Lithuania
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Lithuania — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
You can send Lithuanian data abroad. There is no general rule that data must stay in Lithuania. Private companies follow the European rules. Once you have the right paperwork, data can leave. Government work is different. The data behind the state's most important computer systems must sit in state-run data centres in Lithuania. Lithuania also does the reverse with its most critical state data. A copy of it must be kept outside the country on purpose.
Data governance in Lithuania
The eight things that decide how you handle data about people in Lithuania. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. The rules apply even if you have no office in Lithuania. You are covered if you offer goods or services to people in Lithuania. You are also covered if you track what they do online. There is no size or revenue cut-off. A two-person company is covered exactly like a bank. If you have no office anywhere in the European Union, you must appoint a representative there. Regulators and members of the public must be able to contact that person.
- What you have to do here:
- Appoint a representative
The reach comes from Article 3 of the General Data Protection Regulation, which applies directly in Lithuania. Lithuania's own law adds detail on top. It is the Law on the Legal Protection of Personal Data (Asmens duomenu teisines apsaugos istatymas, Law No. I-1374, restated in 2018). Its Article 1(4) says when the Lithuanian law itself applies. It covers companies based in Lithuania. It covers companies outside the European Union that have a representative in Lithuania. It also covers the use of data about people in the European Union. The duty to appoint a representative is Article 27 of the Regulation. The Lithuanian Cybersecurity Law (Kibernetinio saugumo istatymas) works differently. It picks companies by industry and size, not by nationality. The National Cyber Security Centre decides who is covered and puts them on a register.
Sources
- Official sourceValstybine duomenu apsaugos inspekcija (State Data Protection Inspectorate)Law of the Republic of Lithuania on Legal Protection of Personal Data, Article 1(4) — scope (English translation published by the supervisory authority)
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLegislation — the Lithuanian supervisory authority's own list of the national data protection laws in force
vdai.lrv.lt
Link checked 18 August 2026
Where the data is allowed to live
Yes, for an ordinary business. Lithuania has added no storage-location rule of its own on top of the European rules. Once you have the standard European paperwork, data can leave. Government systems are the exception. If a computer system counts as a state information resource, Lithuania grades it by importance. The top two grades must be held in state data centres inside Lithuania. The bottom two grades can sit abroad, but a copy must stay in a Lithuanian state data centre. Lithuania also does the reverse with its most critical state data. A copy must be kept outside the country. Lithuania calls this a digital embassy.
Industry by industry, checked 18 August 2026. GOVERNMENT AND PUBLIC BODIES. This is the real wall. The Ministry of the Economy and Innovation says that systems graded 'ypatingos svarbos' (critical) and 'svarbus' (important) must be held in state data centres. The Government can set different rules for one named institution by resolution. That power sits in Articles 45(3) and 45(4) of the Law on the Management of State Information Resources. Systems graded 'vidutines svarbos' (medium) and 'mazos svarbos' (low) may be held in state, foreign or private data centres. If they sit in a foreign or private data centre, copies must be kept in state data centres. Government resolution No. 349 sets the list of state data centres. Minister of the Economy and Innovation order No. 4-249 sets the technical and organisational rules for data centres in European Union, European Economic Area and NATO states. So the top two grades are closed, and the bottom two need a copy at home. DIGITAL EMBASSY. This is the reverse. Changes to the same law in May 2022, plus a Government decree of 12 July 2022, made spreading state data compulsory. Some data sits in public data centres, 'but copies will be compulsorily stored outside the territory of Lithuania'. HEALTH. We found no separate location rule. Almost all Lithuanian health records pass through the state e-health system (ESPBI IS). The Ministry of Health runs it, and the state enterprise Centre of Registers handles the data for it. That system is a state information resource, so the government rules above are what really apply. BANKING, PAYMENTS, INSURANCE, SECURITIES. We found no rule that data must stay in Lithuania. We searched the Bank of Lithuania's own catalogue of 239 positions and guidelines. It has incident reporting rules and risk guidance close to outsourcing, but nothing requiring data to be stored in Lithuania. European digital resilience rules for financial firms make you disclose where data is used and stored. They do not make you keep it local. ONLINE GAMBLING. The regulator's technical rules for remote gambling equipment contain no server location rule. They do require logs to be kept for at least 90 days. Medium confidence. TELECOMS. Not confirmed. The Law on Electronic Communications has a version dated 1 July 2026, but we could not read the record-keeping articles from an official source. MAPPING AND LOCATION DATA, EDUCATION, DEFENCE. Not checked. See the list of things we could not confirm. Above all of this sits Regulation (EU) 2018/1807. It stops a member state from forcing non-personal data to be stored on its own soil, unless real public security needs it. Lithuania's state data centre rule is a public buying and security rule, and that is the space the Regulation leaves open.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerija (Ministry of the Economy and Innovation)Valstybes informaciniu istekliu valdymo kryptys — the ministry's own statement of where state information resources must be held, by importance grade
eimin.lrv.lt
“Ypatingos svarbos ir svarbius VII privaloma laikyti valstybiniuose duomenu centruose [...] Vidutines svarbos ir mazos svarbos VII gali buti laikomi tiek valstybiniuose duomenu centruose, tiek uzsienio ar privaciuose duomenu centruose. Jeigu sie istekliai laikomi uzsienio ar privaciuose duomenu centruose, tuomet ju kopijas privaloma laikyti valstybiniuose duomenu centruose.”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaDigital Embassy launches to improve security of state data in emergencies
eimin.lrv.lt
“some of the data will be stored in public data centres, but copies will be compulsorily stored outside the territory of Lithuania”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija / VI Registru centrasE. sveikatos portalas — data security and privacy notice for the state e-health system (ESPBI IS)
esveikata.lt
Link checked 18 August 2026
- Official sourceLosimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijos (Gaming Control Authority)Requirements for remote gambling devices — the gambling regulator's own technical requirements (no server-location rule; 90-day log retention)
lpt.lrv.lt
Link checked 18 August 2026
- Official sourceLietuvos bankas (Bank of Lithuania)Lietuvos banko pozicijos ir gaires — the central bank's own catalogue of positions and guidelines for supervised financial firms (searched for a cloud or storage-location instrument; none found)
lb.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Plan for a database inside Lithuania: this data is not allowed to leave.
Not fully verified — see “What we're not sure about” below.Sending data out of the country
Lithuania follows the European approach. You cannot send data to a country unless you have an approved route. The simplest route is Europe's approved-country list. That list is real and in use. It includes the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and others. It also covers United States companies signed up to the European Union-United States Data Privacy Framework. If your destination is not on the list, use the standard contract published by the European Commission. Lithuania adds one extra step. If you want to write your own contract wording instead, you need written permission from the Lithuanian regulator first.
- What you have to do here:
- Put a transfer safeguard in place
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Government sign-off needed
You can only send data to approved countries, or use one of the approved routes below. The approved-country list is in use. It covers Andorra, Argentina, Brazil (both ways, 26 January 2026), Canada (commercial bodies only), the Faroe Islands, Guernsey, the Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, the United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the European Patent Organisation, and United States companies signed up to the Data Privacy Framework. As at 18 August 2026, no country had been taken off the list or suspended. Routes if your destination is not on the list. The 2021 Standard Contractual Clauses (Decision (EU) 2021/914) are the current version and have not been changed. New clauses were promised for companies abroad that already fall under the Regulation through Article 3(2). Those are still not adopted. You can also get company-wide rules approved, known as Binding Corporate Rules. Article 49 gives a few narrow exceptions, but you cannot use them for regular or large transfers. You are still expected to write down why the destination country is safe, after the Schrems II court ruling. European Data Protection Board Guidelines 02/2024 confirm one point. An order from a foreign government is not on its own a legal reason to hand data over. Lithuania's extra step is Article 15 of the Law on the Legal Protection of Personal Data. It only applies to Article 46(3) of the Regulation. That means contract wording the parties write themselves, and arrangements between public bodies. The State Data Protection Inspectorate must give permission, or refuse in writing with reasons, within 20 working days of getting a complete file. It can extend that once by up to 10 working days. You need no permission to use the standard published clauses. The most time-sensitive point is the European Union-United States Data Privacy Framework. It is still in force and legally valid on 18 August 2026, but it is under pressure. The General Court threw out the Latombe challenge on 3 September 2025. An appeal to the Court of Justice was filed on 31 October 2025 and is still open. On 31 July 2026 the European Data Protection Board wrote to the Commissioner. It asked the Commission to look at whether changes to United States institutions affect the decision. The Commission has not suspended or cancelled it. You can use it today. Do not build on it as your only route.
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Article 15 — permits of the State Data Protection Inspectorate for transfers under Article 46(3) of the General Data Protection Regulation
vdai.lrv.lt
“In accordance with Article 46 (3) of Regulation (EU) 2016/679, the State Data Protection Inspectorate must provide the data controller with permission for the transfer of personal data to the third country or an international organization or a reasoned written refusal to issue this permit no later than within 20 working days.”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 — a foreign authority's order is not by itself a lawful basis to disclose
edpb.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The main regulator is the State Data Protection Inspectorate, and it is busy. In 2025 it received 2,081 complaints, up 48 percent on the year before. It ran 26 inspections and had 54 staff. By 31 July 2026 it had published 122 decisions for that year. The fines are small. It issued only five fines in all of 2025. The largest was 9,000 euros (about 9,800 US dollars). Lithuania also has a second, less known data regulator for journalism. A separate cyber regulator sits inside the defence ministry.
Is the regulator working? Yes, on its own numbers. From the Inspectorate's 2025 annual review, published 1 July 2026: 2,081 complaints received, against 1,408 in 2024; 16 planned and 10 unplanned inspections; 132 monitoring actions; 223 data breach reports covering 1,249,409 people in Lithuania, of which only 63 percent arrived within 72 hours; 34 cross-border complaints led by Lithuania and 28 decisions agreed with other countries; 54 staff posts, up from 46; a budget of 2,198,000 euros (about 2.4 million US dollars). Its published decisions list for 2026 shows 122 decisions between 3 January and 31 July 2026. They are split between 'violations found' and 'no violations found'. Vinted UAB appears seven times. So it is active, but not aggressive. It issues a steady flow of binding decisions and orders. It issues very few fines, and they are small. There were five fines in 2025, from 3,529 euros to 9,000 euros. Part of the reason is built into the law. Article 33 of the national law caps fines on Lithuanian public bodies. For one class of breach the cap is 0.5 percent of that year's budget, and never more than 30,000 euros. For another class it is 1 percent, and never more than 60,000 euros. Private companies still face the full European maximums. There is a second regulator. Article 7 of the national law names the Inspector of Journalist Ethics. That office handles personal data used for journalism, academic work, art and literature. A complaint against a news organisation goes there, not to the Inspectorate. The cyber regulator is the National Cyber Security Centre, under the Ministry of National Defence. It is the authority in charge under the Cybersecurity Law. It can fine you up to 10 million euros or 2 percent of worldwide yearly turnover, whichever is lower. Industry regulators: the Bank of Lithuania covers financial firms, the Communications Regulatory Authority covers telecoms, and the Gaming Control Authority covers gambling. If you want to challenge an Inspectorate decision, you go to the administrative courts. Vilnius Regional Administrative Court comes first, then the Supreme Administrative Court.
Sources
- Official sourceValstybine duomenu apsaugos inspekcija2025 Review of Personal Data Protection Supervision in Lithuania — the supervisory authority's own annual report (complaints, inspections, fines, staffing, budget)
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaVDAI sprendimai (baudos, nurodymai ir kt.) 2026 m. — the register of 2026 decisions, last updated 3 August 2026
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Articles 7, 12, 32 and 33 — supervisory authorities, powers, two-year limitation period and the cap on fines for public institutions
vdai.lrv.lt
“A supervisory authority has the right to impose an administrative fine to a public institution or authority which has infringed the provisions of Article 83 (4) (a), (b) and (c) of Regulation (EU) 2016/679, up to 0.5 per cent of the current year's budget of a public institution or authority [...] but not more than thirty thousand euros.”
Link checked 18 August 2026
- Official sourceZurnalistu etikos inspektoriaus tarnybaZurnalistu etikos inspektoriaus tarnyba — the Inspector of Journalist Ethics, the second Lithuanian data protection supervisory authority
zeit.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos krasto apsaugos ministerija (Ministry of National Defence)Kibernetinio saugumo istatymas — the defence ministry's own explainer naming the National Cyber Security Centre as the competent authority and setting out the penalty ceiling
kam.lt
Link checked 18 August 2026
How long you must keep it — and when to delete it
There are rules pushing both ways. Europe sets the maximum. You must delete personal data once you no longer need it for the reason you collected it. Lithuania sets minimums, through industry rules and keep-it tables issued by the Chief Archivist. Some minimums are very long. Health records in the state e-health system are kept for the patient's whole life plus three years. They are then archived for 75 years. Online gambling systems must keep their logs for at least 90 days. If a minimum and the maximum clash, the minimum wins while it lasts. Keeping the data is a legal duty during that time.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep logs
MAXIMUM. Article 5(1)(e) of the General Data Protection Regulation. You may not keep data in a form that identifies someone for longer than you need it. Lithuania sets no separate national maximum. MINIMUMS we confirmed: - Health: the state e-health system (ESPBI IS) keeps patient data for the patient's lifetime plus three years. It then goes to archive for 75 years. After that it is deleted or passed to the state archives. The Chief Archivist sets the archiving steps. - Online gambling: remote gambling equipment must store authenticity check results, approved change logs and gaming records for at least 90 calendar days. Video of live table games must be kept for 90 days. - General business papers: the Office of the Chief Archivist publishes one general keep-it table plus 19 industry tables. These cover courts, health care, customs, police, notaries and others. Where an industry table sets a different period from the general table for the same task, follow the industry table. WHICH ONE WINS. Lithuania has no special tie-break rule. A legal duty to keep data is itself your legal reason to hold it, under Article 6(1)(c) of the Regulation. So keep the data for the legal minimum. Limit who can see it. Delete it at the end of that minimum, not when the business need ends. ONE MORE CLOCK, and this one helps you. Article 32(3) of the Lithuanian law says a fine can only be imposed within two years of the breach. Not confirmed: the widely repeated claim that Lithuanian accounting records must be kept for ten years. See the list of things we could not confirm.
Sources
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija / VI Registru centrasE. sveikatos portalas — retention in the state e-health system: lifetime plus three years, then 75 years in archive
esveikata.lt
Link checked 18 August 2026
- Official sourceLosimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijosRequirements for remote gambling devices, Articles 7, 12, 13 and 56 — 90-day minimum retention of logs, gaming records and live-table video
lpt.lrv.lt
Link checked 18 August 2026
- Official sourceLietuvos vyriausiojo archyvaro tarnyba (Office of the Chief Archivist of Lithuania)Dokumentu saugojimo terminu rodykles — the Chief Archivist's general and sector-specific document retention indexes
archyvai.lrv.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Article 32(3) — two-year limitation period for imposing an administrative fine
vdai.lrv.lt
“A decision on the imposition of an administrative fine may be adopted if no more than two years have elapsed from the date on which the infringement has been carried out.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
Not fully verified — see “What we're not sure about” below.If something goes wrong
There are at least two deadlines, and they do not match. If personal data is exposed, you have 72 hours to tell the State Data Protection Inspectorate. If the Cybersecurity Law covers you, a serious cyber attack must be reported within 24 hours. That report goes to the National Cyber Security Centre, a full day earlier than the other one. A fuller assessment follows at 72 hours, and a final report within one month. Less serious incidents get 72 hours. Financial firms have a third deadline under European digital resilience rules. Lithuanian organisations often miss the first deadline. Only 63 percent of breach reports in 2025 arrived on time.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents
DEADLINE 1 - personal data breach. Article 33 of the General Data Protection Regulation. Tell the regulator without undue delay, and where you can, within 72 hours of finding out. Article 34: tell the people affected without undue delay where the risk to them is high. In 2025 the Inspectorate received 223 breach reports affecting 1,249,409 people in Lithuania. Cyber attacks caused 29 percent and human error caused 58 percent. Only 63 percent were reported within 72 hours. DEADLINE 2 - cyber incident. The Lithuanian Cybersecurity Law has been in force since 18 October 2024. It puts the European network and information security directive known as NIS 2 into Lithuanian law. A major cyber incident must be reported at once, and no later than 24 hours. A detailed assessment follows within 72 hours, covering how bad it is and what evidence exists. Other incidents get 72 hours. A final report is due within one month of the incident being logged. Reports go to the National Cyber Security Centre. Its own wording: 'Apie dideli kiberneti incidenta organizacijos privalo pranesti nedelsiant, bet ne veliau kaip per 24 val.' DEADLINE 3 - financial firms. Regulation (EU) 2022/2554 on digital operational resilience has applied since 17 January 2025. Major technology incidents must be reported to the Bank of Lithuania on its own timetable. The Bank of Lithuania publishes guidance on this. The overlap is where people get caught. A ransomware attack on a Lithuanian hospital or utility sets off deadline 1 and deadline 2. The cyber deadline comes first. The two reports go to different bodies and must contain different things.
Sources
- Official sourceNacionalinis kibernetinio saugumo centras (National Cyber Security Centre)Kibernetinio saugumo istatymas — frequently asked questions, incident reporting deadlines (24 hours, 72 hours, one month)
nksc.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos krasto apsaugos ministerijaKibernetinio saugumo istatymas — entry into force 18 October 2024 and reporting deadlines
kam.lt
“Apie dideli kibernetini incidenta organizacijos privalo pranesti nedelsiant, bet ne veliau kaip per 24 val.”
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcija2025 Review of Personal Data Protection Supervision in Lithuania — 223 breach notifications, 63 percent reported within 72 hours
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things the summary does not cover. Children can agree for themselves at 14 in Lithuania, not 16. An age gate built for the European default of 16 is wrong here. You may never publish a Lithuanian personal identification number. You may never use one for marketing. Complaining about a government body is worth less than you expect. Fines on public bodies are capped at 30,000 or 60,000 euros. There are two data regulators, and journalism goes to the other one. If you sell cloud services to the Lithuanian state, your data centre may not qualify at all.
- What you have to do here:
- Get a parent's consent for children · Keep the data in the country
- What it costs if you get it wrong:
- Fixed maximum fine
1. AGE 14, NOT 16. Article 6 of the national law says a child over 14 can agree for themselves when online services are offered directly to them. Lithuania picked the lowest age the Regulation allows. A single European age gate set at 16 is stricter than Lithuania needs. One set at 13 to match the United States is against the law here. 2. THE PERSONAL IDENTIFICATION NUMBER IS SPECIAL. Article 3 of the national law covers the personal identification number ('asmens kodas'). You may use it where any Article 6(1) condition applies. But you may never publish it, and you may never use it for direct marketing. Both bans are absolute. Consent does not unlock them. Publishing a supplier list, a court list or a shareholder register that includes personal codes breaks the rule on its face. 3. PUBLIC BODIES ARE CHEAP TO BREACH. Article 33 caps fines on a public body for breaches of Article 83(4)(a) to (c) of the Regulation. The cap is 0.5 percent of its current-year budget, and never more than 30,000 euros. For the more serious class the cap is 1 percent, and never more than 60,000 euros. This is why Lithuania's fine numbers look tiny next to its complaint numbers. 4. TWO REGULATORS. Article 7 names the State Data Protection Inspectorate. It separately names the Inspector of Journalist Ethics for journalism, academic work, art and literature. Filing with the wrong one costs you time. 5. THE GOVERNMENT DATA CENTRE RULE KILLS DEALS. If a Lithuanian public body's system is graded critical or important, it must sit in a state data centre. If it is graded medium or low and you host it, a copy must still be kept in a state data centre. The Minister's order sets technical and organisational rules for data centres in European Union, European Economic Area and NATO states. A large cloud region outside those countries is not an option. 6. THE TWO-YEAR CLOCK CUTS BOTH WAYS. Article 32(3): no fine may be imposed more than two years after the breach. That is good news if you report late. It is bad news if your complaint is about something old.
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Articles 3, 6, 7, 32(3) and 33
vdai.lrv.lt
“It is prohibited to publish the personal identification number. It is prohibited to process personal identification number for purposes of direct marketing.”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — the state data centre requirement by importance grade, and the ministerial order on data centres in European Union, European Economic Area and NATO states
eimin.lrv.lt
Link checked 18 August 2026
- Official sourceZurnalistu etikos inspektoriaus tarnybaZurnalistu etikos inspektoriaus tarnyba — the second supervisory authority, for journalistic and artistic processing
zeit.lt
Link checked 18 August 2026
What's changing next
Two dated changes matter in the next twelve months. Both come from Europe. From 12 January 2027, every cloud provider must let customers move their data out for free. No exit fees at all. Around the same time, the technical security rules in Lithuania's cyber law start to apply to organisations registered in April 2025. That is roughly two years after registration. The bigger Lithuanian risk is not a new law. The government can change where state data must live by resolution. It does not need parliament and it does not have to consult anyone.
DATED AND COMING: - 12 January 2027: the European Data Act makes all cloud switching charges and data export fees zero. It applies in Lithuania directly. - From about 17 April 2026, then 17 April 2027: under the Lithuanian Cybersecurity Law, a company has 12 months from registration to meet the general cyber security rules and 24 months to meet the technical ones. The National Cyber Security Centre had to identify and register companies by 17 April 2025. So the technical rules land on the first group around 17 April 2027. That is why the law counts as partly in force rather than fully in force. - 1 January 2026: changes to the Law on the Management of State Information Resources took effect. They came in Law No. XV-565, adopted 20 November 2025 and published 28 November 2025. They touch 17 articles, including Article 45 on where state systems are held. The detailed rules under it are still settling. POWERS THE GOVERNMENT ALREADY HAS. These can change the answer with no warning: - The Government can set different rules for one named institution's state systems by resolution. The power sits in Articles 45(3) and 45(4) of the Law on the Management of State Information Resources. The cabinet decides who is in and who is out. - The list of state data centres is itself a Government resolution (No. 349). Adding or removing a data centre changes who may legally host state systems overnight. - A Minister of the Economy and Innovation order (No. 4-249) sets the technical and organisational rules. They cover data centres in European Union, European Economic Area and NATO states. A minister can tighten them with a signature. - The importance grade of any state system can be changed. Moving a system from 'medium' to 'important' puts it behind the strict rules, with no new law needed. EUROPEAN ITEMS TO WATCH. None of these are settled: - The European Union-United States Data Privacy Framework is still valid. The Latombe appeal is waiting at the Court of Justice. On 31 July 2026 the European Data Protection Board formally asked the Commission to check whether the decision still holds. - The Digital Omnibus proposal of 19 November 2025 has not been adopted and has no legal effect. Among other things, it would extend breach reporting from 72 to 96 hours. - The European cloud certification scheme has still not been adopted. So national schemes and national buying rules like Lithuania's keep applying. - Artificial Intelligence Act transparency duties started on 2 August 2026.
Sources
- Official sourceNacionalinis kibernetinio saugumo centrasKibernetinio saugumo istatymas FAQ — 12-month and 24-month compliance windows from registration, registration deadline 17 April 2025
nksc.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos Seimas (Parliament of Lithuania), Register of Legal ActsLaw No. XV-565 amending the Law on the Management of State Information Resources No. XI-1807, Articles 4, 6, 10, 11, 12, 17, 23-29, 34, 43, 45 and 46 — adopted 20 November 2025, in force 1 January 2026
e-seimas.lrs.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — the Government resolution and ministerial order that can be changed without parliament
eimin.lrv.lt
“isskyrus atvejus, numatytus VIIVI 45 straipsnio 3 ir 4 dalyse, kai Vyriausybe nutarimu konkrecios institucijos valdomiems VII nustato kita teisini rezima”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapter VI — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
Not fully verified — see “What we're not sure about” below.The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries6 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Government data must stay in the country
Official name: Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas, 45 straipsnis · Law No. XI-1807 on the Management of State Information Resources, Article 45, as amended by Law No. XV-565; Government resolution No. 349 (list of state data centres); Minister of the Economy and Innovation order No. 4-249 (requirements for data centres in European Union, European Economic Area and NATO states) · Act of parliament
If a Lithuanian public body's computer system is graded critical or important, its data must sit in a state-run data centre inside Lithuania. The cabinet can set different rules for one named institution by resolution. No commercial cloud region qualifies on its own.
How this country controls where data goes: Not allowed · Accepted routes: Government sign-off needed
What you have to do
- Keep the data in the countryState systems graded critical ('ypatingos svarbos') or important ('svarbus') must be held in state data centres. The only exception is where the Government sets different rules for a named institution by resolution, under Articles 45(3) and 45(4).
- Hold a security certificateOrder No. 4-249 sets technical and organisational requirements for data centres located in European Union, European Economic Area and NATO states.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — the ministry's own statement of the hosting rule by importance grade, citing Article 45 of the law, Government resolution No. 349 and order No. 4-249
eimin.lrv.lt
“Ypatingos svarbos ir svarbius VII privaloma laikyti valstybiniuose duomenu centruose”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos Seimas, Register of Legal ActsLaw No. XV-565 amending the Law on the Management of State Information Resources — amends Article 45, adopted 20 November 2025, in force 1 January 2026
e-seimas.lrs.lt
Link checked 18 August 2026
- Official sourceTeises aktu registras (Register of Legal Acts)XI-1807 Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — consolidated version effective from 1 January 2026
e-tar.lt
Link checked 18 August 2026
Government data needs a copy kept in the country
Official name: Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — vidutines ir mazos svarbos istekliai · Law No. XI-1807 on the Management of State Information Resources, as explained by the responsible ministry · Act of parliament
For the less critical half of Lithuanian government systems, you may use a private or foreign data centre. You must still keep a copy in a Lithuanian state data centre. This is a copy rule, not a ban.
How this country controls where data goes: Only approved countries · Accepted routes: Certification scheme
What you have to do
- Keep the data in the countryMedium and low importance state information resources may be held in foreign or private data centres, but copies must be kept in state data centres.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — hosting rule for medium and low importance state information resources
eimin.lrv.lt
“Vidutines svarbos ir mazos svarbos VII gali buti laikomi tiek valstybiniuose duomenu centruose, tiek uzsienio ar privaciuose duomenu centruose. Jeigu sie istekliai laikomi uzsienio ar privaciuose duomenu centruose, tuomet ju kopijas privaloma laikyti valstybiniuose duomenu centruose.”
Link checked 18 August 2026
Government data rules
Official name: Skaitmenine ambasada — Vyriausybes nutarimas ir Valstybes informaciniu istekliu valdymo istatymo pakeitimai · Government decree of 12 July 2022, together with May 2022 amendments to the Law on the Management of State Information Resources · Directly binding regulation
Lithuania runs a 'digital embassy'. Copies of the most critical state data must be kept outside Lithuania on purpose. That way the government can keep running in a crisis. State data is graded into four importance levels to decide what goes where.
What you have to do
- Keep the data in the countryThis is the opposite of a rule that keeps data at home. Copies of the most critical state data must be stored OUTSIDE Lithuania. The point is that the state can keep working if its own territory is attacked.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaDigital Embassy launches to improve security of state data in emergencies
eimin.lrv.lt
“some of the data will be stored in public data centres, but copies will be compulsorily stored outside the territory of Lithuania”
Link checked 18 August 2026
Health data rules
Official name: Elektronines sveikatos paslaugu ir bendradarbiavimo infrastrukturos informacine sistema (ESPBI IS) · Regulations of the state e-health information system; controller the Ministry of Health, principal processor the state enterprise Centre of Registers · Directly binding regulation
Lithuania has no separate rule saying health data must stay in the country. But nearly all health records pass through the state e-health system. That system is a state information resource. So the government data centre rules are what really decide where health records sit. Records are kept for life plus three years, then archived for 75 years.
What you have to do
- Keep data for a minimum periodPatient data is kept in the live system for the patient's lifetime plus three years. It then goes to archive for 75 years. After that it is deleted or passed to the state archives.
- Secure the data
Sources
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija / VI Registru centrasE. sveikatos portalas — data security notice: controller, processor and retention periods for the state e-health system
esveikata.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija (Ministry of Health)Elektronines sveikatos paslaugu ir bendradarbiavimo infrastrukturos informacine sistema (ESPBI IS) — the ministry's own page on the state e-health system
sam.lrv.lt
Link checked 18 August 2026
Payment data rules
Official name: Lietuvos banko pozicijos ir gaires finansu rinkos dalyviams · Bank of Lithuania positions and guidelines catalogue; Regulation (EU) 2022/2554 (digital operational resilience) applies directly since 17 January 2025 · Regulator guideline
We found no rule that banks, payment firms, insurers or investment firms in Lithuania must keep data in the country. Checked 18 August 2026. European digital resilience rules make you disclose and control where data is used and stored. They do not make you keep it local.
Enforced by Bank of Lithuania
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Written vendor contractEuropean digital resilience rules say your contract with a technology supplier must state where data is used and stored. It must also give you audit rights and an exit plan. That is disclosure, not a rule that data stays at home.
- Report cyber incidentsMajor technology incidents must be reported to the Bank of Lithuania on the European digital resilience timetable.
Sources
- Official sourceLietuvos bankasLietuvos banko pozicijos ir gaires — the central bank's own catalogue of 239 positions and guidelines for supervised firms; no cloud or storage-location instrument found
lb.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), Articles 28-30
eur-lex.europa.eu
Link checked 18 August 2026
Telecoms rules
Official name: Nuotolinio losimo irenginiams keliami reikalavimai · Requirements for remote gambling devices, approved by the Gaming Control Authority · Government rules
Lithuania's gambling regulator sets detailed technical rules for remote gambling systems, including keeping logs, gaming records and live-table video for at least 90 days. We found no requirement that the servers themselves sit in Lithuania.
Enforced by Gaming Control Authority
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep logs — 3 monthsAt least 90 calendar days for authenticity check results, authorised change logs and gaming records; 90 days for time-stamped video of live table games.
Sources
- Official sourceLosimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijosRequirements for remote gambling devices — Articles 7, 12, 13 and 56
lpt.lrv.lt
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas · Law No. I-1374, as restated in 2018 (Law on Legal Protection of Personal Data) · Act of parliament
Lithuania's own data protection law sits on top of the European rules. It adds no storage-location requirement. It does add four things. Children can agree for themselves at 14. You may never publish a person's national identification number. Fines on public bodies are capped. And any fine must be imposed within two years.
Enforced by State Data Protection Inspectorate
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What you have to do
- Get a parent's consent for children — applies at: A child older than 14 can consent for themselves to information society services (Article 6)
- Put a transfer safeguard in placeArticle 15: you need written permission from the State Data Protection Inspectorate only for transfers under Article 46(3) of the Regulation. That means contract wording you write yourself, or arrangements between public bodies. The answer comes within 20 working days, extendable once by 10 working days.
- Tell people what you doArticle 5: you must tell staff before you monitor video, audio, behaviour, location or movement at work.
What it costs if you get it wrong
- Fixed maximum fine: €30,000 (or 0.5% of the current year's budget, whichever is lower) for a public institution breaching Article 83(4)(a)-(c); €60,000 (or 1%) for the more serious class — about $65 thousandInfringement by a Lithuanian state or municipal institution — Article 33
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw of the Republic of Lithuania on Legal Protection of Personal Data — Articles 3, 5, 6, 7, 15, 32 and 33 (English translation published by the supervisory authority)
vdai.lrv.lt
“When information society services are directly offered to a child, the processing of the child's personal data is legal if consent is given by a child older than 14 years of age in accordance with Article 6 (1) (a) of Regulation (EU) 2016/679.”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos Seimas, Register of Legal ActsI-1374 Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas — the official register entry for the law
e-seimas.lrs.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLegislation — the supervisory authority's own list of the national laws in force
vdai.lrv.lt
Link checked 18 August 2026
Data rules
Official name: Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas, 3 straipsnis (asmens kodas) · Law on Legal Protection of Personal Data, Article 3 · Act of parliament
The Lithuanian national identification number has its own rule. You may use it where you have a legal reason. You may never publish it. You may never use it for marketing. Consent does not get you around either ban.
Enforced by State Data Protection Inspectorate
What you have to do
- Secure the dataYou may never publish a Lithuanian personal identification number. You may never use it for direct marketing. Consent does not change either ban.
What it costs if you get it wrong
- Percentage of global turnover: Enforced through the European ceilings — up to 4% of worldwide group turnover or €20,000,000 — about $22 millionUnlawful processing of the personal identification number
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Article 3 — peculiarities of processing of the personal identification number
vdai.lrv.lt
“It is prohibited to publish the personal identification number. It is prohibited to process personal identification number for purposes of direct marketing.”
Link checked 18 August 2026
Data rules (2027)
Official name: Lietuvos Respublikos kibernetinio saugumo istatymas · Law on Cybersecurity, implementing Directive (EU) 2022/2555 (NIS 2) · Act of parliament
Lithuania's cyber law has been in force since 18 October 2024, but it applies slowly. Registered organisations get twelve months to meet the general requirements. They get twenty-four months for the technical ones. So the real deadline for the first group is around 17 April 2027. The law sets no storage-location rule.
That is a long gap: the duty is real law today, but no penalty can follow until 17 April 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
Enforced by National Cyber Security Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursMajor cyber incident: report to the National Cyber Security Centre immediately and no later than 24 hours.
- Report cyber incidents — within 72 hoursDetailed assessment within 72 hours; other incidents within 72 hours; final report within one month of registration.
- Register or notifyThe National Cyber Security Centre identified and registered the companies it covers by 17 April 2025.
- Secure the data — from 17 April 2026General cybersecurity requirements apply 12 months after registration.
- Hold a security certificate — from 17 April 2027Technical cybersecurity requirements apply 24 months after registration. This is the date the law really starts to matter.
What it costs if you get it wrong
- Percentage of global turnover: Up to €10,000,000 or 2% of worldwide annual turnover, whichever is lower — about $11 millionFailure to meet cybersecurity requirements
Sources
- Official sourceLietuvos Respublikos krasto apsaugos ministerijaKibernetinio saugumo istatymas — entry into force 18 October 2024, 12 and 24 month compliance windows, penalties
kam.lt
Link checked 18 August 2026
- Official sourceNacionalinis kibernetinio saugumo centrasKibernetinio saugumo istatymas — frequently asked questions from the national cyber authority
nksc.lt
Link checked 18 August 2026
How long you keep personal data
Official name: Bendruju ir sritiniu dokumentu saugojimo terminu rodykles · General and sector-specific document retention indexes approved by the Chief Archivist of Lithuania · Government rules
Lithuania sets minimum keep-it periods through retention tables issued by the Chief Archivist, not through one line in a statute. There is a general table and nineteen industry tables, and the industry table wins where they disagree.
Enforced by Office of the Chief Archivist of Lithuania
What you have to do
- Keep data for a minimum periodMinimum keep-it periods come from one general table plus 19 industry tables. These cover courts, health care, customs, police, notaries and others. Where an industry table differs from the general table for the same task, the industry table wins.
Sources
- Official sourceLietuvos vyriausiojo archyvaro tarnybaDokumentu saugojimo terminu rodykles — the Chief Archivist's retention indexes
archyvai.lrv.lt
Link checked 18 August 2026
Applies across the European Union3 rules
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: Europos Parlamento ir Tarybos reglamentas (ES) 2016/679 (Bendrasis duomenu apsaugos reglamentas) · Regulation (EU) 2016/679 · Directly binding regulation
The European base rules cover almost all personal data in Lithuania. They do not require data to stay in Europe. They set the conditions for letting data leave. Lithuania lowered the age at which children can agree for themselves to 14.
Enforced by European Data Protection Board
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What you have to do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of how you use data
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a representativeYou must do this if you have no office in the European Union.
- Put a transfer safeguard in placeYou must also write down why the destination country is safe, after the Schrems II court ruling.
- Do not hand data to foreign authorities on demandAn order from a foreign government is not on its own a legal reason to hand data over (European Data Protection Board Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: 14 in Lithuania — Lithuania took the lowest age the Regulation permits, two years below the default of 16
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe regulator can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 8, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLegislation — the Lithuanian supervisory authority's own list of national data protection laws sitting on top of the Regulation
vdai.lrv.lt
Link checked 18 August 2026
General data protection law
Official name: Reglamentas (ES) 2018/1807 del laisvo ne asmens duomenu judejimo Europos Sajungoje pagrindu · Regulation (EU) 2018/1807 · Directly binding regulation
Lithuania may not force non-personal data to be stored on its own soil. The only exception is where public security really requires it. Lithuania's state data centre rule has to be justified against this.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
Cloud and outsourcing rules
Official name: Reglamentas (ES) 2023/2854 del suderintu saziningos prieigos prie duomenu ir ju naudojimo taisykliu (Duomenu aktas) · Regulation (EU) 2023/2854 (Data Act) · Directly binding regulation
The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must fall to zero.
That is a long gap: the duty is real law today, but no penalty can follow until 12 January 2027. A contract you sign can still hold you to it from day one — and government contracts often do.
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data export fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandChapter VII limits when a foreign government can get non-personal data held in the European Union.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact wording of Article 45 of the Law on the Management of State Information Resources, which is the source of the state data centre requirement.
We could not read the text of the article itself from a government source. We relied on the Ministry of the Economy and Innovation's own summary, which quotes the rule and cites Article 45(3) and 45(4). If you are bidding to host a Lithuanian state system, have a Lithuanian lawyer check the statute text.
The contents of Government resolution No. 349 (the list of state data centres) and Minister of the Economy and Innovation order No. 4-249 (technical requirements for data centres in European Union, European Economic Area and NATO states).
The ministry cites both documents, but we could not read either one. We do not know which data centres are on the list, or whether any commercial provider qualifies. Ask the ministry before you plan a bid.
The legal basis, host country and exact scope of Lithuania's 'digital embassy'.
The ministry's English news page confirms that copies must be stored outside Lithuania, and dates the Government decree to 12 July 2022. We could not read the decree itself, so we do not know which country hosts the copies.
Whether Lithuania imposes a retention obligation on telecoms traffic and location data for law enforcement, for how long, and whether it survives European court rulings.
We could not confirm whether Lithuania makes telecoms companies keep call and location records. The Law on Electronic Communications has a version dated 1 July 2026, but we could not read the relevant articles from a government source. If you run a telecoms business in Lithuania, check this before you rely on it.
Whether Lithuania has any mapping, geospatial or aerial imagery deposit or localisation requirement.
We did not check this. Nearby countries in this dataset do have such rules. Do not read the silence here as a no.
The commonly repeated claim that Lithuanian accounting records must be kept for ten years.
We could not confirm a number from a government source, so we do not state one. If you need an accounting keep-it period, check the Chief Archivist's general table and the Law on Financial Accounting.
Whether the state e-health system is graded as a critical or important state information resource.
The system is clearly a state information resource run by the Ministry of Health. We could not find its importance grade, so we cannot confirm that the strictest state data centre rule applies to it. Ask the Ministry of Health if you host health systems.
Whether the Lithuanian Law on Gambling itself (as opposed to the regulator's technical requirements) contains a server or equipment location rule.
We could not read the Law on Gambling itself. The regulator's technical rules contain no server location rule, which points one way but does not settle it. Check with the Gaming Control Authority before you place servers abroad.
Whether the Inspector of Journalist Ethics has issued data protection decisions recently, and how many.
Its site is live and publishing guidance in 2026, but we found no register of its decisions. Our rating of this office rests on its own website, not on a count of decisions.
Whether the Bank of Lithuania has any cloud or outsourcing instrument affecting storage location.
We read the first page of the Bank of Lithuania's 239-document catalogue and found nothing, but we did not read all 239 entries. Treat 'no storage-location rule in finance' as something we did not find, not something we proved. If you run a bank here, check with the Bank of Lithuania.
The precise commencement dates for the general and technical cybersecurity requirements under the Cybersecurity Law.
The rule is 12 and 24 months from registration, and registration had to be finished by 17 April 2025. We worked out the April 2026 and April 2027 dates from those two facts. We did not read a start-date article confirming them.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.