Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-07-16
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Neither DLA Piper nor Linklaters reports a Lithuania-specific narrowing of this.
What it asks of an app →
Comprehensive regime
cite Republic of Lithuania Law No. XIII-1426, in force 16 July 2018 (as amended)
stage In effect
since 2018-07-16
source VDAI legislation index, vdai.lrv.lt, fetched and read directly (title only)
The Law on Legal Protection of Personal Data gives the General Data Protection Regulation (GDPR) domestic effect in Lithuania and is enforced by the State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija, VDAI), whose title this pass confirmed directly from VDAI's own legislation index.
Two independent secondary legal trackers (DLA Piper, Linklaters) agree that Lithuania sets the digital age of consent for information society services at 14, below the GDPR default of 16, and that VDAI itself issues the authorization for an Article 46(3) cross-border transfer within 20 working days, extendable to 30 in certain cases; neither figure was independently confirmed against the Act's own text, which two fetch attempts (WebFetch and crawler infrastructure) could not retrieve this pass.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-50
stage In effect
since 2018-07-16
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Lithuania outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.
Two independent secondary trackers (DLA Piper, Linklaters) agree that Lithuania adds a national procedural layer: VDAI itself issues the authorization for a transfer based on Article 46(3) ad hoc contractual clauses or administrative arrangements, reported as taking up to 20 working days and, in certain cases, up to 30; not independently confirmed against the Act's own text this pass.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Arts. 15-22
stage In effect
since 2018-07-16
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Lithuania: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect. Neither DLA Piper nor Linklaters reports a Lithuania-specific derogation to these rights beyond the age-of-consent point recorded on the comprehensive-regime instrument.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83
stage In effect
since 2018-07-16
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
VDAI enforces the Act with the General Data Protection Regulation (GDPR) Article 58 corrective powers and fining authority, confirmed by both DLA Piper and Linklaters. The private-sector fine ceiling follows the standard GDPR Article 83(5) figures, up to EUR 20 million or 4 percent of global annual turnover; both sources separately report a lower public-sector ceiling capped at a percentage of that body's own budget, a figure not independently confirmed against primary legislative text this pass.
GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9
stage In effect
since 2018-07-16
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Lithuanian statutory enumeration, illustrative list, or VDAI guidance document text on biometric identifiers, faceprints, or voiceprints was read directly this pass.
Secondary commentary (Linklaters) describes VDAI as having issued an order naming processing of telephone-conversation recordings and use of biometric data among the situations requiring a data protection impact assessment; the order itself was not read, so its content is not restated here beyond this general description.
What it asks of an app →