GDPR Articles 82-83 and VDAI Enforcement in Lithuania
Regulation (EU) 2016/679, Arts. 82-83
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Expect VDAI to have jurisdiction and fining power over your processing of personal data of a person in Lithuania, up to the General Data Protection Regulation (GDPR) Article 83(5) tiers.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor, under GDPR Article 82.
If you get it wrong
Criminal exposureYes
Private right of actionYes
Criminal exposure note
Lithuanian Criminal Code (Baudziamasis kodeksas) Article 167 criminalizes unlawful collection of information about a person's private life, punishable by community service, a fine, restriction of liberty, arrest, or imprisonment for up to three years; a legal entity is also liable for the same act. This is a general Criminal Code privacy offense, not a provision of the GDPR-implementing Act itself, and sits alongside VDAI's administrative fining power under GDPR Article 83.
Penalty structure
GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, for infringements including the Article 9 special category rules, the Article 12 to 22 data subject rights, and the Chapter V transfer rules. The lower Article 83(4) tier, up to EUR 10,000,000 or 2% of turnover, applies instead to the Article 25 to 39 controller and processor obligations, including the Article 33 and 34 breach notification duties. Secondary trackers (DLA Piper, Linklaters) report a lower public-sector fine ceiling, not independently confirmed against the Act's own text.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija, VDAI), Lithuania's independent supervisory authority under the GDPR.
Enforcement record
Counts VDAI's own reported fines for personal data security violations in calendar year 2025 (5), per VDAI's own summary of its 2025 activity, published 2026-04-15: total fines EUR 27,029, largest EUR 9,000, smallest EUR 3,529. In the same period VDAI also issued 66 instructions, 56 reprimands, 78 recommendations, and 2 warnings as corrective measures short of a fine; those are not counted in actions_per_year here. Public enforcement actions only. The release does not state the two other individual fine amounts or a cumulative since-2018 total, so median_fine, p90_fine and total_fines are not recorded here.
- As of
- 2 September 2026
- Currency
- EUR
- Source link
- https://vdai.lrv.lt/lt/naujienos/valstybines-duomenu-apsaugos-inspekcijos-veikla-2025-m-qeY/
- Fines per year
- 27,029
- Actions per year
- 5
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
VDAI enforces the Act with the General Data Protection Regulation (GDPR) Article 58 corrective powers and fining authority, confirmed by both DLA Piper and Linklaters. The private-sector fine ceiling follows the standard GDPR Article 83(5) figures, up to EUR 20 million or 4 percent of global annual turnover; both sources separately report a lower public-sector ceiling capped at a percentage of that body's own budget, a figure not independently confirmed against primary legislative text.
GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.
When LexLint raises it
crawls_webtrains_modelsdeploys_chatbothigh_risk_decisionsprocesses_biometricsprocesses_voice
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2016/679
DLA Piper and Linklaters secondary legal trackers for the public-sector fine ceiling, not independently confirmed against primary text
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.