Law / Lithuania

GDPR Articles 33-34, Breach Notification in Lithuania

Regulation (EU) 2016/679, Arts. 33-34

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A breach notification rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Notify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, unless the breach is unlikely to risk their rights and freedoms.
  • Notify affected individuals without undue delay where a breach is likely to result in a high risk to their rights and freedoms.

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

A controller must notify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Neither DLA Piper nor Linklaters reports a Lithuania-specific narrowing of this.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • processes_biometrics
  • processes_voice

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app