{
 "jurisdiction_id": "LT",
 "jurisdiction": "Lithuania",
 "url": "https://dataprotection.gi/jurisdictions/lithuania/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 51,
  "sub_modules": 57,
  "source_register": 28
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, mature GDPR-aligned framework with an active, EDPB-participating supervisory authority and no material derogation gaps identified.",
   "claims": [
    {
     "statement": "<cite index=\"6-1,6-2\">The State Data Protection Inspectorate, located at L. Sapiegos str. 17, 10312 Vilnius, Lithuania, is listed as the national supervisory authority with contact reachable via ada@ada.lt.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/about-edpb/about-edpb/members_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"1-1\">Lithuania implemented the GDPR through Law No XIII-1426 of 30 June 2018 amending Law No I-1374, together with the General Data Protection Regulation (Regulation (EU) 2016/679).</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"67-8\">The GDPR ensures protection of natural persons where their data is processed by the private sector and by most public-sector entities.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/LT/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"67-31\">Non-EU established companies must apply the same GDPR rules with regard to the offering of goods or services and the monitoring of the behaviour of persons living in the EU.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/LT/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"1-7,1-8\">Article 37 GDPR obliges controllers and processors meeting DPO thresholds to designate a DPO, publish the DPO's contact details, and communicate them to the relevant supervisory authority.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "No national derogation weakening GDPR standards identified; VDAI enforcement activity on biometric data confirms an active special-categories regime.",
   "claims": [
    {
     "statement": "<cite index=\"69-6\">Data controllers can only process personal data lawfully where one of the enumerated legal bases in Article 6 GDPR applies, such as consent, contract, legal obligation, public interest, or legitimate interests.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"69-9\">Where consent is used as a legal basis, controllers must ensure the consent is freely given, informed, specific and unambiguous.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"1-3\">Areas of focus for VDAI have included biometric data, as indicated by its thorough review of the use of biometric data in sports.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"1-26\">VDAI's Recommendation outlines when and how employers in Lithuania can process criminal record data.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"67-35\">To limit the risks of data processing, use of pseudonyms (replacing identifying fields with artificial identifiers) and encryption is promoted.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/LT/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "green",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Rights framework is directly GDPR-derived and actively enforced; no LT-specific narrowing identified.",
   "claims": [
    {
     "statement": "<cite index=\"32-4\">The Lithuanian SA found that the company also failed to demonstrate that it had taken or refused to act in accordance with the applicant's request for the right of access.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/lithuanian-sa-fine-eu-2-385-276-vinted-uab-company_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"32-1\">Lithuanian SA found the company, in response to erasure requests, stated it would not act on a specific request because the applicant did not identify a specific reason under Article 17(1) GDPR and failed to identify all purposes of continued processing.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/lithuanian-sa-fine-eu-2-385-276-vinted-uab-company_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"17-4\">A fine was imposed for infringements of Articles 5(1)(d) and 5(1)(f) GDPR for failure to implement appropriate technical and organisational measures ensuring accuracy of processed personal data.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/lithuanian-dpa-imposes-fine-improperly-processed-personal-data-parents_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"28-11\">Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person or important public interest.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"67-5,67-6\">Data subjects have easier access to their data and a right to data portability, allowing personal data to be transferred more easily between service providers.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/LT/legal-content/summary/general-data-protection-regulation-gdpr.html",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"89-6\">Article 12(3) of the GDPR provides that organizations need to respond to data subject requests without undue delay and in any event within one month of receipt of the request.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/why-these-dpas-are-wrong-about-limiting-dsr-extensions",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "green",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "Core duties are directly GDPR-derived and actively supervised; retention/disposal sub-module lacks a confirmed LT-specific instrument.",
   "claims": [
    {
     "statement": "<cite index=\"91-1\">Lithuania's SA adopted a list of the kind of processing operations which are subject to the requirement for a Data Protection Impact Assessment under Article 35(4) GDPR, per EDPB Opinion 13/2018.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/our-work-tools/consistency-findings/register-decisions/2019/lithuania-sas-list-kind-processing_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"94-6\">DPIA is mandatory for processing of genetic data only while evaluating the data subject's features or scoring, including profiling and forecasting, following revision of the initial blacklist.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-implementation-in-lithuania-almost-a-year-in-review",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"33-10\">VDAI's inspection results reveal DPO role conflicts and emphasize the need for GDPR compliance audits.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"12-7\">In 2018-19, Lithuania's DPA released numerous guidelines and recommendations including recommendations for the records of processing activities.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-implementation-in-lithuania-almost-a-year-in-review",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"61-15,61-16\">Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers and must transparently determine their respective responsibilities by mutual arrangement.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/lt/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"4-5\">VDAI considered that the Center for Registers had not implemented adequate technical and organisational measures, acting in contravention of Article 32 GDPR.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/lithuania-vdai-fines-state-enterprise-center-registers",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"83-5\">In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"41-5\">VDAI reports 116 data breaches in early 2025, mostly due to human error and cyber incidents, affecting 168,822 individuals.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Framework is sound (GDPR Chapter V) but LT-specific TIA practice and confirmation of any localisation rules could not be fully verified in this pass.",
   "claims": [
    {
     "statement": "<cite index=\"80-3\">VDAI recommended that Lithuanian companies ensure the lawfulness of data transfers by determining the types of personal data transferred and assessing available bases such as Standard Contractual Clauses or Binding Corporate Rules.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/advisories/brexit",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "Adequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/eli/reg/2016/679/oj/eng",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"11-21\">Lithuania's VDAI clarifies the use of EU SCCs, highlighting their optional nature and specific applicability to data controller-processor relationships.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"80-2,80-3\">VDAI highlighted that upon expiry of the Brexit transitional period, Lithuanian companies should implement mechanisms ensuring lawfulness of transfers to the UK as a third country, regardless of any adequacy decision.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/advisories/brexit",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Core sectors (telecoms, employment, health, credit) are covered by guidance or investigation; education and insurance sub-modules show a coverage gap.",
   "claims": [
    {
     "statement": "<cite index=\"1-14\">VDAI investigates Revolut for a data breach affecting over 50,000 customers, assessing GDPR violations.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"5-4\">Employers must ensure health data collection is necessary, use less intrusive means, and process data according to GDPR Article 5.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/lithuania-vdai-issues-faq-use-employee-health-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"78-1\">In addition to Law No XIII-1426 and the GDPR, the Law on Electronic Communications of 15 April 2004, No. IX-2135, as amended, applies to e-marketing in Lithuania.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/notes/lithuania-emarketing",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"3-3\">VDAI published three guides: one for employees, one for businesses, and one for the public sector, all in the context of employment relations.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/lithuania-vdai-publishes-guides-personal-data",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"2-4\">The VDAI recommendation on debtors' data outlines data processing principles, lawful grounds, and roles of parties, emphasizing that data subject rights do not affect debtors' contractual obligations.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/lithuania-vdai-issues-recommendation-processing-debtors",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookie and direct-marketing rules are covered; opt-out-signal and clean-room concepts are not applicable/found under the EU framework.",
   "claims": [
    {
     "statement": "<cite index=\"1-21\">Lithuania's VDAI outlines cookie practices for compliance with GDPR and user-friendly design.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"32-2,32-3\">The company unlawfully, in violation of the principles of fairness and transparency, processed personal data in the context of 'shadow blocking', i.e. processing intended to make a user leave the platform without being aware of it.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/lithuanian-sa-fine-eu-2-385-276-vinted-uab-company_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"9-4,9-5\">VDAI guidance clarifies that direct marketing includes inquiries about opinions on goods or services, including via post, telephone, or other direct means to subscribers or users of electronic communications services.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/lithuania-vdai-issues-guidance-direct-marketing-public",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Biometric/genetic governance is documented; ADM-transparency and state-surveillance-carveout sub-modules rely on general GDPR text without LT-specific enforcement examples.",
   "claims": [
    {
     "statement": "<cite index=\"94-6\">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/gdpr-implementation-in-lithuania-almost-a-year-in-review",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"113-4\">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or to think carefully about how they use it, citing insufficient information about its privacy practices.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/how-dpas-are-trying-to-keep-up-with-ai-advances",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"66-8\">VDAI's FAQ guides organizations on starting with AI systems, emphasizing GDPR compliance and expert involvement.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"95-7,95-8\">Lithuania's SA list stated that biometric-data processing on its own would create the obligation to perform a DPIA; the EDPB requested amendment so that biometric processing to uniquely identify a person requires a DPIA only in conjunction with at least one other criterion.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/whats-subject-to-a-dpia-under-the-gdpr-edpb-on-draft-lists-of-22-supervisory-authorities",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"1-13\">Praktiškas was fined €6,000 for GDPR violations related to biometric data processing at its sports clubs.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/jurisdictions/lithuania",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"83-11\">Union or Member State law may restrict the scope of certain GDPR obligations and rights where necessary to safeguard the prevention, investigation, detection or prosecution of criminal offences, public security, or other important objectives of general public interest.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/EN/TXT/HTML/?uri=CELEX:02016R0679-20160504",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Core Art. 8 framework applies but the exact Lithuanian national age-of-consent derogation (if any) could not be confirmed; education-settings and dependent-adults sub-modules lack dedicated LT instruments.",
   "claims": [
    {
     "statement": "<cite index=\"61-8\">The controller shall, taking into account available technologies, make reasonable efforts to verify that consent has been given or authorised by the holder of parental responsibility over the child.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EUR-Lex",
     "source_url": "https://eur-lex.europa.eu/legal-content/lt/TXT/?uri=CELEX:32016R0679",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"69-2,69-3\">Children aged 16 and above are considered able to give their own consent; for children below 16, the organisation must request consent from that child's legal guardian or parent, absent a lower national threshold.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Uncertain",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/be-compliant/process-personal-data-lawfully_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"45-13,45-14\">The organisation's processing of children's image data without GDPR-compliant consent, including failure to allow free choice or withdrawal without detriment, infringed the principle of lawfulness and the conditions of consent under Articles 5(1)(a), 6 and 7 GDPR.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2023/lithuanian-sa-adopted-decision-actions-organisation-processing-childrens_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/lithuania/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers and recent activity are well evidenced; funding/capacity and collective-redress sub-modules lack confirmed LT-specific detail.",
   "claims": [
    {
     "statement": "<cite index=\"102-1\">A supervisory authority can impose fines that go up to a maximum of 20 million or 4% of total worldwide annual turnover in the previous financial year for breaches such as unlawful processing or breaches of data subject rights.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB",
     "source_url": "https://www.edpb.europa.eu/sme/find-practical-info/data-protection-authority-you_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"32-10\">In fining Vinted, the Lithuanian SA relied on EDPB Guidelines 04/2022 on calculation of administrative fines, taking into account the cross-border scope of processing, the large number of data subjects affected, and the duration of the infringements.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/news/2024/lithuanian-sa-fine-eu-2-385-276-vinted-uab-company_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"17-2\">A fine in the amount of EUR 15,000 was imposed on Vilnius City Municipality Administration for improperly processed personal data of the parents of an adopted child.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/lithuanian-dpa-imposes-fine-improperly-processed-personal-data-parents_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"4-1\">VDAI fined the State Enterprise Center for Registers €15,000 for implementing inadequate technical and organisational measures for data security.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/news/lithuania-vdai-fines-state-enterprise-center-registers",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"17-16\">The decision of the SDPI is not effective and may be appealed against to the court.</cite>",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "EDPB / VDAI",
     "source_url": "https://www.edpb.europa.eu/news/national-news/2020/lithuanian-dpa-imposes-fine-improperly-processed-personal-data-parents_en",
     "source_tier": null,
     "observed_at": "2026-08-05"
    },
    {
     "statement": "<cite index=\"113-4\">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or think carefully about how they use it, citing insufficient information about its privacy practices.</cite>",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/how-dpas-are-trying-to-keep-up-with-ai-advances",
     "source_tier": null,
     "observed_at": "2026-08-05"
    }
   ]
  }
 ]
}