Skip to the content
Global Data RulesData governance rules, country by country

Lithuania

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Lithuania — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Active

You can send Lithuanian data abroad. There is no general rule that data must stay in Lithuania. Private companies follow the European rules. Once you have the right paperwork, data can leave. Government work is different. The data behind the state's most important computer systems must sit in state-run data centres in Lithuania. Lithuania also does the reverse with its most critical state data. A copy of it must be kept outside the country on purpose.

Data governance in Lithuania

The eight things that decide how you handle data about people in Lithuania. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. The rules apply even if you have no office in Lithuania. You are covered if you offer goods or services to people in Lithuania. You are also covered if you track what they do online. There is no size or revenue cut-off. A two-person company is covered exactly like a bank. If you have no office anywhere in the European Union, you must appoint a representative there. Regulators and members of the public must be able to contact that person.

What you have to do here:
Appoint a representative

Where the data is allowed to live

Yes, for an ordinary business. Lithuania has added no storage-location rule of its own on top of the European rules. Once you have the standard European paperwork, data can leave. Government systems are the exception. If a computer system counts as a state information resource, Lithuania grades it by importance. The top two grades must be held in state data centres inside Lithuania. The bottom two grades can sit abroad, but a copy must stay in a Lithuanian state data centre. Lithuania also does the reverse with its most critical state data. A copy must be kept outside the country. Lithuania calls this a digital embassy.

What to do: Plan for a database inside Lithuania: this data is not allowed to leave.

Not fully verified — see “What we're not sure about” below.

Sending data out of the country

Lithuania follows the European approach. You cannot send data to a country unless you have an approved route. The simplest route is Europe's approved-country list. That list is real and in use. It includes the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and others. It also covers United States companies signed up to the European Union-United States Data Privacy Framework. If your destination is not on the list, use the standard contract published by the European Commission. Lithuania adds one extra step. If you want to write your own contract wording instead, you need written permission from the Lithuanian regulator first.

What you have to do here:
Put a transfer safeguard in place
Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The main regulator is the State Data Protection Inspectorate, and it is busy. In 2025 it received 2,081 complaints, up 48 percent on the year before. It ran 26 inspections and had 54 staff. By 31 July 2026 it had published 122 decisions for that year. The fines are small. It issued only five fines in all of 2025. The largest was 9,000 euros (about 9,800 US dollars). Lithuania also has a second, less known data regulator for journalism. A separate cyber regulator sits inside the defence ministry.

How long you must keep it — and when to delete it

There are rules pushing both ways. Europe sets the maximum. You must delete personal data once you no longer need it for the reason you collected it. Lithuania sets minimums, through industry rules and keep-it tables issued by the Chief Archivist. Some minimums are very long. Health records in the state e-health system are kept for the patient's whole life plus three years. They are then archived for 75 years. Online gambling systems must keep their logs for at least 90 days. If a minimum and the maximum clash, the minimum wins while it lasts. Keeping the data is a legal duty during that time.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep logs

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

Not fully verified — see “What we're not sure about” below.

If something goes wrong

There are at least two deadlines, and they do not match. If personal data is exposed, you have 72 hours to tell the State Data Protection Inspectorate. If the Cybersecurity Law covers you, a serious cyber attack must be reported within 24 hours. That report goes to the National Cyber Security Centre, a full day earlier than the other one. A fuller assessment follows at 72 hours, and a final report within one month. Less serious incidents get 72 hours. Financial firms have a third deadline under European digital resilience rules. Lithuanian organisations often miss the first deadline. Only 63 percent of breach reports in 2025 arrived on time.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things the summary does not cover. Children can agree for themselves at 14 in Lithuania, not 16. An age gate built for the European default of 16 is wrong here. You may never publish a Lithuanian personal identification number. You may never use one for marketing. Complaining about a government body is worth less than you expect. Fines on public bodies are capped at 30,000 or 60,000 euros. There are two data regulators, and journalism goes to the other one. If you sell cloud services to the Lithuanian state, your data centre may not qualify at all.

What you have to do here:
Get a parent's consent for children · Keep the data in the country
What it costs if you get it wrong:
Fixed maximum fine

What's changing next

Two dated changes matter in the next twelve months. Both come from Europe. From 12 January 2027, every cloud provider must let customers move their data out for free. No exit fees at all. Around the same time, the technical security rules in Lithuania's cyber law start to apply to organisations registered in April 2025. That is roughly two years after registration. The bigger Lithuanian risk is not a new law. The government can change where state data must live by resolution. It does not need parliament and it does not have to consult anyone.

What to do: Diarise 12 January 2027 — that is the date this changes.

Not fully verified — see “What we're not sure about” below.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries6 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Government

Government data must stay in the country

Official name: Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas, 45 straipsnis · Law No. XI-1807 on the Management of State Information Resources, Article 45, as amended by Law No. XV-565; Government resolution No. 349 (list of state data centres); Minister of the Economy and Innovation order No. 4-249 (requirements for data centres in European Union, European Economic Area and NATO states) · Act of parliament

In forceNo — it stays put

If a Lithuanian public body's computer system is graded critical or important, its data must sit in a state-run data centre inside Lithuania. The cabinet can set different rules for one named institution by resolution. No commercial cloud region qualifies on its own.

In force since 1 May 2012Enforced from 1 January 2026

How this country controls where data goes: Not allowed · Accepted routes: Government sign-off needed

Not fully verified — see “What we're not sure about” below.
Government

Government data needs a copy kept in the country

Official name: Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — vidutines ir mazos svarbos istekliai · Law No. XI-1807 on the Management of State Information Resources, as explained by the responsible ministry · Act of parliament

In forceA copy must stay

For the less critical half of Lithuanian government systems, you may use a private or foreign data centre. You must still keep a copy in a Lithuanian state data centre. This is a copy rule, not a ban.

In force since 1 May 2012Enforced from 1 January 2026

How this country controls where data goes: Only approved countries · Accepted routes: Certification scheme

Not fully verified — see “What we're not sure about” below.
Government

Government data rules

Official name: Skaitmenine ambasada — Vyriausybes nutarimas ir Valstybes informaciniu istekliu valdymo istatymo pakeitimai · Government decree of 12 July 2022, together with May 2022 amendments to the Law on the Management of State Information Resources · Directly binding regulation

In forceA copy must stay

Lithuania runs a 'digital embassy'. Copies of the most critical state data must be kept outside Lithuania on purpose. That way the government can keep running in a crisis. State data is graded into four importance levels to decide what goes where.

In force since 12 July 2022
Not fully verified — see “What we're not sure about” below.

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas · Law No. I-1374, as restated in 2018 (Law on Legal Protection of Personal Data) · Act of parliament

In forceYes — store it anywhere

Lithuania's own data protection law sits on top of the European rules. It adds no storage-location requirement. It does add four things. Children can agree for themselves at 14. You may never publish a person's national identification number. Fines on public bodies are capped. And any fine must be imposed within two years.

In force since 16 July 2018

Enforced by State Data Protection Inspectorate

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed

Data rules

Official name: Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas, 3 straipsnis (asmens kodas) · Law on Legal Protection of Personal Data, Article 3 · Act of parliament

In forceYes — store it anywhere

The Lithuanian national identification number has its own rule. You may use it where you have a legal reason. You may never publish it. You may never use it for marketing. Consent does not get you around either ban.

In force since 16 July 2018

Enforced by State Data Protection Inspectorate

Data rules (2027)

Official name: Lietuvos Respublikos kibernetinio saugumo istatymas · Law on Cybersecurity, implementing Directive (EU) 2022/2555 (NIS 2) · Act of parliament

Partly in forceYes — store it anywhere

Lithuania's cyber law has been in force since 18 October 2024, but it applies slowly. Registered organisations get twelve months to meet the general requirements. They get twenty-four months for the technical ones. So the real deadline for the first group is around 17 April 2027. The law sets no storage-location rule.

In force since 18 October 2024In force now, but not enforced until 17 April 2027

That is a long gap: the duty is real law today, but no penalty can follow until 17 April 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

Enforced by National Cyber Security Centre

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union3 rules

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: Europos Parlamento ir Tarybos reglamentas (ES) 2016/679 (Bendrasis duomenu apsaugos reglamentas) · Regulation (EU) 2016/679 · Directly binding regulation

In forceYes, with paperwork

The European base rules cover almost all personal data in Lithuania. They do not require data to stay in Europe. They set the conditions for letting data leave. Lithuania lowered the age at which children can agree for themselves to 14.

In force since 25 May 2018

Enforced by European Data Protection Board

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims

General data protection law

Official name: Reglamentas (ES) 2018/1807 del laisvo ne asmens duomenu judejimo Europos Sajungoje pagrindu · Regulation (EU) 2018/1807 · Directly binding regulation

In forceYes — store it anywhere

Lithuania may not force non-personal data to be stored on its own soil. The only exception is where public security really requires it. Lithuania's state data centre rule has to be justified against this.

In force since 28 May 2019

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Cloud and outsourcing rules

Official name: Reglamentas (ES) 2023/2854 del suderintu saziningos prieigos prie duomenu ir ju naudojimo taisykliu (Duomenu aktas) · Regulation (EU) 2023/2854 (Data Act) · Directly binding regulation

Partly in forceYes — store it anywhere

The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must fall to zero.

In force since 12 September 2025In force now, but not enforced until 12 January 2027

That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Who you would hear from

  • Valstybine duomenu apsaugos inspekcija

    General data protection supervisory authority for Lithuania, except processing for journalistic, academic, artistic and literary purposes.

    Clearly working. In 2025 it had 2,081 complaints (up 48 percent), 26 inspections, 223 breach reports, 54 staff posts and a budget of 2,198,000 euros. It issued five fines in 2025, from 3,529 euros to 9,000 euros. It published 122 decisions between 3 January and 31 July 2026. It led 34 cross-border complaints.

  • Zurnalistu etikos inspektoriaus tarnyba

    Second data protection supervisory authority, named in Article 7 of the national law, covering personal data processed for journalistic, academic, artistic and literary purposes.

    It publishes news and guidance in 2026, including guidance on when data use counts as journalism. We could not confirm how many data protection decisions it issued in 2025 or 2026.

  • Nacionalinis kibernetinio saugumo centras

    Competent authority under the Cybersecurity Law; incident reporting, registration of in-scope entities, cybersecurity requirements.

    Sits under the Ministry of National Defence. It finished identifying and registering the companies it covers by 17 April 2025. It publishes a yearly national cybersecurity report.

  • Lietuvos bankas

    Central bank and supervisor of banks, electronic money and payment institutions, insurers and investment firms.

    Publishes a live catalogue of 239 positions and guidelines and a register of supervisory service decisions.

  • Lietuvos Respublikos rysiu reguliavimo tarnyba

    Electronic communications regulator.

    It keeps the official register of laws covering electronic communications. We could not confirm its role in overseeing how long call records are kept.

  • Losimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijos

    Licensing and supervision of gambling and large lotteries, including technical requirements for remote gambling devices.

    Publishes and maintains detailed technical requirements for remote gambling devices.

  • Lietuvos vyriausiojo archyvaro tarnyba

    Sets document retention periods through general and sector-specific retention indexes.

    Actively publishing amended document management and retention rules.

  • European Data Protection Board

    Consistency, guidelines and dispute resolution across the European Economic Area. Lithuania's supervisory authority is a member.

    Active. On 31 July 2026 it formally asked the Commission to review the European Union-United States Data Privacy Framework. That is the decision saying the United States is safe enough.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact wording of Article 45 of the Law on the Management of State Information Resources, which is the source of the state data centre requirement.

    We could not read the text of the article itself from a government source. We relied on the Ministry of the Economy and Innovation's own summary, which quotes the rule and cites Article 45(3) and 45(4). If you are bidding to host a Lithuanian state system, have a Lithuanian lawyer check the statute text.

  • The contents of Government resolution No. 349 (the list of state data centres) and Minister of the Economy and Innovation order No. 4-249 (technical requirements for data centres in European Union, European Economic Area and NATO states).

    The ministry cites both documents, but we could not read either one. We do not know which data centres are on the list, or whether any commercial provider qualifies. Ask the ministry before you plan a bid.

  • The legal basis, host country and exact scope of Lithuania's 'digital embassy'.

    The ministry's English news page confirms that copies must be stored outside Lithuania, and dates the Government decree to 12 July 2022. We could not read the decree itself, so we do not know which country hosts the copies.

  • Whether Lithuania imposes a retention obligation on telecoms traffic and location data for law enforcement, for how long, and whether it survives European court rulings.

    We could not confirm whether Lithuania makes telecoms companies keep call and location records. The Law on Electronic Communications has a version dated 1 July 2026, but we could not read the relevant articles from a government source. If you run a telecoms business in Lithuania, check this before you rely on it.

  • Whether Lithuania has any mapping, geospatial or aerial imagery deposit or localisation requirement.

    We did not check this. Nearby countries in this dataset do have such rules. Do not read the silence here as a no.

  • The commonly repeated claim that Lithuanian accounting records must be kept for ten years.

    We could not confirm a number from a government source, so we do not state one. If you need an accounting keep-it period, check the Chief Archivist's general table and the Law on Financial Accounting.

  • Whether the state e-health system is graded as a critical or important state information resource.

    The system is clearly a state information resource run by the Ministry of Health. We could not find its importance grade, so we cannot confirm that the strictest state data centre rule applies to it. Ask the Ministry of Health if you host health systems.

  • Whether the Lithuanian Law on Gambling itself (as opposed to the regulator's technical requirements) contains a server or equipment location rule.

    We could not read the Law on Gambling itself. The regulator's technical rules contain no server location rule, which points one way but does not settle it. Check with the Gaming Control Authority before you place servers abroad.

  • Whether the Inspector of Journalist Ethics has issued data protection decisions recently, and how many.

    Its site is live and publishing guidance in 2026, but we found no register of its decisions. Our rating of this office rests on its own website, not on a count of decisions.

  • Whether the Bank of Lithuania has any cloud or outsourcing instrument affecting storage location.

    We read the first page of the Bank of Lithuania's 239-document catalogue and found nothing, but we did not read all 239 entries. Treat 'no storage-location rule in finance' as something we did not find, not something we proved. If you run a bank here, check with the Bank of Lithuania.

  • The precise commencement dates for the general and technical cybersecurity requirements under the Cybersecurity Law.

    The rule is 12 and 24 months from registration, and registration had to be finished by 17 April 2025. We worked out the April 2026 and April 2027 dates from those two facts. We did not read a start-date article confirming them.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 60 days. Next check due 17 October 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.