Law / Lithuania

Lithuania

European Union law applies in Lithuania Lithuania is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Lithuania, described on this page below, applies here too.

16 of 18 named instruments researched to a stage, across all six areas of law we track: 16 in force. As of 14 September 2026.

When they take effect15 of 16 carry a date, 1 does not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 0 instruments 2018: 6 instruments (6 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 1 instrument (1 in force) 2022: 3 instruments (3 in force) 2023: 0 instruments 2024: 2 instruments (2 in force) 2025: 2 instruments (2 in force) 2026: 0 instruments ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 2
  2. Privacy law 6
  3. Scraping law 1
  4. Cybersecurity law 2
  5. Age gating law 1
  6. News aggregation law 4

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (160 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Lithuania and is not restated here as Lithuanian law. Lithuania has added two of its own instruments.

Seimas amendments adopted 14 January 2025 to the Law on Technology and Innovation and the Law on Information Society Services designated the Communications Regulatory Authority (RRT) as the AI Act's market-surveillance authority and single point of contact and the Innovation Agency as the notifying authority, and the Innovation Agency also operates an AI regulatory sandbox.

Separately, Criminal Code Article 309(2) bans producing, acquiring, possessing, exhibiting, or distributing child-sexual-abuse material, in a technology-neutral formulation that reaches material in which a person is presented as a child as well as material depicting a real child.

A May 2024 Seimas resolution calling for responsible AI use in the public sector and the Ministry of Economy and Innovation's National Artificial Intelligence Strategic Guidelines 2026-2035 are both non-binding policy documents that create no obligation for a private-sector developer.

AI governance

Lithuanian Law Amendments Designating National Competent Authorities under the AI Act

Seimas amendments to the Law on Technology and Innovation and the Law on Information Society Services, adopted 14 January 2025Ministry of Economy and Innovation of the Republic of Lithuania, official sector-activities page on Artificial Intelligence

In force. Binds public and private bodies.

What this law does

The Seimas adopted these amendments to the Law on Technology and Innovation and the Law on Information Society Services on 14 January 2025. Per the Ministry of Economy and Innovation's own account, the amendments designate the Communications Regulatory Authority (RRT) as market-surveillance authority and single point of contact for the EU AI Act. The same amendments designate the Innovation Agency as the notifying authority.

The Innovation Agency also operates an AI regulatory sandbox where companies will receive expert advice on the compliance of their solutions with the AI Act and other relevant regulations. The Ministry's own account states only this adoption date, not a separate commencement date.

What it requires

AI prohibited practices

Criminal Code Art. 309(2), Dealing in Child Sexual Abuse Material Including Simulated Depictions

BK art. 309(2)-(3), (5)Criminal Code of the Republic of Lithuania, Art. 309, INFOLEX mirror of the official text

In force since 1 February 2025. Binds public and private bodies.

What this law does

Criminal Code Art. 309(2) bans producing, acquiring, possessing, exhibiting, advertising, offering, or distributing pornographic material depicting a child, or a person presented as a child, or using information and communication technologies to acquire or provide access to such material, punishable by a fine, restriction of liberty, arrest, or imprisonment for up to four years.

The 'person presented as a child' wording reaches a simulated or artificially generated depiction and does not require the material to show a real child. Article 309(3) raises the maximum to five years' imprisonment for producing, acquiring, or distributing a large quantity of material depicting a minor. A legal entity is also liable under Article 309(5).

This is a general criminal-law prohibition rather than an AI-specific statute, and it binds any person regardless of the tool used to produce the material.

What it requires

Privacy law6 instruments, 6 in force

Research summary (93 words)

Lithuania's private-sector regime is the General Data Protection Regulation (GDPR) plus the Law on Legal Protection of Personal Data (Republic of Lithuania Law No. XIII-1426, in force 16 July 2018), enforced by the State Data Protection Inspectorate (VDAI).

VDAI's own title is confirmed from its legislation index; the Act's own numbered provisions have not been located, so the national specifics below, the digital age of consent at 14, the VDAI Article 46(3) transfer authorization, and the public-sector fine ceiling, rest on two independent secondary legal trackers. As at 24 August 2026; later amendment is not independently confirmed.

Breach notification

GDPR Articles 33-34, Breach Notification in Lithuania

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify VDAI without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach affecting a person in Lithuania, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. Neither DLA Piper nor Linklaters reports a Lithuania-specific narrowing of this.

What it requires

Comprehensive regime

Law on Legal Protection of Personal Data

Republic of Lithuania Law No. XIII-1426, in force 16 July 2018 (as amended)VDAI legislation index, vdai.lrv.lt (title only)

In force since 16 July 2018. Binds public and private bodies.

What this law does

The Law on Legal Protection of Personal Data gives the General Data Protection Regulation (GDPR) domestic effect in Lithuania and is enforced by the State Data Protection Inspectorate (Valstybine duomenu apsaugos inspekcija, VDAI), whose title is confirmed directly from VDAI's own legislation index.

Two independent secondary legal trackers (DLA Piper, Linklaters) agree that Lithuania sets the digital age of consent for information society services at 14, below the GDPR default of 16, and that VDAI itself issues the authorization for an Article 46(3) cross-border transfer within 20 working days, extendable to 30 in certain cases; neither figure is independently confirmed against the Act's own text, which the gazette's URL does not serve.

What it requires

Cross border transfer

GDPR Chapter V and VDAI Article 46(3) Authorization, Cross-Border Transfer from Lithuania

Regulation (EU) 2016/679, Arts. 44-50Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Lithuania outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the Article 83(5) top fine tier.

Two independent secondary trackers (DLA Piper, Linklaters) agree that Lithuania adds a national procedural layer: VDAI itself issues the authorization for a transfer based on Article 46(3) ad hoc contractual clauses or administrative arrangements, reported as taking up to 20 working days and, in certain cases, up to 30; not independently confirmed against the Act's own text.

What it requires

Data subject rights

GDPR Article 22 and Data Subject Rights as Applied in Lithuania

Regulation (EU) 2016/679, Arts. 15-22Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 15 to 21 apply directly in Lithuania: access, rectification, erasure, restriction, portability, and objection, exercisable against the controller. Article 22 gives a qualified right against a decision based solely on automated processing with legal or similarly significant effect. Neither DLA Piper nor Linklaters reports a Lithuania-specific derogation to these rights beyond the age-of-consent point recorded on the comprehensive-regime instrument.

What it requires

Enforcement supervision

GDPR Articles 82-83 and VDAI Enforcement in Lithuania

Regulation (EU) 2016/679, Arts. 82-83Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

VDAI enforces the Act with the General Data Protection Regulation (GDPR) Article 58 corrective powers and fining authority, confirmed by both DLA Piper and Linklaters. The private-sector fine ceiling follows the standard GDPR Article 83(5) figures, up to EUR 20 million or 4 percent of global annual turnover; both sources separately report a lower public-sector ceiling capped at a percentage of that body's own budget, a figure not independently confirmed against primary legislative text.

GDPR Article 82 gives any person who suffered material or non-material damage a right to compensation from the controller or processor.

What it requires

Sensitive categories

GDPR Article 9, Special Categories of Personal Data as Applied in Lithuania

Regulation (EU) 2016/679, Art. 9Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) classifies biometric data processed for unique identification as a special category. No Lithuanian statutory enumeration, illustrative list, or VDAI guidance document text on biometric identifiers, faceprints, or voiceprints was independently confirmed.

Secondary commentary (Linklaters) describes VDAI as having issued an order naming processing of telephone-conversation recordings and use of biometric data among the situations requiring a data protection impact assessment; the order itself is not reproduced here beyond this general description.

What it requires

Scraping law1 instrument, 1 in force

Research summary (172 words)

Lithuania's Criminal Code (Baudziamasis kodeksas) criminalizes unauthorized access to, and interference with, an information system or its electronic data at Articles 196 to 198 and 198-1, reaching any person with an aggravated tier and legal-entity liability throughout; Article 198-1's authorization test is keyed to breaching the system's own security measures, so a crawl of a page that imposes no technical access control is not reached by it.

The Autoriu teisiu ir gretutiniu teisiu istatymas (Law on Copyright and Related Rights) has, per the Seimas's own document index, an electronic press-publishers' right (Art. 57-1), text-and-data-mining exceptions (Arts. 22-1 and 22-2), and database-producer rights (Arts. 61-64); the operative wording of those articles is not reproduced in the copies of the Act available here, so the copyright and text-and-data-mining exception, database rights, and terms-of-service enforceability are not independently confirmed for Lithuania in this topic.

Personal-data reach over scraped public data is covered at EU level by the General Data Protection Regulation (GDPR) and is not restated in this topic. Unfair competition and robots.txt legal weight are not described here.

Computer misuse

Criminal Code Arts. 196-198 and 198-1, Computer Misuse and Unauthorised Access Offenses

BK arts. 196, 197, 198, 198-1Criminal Code of the Republic of Lithuania, Arts. 196-198 and 198-1, INFOLEX mirror of the official text

In force since 1 February 2025. Binds public and private bodies.

What this law does

Article 198-1 punishes unlawfully connecting to an information system or part of it by breaching that system's security measures, up to two years' imprisonment, rising to three years where the system has strategic national-security or major state-governance, economic, or financial significance; the authorization test is keyed to circumventing a technical protection measure, so a crawl of an unprotected public page is not reached by it.

Articles 196 and 197 punish unlawfully destroying, damaging, deleting, or altering electronic data, or disrupting an information system's operation, causing damage, up to two years, rising to six years for the same aggravating circumstances or a large-scale effect across multiple systems or use of another person's personal data.

Article 198 punishes unlawfully observing, recording, intercepting, acquiring, holding, disseminating, or otherwise using non-public electronic data, up to four years, rising to six years for the same aggravating circumstances. A legal entity is also liable for each offense.

What it requires

Cybersecurity law2 instruments, 2 in force

Research summary (527 words)

Lithuania's NIS2 transposition is enacted and in force. The Lietuvos Respublikos kibernetinio saugumo įstatymo Nr. XII-1428 pakeitimo įstatymas (the Law amending the Republic of Lithuania's Law on Cyber Security No. XII-1428), Document No. XIV-2902, was adopted by the Seimas on 11 July 2024, published in the Register of Legal Acts (TAR) on 24 July 2024, and entered into force on 18 October 2024.

It restates the Law on Cyber Security in a new consolidated wording that transposes NIS2 (Directive (EU) 2022/2555).

Article 14 requires a cybersecurity subject (essential or important entity, kibernetinio saugumo subjektas), identified against the Annex 1 and Annex 2 sector lists that the National Cyber Security Centre (Nacionalinis kibernetinio saugumo centras, NKSC, under the Ministry of National Defence) maintains in a Cybersecurity Subjects Register, to adopt cybersecurity policy documents, periodically analyse and manage its cybersecurity risks, designate a cybersecurity manager and/or security officer, manage and report cybersecurity incidents, secure its supply chain, and deploy technical cybersecurity measures, detailed further in the Government's Cybersecurity Requirements Description (Kibernetinio saugumo reikalavimų aprašas, Government Resolution No. 818 of 13 August 2018, as restated) with a 12-month grace period for organisational measures and 24 months for technical measures from an entity's own registration date.

A named subset of digital-service "special subjects" (specialieji subjektai), including a DNS service provider, a top-level-domain registry, a cloud or data-centre service provider, a content-delivery-network or managed-service provider, an electronic-marketplace provider, and an internet-search-engine or social-networking-service-platform provider, follow instead the directly-applicable European Commission Implementing Regulation (EU) 2024/2690, in force since 7 November 2024.

Article 18 requires the same essential and important entities to notify NKSC of a significant cyber incident within 24 hours of becoming aware of it, follow within 72 hours with a severity and impact assessment and any evidence of compromise, and submit a final report within one month of the incident's registration; Lithuania's transposition extends the reporting duty beyond NIS2's own floor by also requiring notice of a minor incident, within 72 hours, and of a near-miss, and by letting a subject with no statutory duty report voluntarily.

NKSC enforces both duties through a graduated ladder of NKSC-ordered measures culminating in a fine of up to EUR 10,000,000 or up to 2 percent of total worldwide annual turnover, and, for an essential entity only, temporary suspension of part or all of its activity or right to provide services, or temporary removal of its head from office by order of a district court on NKSC's request.

Industry commentary reports a lower important-entity fine tier of up to EUR 7,000,000 or 1.4 percent of turnover, consistent with the floor NIS2 Article 34(5) itself sets; that report is not independently confirmed against the Law's own text.

Personal-data breach notification under General Data Protection Regulation (GDPR) Articles 33 and 34 is separate law that sits in the privacy topic rather than here. e-seimas.lrs.lt, the Seimas legal-acts register, returns an HTTP 522 origin-server error; e-tar.lt, the Official Gazette register, and nksc.lt, NKSC's own site, both return an HTTP 403 despite resolving their Cloudflare challenge; and infolex.lt disallows every path in robots.txt. The Ministry of National Defence, which formed and administers Lithuania's cybersecurity policy, publishes public guidance on the Law at kam.lt.

Sector security regimes

Kibernetinio saugumo įstatymas (Law on Cyber Security), Risk-Management Measures

Lietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428 as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 14Krašto apsaugos ministerija (Ministry of National Defence), public guidance FAQ on the Law on Cyber Security, kam.lt

In force since 18 October 2024. Binds public and private bodies.

What this law does

Article 14 requires a cybersecurity subject entered in NKSC's Cybersecurity Subjects Register under Annex 1 or Annex 2 of the Law to adopt and keep current cybersecurity policy documents, periodically analyse and manage its cybersecurity risks, designate the persons responsible for cybersecurity, manage cybersecurity incidents and report on them, secure its supply chain, and deploy technical cybersecurity measures.

The Government's Cybersecurity Requirements Description sets out the detailed technical and organisational measures Article 14 requires, with a 12-month grace period from registration for the organisational measures and 24 months for the technical measures. Article 14(7) separately requires the subject's management-body members, head and designated representative to complete cybersecurity training at least once every two years.

A named subset of digital-service "special subjects" includes a DNS service provider, a top-level-domain registry, a cloud or data-centre service provider, a content-delivery-network, managed-service or managed-cybersecurity-service provider, an electronic-marketplace provider, and an internet-search-engine or social-networking-service-platform provider.

A special subject or trust service provider must comply only with the European Commission's directly-applicable Implementing Regulation (EU) 2024/2690 risk-management measures from the moment of its own entry into the Register, under Article 14(4) of the Law. Only an essential entity's activity or services may be temporarily suspended, and only an essential entity's head may be temporarily removed from office by a district court order on NKSC's request.

What it requires

Vulnerability and incident reporting

Kibernetinio saugumo įstatymas (Law on Cyber Security), Incident Notification

Lietuvos Respublikos kibernetinio saugumo įstatymas Nr. XII-1428 as restated by Įstatymo Nr. XIV-2902 pakeitimo įstatymas of 11 July 2024, in force since 18 October 2024, Art. 18Krašto apsaugos ministerija (Ministry of National Defence), public guidance FAQ on the Law on Cyber Security, kam.lt

In force since 18 October 2024. Binds public and private bodies.

What this law does

Article 18 requires an essential or important cybersecurity subject to notify NKSC of a significant cyber incident without delay and not later than within 24 hours of becoming aware of it, then follow within 72 hours with an assessment of the incident's severity and impact and any evidence of compromise.

A final report is due within one month of the incident's registration, with NKSC able to request an interim report, and a minor incident is reported within 72 hours without a separate 24-hour early warning. The Law requires an essential or important subject to notify NKSC of every cyber incident affecting it, not only a significant one. A subject with no statutory duty to report may still notify NKSC of a cyber incident, threat or near-miss voluntarily.

NKSC is developing a centralised national cyber-incident reporting and management platform, not yet launched, under a single-window principle for NKSC, the Lithuanian police and the State Data Protection Inspectorate to coordinate on.

What it requires

Age gating law1 instrument, 1 in force

Research summary (187 words)

Lithuania's general child-protection information statute, the Law on the Protection of Minors against the Detrimental Effect of Public Information (Nepilnamečių apsaugos nuo neigiamo viešosios informacijos poveikio įstatymas, No. IX-1067), classifies public information that has a negative effect on minors, erotic content among the enumerated categories, and requires anyone creating or disseminating such information to restrict minors' access to it through time-of-day and place segregation, content-rating indices, or technical measures capable of verifying a user's age, and separately obliges any provider of public computer-network (internet) access to install content-filtering measures approved by the Communications Regulatory Authority (RRT).

A 18 December 2024 Constitutional Court ruling struck down the Act's separate discriminatory-content category (Art. 4(2)(12)) as unconstitutional; the erotic-content category this instrument rests on is unaffected.

Lithuania's Law on the Provision of Information to the Public (No. I-1418), which as amended transposes the Audiovisual Media Services Directive's video-sharing-platform duties toward minors already recorded at the EU level (Directive 2010/13/EU Arts. 6a and 28b, as amended), was not reached in this review. No social-media-specific minor-access statute, app-store age-verification statute, or age-appropriate design code distinct from this general regime has been identified.

Adult content age verification (AV)

Law on the Protection of Minors against the Detrimental Effect of Public Information, Arts. 4 and 7 (Content Classification and Age-Restricted Access)

Nepilnamečių apsaugos nuo neigiamo viešosios informacijos poveikio įstatymas (Nr. IX-1067) 4 ir 7 str.Nepilnamečių apsaugos nuo neigiamo viešosios informacijos poveikio įstatymas (Nr. IX-1067)

In force since 1 February 2021. Binds public and private bodies.

What this law does

Article 4 classifies public information causing a negative effect on minors' mental or physical health or their physical, mental, spiritual or moral development. Content of an erotic nature is one of 21 enumerated categories the article lists, alongside violence, gambling promotion, self-harm, and other harmful subject matter.

The restrictions, exceptions and prohibitions this Law sets apply to all public information, including advertising, commercial audiovisual messages, trailers, trademarks, user-generated video, and public events.

Article 7 bars disseminating such information directly to minors and confines it to places minors cannot access or times they would not be using it, unless the discloser instead uses technical measures that let a person responsible for a child's upbringing control the child's exposure, among them tools intended to verify a user's age, parental-control tools, or content-filtering systems.

Content still reaching a general audience without such technical measures must instead carry an index and observe a broadcast-time band.

Index 'S' runs from 23:00 to 06:00, index 'N-14' runs from 21:00 to 06:00 for content harmful to under-14s, and index 'N-7' applies at any time for content harmful to under-7s. A provider of public computer-network (internet) access must install and operate content-filtering measures the Communications Regulatory Authority (Ryšių reguliavimo tarnyba, RRT) approves, and RRT itself supervises that duty's implementation.

A computer game's producer or distributor must separately label the game by a user age threshold under Government-set procedure. Supervision of the Law's implementation generally rests with the Inspector (Žurnalistų etikos inspektorius, the Office of the Inspector of Journalist Ethics). The Inspector may open administrative-offense proceedings under the Code of Administrative Offenses and impose an administrative penalty against a violator.

Note and primary source

News aggregation law4 instruments, 4 in force

Research summary (167 words)

Lithuania transposed the EU Digital Single Market Copyright Directive's press-publisher neighbouring right into the Autoriu teisiu ir gretutiniu teisiu istatymas (Law on Copyright and Related Rights, No. VIII-1185) at Article 57-1, added together with new text-and-data-mining exceptions at Articles 22-1 and 22-2 by Law No. XIV-970 of 24 March 2022.

The older quotation exception (Art. 21) and the exception for using a work for information purposes (Art. 24) separately let a person cite or reproduce short extracts and press articles on current affairs without authorization.

The Act's sui generis database-producer right (Arts. 61 to 64) protects a database maker's substantial investment in its content for 15 years from creation or first publication, and carries the same text-and-data-mining carve-out found in Articles 22-1 and 22-2, applied to a database's contents at Article 63(1)(6) and (7).

Lithuania has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act, and no hot-news or misappropriation doctrine distinct from these copyright provisions has been identified.

Press publishers' right

Copyright Act Art. 57-1, Electronic Press Publishers' Right

ATGTĮ (Nr. VIII-1185) 57-1 str., added by Įstatymas Nr. XIV-970 (2022-03-24)Autoriu teisiu ir gretutiniu teisiu istatymas (ATGTI), consolidated text, INFOLEX mirror of the Seimas register

In force since 1 May 2022. Binds public and private bodies.

What this law does

Article 57-1 gives an electronic press publisher the exclusive right to permit or prohibit an information-society service provider from reproducing an electronic press publication or part of it, or making it publicly available online. The right does not reach an individual user's private or non-commercial use, a hyperlink, or a publication first published before 6 June 2019.

It also does not reach the use of individual words from the publication or an extract of 125 or fewer print characters, not counting the heading and spaces. An electronic press publisher must ensure that the authors of works included in the publication receive an appropriate share of the revenue the publisher earns from an information-society service provider's use. Absent another agreement between the publisher and the author, that revenue is split equally.

Note and primary source

Snippet reproduction

Copyright Act Art. 21, Quotation Exception

ATGTĮ (Nr. VIII-1185) 21 str.Autoriu teisiu ir gretutiniu teisiu istatymas (ATGTI), consolidated text, INFOLEX mirror of the Seimas register

In force since 1 May 2022. Binds public and private bodies.

What this law does

Article 21 permits reproducing, publishing, and communicating to the public, including online, a small part of a lawfully published or publicly disclosed work, in the original language or in translation, as a quotation for criticism or review in another work, without the author's permission or remuneration, provided the source and author's name are cited where possible and the use is fair and does not exceed what the purpose of quotation requires.

The article's current wording took effect 1 May 2022, per the INFOLEX mirror's own redaction-history field, though its quotation exception itself dates to an earlier amendment (Law No. XI-1833 of 21 December 2011).

Note and primary source

Copyright Act Art. 24, Use of a Work for Information Purposes

ATGTĮ (Nr. VIII-1185) 24 str.Autoriu teisiu ir gretutiniu teisiu istatymas (ATGTI), consolidated text, INFOLEX mirror of the Seimas register

In force since 10 January 2012. Binds public and private bodies.

What this law does

Article 24 permits reproducing in the press and communicating to the public, including online, published or publicly disclosed articles on current economic, political, or religious topics, and analogous broadcast works, without the author's permission or remuneration. This use is permitted unless the authors or other rightsholders have prohibited such use, and provided the source and author's name are given in the copies bearing the work or by other means.

A separate paragraph permits reproducing and broadcasting speeches, lecture excerpts, and similar works, including courtroom speeches, for information purposes. The article's current wording took effect 10 January 2012, per the INFOLEX mirror's own redaction-history field.

Note and primary source

Text and data mining (TDM) opt-out

Copyright Act Arts. 22-1 and 22-2, Text and Data Mining Exceptions

ATGTĮ (Nr. VIII-1185) 22-1 ir 22-2 str., added by Įstatymas Nr. XIV-970 (2022-03-24)Autoriu teisiu ir gretutiniu teisiu istatymas (ATGTI), consolidated text, INFOLEX mirror of the Seimas register

In force since 1 May 2022. Binds public and private bodies.

What this law does

Article 22-1 lets a research organization or cultural-heritage institution reproduce, without the author's permission or remuneration, a work it can lawfully access for non-commercial text-and-data-mining research, keeping the copy only as long as the research requires. A contract term barring reliance on this exception is void. Article 22-2 lets anyone reproduce a lawfully accessible work for text-and-data-mining purposes without permission or remuneration.

That limitation applies only unless the rightsholder has expressly reserved that use by appropriate means, which for content publicly available online means machine-readable means. The same pairing of exceptions reaches a database's contents. Article 63(1)(6) gives research organizations and cultural-heritage institutions an equivalent unconditional right to extract a database for text-and-data-mining research.

Article 63(1)(7) extends the general, opt-out-conditioned exception to any lawful user extracting a database for text-and-data-mining purposes.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.