Law / Lithuania

GDPR Articles 82-83 and VDAI Enforcement in Lithuania

Regulation (EU) 2016/679, Arts. 82-83

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

An enforcement supervision rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Expect VDAI to have jurisdiction and fining power over your processing of personal data of a person in Lithuania, up to the General Data Protection Regulation (GDPR) Article 83(5) tiers.
  • Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.

If you get it wrong

Criminal exposureYes

Private right of actionYes

Criminal exposure note

Lithuanian Criminal Code (Baudziamasis kodeksas) Article 167 criminalizes unlawful collection of information about a person's private life, punishable by community service, a fine, restriction of liberty, arrest, or imprisonment for up to three years; a legal entity is also liable for the same act. This is a general Criminal Code privacy offense, not a provision of the GDPR-implementing Act itself, and sits alongside VDAI's administrative fining power under GDPR Article 83.

Penalty structure

GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, for infringements including the Article 9 special category rules, the Article 12 to 22 data subject rights, and the Chapter V transfer rules. The lower Article 83(4) tier, up to EUR 10,000,000 or 2% of turnover, applies instead to the Article 25 to 39 controller and processor obligations, including the Article 33 and 34 breach notification duties. Secondary trackers (DLA Piper, Linklaters) report a lower public-sector fine ceiling, not independently confirmed against the Act's own text.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija, VDAI), Lithuania's independent supervisory authority under the GDPR.

Enforcement record

Counts VDAI's own reported fines for personal data security violations in calendar year 2025 (5), per VDAI's own summary of its 2025 activity, published 2026-04-15: total fines EUR 27,029, largest EUR 9,000, smallest EUR 3,529. In the same period VDAI also issued 66 instructions, 56 reprimands, 78 recommendations, and 2 warnings as corrective measures short of a fine; those are not counted in actions_per_year here. Public enforcement actions only. The release does not state the two other individual fine amounts or a cumulative since-2018 total, so median_fine, p90_fine and total_fines are not recorded here.

As of
2 September 2026
Currency
EUR
Source link
https://vdai.lrv.lt/lt/naujienos/valstybines-duomenu-apsaugos-inspekcijos-veikla-2025-m-qeY/
Fines per year
27,029
Actions per year
5

What it reaches

Obligation class

Governance

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

VDAI enforces the Act with the General Data Protection Regulation (GDPR) Article 58 corrective powers and fining authority, confirmed by both DLA Piper and Linklaters. The private-sector fine ceiling follows the standard GDPR Article 83(5) figures, up to EUR 20 million or 4 percent of global annual turnover; both sources separately report a lower public-sector ceiling capped at a percentage of that body's own budget, a figure not independently confirmed against primary legislative text.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • high_risk_decisions
  • processes_biometrics
  • processes_voice

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679
DLA Piper and Linklaters secondary legal trackers for the public-sector fine ceiling, not independently confirmed against primary text

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app