EnglishLT
Lithuania flag

Lithuania

Lithuania Data Privacy Laws: GDPR, VDAI Enforcement & Compliance Guide (2026)

By Recording Law Editorial TeamReviewed May 20, 202620 min read
Lithuania Data Privacy Laws: GDPR, VDAI Enforcement & Compliance Guide (2026)

Frequently Asked Questions

What is Lithuania's main data protection law?

Lithuania's data protection regime rests on two instruments. The EU General Data Protection Regulation (GDPR) applies directly as EU law. The national Law on Legal Protection of Personal Data, amended on 16 July 2018, supplements the GDPR with provisions on the supervisory authority, personal identification codes, employment data, journalistic exemptions, and the digital consent age of 14.

What is the VDAI and what does it do?

The State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija, VDAI) is Lithuania's independent data protection supervisory authority, based in Vilnius. The VDAI investigates complaints, conducts inspections, issues guidance, and imposes administrative fines for GDPR violations. It also represents Lithuania on the European Data Protection Board. Its Director is appointed by the Lithuanian Parliament (Seimas).

What was the largest GDPR fine in Lithuania?

The largest GDPR fine in Lithuania was EUR 2,385,276, imposed on Vinted UAB in July 2024. The VDAI found that Vinted was shadow-blocking users who submitted erasure requests while appearing to process those requests, and that the company's transparency disclosures were inadequate. The fine addressed violations of GDPR Articles 5(1)(a), 5(2), 12(1), and 12(4).

What is the age of digital consent in Lithuania?

Lithuania set the digital consent age at 14. Children aged 14 and older may independently consent to information society services such as social media and apps. Children under 14 require verifiable parental or guardian authorization. This is below the GDPR default of 16, which Lithuania reduced using the discretion the GDPR grants member states.

What are Lithuania's data breach notification requirements?

Controllers must notify the VDAI within 72 hours of becoming aware of a personal data breach that poses a risk to individuals' rights and freedoms. If the breach is likely to result in high risk to data subjects, those individuals must also be notified directly without undue delay. In 2024, the VDAI received 273 breach reports and 21% of controllers filed late.

Does Lithuania have special rules for journalistic data processing?

Yes. Lithuania created a dual supervisory structure in which the Inspector of Journalist Ethics shares oversight responsibilities with the VDAI for data processing connected to journalistic, academic, artistic, or literary purposes. The Inspector cooperates with the VDAI to ensure GDPR compliance while bringing media freedom expertise to the oversight function.

How does the EU AI Act interact with Lithuania's GDPR framework?

The EU AI Act and the GDPR operate as parallel frameworks. For AI systems that process personal data, controllers must satisfy both the AI Act's high-risk system requirements and GDPR lawfulness requirements. Lithuania designated the Communications Regulatory Authority (RRT) as its AI Act national competent authority and market surveillance authority. The VDAI retains its GDPR enforcement authority over personal data in AI systems.

How can personal data be transferred from Lithuania to countries outside the EU?

Transfers from Lithuania to third countries outside the EEA require a legal mechanism: an EU adequacy decision for the destination country, Standard Contractual Clauses, Binding Corporate Rules, approved codes of conduct, or specific derogations. Following the Schrems II judgment, controllers must also conduct transfer impact assessments to verify that third-country legal protections do not undermine the safeguards in practice.

Updates

Full audit-and-evolve refresh. Expanded from approximately 2,250 words to approximately 5,800 words. Added constitutional foundation section (Article 22), detailed legal bases section covering all six GDPR bases, full data subject rights catalog, DPO requirements and registration, cross-border transfers with Schrems II context and TIA requirement, EU AI Act overlay (RRT designation as national competent authority), expanded enforcement record (CityBee EUR 110,000, sports club EUR 20,000, 2025 second-hand platform fine), 2024 breach statistics (273 notifications, 1,467,368 affected subjects, 52% human error, 21% late filings), July 2024 criminal record data amendment, 2025 VDAI guidance on non-breach incidents, fintech hub context, and updated business compliance section.

Sources and References

  1. VDAI Official Site(vdai.lrv.lt).gov
  2. VDAI Legislation(vdai.lrv.lt).gov
  3. VDAI Decisions(vdai.lrv.lt).gov
  4. VDAI 2024 Activities(vdai.lrv.lt).gov
  5. VDAI 2024 Breach Stats(vdai.lrv.lt).gov
  6. Lithuanian Data Protection Law(e-seimas.lrs.lt).gov
  7. LRT Vinted Fine(lrt.lt)
  8. VDAI CityBee FAQ(vdai.lrv.lt).gov
  9. EDPB(edpb.europa.eu).gov
  10. EU SCCs(commission.europa.eu).gov
  11. EU AI Act National Plans(artificialintelligenceact.eu)
  12. Lithuania AI Policy(eimin.lrv.lt).gov
  13. DLA Piper Lithuania(dlapiperdataprotection.com)
  14. Linklaters Lithuania(linklaters.com)
Share: