Skip to the content
Global Data RulesData governance rules, country by country

Lithuania

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Active

Lithuania has no general rule that data must stay in the country. Private companies follow the European rulebook: data can go abroad once the right paperwork is in place. The wall is in government. The data behind the state's most important computer systems must sit in Lithuanian state data centres — and a copy of the most critical state data must be kept abroad on purpose.

Eight questions about Lithuania

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Lithuania's rules apply to my company?

Yes. A company with no office in Lithuania is still caught if it offers goods or services to people in Lithuania, or watches what they do online. There is no size or revenue threshold to hide under — a two-person company is covered exactly like a bank. If you have no office anywhere in the European Union, you must appoint a representative inside the Union who can be contacted by regulators and by the public.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Lithuania?

For an ordinary business, yes. Lithuania has not added a national storage-location rule on top of the European rules, so data can leave once you have the standard European paperwork. The exception is government. If a computer system counts as a state information resource, Lithuania grades it by importance, and the two top grades must be held in state data centres inside Lithuania. The two lower grades can sit abroad, but a copy must still be kept in a Lithuanian state data centre. Lithuania also forces the opposite move for its most critical state data: a copy must be kept outside the country, in what it calls a digital embassy.

Medium confidenceDepends on your industryNo — it stays putA copy must stayGovernmentHealth and social careFinanceOnline gaming

What do I need in place before data leaves Lithuania?

Lithuania uses the European model: a destination is off-limits unless you have an approved route out. The easiest route is an approved-country list, which is populated and currently includes the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and others, plus United States companies signed up to the European Union–United States Data Privacy Framework. If your destination is not on the list, the normal answer is a set of standard contract clauses published by the European Commission. Lithuania adds one local step: if you want to use your own custom contract wording instead of the standard clauses, you need written permission from the Lithuanian regulator first.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesGovernment sign-off neededPut a transfer safeguard in place

Who enforces the rules in Lithuania, and what can they do?

The main regulator is the State Data Protection Inspectorate, and it is genuinely working. In 2025 it received 2,081 complaints, up 48 percent on the year before, ran 26 inspections and had 54 staff. By 31 July 2026 it had already published 122 decisions for the year. But the fines are small: it issued only five fines in the whole of 2025, the largest being 9,000 euros (about 9,800 US dollars). Lithuania also has a second, less well known data regulator for journalism, and a separate cyber regulator inside the defence ministry.

High confidenceActiveRegulator

How long do I have to keep the data?

Both directions apply and they pull against each other. The ceiling comes from Europe: you must delete personal data once you no longer need it for the purpose you collected it for. The floors come from Lithuanian sector rules and from retention tables issued by the Chief Archivist. Some floors are very long. Health records in the state e-health system are kept for the patient's whole life plus three years, then archived for 75 years. Online gambling systems must keep their logs for at least 90 days. When a floor and the ceiling clash, the floor wins for as long as it lasts, because keeping the data is then a legal duty.

Medium confidenceKeep data for a minimum periodDelete data after a periodKeep logs

What happens if there is a breach?

Count at least two clocks, and they do not agree. If personal data is exposed, you have 72 hours to tell the State Data Protection Inspectorate. If you are covered by the Cybersecurity Law, a serious cyber incident must be reported to the National Cyber Security Centre within 24 hours — a full day earlier — with a fuller assessment at 72 hours and a final report within one month. Other incidents get 72 hours. Financial firms have a third clock under European digital resilience rules. Lithuanian organisations are visibly bad at the first clock: only 63 percent of breach reports in 2025 arrived on time.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidents

What trips people up in Lithuania?

Five things that are not in the summary. Children can consent for themselves at 14 in Lithuania, not 16, so an age gate built for the European default is wrong here. You may never publish a Lithuanian personal identification number, and you may never use one for marketing. Complaining about a government body is worth less than you think, because fines on public institutions are capped at 30,000 or 60,000 euros. There are two data regulators, and journalism goes to the other one. And if you sell cloud services to the Lithuanian state, your data centre may simply be ineligible.

High confidenceChildren's dataGet a parent's consent for childrenFixed maximum fineKeep the data in the country

What is changing soon in Lithuania?

Two dated changes matter in the next twelve months, and both are European. From 12 January 2027 every cloud provider must let customers move their data out for free — no exit fees at all. Around the same period, the technical security requirements of Lithuania's cyber law start biting for organisations registered in April 2025, roughly two years after registration. The bigger Lithuanian risk is not a new law at all: the government can change where state data must live by resolution, without going to parliament and without consulting anyone.

Medium confidenceProposedPartly in force

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    3 rules here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    6 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules3 rules

Europos Parlamento ir Tarybos reglamentas (ES) 2016/679 (Bendrasis duomenu apsaugos reglamentas)

Directly binding regulation · Regulation (EU) 2016/679

In forceYes, with paperwork

The European baseline that governs almost all personal data in Lithuania. It does not require data to stay in Europe; it sets the conditions under which data may leave. Lithuania lowered the children's consent age to 14.

In force since 25 May 2018

Enforced by European Data Protection Board

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

High confidence

Reglamentas (ES) 2018/1807 del laisvo ne asmens duomenu judejimo Europos Sajungoje pagrindu

Directly binding regulation · Regulation (EU) 2018/1807

In forceYes — store it anywhere

Lithuania is forbidden from forcing non-personal data to be stored on its territory, except where public security genuinely requires it. This is the rule Lithuania's state data centre requirement has to justify itself against.

In force since 28 May 2019

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Reglamentas (ES) 2023/2854 del suderintu saziningos prieigos prie duomenu ir ju naudojimo taisykliu (Duomenu aktas)

Directly binding regulation · Regulation (EU) 2023/2854 (Data Act)

Partly in forceYes — store it anywhere

The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must fall to zero.

In force since 12 September 2025But only enforceable from 12 January 2027

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

National rules4 rules

Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas

Act of parliament · Law No. I-1374, as restated in 2018 (Law on Legal Protection of Personal Data)

In forceYes — store it anywhere

Lithuania's own data protection law sits on top of the European rules and adds no storage-location requirement. What it does add is a lower children's consent age of 14, a flat ban on publishing a person's national identification number, a cap on fines for public bodies, and a two-year limit on imposing any fine.

In force since 16 July 2018

Enforced by State Data Protection Inspectorate

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

High confidence

Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas, 3 straipsnis (asmens kodas)

Act of parliament · Law on Legal Protection of Personal Data, Article 3

In forceYes — store it anywhere

The Lithuanian national identification number gets its own rule. You may process it where you have a lawful basis, but you may never publish it and you may never use it for marketing. There is no consent workaround.

In force since 16 July 2018

Enforced by State Data Protection Inspectorate

High confidence

Lietuvos Respublikos kibernetinio saugumo istatymas

Act of parliament · Law on Cybersecurity, implementing Directive (EU) 2022/2555 (NIS 2)

Partly in forceYes — store it anywhere

Lithuania's cyber law has been in force since 18 October 2024 but its teeth arrive late. Registered organisations get twelve months to meet the general requirements and twenty-four months for the technical ones, so the hard deadline for the first cohort is around 17 April 2027. It imposes no storage-location rule.

In force since 18 October 2024But only enforceable from 17 April 2027

Enforced by National Cyber Security Centre

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules6 rules

Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas, 45 straipsnis

Act of parliament · Law No. XI-1807 on the Management of State Information Resources, Article 45, as amended by Law No. XV-565; Government resolution No. 349 (list of state data centres); Minister of the Economy and Innovation order No. 4-249 (requirements for data centres in European Union, European Economic Area and NATO states) · Government

In forceNo — it stays put

If a Lithuanian public body's computer system is graded critical or important, its data must be held in a state-run data centre inside Lithuania. Cabinet can carve out a named institution by resolution, but no commercial cloud region qualifies by default.

In force since 1 May 2012But only enforceable from 1 January 2026

Transfer model: Not allowed · Accepted routes: Government sign-off needed

Medium confidence

Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — vidutines ir mazos svarbos istekliai

Act of parliament · Law No. XI-1807 on the Management of State Information Resources, as explained by the responsible ministry · Government

In forceA copy must stay

For the less critical half of Lithuanian government systems you may use a private or foreign data centre, but you must still keep a copy in a Lithuanian state data centre. This is a mirror rule, not a ban.

In force since 1 May 2012But only enforceable from 1 January 2026

Transfer model: Allowlist · Accepted routes: Certification scheme

Medium confidence

Skaitmenine ambasada — Vyriausybes nutarimas ir Valstybes informaciniu istekliu valdymo istatymo pakeitimai

Directly binding regulation · Government decree of 12 July 2022, together with May 2022 amendments to the Law on the Management of State Information Resources · Government

In forceA copy must stay

Lithuania runs a 'digital embassy'. Copies of the most critical state data must be kept outside Lithuania on purpose, so government can keep running in a crisis. Data is graded into four criticality levels to decide what goes where.

In force since 12 July 2022
Medium confidence

Who you would hear from

  • Valstybine duomenu apsaugos inspekcija

    General data protection supervisory authority for Lithuania, except processing for journalistic, academic, artistic and literary purposes.

    Clearly operational. 2025: 2,081 complaints (up 48 percent), 26 inspections, 223 breach notifications, 54 established posts, budget EUR 2,198,000. Five fines in 2025 ranging from EUR 3,529 to EUR 9,000. 122 published decisions between 3 January and 31 July 2026. Lead authority in 34 cross-border complaints.

  • Zurnalistu etikos inspektoriaus tarnyba

    Second data protection supervisory authority, named in Article 7 of the national law, covering personal data processed for journalistic, academic, artistic and literary purposes.

    Publishing news and guidance in 2026, including guidance on when processing counts as journalistic. We did not verify how many data protection decisions it issued in 2025 or 2026.

  • Nacionalinis kibernetinio saugumo centras

    Competent authority under the Cybersecurity Law; incident reporting, registration of in-scope entities, cybersecurity requirements.

    Sits under the Ministry of National Defence. Completed identification and registration of in-scope entities by 17 April 2025 and publishes an annual national cybersecurity report.

  • Lietuvos bankas

    Central bank and supervisor of banks, electronic money and payment institutions, insurers and investment firms.

    Publishes a live catalogue of 239 positions and guidelines and a register of supervisory service decisions.

  • Lietuvos Respublikos rysiu reguliavimo tarnyba

    Electronic communications regulator.

    Maintains the official register of legal acts governing electronic communications. We could not verify its role in traffic data retention supervision in this run.

  • Losimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijos

    Licensing and supervision of gambling and large lotteries, including technical requirements for remote gambling devices.

    Publishes and maintains detailed technical requirements for remote gambling devices.

  • Lietuvos vyriausiojo archyvaro tarnyba

    Sets document retention periods through general and sector-specific retention indexes.

    Actively publishing amended document management and retention rules.

  • European Data Protection Board

    Consistency, guidelines and dispute resolution across the European Economic Area. Lithuania's supervisory authority is a member.

    Active. On 31 July 2026 it formally asked the Commission to examine the validity of the European Union-United States Data Privacy Framework adequacy decision.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact wording of Article 45 of the Law on the Management of State Information Resources, which is the source of the state data centre requirement.

    The parliament's own portal and the Register of Legal Acts serve only metadata and a table of contents to automated fetching; the article text is behind a download. We relied on the Ministry of the Economy and Innovation's own published summary, which quotes the rule and cites Article 45(3) and 45(4). Government backlink exists, but it is a ministry explainer rather than the statute text.

  • The contents of Government resolution No. 349 (the list of state data centres) and Minister of the Economy and Innovation order No. 4-249 (technical requirements for data centres in European Union, European Economic Area and NATO states).

    Both are cited by the ministry but neither was fetched. We do not know which data centres are on the list, or whether any commercial provider qualifies.

  • The legal basis, host country and exact scope of Lithuania's 'digital embassy'.

    The ministry's English news page confirms that copies must be stored outside Lithuania and dates the Government decree to 12 July 2022, but the Lithuanian-language announcement returned a 404 and we did not read the decree itself. We do not know which country hosts the copies.

  • Whether Lithuania imposes a retention obligation on telecoms traffic and location data for law enforcement, for how long, and whether it survives European court rulings.

    The Law on Electronic Communications has a consolidated version dated 1 July 2026, but neither the regulator's site nor the legal act register returned article text to automated fetching, and the web search budget ran out before an alternative route could be tried. This is the most likely place for a rule in the 'disapplied' state, and it is unresolved.

  • Whether Lithuania has any mapping, geospatial or aerial imagery deposit or localisation requirement.

    Not checked in this run. Neighbouring jurisdictions in this dataset do have such rules, so its absence here should not be read as a finding.

  • The commonly repeated claim that Lithuanian accounting records must be kept for ten years.

    We could not open the Chief Archivist's general retention index or the Law on Financial Accounting from a government source, so we did not assert a number. Only the retention index landing page was verified.

  • Whether the state e-health system is graded as a critical or important state information resource.

    It is plainly a state information resource controlled by the Ministry of Health, but we did not find the grading decision, so we could not confirm that the strictest state data centre rule applies to it.

  • Whether the Lithuanian Law on Gambling itself (as opposed to the regulator's technical requirements) contains a server or equipment location rule.

    The Register of Legal Acts returned only metadata for the Law on Gambling. The regulator's own technical requirements document contains no location rule, which is suggestive but not conclusive.

  • Whether the Inspector of Journalist Ethics has issued data protection decisions recently, and how many.

    Its site is live and publishing guidance in 2026, but we did not locate a decisions register. Its operational rating as a data protection regulator rests on its own site rather than on a decision count.

  • Whether the Bank of Lithuania has any cloud or outsourcing instrument affecting storage location.

    We read the first page of a 239-document catalogue of positions and guidelines and found none, but we did not read all 239 entries. Treat the 'no localisation in finance' finding as a negative check, not a proof.

  • The precise commencement dates for the general and technical cybersecurity requirements under the Cybersecurity Law.

    The rule is 12 and 24 months from registration, and registration had to be completed by 17 April 2025. We inferred the April 2026 and April 2027 dates from those two facts rather than reading a commencement provision.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.