🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
LT · run data-protection-2026-08-05 v13-gdpri-1.0.0
content: ai_generated 28 sources retrieved model claude-sonnet-5 ·

Lithuania

LT schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 51 claims · 28 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
51Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

No content recorded at this JID path.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, mature GDPR-aligned framework with an active, EDPB-participating supervisory authority and no material derogation gaps identified.

Primary frameworkGeneral Data Protection Regulation (EU) 2016/679, as implemented by Law No XIII-1426 of 30 June 2018 amending Law No I-1374 (Law on Legal Protection of Personal Data)
Traffic-light rationale — GreenComprehensive, mature GDPR-aligned framework with an active, EDPB-participating supervisory authority and no material derogation gaps identified.

Sub-modules (5)

Regulator And AuthorityGreen

VDAI is the single national supervisory authority under GDPR Art. 51, participating in the EDPB.

Claims: CLM-LT-a1b2c301

Act And InstrumentsGreen

GDPR is directly applicable; national implementation is via Law No XIII-1426/2018 amending the Law on Legal Protection of Personal Data.

Claims: CLM-LT-a1b2c302

Material ScopeGreen

Material scope follows GDPR: covers processing by private-sector and most public-sector bodies.

Claims: CLM-LT-a1b2c303

Territorial ScopeGreen

GDPR extraterritorial reach applies: non-EU established entities offering goods/services to, or monitoring, Lithuania-based data subjects are in scope.

Claims: CLM-LT-a1b2c304

Regulator Registration And FilingAmber

No general notification regime; controllers/processors must communicate DPO contact details to VDAI where a DPO is appointed.

Claims: CLM-LT-a1b2c305

Category narrative41 words

Lithuania is an EU Member State fully subject to the GDPR, supervised by the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija, 'VDAI'), and implementing GDPR via a national amending law to the pre-existing Law on Legal Protection of Personal Data.

Sources and claims (5)
  1. ConfirmedEDPB<cite index="6-1,6-2">The State Data Protection Inspectorate, located at L. Sapiegos str. 17, 10312 Vilnius, Lithuania, is listed as the national supervisory authority with contact reachable via [email protected].</cite>
  2. ConfirmedDataGuidance<cite index="1-1">Lithuania implemented the GDPR through Law No XIII-1426 of 30 June 2018 amending Law No I-1374, together with the General Data Protection Regulation (Regulation (EU) 2016/679).</cite>
  3. ConfirmedEUR-Lex<cite index="67-8">The GDPR ensures protection of natural persons where their data is processed by the private sector and by most public-sector entities.</cite>
  4. ConfirmedEUR-Lex<cite index="67-31">Non-EU established companies must apply the same GDPR rules with regard to the offering of goods or services and the monitoring of the behaviour of persons living in the EU.</cite>
  5. ConfirmedDataGuidance<cite index="1-7,1-8">Article 37 GDPR obliges controllers and processors meeting DPO thresholds to designate a DPO, publish the DPO's contact details, and communicate them to the relevant supervisory authority.</cite>

#

No national derogation weakening GDPR standards identified; VDAI enforcement activity on biometric data confirms an active special-categories regime.

Primary frameworkGDPR Arts. 6, 7, 9, 10; Law No XIII-1426/2018
Traffic-light rationale — GreenNo national derogation weakening GDPR standards identified; VDAI enforcement activity on biometric data confirms an active special-categories regime.

Sub-modules (4)

Lawful BasesGreen

Standard GDPR Art. 6(1) bases apply (consent, contract, legal obligation, vital interests, public task, legitimate interests).

Claims: CLM-LT-b2c3d401

Special CategoriesAmber

VDAI has prioritised biometric-data enforcement (including in sports contexts) and issued recommendations on criminal-record data processing by employers.

Claims: CLM-LT-b2c3d403, CLM-LT-b2c3d404

Pseudonymisation And AnonymisationGreen

GDPR promotes pseudonymisation and encryption as risk-mitigation techniques; no LT-specific safe-harbour beyond the Regulation was identified.

Claims: CLM-LT-b2c3d405

Category narrative28 words

Lawful bases and consent standards follow GDPR Art. 6/7 directly. VDAI has issued sector guidance on special-category data (biometric, criminal-record) reflecting active supervisory focus on Art. 9/10 categories.

Sources and claims (5)
  1. ConfirmedEDPB<cite index="69-6">Data controllers can only process personal data lawfully where one of the enumerated legal bases in Article 6 GDPR applies, such as consent, contract, legal obligation, public interest, or legitimate interests.</cite>
  2. ConfirmedEDPB<cite index="69-9">Where consent is used as a legal basis, controllers must ensure the consent is freely given, informed, specific and unambiguous.</cite>
  3. ProbableDataGuidance<cite index="1-3">Areas of focus for VDAI have included biometric data, as indicated by its thorough review of the use of biometric data in sports.</cite>
  4. ProbableDataGuidance<cite index="1-26">VDAI's Recommendation outlines when and how employers in Lithuania can process criminal record data.</cite>
  5. ConfirmedEUR-Lex<cite index="67-35">To limit the risks of data processing, use of pseudonyms (replacing identifying fields with artificial identifiers) and encryption is promoted.</cite>

#

Rights framework is directly GDPR-derived and actively enforced; no LT-specific narrowing identified.

Primary frameworkGDPR Arts. 12-22
Traffic-light rationale — GreenRights framework is directly GDPR-derived and actively enforced; no LT-specific narrowing identified.

Sub-modules (5)

Access RightAmber

VDAI found Vinted failed to properly evidence action taken on access requests.

Claims: CLM-LT-c3d4e501

Rectification And ErasureAmber

VDAI enforcement covers both erasure-request handling (Vinted) and data-accuracy/rectification duties (Vilnius Municipality).

Claims: CLM-LT-c3d4e502, CLM-LT-c3d4e503

Restriction And ObjectionGreen

GDPR Art. 18 restriction regime applies directly; no LT derogation found.

Claims: CLM-LT-c3d4e504

Data PortabilityGreen

Standard Art. 20 portability right applies without LT-specific modification.

Claims: CLM-LT-c3d4e505

Deadlines And Response WindowsGreen

Controllers must respond within the GDPR's one-month (extendable by two months) statutory deadline.

Claims: CLM-LT-c3d4e506

Category narrative25 words

Data subject rights follow GDPR Arts. 15-22 directly. VDAI enforcement against Vinted (access/erasure) and against Vilnius Municipality (accuracy/rectification) demonstrates active application of these rights domestically.

Sources and claims (6)
  1. ConfirmedEDPB / VDAI<cite index="32-4">The Lithuanian SA found that the company also failed to demonstrate that it had taken or refused to act in accordance with the applicant's request for the right of access.</cite>
  2. ConfirmedEDPB / VDAI<cite index="32-1">Lithuanian SA found the company, in response to erasure requests, stated it would not act on a specific request because the applicant did not identify a specific reason under Article 17(1) GDPR and failed to identify all purposes of continued processing.</cite>
  3. ConfirmedEDPB / VDAI<cite index="17-4">A fine was imposed for infringements of Articles 5(1)(d) and 5(1)(f) GDPR for failure to implement appropriate technical and organisational measures ensuring accuracy of processed personal data.</cite>
  4. ConfirmedEUR-Lex<cite index="28-11">Where processing has been restricted, such personal data shall, with the exception of storage, only be processed with the data subject's consent or for the establishment, exercise or defence of legal claims or for the protection of the rights of another person or important public interest.</cite>
  5. ConfirmedEUR-Lex<cite index="67-5,67-6">Data subjects have easier access to their data and a right to data portability, allowing personal data to be transferred more easily between service providers.</cite>
  6. ConfirmedIAPP<cite index="89-6">Article 12(3) of the GDPR provides that organizations need to respond to data subject requests without undue delay and in any event within one month of receipt of the request.</cite>

#

Core duties are directly GDPR-derived and actively supervised; retention/disposal sub-module lacks a confirmed LT-specific instrument.

Primary frameworkGDPR Arts. 5, 24-39
Traffic-light rationale — GreenCore duties are directly GDPR-derived and actively supervised; retention/disposal sub-module lacks a confirmed LT-specific instrument.

Sub-modules (7)

Accountability And DpiaAmber

VDAI adopted a national DPIA list under Art. 35(4), reviewed and partly revised following EDPB Opinion 13/2018.

Claims: CLM-LT-d4e5f601, CLM-LT-d4e5f602

Dpo RequirementsAmber

Art. 37 DPO designation applies; VDAI inspections have identified DPO role-conflict issues in practice.

Claims: CLM-LT-d4e5f603

Ropa RequirementsGreen

VDAI has published guidance/recommendations on records of processing activities.

Claims: CLM-LT-d4e5f604

Joint Controller ArrangementsGreen

Standard Art. 26 joint-controller allocation-of-responsibility rule applies.

Claims: CLM-LT-d4e5f605

Security MeasuresAmber

VDAI has fined controllers for inadequate technical/organisational security measures under Art. 32.

Claims: CLM-LT-d4e5f606

Breach NotificationAmber

Standard 72-hour regulator notification duty applies; VDAI reports rising breach volumes.

Claims: CLM-LT-d4e5f607, CLM-LT-d4e5f608

Retention And DisposalRed

No LT sector-specific retention/disposal statute beyond the GDPR storage-limitation principle was located in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Category narrative47 words

Accountability, DPIA, DPO, ROPA, joint-controller, security and breach-notification duties follow GDPR directly. VDAI has published a national DPIA 'blacklist' under Art. 35(4), and has fined controllers for security failures (Art. 32). Retention/disposal rules are governed by the general storage-limitation principle; no LT sector-specific retention statute was identified.

Sources and claims (8)
  1. ConfirmedEDPB<cite index="91-1">Lithuania's SA adopted a list of the kind of processing operations which are subject to the requirement for a Data Protection Impact Assessment under Article 35(4) GDPR, per EDPB Opinion 13/2018.</cite>
  2. ConfirmedIAPP<cite index="94-6">DPIA is mandatory for processing of genetic data only while evaluating the data subject's features or scoring, including profiling and forecasting, following revision of the initial blacklist.</cite>
  3. ProbableDataGuidance<cite index="33-10">VDAI's inspection results reveal DPO role conflicts and emphasize the need for GDPR compliance audits.</cite>
  4. ProbableIAPP<cite index="12-7">In 2018-19, Lithuania's DPA released numerous guidelines and recommendations including recommendations for the records of processing activities.</cite>
  5. ConfirmedEUR-Lex<cite index="61-15,61-16">Where two or more controllers jointly determine the purposes and means of processing, they are joint controllers and must transparently determine their respective responsibilities by mutual arrangement.</cite>
  6. ConfirmedDataGuidance<cite index="4-5">VDAI considered that the Center for Registers had not implemented adequate technical and organisational measures, acting in contravention of Article 32 GDPR.</cite>
  7. ConfirmedEUR-Lex<cite index="83-5">In the case of a personal data breach, the controller shall without undue delay and, where feasible, not later than 72 hours after becoming aware of it, notify the breach to the competent supervisory authority, unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons.</cite>
  8. ConfirmedDataGuidance<cite index="41-5">VDAI reports 116 data breaches in early 2025, mostly due to human error and cyber incidents, affecting 168,822 individuals.</cite>

#

Framework is sound (GDPR Chapter V) but LT-specific TIA practice and confirmation of any localisation rules could not be fully verified in this pass.

Primary frameworkGDPR Arts. 44-49
Traffic-light rationale — AmberFramework is sound (GDPR Chapter V) but LT-specific TIA practice and confirmation of any localisation rules could not be fully verified in this pass.

Sub-modules (6)

Transfer MechanismsGreen

VDAI guidance recommends SCCs or BCRs as the operative transfer mechanisms for third-country transfers.

Claims: CLM-LT-e5f6a701

Adequacy ReceivedGreen

Adequacy determinations are adopted at EU level and apply uniformly across Member States; Lithuania does not issue separate national adequacy findings.

Claims: CLM-LT-e5f6a702

Adequacy GrantedGreen

Adequacy decisions regarding third countries are an EU Commission competence, not a Lithuanian national act.

Claims: CLM-LT-e5f6a702

Sccs And BcrsGreen

VDAI has issued guidance clarifying the optional nature of the EU SCCs for controller-processor relationships.

Claims: CLM-LT-e5f6a703

Transfer Impact AssessmentAmber

VDAI's Brexit FAQ recommended Lithuanian companies assess transfer bases irrespective of any adequacy decision, consistent with post-Schrems II TIA practice.

Claims: CLM-LT-e5f6a704

Data LocalisationRed

No general LT-specific data-localisation mandate was identified in this research pass beyond GDPR Chapter V.

Absence provenance: not recorded. Searched: not recorded.

Category narrative48 words

As an EU Member State, Lithuania relies on GDPR Chapter V transfer mechanisms (adequacy, SCCs, BCRs, derogations); adequacy decisions are an EU-level competence and not issued/received bilaterally by Lithuania. VDAI has issued practical guidance (e.g. on Brexit-related transfers and SCC use) but no LT-specific data-localisation mandate was found.

Sources and claims (4)
  1. ProbableDataGuidance<cite index="80-3">VDAI recommended that Lithuanian companies ensure the lawfulness of data transfers by determining the types of personal data transferred and assessing available bases such as Standard Contractual Clauses or Binding Corporate Rules.</cite>
  2. ConfirmedEUR-LexAdequacy decisions under GDPR Chapter V are adopted by the European Commission at EU level and apply directly to all Member States including Lithuania; VDAI does not issue separate national adequacy determinations.
  3. ProbableDataGuidance<cite index="11-21">Lithuania's VDAI clarifies the use of EU SCCs, highlighting their optional nature and specific applicability to data controller-processor relationships.</cite>
  4. ProbableDataGuidance<cite index="80-2,80-3">VDAI highlighted that upon expiry of the Brexit transitional period, Lithuanian companies should implement mechanisms ensuring lawfulness of transfers to the UK as a third country, regardless of any adequacy decision.</cite>

#

Core sectors (telecoms, employment, health, credit) are covered by guidance or investigation; education and insurance sub-modules show a coverage gap.

Primary frameworkGDPR; Law on Electronic Communications No. IX-2135 (as amended); Civil Service Law
Traffic-light rationale — AmberCore sectors (telecoms, employment, health, credit) are covered by guidance or investigation; education and insurance sub-modules show a coverage gap.

Sub-modules (7)

Financial Sector OverlayAmber

VDAI opened an investigation into fintech Revolut over a data breach affecting over 50,000 customers.

Claims: CLM-LT-f6a7b801

Health Sector OverlayGreen

VDAI issued FAQs on employer collection of employee health data under the Civil Service Law and GDPR Art. 5.

Claims: CLM-LT-f6a7b802

Telecoms And EprivacyGreen

ePrivacy obligations are transposed via the Law on Electronic Communications No. IX-2135 alongside GDPR.

Claims: CLM-LT-f6a7b803

Employment DataGreen

VDAI published three separate guides addressing employee, business, and public-sector employment data protection.

Claims: CLM-LT-f6a7b804

Credit And ScoringGreen

VDAI issued a recommendation on the processing of debtors' personal data covering lawful grounds and limits on data subject rights.

Claims: CLM-LT-f6a7b805

EducationRed

No LT-specific education-sector data-protection instrument was identified beyond general GDPR application (illustrated indirectly by the children's-camp consent case).

Absence provenance: not recorded. Searched: not recorded.

InsuranceRed

No LT-specific insurance-sector data-protection instrument was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative41 words

Sectoral overlays are thin in Lithuania beyond GDPR: telecoms/eprivacy is transposed via the Law on Electronic Communications; VDAI has issued employment and health-sector guidance; a fintech (Revolut) breach investigation illustrates financial-sector overlap. No LT-specific education or insurance-sector DP rules were found.

Sources and claims (5)
  1. ProbableDataGuidance<cite index="1-14">VDAI investigates Revolut for a data breach affecting over 50,000 customers, assessing GDPR violations.</cite>
  2. ConfirmedDataGuidance<cite index="5-4">Employers must ensure health data collection is necessary, use less intrusive means, and process data according to GDPR Article 5.</cite>
  3. ConfirmedDataGuidance<cite index="78-1">In addition to Law No XIII-1426 and the GDPR, the Law on Electronic Communications of 15 April 2004, No. IX-2135, as amended, applies to e-marketing in Lithuania.</cite>
  4. ConfirmedDataGuidance<cite index="3-3">VDAI published three guides: one for employees, one for businesses, and one for the public sector, all in the context of employment relations.</cite>
  5. ProbableDataGuidance<cite index="2-4">The VDAI recommendation on debtors' data outlines data processing principles, lawful grounds, and roles of parties, emphasizing that data subject rights do not affect debtors' contractual obligations.</cite>

#

Cookie and direct-marketing rules are covered; opt-out-signal and clean-room concepts are not applicable/found under the EU framework.

Primary frameworkGDPR; ePrivacy Directive 2002/58/EC as transposed via Law on Electronic Communications No. IX-2135
Traffic-light rationale — AmberCookie and direct-marketing rules are covered; opt-out-signal and clean-room concepts are not applicable/found under the EU framework.

Sub-modules (6)

Cookies And TrackersGreen

VDAI has issued cookie-compliance guidance emphasising user-friendly consent design.

Claims: CLM-LT-a7b8c901

Dark PatternsAmber

VDAI's Vinted decision found 'shadow blocking' practices unlawful for violating fairness and transparency principles, functioning as a dark-pattern precedent.

Claims: CLM-LT-a7b8c902

Opt Out SignalsRed

No LT-specific Global Privacy Control/DAA-equivalent opt-out signal regime was identified; not a feature of the EU consent-based model.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No LT-specific data clean-room regulation was identified.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingRed

The CPRA 'sale'/'share' construct has no direct EU/LT analogue; GDPR consent and legitimate-interest rules govern comparable adtech processing instead.

Absence provenance: not recorded. Searched: not recorded.

Direct MarketingGreen

VDAI guidance addresses direct marketing scope and consent/third-party-data requirements, including in the public sector.

Claims: CLM-LT-a7b8c903

Category narrative37 words

Cookie consent and direct-marketing rules follow GDPR/ePrivacy transposition. VDAI's Vinted enforcement establishes a precedent against non-transparent 'shadow blocking' practices analogous to dark patterns. No CPRA-style 'sale/share' concept or GPC-equivalent opt-out signal regime exists in this EU jurisdiction.

Sources and claims (3)
  1. ProbableDataGuidance<cite index="1-21">Lithuania's VDAI outlines cookie practices for compliance with GDPR and user-friendly design.</cite>
  2. ConfirmedEDPB / VDAI<cite index="32-2,32-3">The company unlawfully, in violation of the principles of fairness and transparency, processed personal data in the context of 'shadow blocking', i.e. processing intended to make a user leave the platform without being aware of it.</cite>
  3. ConfirmedDataGuidance<cite index="9-4,9-5">VDAI guidance clarifies that direct marketing includes inquiries about opinions on goods or services, including via post, telephone, or other direct means to subscribers or users of electronic communications services.</cite>

#

Biometric/genetic governance is documented; ADM-transparency and state-surveillance-carveout sub-modules rely on general GDPR text without LT-specific enforcement examples.

Primary frameworkGDPR Arts. 9, 22, 35; VDAI DPIA Order of 14 March 2019
Traffic-light rationale — AmberBiometric/genetic governance is documented; ADM-transparency and state-surveillance-carveout sub-modules rely on general GDPR text without LT-specific enforcement examples.

Sub-modules (6)

Profiling RestrictionsAmber

DPIA is required for genetic-data processing used for profiling/scoring/forecasting individuals.

Claims: CLM-LT-b8c9d001

Automated Decision Making TransparencyRed

No LT-specific Art. 22 ADM enforcement precedent was located in this research pass; GDPR Art. 22 applies directly as EU law.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsAmber

VDAI has publicly warned about AI tool risk (DeepSeek) and issued FAQ guidance for organisations starting AI system deployments.

Claims: CLM-LT-b8c9d002, CLM-LT-b8c9d003

Biometric RegimeAmber

Lithuania's DPIA list treats standalone biometric-identification processing as a DPIA trigger; VDAI fined a sports-club operator for unlawful biometric processing.

Claims: CLM-LT-b8c9d004, CLM-LT-b8c9d005

Genetic DataGreen

Genetic-data DPIA obligation was narrowed to profiling/scoring contexts after EDPB review of the initial 2018 list.

Claims: CLM-LT-b8c9d001

State Surveillance CarveoutsGreen

GDPR permits Member State law to restrict certain data-subject rights and obligations for criminal-law-enforcement and public-security purposes.

Claims: CLM-LT-b8c9d006

Category narrative42 words

Lithuania's DPIA 'blacklist' treats biometric- and genetic-data processing as DPIA triggers (partially revised after EDPB opinion). VDAI has fined a biometric-data controller and issued a public AI-risk warning regarding DeepSeek. No LT-specific Art. 22 ADM enforcement precedent was located in this pass.

Sources and claims (6)
  1. ConfirmedIAPP<cite index="94-6">DPIA is mandatory for the processing of genetic data specifically while evaluating the data subject's features or scoring, including profiling and forecasting.</cite>
  2. ConfirmedIAPP<cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or to think carefully about how they use it, citing insufficient information about its privacy practices.</cite>
  3. ProbableDataGuidance<cite index="66-8">VDAI's FAQ guides organizations on starting with AI systems, emphasizing GDPR compliance and expert involvement.</cite>
  4. UncertainIAPP<cite index="95-7,95-8">Lithuania's SA list stated that biometric-data processing on its own would create the obligation to perform a DPIA; the EDPB requested amendment so that biometric processing to uniquely identify a person requires a DPIA only in conjunction with at least one other criterion.</cite>
  5. ConfirmedDataGuidance<cite index="1-13">Praktiškas was fined €6,000 for GDPR violations related to biometric data processing at its sports clubs.</cite>
  6. ConfirmedEUR-Lex<cite index="83-11">Union or Member State law may restrict the scope of certain GDPR obligations and rights where necessary to safeguard the prevention, investigation, detection or prosecution of criminal offences, public security, or other important objectives of general public interest.</cite>

#

Core Art. 8 framework applies but the exact Lithuanian national age-of-consent derogation (if any) could not be confirmed; education-settings and dependent-adults sub-modules lack dedicated LT instruments.

Primary frameworkGDPR Art. 8
Traffic-light rationale — AmberCore Art. 8 framework applies but the exact Lithuanian national age-of-consent derogation (if any) could not be confirmed; education-settings and dependent-adults sub-modules lack dedicated LT instruments.

Sub-modules (5)

Age VerificationAmber

Controllers must make reasonable efforts to verify parental-responsibility-holder consent for children below the applicable age threshold.

Claims: CLM-LT-c9d0e101

Minor Profiling BansAmber

VDAI found a children's-camp organiser's consent mechanism for processing children's image data did not meet GDPR consent conditions (freely given, specific, revocable).

Claims: CLM-LT-c9d0e103

Education SettingsRed

No dedicated LT education-sector children's-data instrument was identified beyond the general consent enforcement precedent noted above.

Absence provenance: not recorded. Searched: not recorded.

Dependent AdultsRed

No LT-specific dependent-adults (elderly/mentally incapacitated) data-protection provision was identified.

Absence provenance: not recorded. Searched: not recorded.

Category narrative55 words

GDPR Art. 8 sets a default digital-consent age of 16 with Member State discretion to lower to no less than 13; no confirmed Lithuanian national derogation was found in this research pass, so the GDPR default is presumed to apply. VDAI enforcement against a children's-camp operator illustrates active supervision of consent for minors' image data.

Sources and claims (3)
  1. ConfirmedEUR-Lex<cite index="61-8">The controller shall, taking into account available technologies, make reasonable efforts to verify that consent has been given or authorised by the holder of parental responsibility over the child.</cite>
  2. UncertainEDPB<cite index="69-2,69-3">Children aged 16 and above are considered able to give their own consent; for children below 16, the organisation must request consent from that child's legal guardian or parent, absent a lower national threshold.</cite>
  3. ConfirmedEDPB / VDAI<cite index="45-13,45-14">The organisation's processing of children's image data without GDPR-compliant consent, including failure to allow free choice or withdrawal without detriment, infringed the principle of lawfulness and the conditions of consent under Articles 5(1)(a), 6 and 7 GDPR.</cite>

#

Enforcement powers and recent activity are well evidenced; funding/capacity and collective-redress sub-modules lack confirmed LT-specific detail.

Primary frameworkGDPR Arts. 58, 77-84
Traffic-light rationale — GreenEnforcement powers and recent activity are well evidenced; funding/capacity and collective-redress sub-modules lack confirmed LT-specific detail.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

VDAI can impose fines up to the GDPR statutory maxima of €20 million or 4% of global annual turnover, whichever is higher.

Claims: CLM-LT-d0e1f201

Enforcement Activity IndexAmber

Notable 2021-2024 fines include Vinted (€2.38M, 2024), Vilnius Municipality (€15,000, 2021) and State Enterprise Centre of Registers (€15,000, 2021).

Claims: CLM-LT-d0e1f202, CLM-LT-d0e1f203, CLM-LT-d0e1f204

Regulator Funding And CapacityRed

No confirmed data on VDAI's budget or headcount was located in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Collective Redress And Class ActionsRed

GDPR Art. 80 permits representative actions by not-for-profit bodies on behalf of data subjects; no LT-specific implementing detail was confirmed in this pass.

Absence provenance: not recorded. Searched: not recorded.

Private Right Of ActionGreen

VDAI decisions are subject to judicial appeal, evidencing an available private right of action/judicial remedy route.

Claims: CLM-LT-d0e1f205

Recent Developments 180DAmber

Within the last 180 days, VDAI's public warning regarding DeepSeek's data practices reflects the most notable documented development.

Claims: CLM-LT-d0e1f206

Category narrative63 words

VDAI actively exercises GDPR Art. 83 fining powers, with a notable escalation to a €2.38M fine against Vinted in 2024 alongside multiple smaller fines (Vilnius Municipality, State Enterprise Centre of Registers, Praktiškas). Judicial appeal of VDAI decisions is available. Regulator funding/capacity data and collective-redress mechanisms were not confirmed in this pass; the most recent notable development is VDAI's 2026 public warning on DeepSeek.

Sources and claims (6)
  1. ConfirmedEDPB<cite index="102-1">A supervisory authority can impose fines that go up to a maximum of 20 million or 4% of total worldwide annual turnover in the previous financial year for breaches such as unlawful processing or breaches of data subject rights.</cite>
  2. ConfirmedEDPB / VDAI<cite index="32-10">In fining Vinted, the Lithuanian SA relied on EDPB Guidelines 04/2022 on calculation of administrative fines, taking into account the cross-border scope of processing, the large number of data subjects affected, and the duration of the infringements.</cite>
  3. ConfirmedEDPB / VDAI<cite index="17-2">A fine in the amount of EUR 15,000 was imposed on Vilnius City Municipality Administration for improperly processed personal data of the parents of an adopted child.</cite>
  4. ConfirmedDataGuidance<cite index="4-1">VDAI fined the State Enterprise Center for Registers €15,000 for implementing inadequate technical and organisational measures for data security.</cite>
  5. ConfirmedEDPB / VDAI<cite index="17-16">The decision of the SDPI is not effective and may be appealed against to the court.</cite>
  6. ConfirmedIAPP<cite index="113-4">Lithuania's State Data Protection Inspector urged residents to not use the DeepSeek app or think carefully about how they use it, citing insufficient information about its privacy practices.</cite>
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Lithuania
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 51 claim(s), 28 source(s) in the cumulative register.