General Data Protection Regulation Compliance in Lithuania
GDPR governs the processing of personal data of EU residents. It requires lawful basis for processing, data subject rights, breach notification, and accountability measures.
How does GDPR apply in Lithuania?
GDPR applies in Lithuania under EU law with the same obligations as across the bloc — maximum fine €20M or 4% of global turnover. The national supervisory authority is the VDAI (Valstybinė duomenų apsaugos inspekcija), which handles enforcement, complaints, and notifications. Deadline: In force since May 25, 2018.
- Supervisory authority: VDAI (Valstybinė duomenų apsaugos inspekcija)
- Maximum fine: €20M or 4% of global turnover
- Key deadline: In force since May 25, 2018
| Supervisory authority | VDAI (Valstybinė duomenų apsaugos inspekcija) |
| Maximum fine | €20M or 4% of global turnover |
| Key deadline | In force since May 25, 2018 |
| Sectors affected | All sectors processing EU personal data |
In force since May 25, 2018
€20M or 4% of global turnover
All sectors processing EU personal data
What are my GDPR obligations in Lithuania?
- Maintain records of processing activities (ROPA)
- Conduct Data Protection Impact Assessments
- Appoint a Data Protection Officer (if required)
- Implement data subject rights procedures
- Report breaches within 72 hours
Does GDPR apply to your Lithuania business?
Find out in 2 minutes with our free regulation checker.
Check now — freeGDPR compliance in other EU countries
Check Your Compliance Obligations
Find out which GDPR obligations apply to your Lithuania organisation in under 2 minutes.
Explore GDPR Compliance
For informational purposes only. This is not legal advice — consult qualified legal counsel.