a first-instance fine and establishes the decision as a settled benchmark for how the VDAI expects controllers to handle data-subject erasure requests and transparency obligations going forward.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, mature GDPR-aligned framework with an active, EDPB-participating supervisory authority and no material derogation gaps identified.

Primary frameworkGeneral Data Protection Regulation (EU) 2016/679, as implemented by Law No XIII-1426 of 30 June 2018 amending Law No I-1374 (Law on Legal Protection of Personal Data)
Traffic-light rationale — GreenComprehensive, mature GDPR-aligned framework with an active, EDPB-participating supervisory authority and no material derogation gaps identified.

Sub-modules (5)

Regulator And AuthorityGreen

VDAI is the single national supervisory authority under GDPR Art. 51, participating in the EDPB.

Claims (1):

  • <cite index="6-1,6-2">The State Data Protection Inspectorate, located at L. Sapiegos str. 17, 10312 Vilnius, Lithuania, is listed as the national supervisory authority with contact reachable via ada@ada.lt.</cite>

Act And InstrumentsGreen

GDPR is directly applicable; national implementation is via Law No XIII-1426/2018 amending the Law on Legal Protection of Personal Data.

Claims (1):

  • <cite index="1-1">Lithuania implemented the GDPR through Law No XIII-1426 of 30 June 2018 amending Law No I-1374, together with the General Data Protection Regulation (Regulation (EU) 2016/679).</cite>

Material ScopeGreen

Material scope follows GDPR: covers processing by private-sector and most public-sector bodies.

Claims (1):

  • <cite index="67-8">The GDPR ensures protection of natural persons where their data is processed by the private sector and by most public-sector entities.</cite>

Territorial ScopeGreen

GDPR extraterritorial reach applies: non-EU established entities offering goods/services to, or monitoring, Lithuania-based data subjects are in scope.

Claims (1):

  • <cite index="67-31">Non-EU established companies must apply the same GDPR rules with regard to the offering of goods or services and the monitoring of the behaviour of persons living in the EU.</cite>

Regulator Registration And FilingAmber

No general notification regime; controllers/processors must communicate DPO contact details to VDAI where a DPO is appointed.

Claims (1):

  • <cite index="1-7,1-8">Article 37 GDPR obliges controllers and processors meeting DPO thresholds to designate a DPO, publish the DPO's contact details, and communicate them to the relevant supervisory authority.</cite>
Category narrative41 words

Lithuania is an EU Member State fully subject to the GDPR, supervised by the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, 'VDAI'), and implementing GDPR via a national amending law to the pre-existing Law on Legal Protection of Personal Data.

Sources and claims (5)
  1. ConfirmedEDPB — <cite index="6-1,6-2">The State Data Protection Inspectorate, located at L. Sapiegos str. 17, 10312 Vilnius, Lithuania, is listed as the national supervisory authority with contact reachable via ada@ada.lt.</cite>observed
  2. ConfirmedDataGuidance — <cite index="1-1">Lithuania implemented the GDPR through Law No XIII-1426 of 30 June 2018 amending Law No I-1374, together with the General Data Protection Regulation (Regulation (EU) 2016/679).</cite>observed
  3. ConfirmedEUR-Lex — <cite index="67-8">The GDPR ensures protection of natural persons where their data is processed by the private sector and by most public-sector entities.</cite>observed
  4. ConfirmedEUR-Lex — <cite index="67-31">Non-EU established companies must apply the same GDPR rules with regard to the offering of goods or services and the monitoring of the behaviour of persons living in the EU.</cite>observed
  5. ConfirmedDataGuidance — <cite index="1-7,1-8">Article 37 GDPR obliges controllers and processors meeting DPO thresholds to designate a DPO, publish the DPO's contact details, and communicate them to the relevant supervisory authority.</cite>observed

#

No national derogation weakening GDPR standards identified; VDAI enforcement activity on biometric data confirms an active special-categories regime.

Primary frameworkGDPR Arts. 6, 7, 9, 10; Law No XIII-1426/2018
Traffic-light rationale — GreenNo national derogation weakening GDPR standards identified; VDAI enforcement activity on biometric data confirms an active special-categories regime.

Sub-modules (4)

Lawful BasesGreen

Standard GDPR Art. 6(1) bases apply (consent, contract, legal obligation, vital interests, public task, legitimate interests).

Claims (1):

  • <cite index="69-6">Data controllers can only process personal data lawfully where one of the enumerated legal bases in Article 6 GDPR applies, such as consent, contract, legal obligation, public interest, or legitimate interests.</cite>

Special CategoriesAmber

VDAI has prioritised biometric-data enforcement (including in sports contexts) and issued recommendations on criminal-record data processing by employers.

Claims (2):

  • <cite index="1-3">Areas of focus for VDAI have included biometric data, as indicated by its thorough review of the use of biometric data in sports.</cite>
  • <cite index="1-26">VDAI's Recommendation outlines when and how employers in Lithuania can process criminal record data.</cite>

Pseudonymisation And AnonymisationGreen

GDPR promotes pseudonymisation and encryption as risk-mitigation techniques; no LT-specific safe-harbour beyond the Regulation was identified.

Claims (1):

  • <cite index="67-35">To limit the risks of data processing, use of pseudonyms (replacing identifying fields with artificial identifiers) and encryption is promoted.</cite>
Category narrative28 words

Lawful bases and consent standards follow GDPR Art. 6/7 directly. VDAI has issued sector guidance on special-category data (biometric, criminal-record) reflecting active supervisory focus on Art. 9/10 categories.

Sources and claims (5)
  1. ConfirmedEDPB — <cite index="69-6">Data controllers can only process personal data lawfully where one of the enumerated legal bases in Article 6 GDPR applies, such as consent, contract, legal obligation, public interest, or legitimate interests.</cite>observed
  2. ConfirmedEDPB — <cite index="69-9">Where consent is used as a legal basis, controllers must ensure the consent is freely given, informed, specific and unambiguous.</cite>observed
  3. ProbableDataGuidance — <cite index="1-3">Areas of focus for VDAI have included biometric data, as indicated by its thorough review of the use of biometric data in sports.</cite>observed
  4. ProbableDataGuidance — <cite index="1-26">VDAI's Recommendation outlines when and how employers in Lithuania can process criminal record data.</cite>observed
  5. ConfirmedEUR-Lex — <cite index="67-35">To limit the risks of data processing, use of pseudonyms (replacing identifying fields with artificial identifiers) and encryption is promoted.</cite>observed

#

Rights framework is directly GDPR-derived and actively enforced; no LT-specific narrowing identified.

Primary frameworkGDPR Arts. 12-22
Traffic-light rationale — GreenRights framework is directly GDPR-derived and actively enforced; no LT-specific narrowing identified.

Sub-modules (5)

Access RightAmber

VDAI found Vinted failed to properly evidence action taken on access requests.

Claims (1):

  • <cite index="32-4">The Lithuanian SA found that the company also failed to demonstrate that it had taken or refused to act in accordance with the applicant's request for the right of access.</cite>

Rectification And ErasureAmber

VDAI enforcement covers both erasure-request handling (Vinted) and data-accuracy/rectification duties (Vilnius Municipality).

Claims (2):

  • <cite index="32-1">Lithuanian SA found the company, in response to erasure requests, stated it would not act on a specific request because the applicant did not identify a specific reason under Article 17(1) GDPR and failed to identify all purposes of continued processing.</cite>
  • <cite index="17-4">A fine was imposed for infringements of Articles 5(1)(d) and 5(1)(f) GDPR for failure to implement appropriate technical and organisational measures ensuring accuracy of processed personal data.</cite>

Restriction And ObjectionGreen

GDPR Art. 18 restriction regime applies directly; no LT derogation found.

Claims (1):

  • <cite index="28-11">Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person or important public interest.</cite>

Data PortabilityGreen

Standard Art. 20 portability right applies without LT-specific modification.

Claims (1):

  • <cite index="67-5,67-6">Data subjects have easier access to their data and a right to data portability, allowing personal data to be transferred more easily between service providers.</cite>

Deadlines And Response WindowsGreen

Controllers must respond within the GDPR's one-month (extendable by two months) statutory deadline.

Claims (1):

  • <cite index="89-6">Article 12(3) of the GDPR provides that organizations need to respond to data subject requests without undue delay and in any event within one month of receipt of the request.</cite>
Category narrative25 words

Data subject rights follow GDPR Arts. 15-22 directly. VDAI enforcement against Vinted (access/erasure) and against Vilnius Municipality (accuracy/rectification) demonstrates active application of these rights domestically.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedEDPB / VDAI — <cite index="32-4">The Lithuanian SA found that the company also failed to demonstrate that it had taken or refused to act in accordance with the applicant's request for the right of access.</cite>observed
  2. ConfirmedEDPB / VDAI — <cite index="32-1">Lithuanian SA found the company, in response to erasure requests, stated it would not act on a specific request because the applicant did not identify a specific reason under Article 17(1) GDPR and failed to identify all purposes of continued processing.</cite>observed
  3. ConfirmedEDPB / VDAI — <cite index="17-4">A fine was imposed for infringements of Articles 5(1)(d) and 5(1)(f) GDPR for failure to implement appropriate technical and organisational measures ensuring accuracy of processed personal data.</cite>observed
  4. ConfirmedEUR-Lex — <cite index="28-11">Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person or important public interest.</cite>observed
  5. ConfirmedEUR-Lex — <cite index="67-5,67-6">Data subjects have easier access to their data and a right to data portability, allowing personal data to be transferred more easily between service providers.</cite>observed
  6. ConfirmedIAPP — <cite index="89-6">Article 12(3) of the GDPR provides that organizations need to respond to data subject requests without undue delay and in any event within one month of receipt of the request.</cite>observed

#

Core duties are directly GDPR-derived and actively supervised; retention/disposal sub-module lacks a confirmed LT-specific instrument.

Primary frameworkGDPR Arts. 5, 24-39
Traffic-light rationale — GreenCore duties are directly GDPR-derived and actively supervised; retention/disposal sub-module lacks a confirmed LT-specific instrument.

Sub-modules (7)

Accountability And DpiaAmber

VDAI adopted a national DPIA list under Art. 35(4), reviewed and partly revised following EDPB Opinion 13/2018.

Claims (2):

  • <cite index="91-1">Lithuania's SA adopted a list of the kind of processing operations which are subject to the requirement for a Data Protection Impact Assessment under Article 35(4) GDPR, per EDPB Opinion 13/2018.</cite>
  • <cite index="94-6">DPIA is mandatory for processing of genetic data only while evaluating the data subject's features or scoring, including profiling and forecasting, following revision of the initial blacklist.</cite>

Dpo RequirementsAmber

Art. 37 DPO designation applies; VDAI inspections have identified DPO role-conflict issues in practice.

Claims (1):

  • <cite index="33-10">VDAI's inspection results reveal DPO role conflicts and emphasize the need for GDPR compliance audits.</cite>

Ropa RequirementsGreen

VDAI has published guidance/recommendations on records of processing activities.

Claims (1):

  • <cite index="12-7">In 2018-19, Lithuania's DPA released numerous guidelines and recommendations including recommendations for the records of processing activities.</cite>

Joint Controller ArrangementsGreen

Standard Art. 26 joint-controller allocation-of-responsibility rule applies.

Claims (1):

  • <cite index="61-15,61-16">Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers and must transparently determine their respective responsibilities by mutual arrangement.</cite>

Security MeasuresAmber

VDAI has fined controllers for inadequate technical/organisational security measures under Art. 32.

Claims (1):

  • <cite index="4-5">VDAI considered that the Center for Registers had not implemented adequate technical and organisational measures, acting in contravention of Article 32 GDPR.</cite>

Breach NotificationAmber

Standard 72-hour regulator notification duty applies; VDAI reports rising breach volumes.

Claims (2):

  • <cite index="83-5">In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.</cite>
  • <cite index="41-5">VDAI reports 116 data breaches in early 2025, mostly due to human error and cyber incidents, affecting 168,822 individuals.</cite>

Retention And DisposalRed

No LT sector-specific retention/disposal statute beyond the GDPR storage-limitation principle was located in this research pass.

Absence provenance: unavailable. Searched: unavailable.

Category narrative47 words

Accountability, DPIA, DPO, ROPA, joint-controller, security and breach-notification duties follow GDPR directly. VDAI has published a national DPIA 'blacklist' under Art. 35(4), and has fined controllers for security failures (Art. 32). Retention/disposal rules are governed by the general storage-limitation principle; no LT sector-specific retention statute was identified.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (8)
  1. ConfirmedEDPB — <cite index="91-1">Lithuania's SA adopted a list of the kind of processing operations which are subject to the requirement for a Data Protection Impact Assessment under Article 35(4) GDPR, per EDPB Opinion 13/2018.</cite>observed
  2. ConfirmedIAPP — <cite index="94-6">DPIA is mandatory for processing of genetic data only while evaluating the data subject's features or scoring, including profiling and forecasting, following revision of the initial blacklist.</cite>observed
  3. ProbableDataGuidance — <cite index="33-10">VDAI's inspection results reveal DPO role conflicts and emphasize the need for GDPR compliance audits.</cite>observed
  4. ProbableIAPP — <cite index="12-7">In 2018-19, Lithuania's DPA released numerous guidelines and recommendations including recommendations for the records of processing activities.</cite>observed
  5. ConfirmedEUR-Lex — <cite index="61-15,61-16">Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers and must transparently determine their respective responsibilities by mutual arrangement.</cite>observed
  6. ConfirmedDataGuidance — <cite index="4-5">VDAI considered that the Center for Registers had not implemented adequate technical and organisational measures, acting in contravention of Article 32 GDPR.</cite>observed
  7. ConfirmedEUR-Lex — <cite index="83-5">In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.</cite>observed
  8. ConfirmedDataGuidance — <cite index="41-5">VDAI reports 116 data breaches in early 2025, mostly due to human error and cyber incidents, affecting 168,822 individuals.</cite>observed

#

Framework is sound (GDPR Chapter V) but LT-specific TIA practice and confirmation of any localisation rules could not be fully verified in this pass.

Primary frameworkGDPR Arts. 44-49
Traffic-light rationale — AmberFramework is sound (GDPR Chapter V) but LT-specific TIA practice and confirmation of any localisation rules could not be fully verified in this pass.

Sub-modules (6)

Transfer MechanismsGreen

VDAI guidance recommends SCCs or BCRs as the operative transfer mechanisms for third-country transfers.

Claims (1):

  • <cite index="80-3">VDAI recommended that Lithuanian companies ensure the lawfulness of data transfers by determining the types of personal data transferred and assessing available bases such as Standard Contractual Clauses or Binding Corporate Rules.</cite>

Adequacy ReceivedGreen

Adequacy determinations are adopted at EU level and apply uniformly across Member States; Lithuania does not issue separate national adequacy findings.

Claims (1):

  • Adequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.

Adequacy GrantedGreen

Adequacy decisions regarding third countries are an EU Commission competence, not a Lithuanian national act.

Claims (1):

  • Adequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.

Sccs And BcrsGreen

VDAI has issued guidance clarifying the optional nature of the EU SCCs for controller-processor relationships.

Claims (1):

  • <cite index="11-21">Lithuania's VDAI clarifies the use of EU SCCs, highlighting their optional nature and specific applicability to data controller-processor relationships.</cite>

Transfer Impact AssessmentAmber

VDAI's Brexit FAQ recommended Lithuanian companies assess transfer bases irrespective of any adequacy decision, consistent with post-Schrems II TIA practice.

Claims (1):

  • <cite index="80-2,80-3">VDAI highlighted that upon expiry of the Brexit transitional period, Lithuanian companies should implement mechanisms ensuring lawfulness of transfers to the UK as a third country, regardless of any adequacy decision.</cite>

Data LocalisationRed

No general LT-specific data-localisation mandate was identified in this research pass beyond GDPR Chapter V.

Absence provenance: unavailable. Searched: unavailable.

Category narrative48 words

As an EU Member State, Lithuania relies on GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, derogations); adequacy decisions are an EU-level competence and not issued/received bilaterally by Lithuania. VDAI has issued practical guidance (e.g. on Brexit-related transfers and SCC use) but no LT-specific data-localisation mandate was found.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (4)
  1. ProbableDataGuidance — <cite index="80-3">VDAI recommended that Lithuanian companies ensure the lawfulness of data transfers by determining the types of personal data transferred and assessing available bases such as Standard Contractual Clauses or Binding Corporate Rules.</cite>observed
  2. ConfirmedEUR-Lex — Adequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.observed
  3. ProbableDataGuidance — <cite index="11-21">Lithuania's VDAI clarifies the use of EU SCCs, highlighting their optional nature and specific applicability to data controller-processor relationships.</cite>observed
  4. ProbableDataGuidance — <cite index="80-2,80-3">VDAI highlighted that upon expiry of the Brexit transitional period, Lithuanian companies should implement mechanisms ensuring lawfulness of transfers to the UK as a third country, regardless of any adequacy decision.</cite>observed

#

Core sectors (telecoms, employment, health, credit) are covered by guidance or investigation; education and insurance sub-modules show a coverage gap.

Primary frameworkGDPR; Law on Electronic Communications No. IX-2135 (as amended); Civil Service Law
Traffic-light rationale — AmberCore sectors (telecoms, employment, health, credit) are covered by guidance or investigation; education and insurance sub-modules show a coverage gap.

Sub-modules (7)

Financial Sector OverlayAmber

VDAI opened an investigation into fintech Revolut over a data breach affecting over 50,000 customers.

Claims (1):

  • <cite index="1-14">VDAI investigates Revolut for a data breach affecting over 50,000 customers, assessing GDPR violations.</cite>

Health Sector OverlayGreen

VDAI issued FAQs on employer collection of employee health data under the Civil Service Law and GDPR Art. 5.

Claims (1):

  • <cite index="5-4">Employers must ensure health data collection is necessary, use less intrusive means, and process data according to GDPR Article 5.</cite>

Telecoms And EprivacyGreen

ePrivacy obligations are transposed via the Law on Electronic Communications No. IX-2135 alongside GDPR.

Claims (1):

  • <cite index="78-1">In addition to Law No XIII-1426 and the GDPR, the Law on Electronic Communications of 15 April 2004, No. IX-2135, as amended, applies to e-marketing in Lithuania.</cite>

Employment DataGreen

VDAI published three separate guides addressing employee, business, and public-sector employment data protection.

Claims (1):

  • <cite index="3-3">VDAI published three guides: one for employees, one for businesses, and one for the public sector, all in the context of employment relations.</cite>

Credit And ScoringGreen

VDAI issued a recommendation on the processing of debtors' personal data covering lawful grounds and limits on data subject rights.

Claims (1):

  • <cite index="2-4">The VDAI recommendation on debtors' data outlines data processing principles, lawful grounds, and roles of parties, emphasizing that data subject rights do not affect debtors' contractual obligations.</cite>

EducationRed

No LT-specific education-sector data-protection instrument was identified beyond general GDPR application (illustrated indirectly by the children's-camp consent case).

Absence provenance: unavailable. Searched: unavailable.

InsuranceRed

No LT-specific insurance-sector data-protection instrument was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative41 words

Sectoral overlays are thin in Lithuania beyond GDPR: telecoms/eprivacy is transposed via the Law on Electronic Communications; VDAI has issued employment and health-sector guidance; a fintech (Revolut) breach investigation illustrates financial-sector overlap. No LT-specific education or insurance-sector DP rules were found.

Sources and claims (5)
  1. ProbableDataGuidance — <cite index="1-14">VDAI investigates Revolut for a data breach affecting over 50,000 customers, assessing GDPR violations.</cite>observed
  2. ConfirmedDataGuidance — <cite index="5-4">Employers must ensure health data collection is necessary, use less intrusive means, and process data according to GDPR Article 5.</cite>observed
  3. ConfirmedDataGuidance — <cite index="78-1">In addition to Law No XIII-1426 and the GDPR, the Law on Electronic Communications of 15 April 2004, No. IX-2135, as amended, applies to e-marketing in Lithuania.</cite>observed
  4. ConfirmedDataGuidance — <cite index="3-3">VDAI published three guides: one for employees, one for businesses, and one for the public sector, all in the context of employment relations.</cite>observed
  5. ProbableDataGuidance — <cite index="2-4">The VDAI recommendation on debtors' data outlines data processing principles, lawful grounds, and roles of parties, emphasizing that data subject rights do not affect debtors' contractual obligations.</cite>observed

#

Cookie and direct-marketing rules are covered; opt-out-signal and clean-room concepts are not applicable/found under the EU framework.

Primary frameworkGDPR; ePrivacy Directive 2002/58/EC as transposed via Law on Electronic Communications No. IX-2135
Traffic-light rationale — AmberCookie and direct-marketing rules are covered; opt-out-signal and clean-room concepts are not applicable/found under the EU framework.

Sub-modules (6)

Cookies And TrackersGreen

VDAI has issued cookie-compliance guidance emphasising user-friendly consent design.

Claims (1):

  • <cite index="1-21">Lithuania's VDAI outlines cookie practices for compliance with GDPR and user-friendly design.</cite>

Dark PatternsAmber

VDAI's Vinted decision found 'shadow blocking' practices unlawful for violating fairness and transparency principles, functioning as a dark-pattern precedent.

Claims (1):

  • <cite index="32-2,32-3">The company unlawfully, in violation of the principles of fairness and transparency, processed personal data in the context of 'shadow blocking', i.e. processing intended to make a user leave the platform without being aware of it.</cite>

Opt Out SignalsRed

No LT-specific Global Privacy Control/DAA-equivalent opt-out signal regime was identified; not a feature of the EU consent-based model.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No LT-specific data clean-room regulation was identified.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingRed

The CPRA 'sale'/'share' construct has no direct EU/LT analogue; GDPR consent and legitimate-interest rules govern comparable adtech processing instead.

Absence provenance: unavailable. Searched: unavailable.

Direct MarketingGreen

VDAI guidance addresses direct marketing scope and consent/third-party-data requirements, including in the public sector.

Claims (1):

  • <cite index="9-4,9-5">VDAI guidance clarifies that direct marketing includes inquiries about opinions on goods or services, including via post, telephone, or other direct means to subscribers or users of electronic communications services.</cite>
Category narrative37 words

Cookie consent and direct-marketing rules follow GDPR/ePrivacy transposition. VDAI's Vinted enforcement establishes a precedent against non-transparent 'shadow blocking' practices analogous to dark patterns. No CPRA-style 'sale/share' concept or GPC-equivalent opt-out signal regime exists in this EU jurisdiction.

Sources and claims (3)
  1. ProbableDataGuidance — <cite index="1-21">Lithuania's VDAI outlines cookie practices for compliance with GDPR and user-friendly design.</cite>observed
  2. ConfirmedEDPB / VDAI — <cite index="32-2,32-3">The company unlawfully, in violation of the principles of fairness and transparency, processed personal data in the context of 'shadow blocking', i.e. processing intended to make a user leave the platform without being aware of it.</cite>observed
  3. ConfirmedDataGuidance — <cite index="9-4,9-5">VDAI guidance clarifies that direct marketing includes inquiries about opinions on goods or services, including via post, telephone, or other direct means to subscribers or users of electronic communications services.</cite>observed

#

Biometric/genetic governance is documented; ADM-transparency and state-surveillance-carveout sub-modules rely on general GDPR text without LT-specific enforcement examples.

Primary frameworkGDPR Arts. 9, 22, 35; VDAI DPIA Order of 14 March 2019
Traffic-light rationale — AmberBiometric/genetic governance is documented; ADM-transparency and state-surveillance-carveout sub-modules rely on general GDPR text without LT-specific enforcement examples.

Sub-modules (6)

Profiling RestrictionsAmber

DPIA is required for genetic-data processing used for profiling/scoring/forecasting individuals.

Claims (1):

  • <cite index="94-6">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>

Automated Decision Making TransparencyRed

No LT-specific Art. 22 ADM enforcement precedent was located in this research pass; GDPR Art. 22 applies directly as EU law.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsAmber

VDAI has publicly warned about AI tool risk (DeepSeek) and issued FAQ guidance for organisations starting AI system deployments.

Claims (2):

  • <cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or to think carefully about how they use it, citing insufficient information about its privacy practices.</cite>
  • <cite index="66-8">VDAI's FAQ guides organizations on starting with AI systems, emphasizing GDPR compliance and expert involvement.</cite>

Biometric RegimeAmber

Lithuania's DPIA list treats standalone biometric-identification processing as a DPIA trigger; VDAI fined a sports-club operator for unlawful biometric processing.

Claims (2):

  • <cite index="95-7,95-8">Lithuania's SA list stated that biometric-data processing on its own would create the obligation to perform a DPIA; the EDPB requested amendment so that biometric processing to uniquely identify a person requires a DPIA only in conjunction with at least one other criterion.</cite>
  • <cite index="1-13">Praktiškas was fined €6,000 for GDPR violations related to biometric data processing at its sports clubs.</cite>

Genetic DataGreen

Genetic-data DPIA obligation was narrowed to profiling/scoring contexts after EDPB review of the initial 2018 list.

Claims (1):

  • <cite index="94-6">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>

State Surveillance CarveoutsGreen

GDPR permits Member State law to restrict certain data-subject rights and obligations for criminal-law-enforcement and public-security purposes.

Claims (1):

  • <cite index="83-11">Union or Member State law may restrict the scope of certain GDPR obligations and rights where necessary to safeguard the prevention, investigation, detection or prosecution of criminal offences, public security, or other important objectives of general public interest.</cite>
Category narrative42 words

Lithuania's DPIA 'blacklist' treats biometric- and genetic-data processing as DPIA triggers (partially revised after EDPB opinion). VDAI has fined a biometric-data controller and issued a public AI-risk warning regarding DeepSeek. No LT-specific Art. 22 ADM enforcement precedent was located in this pass.

Sources and claims (6)
  1. ConfirmedIAPP — <cite index="94-6">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>observed
  2. ConfirmedIAPP — <cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or to think carefully about how they use it, citing insufficient information about its privacy practices.</cite>observed
  3. ProbableDataGuidance — <cite index="66-8">VDAI's FAQ guides organizations on starting with AI systems, emphasizing GDPR compliance and expert involvement.</cite>observed
  4. UncertainIAPP — <cite index="95-7,95-8">Lithuania's SA list stated that biometric-data processing on its own would create the obligation to perform a DPIA; the EDPB requested amendment so that biometric processing to uniquely identify a person requires a DPIA only in conjunction with at least one other criterion.</cite>observed
  5. ConfirmedDataGuidance — <cite index="1-13">Praktiškas was fined €6,000 for GDPR violations related to biometric data processing at its sports clubs.</cite>observed
  6. ConfirmedEUR-Lex — <cite index="83-11">Union or Member State law may restrict the scope of certain GDPR obligations and rights where necessary to safeguard the prevention, investigation, detection or prosecution of criminal offences, public security, or other important objectives of general public interest.</cite>observed

#

Core Art. 8 framework applies but the exact Lithuanian national age-of-consent derogation (if any) could not be confirmed; education-settings and dependent-adults sub-modules lack dedicated LT instruments.

Primary frameworkGDPR Art. 8
Traffic-light rationale — AmberCore Art. 8 framework applies but the exact Lithuanian national age-of-consent derogation (if any) could not be confirmed; education-settings and dependent-adults sub-modules lack dedicated LT instruments.

Sub-modules (5)

Age VerificationAmber

Controllers must make reasonable efforts to verify parental-responsibility-holder consent for children below the applicable age threshold.

Claims (1):

  • <cite index="61-8">The controller shall, taking into account available technologies, make reasonable efforts to verify that consent has been given or authorised by the holder of parental responsibility over the child.</cite>

Minor Profiling BansAmber

VDAI found a children's-camp organiser's consent mechanism for processing children's image data did not meet GDPR consent conditions (freely given, specific, revocable).

Claims (1):

  • <cite index="45-13,45-14">The organisation's processing of children's image data without GDPR-compliant consent, including failure to allow free choice or withdrawal without detriment, infringed the principle of lawfulness and the conditions of consent under Articles 5(1)(a), 6 and 7 GDPR.</cite>

Education SettingsRed

No dedicated LT education-sector children's-data instrument was identified beyond the general consent enforcement precedent noted above.

Absence provenance: unavailable. Searched: unavailable.

Dependent AdultsRed

No LT-specific dependent-adults (elderly/mentally incapacitated) data-protection provision was identified.

Absence provenance: unavailable. Searched: unavailable.

Category narrative55 words

GDPR Art. 8 sets a default digital-consent age of 16 with Member State discretion to lower to no less than 13; no confirmed Lithuanian national derogation was found in this research pass, so the GDPR default is presumed to apply. VDAI enforcement against a children's-camp operator illustrates active supervision of consent for minors' image data.

Sources and claims (3)
  1. ConfirmedEUR-Lex — <cite index="61-8">The controller shall, taking into account available technologies, make reasonable efforts to verify that consent has been given or authorised by the holder of parental responsibility over the child.</cite>observed
  2. UncertainEDPB — <cite index="69-2,69-3">Children aged 16 and above are considered able to give their own consent; for children below 16, the organisation must request consent from that child's legal guardian or parent, absent a lower national threshold.</cite>observed
  3. ConfirmedEDPB / VDAI — <cite index="45-13,45-14">The organisation's processing of children's image data without GDPR-compliant consent, including failure to allow free choice or withdrawal without detriment, infringed the principle of lawfulness and the conditions of consent under Articles 5(1)(a), 6 and 7 GDPR.</cite>observed

#

Enforcement powers and recent activity are well evidenced; funding/capacity and collective-redress sub-modules lack confirmed LT-specific detail.

Primary frameworkGDPR Arts. 58, 77-84
Traffic-light rationale — GreenEnforcement powers and recent activity are well evidenced; funding/capacity and collective-redress sub-modules lack confirmed LT-specific detail.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

VDAI can impose fines up to the GDPR statutory maxima of €20 million or 4% of global annual turnover, whichever is higher.

Claims (1):

  • <cite index="102-1">A supervisory authority can impose fines that go up to a maximum of 20 million or 4% of total worldwide annual turnover in the previous financial year for breaches such as unlawful processing or breaches of data subject rights.</cite>

Enforcement Activity IndexAmber

Notable 2021-2024 fines include Vinted (€2.38M, 2024), Vilnius Municipality (€15,000, 2021) and State Enterprise Centre of Registers (€15,000, 2021).

Claims (3):

  • <cite index="32-10">In fining Vinted, the Lithuanian SA relied on EDPB Guidelines 04/2022 on calculation of administrative fines, taking into account the cross-border scope of processing, the large number of data subjects affected, and the duration of the infringements.</cite>
  • <cite index="17-2">A fine in the amount of EUR 15,000 was imposed on Vilnius City Municipality Administration for improperly processed personal data of the parents of an adopted child.</cite>
  • <cite index="4-1">VDAI fined the State Enterprise Center for Registers €15,000 for implementing inadequate technical and organisational measures for data security.</cite>

Regulator Funding And CapacityRed

No confirmed data on VDAI's budget or headcount was located in this research pass.

Absence provenance: unavailable. Searched: unavailable.

Collective Redress And Class ActionsRed

GDPR Art. 80 permits representative actions by not-for-profit bodies on behalf of data subjects; no LT-specific implementing detail was confirmed in this pass.

Absence provenance: unavailable. Searched: unavailable.

Private Right Of ActionGreen

VDAI decisions are subject to judicial appeal, evidencing an available private right of action/judicial remedy route.

Claims (1):

  • <cite index="17-16">The decision of the SDPI is not effective and may be appealed against to the court.</cite>

Recent Developments 180DAmber

Within the last 180 days, VDAI's public warning regarding DeepSeek's data practices reflects the most notable documented development.

Claims (1):

  • <cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or think carefully about how they use it, citing insufficient information about its privacy practices.</cite>
Category narrative63 words

VDAI actively exercises GDPR Art. 83 fining powers, with a notable escalation to a €2.38M fine against Vinted in 2024 alongside multiple smaller fines (Vilnius Municipality, State Enterprise Centre of Registers, Praktiškas). Judicial appeal of VDAI decisions is available. Regulator funding/capacity data and collective-redress mechanisms were not confirmed in this pass; the most recent notable development is VDAI's 2026 public warning on DeepSeek.

No new data since the standing brief. 1 periodic run re-emitted it unchanged.

Sources and claims (6)
  1. ConfirmedEDPB — <cite index="102-1">A supervisory authority can impose fines that go up to a maximum of 20 million or 4% of total worldwide annual turnover in the previous financial year for breaches such as unlawful processing or breaches of data subject rights.</cite>observed
  2. ConfirmedEDPB / VDAI — <cite index="32-10">In fining Vinted, the Lithuanian SA relied on EDPB Guidelines 04/2022 on calculation of administrative fines, taking into account the cross-border scope of processing, the large number of data subjects affected, and the duration of the infringements.</cite>observed
  3. ConfirmedEDPB / VDAI — <cite index="17-2">A fine in the amount of EUR 15,000 was imposed on Vilnius City Municipality Administration for improperly processed personal data of the parents of an adopted child.</cite>observed
  4. ConfirmedDataGuidance — <cite index="4-1">VDAI fined the State Enterprise Center for Registers €15,000 for implementing inadequate technical and organisational measures for data security.</cite>observed
  5. ConfirmedEDPB / VDAI — <cite index="17-16">The decision of the SDPI is not effective and may be appealed against to the court.</cite>observed
  6. ConfirmedIAPP — <cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or think carefully about how they use it, citing insufficient information about its privacy practices.</cite>observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metn/a — no subject in this jurisdiction
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct46.88
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Lithuania
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 51 claim(s) (51 category placement(s)), 39 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (41 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 8Children & Vulnerable Groupsparental consent
Art. 9Lawful Processing & Special Dataspecial categories
Art. 10Lawful Processing & Special Dataspecial categories
Art. 12Data Subject Rightsdeadlines and response windows
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrectification and erasure
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer impact assessment
Art. 49Cross-Border & Adequacytransfer impact assessment
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressregulator powers and penalties
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressregulator powers and penalties
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

Regulator identity, GDPR/national-law framework, lawful bases, breach notification, DPIA list, and enforcement-activity modules rest on T1 (EUR-Lex, EDPB official registers/news, VDAI order text) and T2 (EDPB-published national-authority decisions) sources with high confidence. Sectoral overlays (telecoms/eprivacy, employment, health, credit) and adtech/dark-pattern findings rely primarily on T3 secondary commentary (DataGuidance, IAPP, CNIL) summarizing official VDAI/EDPB actions, which is treated as Probable/Confirmed depending on corroboration. Education, insurance, dependent-adults, opt-out-signal, clean-room, cross-context-advertising, data-localisation, regulator-funding, and collective-redress sub-modules returned no LT-specific instrument in this pass and are marked red with explicit absent_field_provenance. The exact Lithuanian national derogation (if any) on the GDPR Art. 8 child-consent age threshold could not be confirmed and is flagged Uncertain.

Unresolved questions (6):

  • Has Lithuania enacted a national derogation lowering the GDPR Article 8 default digital-consent age below 16 (as permitted down to 13)?
  • Was VDAI's 2019 DPIA 'blacklist' formally amended to align with the EDPB's request to limit standalone biometric- and genetic-data DPIA triggers to combination-with-other-criteria cases, and if so, on what date?
  • What is VDAI's current annual budget and staffing/headcount, relevant to assessing regulator capacity?
  • Does Lithuania have any implementing detail for GDPR Article 80 representative/collective-redress actions beyond the general Regulation text?
  • Is there a dedicated Lithuanian education-sector or insurance-sector data-protection instrument not surfaced by this research pass?
  • What was the final outcome/status of the VDAI investigation into Revolut's data breach affecting over 50,000 customers?

Escalate to primary-source review: yes