Lithuania
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Lithuania has no general rule that data must stay in the country. Private companies follow the European rulebook: data can go abroad once the right paperwork is in place. The wall is in government. The data behind the state's most important computer systems must sit in Lithuanian state data centres — and a copy of the most critical state data must be kept abroad on purpose.
Eight questions about Lithuania
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Lithuania's rules apply to my company?
Yes. A company with no office in Lithuania is still caught if it offers goods or services to people in Lithuania, or watches what they do online. There is no size or revenue threshold to hide under — a two-person company is covered exactly like a bank. If you have no office anywhere in the European Union, you must appoint a representative inside the Union who can be contacted by regulators and by the public.
Territorial reach comes from Article 3 of the General Data Protection Regulation, which applies directly in Lithuania. The Lithuanian Law on the Legal Protection of Personal Data (Asmens duomenu teisines apsaugos istatymas, Law No. I-1374 as restated in 2018) adds national detail on top; its Article 1(4) sets out when the Lithuanian law itself applies, covering controllers established in Lithuania, controllers outside the Union that have a representative in Lithuania, and processing of data about people in the Union. The representative duty is Article 27 of the Regulation. Separately, the Lithuanian Cybersecurity Law (Kibernetinio saugumo istatymas) catches entities by sector and size rather than by nationality; the National Cyber Security Centre identifies and registers who is in scope.
Sources
- Official sourceValstybine duomenu apsaugos inspekcija (State Data Protection Inspectorate)Law of the Republic of Lithuania on Legal Protection of Personal Data, Article 1(4) — scope (English translation published by the supervisory authority)
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3 and 27
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLegislation — the Lithuanian supervisory authority's own list of the national data protection laws in force
vdai.lrv.lt
Link checked 18 August 2026
Can I store my users' data outside Lithuania?
For an ordinary business, yes. Lithuania has not added a national storage-location rule on top of the European rules, so data can leave once you have the standard European paperwork. The exception is government. If a computer system counts as a state information resource, Lithuania grades it by importance, and the two top grades must be held in state data centres inside Lithuania. The two lower grades can sit abroad, but a copy must still be kept in a Lithuanian state data centre. Lithuania also forces the opposite move for its most critical state data: a copy must be kept outside the country, in what it calls a digital embassy.
Sector by sector, checked 18 August 2026. GOVERNMENT AND PUBLIC SECTOR — the real wall. The Ministry of the Economy and Innovation states that resources graded 'ypatingos svarbos' (critical) and 'svarbus' (important) must be held in state data centres, except where the Government by resolution sets a different regime for a named institution under Articles 45(3) and 45(4) of the Law on the Management of State Information Resources. Resources graded 'vidutines svarbos' (medium) and 'mazos svarbos' (low) may be held in state, foreign or private data centres, but if they are held in a foreign or private data centre their copies must be kept in state data centres. A Government resolution (No. 349) sets the list of state data centres; a Minister of the Economy and Innovation order (No. 4-249) sets the technical and organisational requirements for data centres in European Union, European Economic Area and NATO states. Rating: closed for the top two grades, mirror for the bottom two. DIGITAL EMBASSY — the reverse of localisation. Amendments to the same law in May 2022 and a Government decree of 12 July 2022 made diversification of state data mandatory: some data sits in public data centres, 'but copies will be compulsorily stored outside the territory of Lithuania'. HEALTH — no separate location rule found. Almost all Lithuanian health records pass through the state e-health system (ESPBI IS), controlled by the Ministry of Health with the state enterprise Centre of Registers as principal processor. That is a state information resource, so the government wall above is what actually governs it. Rating: conditional, with the government wall behind it. BANKING, PAYMENTS, INSURANCE, SECURITIES — no localisation rule found. We searched the Bank of Lithuania's own catalogue of positions and guidelines (239 documents) and found digital operational resilience incident reporting and outsourcing-adjacent risk guidance, but no instrument requiring data to be stored in Lithuania. European rules on digital operational resilience for financial entities require you to disclose where processing happens, not to keep it local. Rating: conditional. ONLINE GAMBLING — no server-location rule found in the regulator's own technical requirements for remote gambling devices. Those requirements do impose 90-day minimum log retention. Rating: open, medium confidence. TELECOMS — not verified. The Law on Electronic Communications has a consolidated version dated 1 July 2026, but we could not read the retention articles from an official source in this run. MAPPING AND GEOSPATIAL, EDUCATION, DEFENCE — not checked in this run. See the unconfirmed list. Across all of this sits Regulation (EU) 2018/1807, which forbids a member state from imposing localisation on non-personal data except on genuine public-security grounds. Lithuania's state data centre rule is a public-sector procurement and security rule, which is the space that Regulation leaves open.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerija (Ministry of the Economy and Innovation)Valstybes informaciniu istekliu valdymo kryptys — the ministry's own statement of where state information resources must be held, by importance grade
eimin.lrv.lt
“Ypatingos svarbos ir svarbius VII privaloma laikyti valstybiniuose duomenu centruose [...] Vidutines svarbos ir mazos svarbos VII gali buti laikomi tiek valstybiniuose duomenu centruose, tiek uzsienio ar privaciuose duomenu centruose. Jeigu sie istekliai laikomi uzsienio ar privaciuose duomenu centruose, tuomet ju kopijas privaloma laikyti valstybiniuose duomenu centruose.”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaDigital Embassy launches to improve security of state data in emergencies
eimin.lrv.lt
“some of the data will be stored in public data centres, but copies will be compulsorily stored outside the territory of Lithuania”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija / VI Registru centrasE. sveikatos portalas — data security and privacy notice for the state e-health system (ESPBI IS)
esveikata.lt
Link checked 18 August 2026
- Official sourceLosimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijos (Gaming Control Authority)Requirements for remote gambling devices — the gambling regulator's own technical requirements (no server-location rule; 90-day log retention)
lpt.lrv.lt
Link checked 18 August 2026
- Official sourceLietuvos bankas (Bank of Lithuania)Lietuvos banko pozicijos ir gaires — the central bank's own catalogue of positions and guidelines for supervised financial firms (searched for a cloud or storage-location instrument; none found)
lb.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
What do I need in place before data leaves Lithuania?
Lithuania uses the European model: a destination is off-limits unless you have an approved route out. The easiest route is an approved-country list, which is populated and currently includes the United Kingdom, Switzerland, Japan, South Korea, Canada, Brazil and others, plus United States companies signed up to the European Union–United States Data Privacy Framework. If your destination is not on the list, the normal answer is a set of standard contract clauses published by the European Commission. Lithuania adds one local step: if you want to use your own custom contract wording instead of the standard clauses, you need written permission from the Lithuanian regulator first.
Model: allowlist. The list is populated — Andorra, Argentina, Brazil (mutual, 26 January 2026), Canada (commercial bodies only), Faroe Islands, Guernsey, Isle of Man, Israel, Japan, Jersey, New Zealand, South Korea (first review confirmed 23 July 2026), Switzerland, United Kingdom (renewed 19 December 2025, running to 2031), Uruguay, the United States for entities self-certified under the Data Privacy Framework, and the European Patent Organisation. No adequacy decision has been withdrawn or suspended as at 18 August 2026. Mechanisms: the 2021 Standard Contractual Clauses (Decision (EU) 2021/914) remain the operative set and are unamended. The promised new clauses for importers already directly subject to the Regulation under Article 3(2) are still not adopted. Binding Corporate Rules remain available. Article 49 derogations are narrow and not for systematic or large-scale transfers. A transfer impact assessment is still expected following Schrems II. EDPB Guidelines 02/2024 confirm that a third-country authority's order is not by itself a lawful basis to disclose. The Lithuanian addition is Article 15 of the Law on the Legal Protection of Personal Data. It applies only to Article 46(3) of the Regulation — that is, ad hoc contractual clauses agreed between the parties, and administrative arrangements between public bodies. The State Data Protection Inspectorate must grant permission or give a reasoned written refusal within 20 working days of receiving a complete file, extendable once by up to 10 working days. Using the standard published clauses needs no permission. Most time-sensitive item: the European Union–United States Data Privacy Framework is still in force and legally valid on 18 August 2026, but is under pressure. The General Court dismissed the Latombe challenge on 3 September 2025 and an appeal to the Court of Justice was lodged on 31 October 2025 and is pending. On 31 July 2026 the European Data Protection Board wrote formally to the Commissioner asking the Commission to examine whether United States institutional changes affect the decision's validity. The Commission has not suspended or revoked it. Practical advice: usable today, never as a single-mechanism architecture.
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Article 15 — permits of the State Data Protection Inspectorate for transfers under Article 46(3) of the General Data Protection Regulation
vdai.lrv.lt
“In accordance with Article 46 (3) of Regulation (EU) 2016/679, the State Data Protection Inspectorate must provide the data controller with permission for the transfer of personal data to the third country or an international organization or a reasoned written refusal to issue this permit no later than within 20 working days.”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionCommission Implementing Decision (EU) 2021/914 on standard contractual clauses for transfers to third countries
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean Data Protection BoardEDPB Guidelines 02/2024 on Article 48 — a foreign authority's order is not by itself a lawful basis to disclose
edpb.europa.eu
Link checked 18 August 2026
Who enforces the rules in Lithuania, and what can they do?
The main regulator is the State Data Protection Inspectorate, and it is genuinely working. In 2025 it received 2,081 complaints, up 48 percent on the year before, ran 26 inspections and had 54 staff. By 31 July 2026 it had already published 122 decisions for the year. But the fines are small: it issued only five fines in the whole of 2025, the largest being 9,000 euros (about 9,800 US dollars). Lithuania also has a second, less well known data regulator for journalism, and a separate cyber regulator inside the defence ministry.
Is it operational? Yes, on its own evidence. From the Inspectorate's 2025 annual review, published 1 July 2026: 2,081 complaints received (1,408 in 2024); 16 scheduled and 10 unscheduled inspections; 132 monitoring actions; 223 personal data breach notifications received, covering 1,249,409 people in Lithuania, of which only 63 percent arrived within 72 hours; 34 cross-border complaints handled as lead authority and 28 decisions coordinated internationally; 54 established posts, up from 46; a budget of 2,198,000 euros (about 2.4 million US dollars). Its published decisions register for 2026 lists 122 decisions between 3 January and 31 July 2026, split between 'violations found' and 'no violations found', with Vinted UAB appearing seven times. Rating: active, not aggressive. The Inspectorate issues a steady flow of binding decisions and orders, but very few fines and small ones — five fines in 2025 ranging from 3,529 euros to 9,000 euros. Part of the reason is structural: Article 33 of the national law caps fines on Lithuanian public institutions at 0.5 percent of the current year's budget and never more than 30,000 euros for one class of breach, or 1 percent and never more than 60,000 euros for another. Private companies remain exposed to the full European ceilings. Second regulator: Article 7 of the national law names the Inspector of Journalist Ethics as the supervisory authority for personal data processed for journalistic, academic, artistic and literary purposes. A complaint against a news organisation goes there, not to the Inspectorate. Cyber regulator: the National Cyber Security Centre, under the Ministry of National Defence, is the competent authority under the Cybersecurity Law. It can impose fines of up to 10 million euros or 2 percent of worldwide annual turnover, whichever is lower. Sectoral regulators: the Bank of Lithuania supervises financial firms, the Communications Regulatory Authority supervises telecoms, and the Gaming Control Authority supervises gambling. Appeals against Inspectorate decisions go to the administrative courts — Vilnius Regional Administrative Court first, then the Supreme Administrative Court.
Sources
- Official sourceValstybine duomenu apsaugos inspekcija2025 Review of Personal Data Protection Supervision in Lithuania — the supervisory authority's own annual report (complaints, inspections, fines, staffing, budget)
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaVDAI sprendimai (baudos, nurodymai ir kt.) 2026 m. — the register of 2026 decisions, last updated 3 August 2026
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Articles 7, 12, 32 and 33 — supervisory authorities, powers, two-year limitation period and the cap on fines for public institutions
vdai.lrv.lt
“A supervisory authority has the right to impose an administrative fine to a public institution or authority which has infringed the provisions of Article 83 (4) (a), (b) and (c) of Regulation (EU) 2016/679, up to 0.5 per cent of the current year's budget of a public institution or authority [...] but not more than thirty thousand euros.”
Link checked 18 August 2026
- Official sourceZurnalistu etikos inspektoriaus tarnybaZurnalistu etikos inspektoriaus tarnyba — the Inspector of Journalist Ethics, the second Lithuanian data protection supervisory authority
zeit.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos krasto apsaugos ministerija (Ministry of National Defence)Kibernetinio saugumo istatymas — the defence ministry's own explainer naming the National Cyber Security Centre as the competent authority and setting out the penalty ceiling
kam.lt
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply and they pull against each other. The ceiling comes from Europe: you must delete personal data once you no longer need it for the purpose you collected it for. The floors come from Lithuanian sector rules and from retention tables issued by the Chief Archivist. Some floors are very long. Health records in the state e-health system are kept for the patient's whole life plus three years, then archived for 75 years. Online gambling systems must keep their logs for at least 90 days. When a floor and the ceiling clash, the floor wins for as long as it lasts, because keeping the data is then a legal duty.
CEILING. Article 5(1)(e) of the General Data Protection Regulation — storage limitation. Data must be kept in a form allowing identification no longer than necessary for the purposes. There is no separate national ceiling in the Lithuanian law. FLOORS verified in this run: - Health: the state e-health system (ESPBI IS) keeps patient data for the patient's lifetime plus three years, then transfers it to archive for 75 years, after which it is deleted or passed to the state archives. The Chief Archivist sets the archiving procedure. - Online gambling: remote gambling devices must store authenticity check results, authorised change logs and gaming records for at least 90 calendar days, and video records of live table games for 90 days. - General business documents: the Office of the Chief Archivist publishes a general retention index plus 19 sector-specific indexes (courts, health care, customs, police, notaries and others). Where a sector index sets a different period from the general index for the same administrative function, the sector index is the one to check. CONFLICT RULE. Lithuania does not have a special tie-break provision. In practice the legal obligation to retain gives you the lawful basis under Article 6(1)(c) of the Regulation, so you keep the data for the statutory floor, minimise access to it, and delete at the end of the floor rather than at the end of the business need. ONE MORE CLOCK, in your favour. Article 32(3) of the Lithuanian law says a decision imposing an administrative fine may only be adopted if no more than two years have passed since the infringement was carried out. Not verified in this run: the widely repeated claim that Lithuanian accounting records must be kept for ten years. See the unconfirmed list.
Sources
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija / VI Registru centrasE. sveikatos portalas — retention in the state e-health system: lifetime plus three years, then 75 years in archive
esveikata.lt
Link checked 18 August 2026
- Official sourceLosimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijosRequirements for remote gambling devices, Articles 7, 12, 13 and 56 — 90-day minimum retention of logs, gaming records and live-table video
lpt.lrv.lt
Link checked 18 August 2026
- Official sourceLietuvos vyriausiojo archyvaro tarnyba (Office of the Chief Archivist of Lithuania)Dokumentu saugojimo terminu rodykles — the Chief Archivist's general and sector-specific document retention indexes
archyvai.lrv.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Article 32(3) — two-year limitation period for imposing an administrative fine
vdai.lrv.lt
“A decision on the imposition of an administrative fine may be adopted if no more than two years have elapsed from the date on which the infringement has been carried out.”
Link checked 18 August 2026
What happens if there is a breach?
Count at least two clocks, and they do not agree. If personal data is exposed, you have 72 hours to tell the State Data Protection Inspectorate. If you are covered by the Cybersecurity Law, a serious cyber incident must be reported to the National Cyber Security Centre within 24 hours — a full day earlier — with a fuller assessment at 72 hours and a final report within one month. Other incidents get 72 hours. Financial firms have a third clock under European digital resilience rules. Lithuanian organisations are visibly bad at the first clock: only 63 percent of breach reports in 2025 arrived on time.
Clock 1 — personal data breach. Article 33 of the General Data Protection Regulation: notify the supervisory authority without undue delay and where feasible within 72 hours of becoming aware. Article 34: tell the affected people without undue delay where the risk to them is high. In 2025 the Inspectorate received 223 breach notifications affecting 1,249,409 people in Lithuania; 29 percent were caused by cyber incidents, 58 percent by human error; only 63 percent were reported within 72 hours. Clock 2 — cyber incident. Under the Lithuanian Cybersecurity Law, in force since 18 October 2024 and implementing the European network and information security directive known as NIS 2: a major cyber incident must be reported immediately and no later than 24 hours; a detailed assessment including severity and evidence within 72 hours; other incidents within 72 hours; a final report within one month of the incident being registered. The National Cyber Security Centre is the recipient. Its stated wording: 'Apie dideli kiberneti incidenta organizacijos privalo pranesti nedelsiant, bet ne veliau kaip per 24 val.' Clock 3 — financial entities. Regulation (EU) 2022/2554 on digital operational resilience has applied since 17 January 2025 and requires major information and communication technology incidents to be reported to the Bank of Lithuania on its own timetable. The Bank of Lithuania publishes guidance on digital resilience incident reporting. The overlap is the failure mode. A ransomware attack on a Lithuanian hospital or utility triggers all of clock 1 and clock 2, with the earlier deadline being the cyber one, and the two reports go to different institutions with different content requirements.
Sources
- Official sourceNacionalinis kibernetinio saugumo centras (National Cyber Security Centre)Kibernetinio saugumo istatymas — frequently asked questions, incident reporting deadlines (24 hours, 72 hours, one month)
nksc.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos krasto apsaugos ministerijaKibernetinio saugumo istatymas — entry into force 18 October 2024 and reporting deadlines
kam.lt
“Apie dideli kibernetini incidenta organizacijos privalo pranesti nedelsiant, bet ne veliau kaip per 24 val.”
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcija2025 Review of Personal Data Protection Supervision in Lithuania — 223 breach notifications, 63 percent reported within 72 hours
vdai.lrv.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679, Articles 33 and 34 — 72-hour breach notification
eur-lex.europa.eu
Link checked 18 August 2026
What trips people up in Lithuania?
Five things that are not in the summary. Children can consent for themselves at 14 in Lithuania, not 16, so an age gate built for the European default is wrong here. You may never publish a Lithuanian personal identification number, and you may never use one for marketing. Complaining about a government body is worth less than you think, because fines on public institutions are capped at 30,000 or 60,000 euros. There are two data regulators, and journalism goes to the other one. And if you sell cloud services to the Lithuanian state, your data centre may simply be ineligible.
1. AGE 14, NOT 16. Article 6 of the national law: 'When information society services are directly offered to a child, the processing of the child's personal data is legal if consent is given by a child older than 14 years of age.' Lithuania took the lowest age the Regulation allows. A pan-European age gate set at 16 is over-restrictive in Lithuania; one set at 13 for United States parity is illegal here. 2. THE PERSONAL IDENTIFICATION NUMBER IS SPECIAL. Article 3 of the national law: the personal identification number ('asmens kodas') may be processed where any Article 6(1) condition applies, BUT 'it is prohibited to publish the personal identification number' and 'it is prohibited to process personal identification number for purposes of direct marketing'. These are flat prohibitions with no consent override. Publishing a supplier list, a court list or a shareholder register that includes personal codes is a breach on its face. 3. PUBLIC BODIES ARE CHEAP TO BREACH. Article 33 caps fines on a public institution at 0.5 percent of its current-year budget and never more than 30,000 euros for infringements of Article 83(4)(a) to (c) of the Regulation, and at 1 percent and never more than 60,000 euros for the more serious class. This is why Lithuania's fine numbers look tiny next to its complaint numbers. 4. TWO REGULATORS. Article 7 names the State Data Protection Inspectorate and, separately, the Inspector of Journalist Ethics for journalistic, academic, artistic and literary processing. Filing with the wrong one loses you time. 5. THE GOVERNMENT DATA CENTRE WALL IS A PROCUREMENT KILLER. If a Lithuanian public body's system is graded critical or important, it must sit in a state data centre. If it is graded medium or low and you host it, a copy still has to be kept in a state data centre, and the Minister's order sets technical and organisational requirements for data centres in European Union, European Economic Area and NATO states. A hyperscale region outside that footprint is not a candidate. 6. THE TWO-YEAR CLOCK CUTS BOTH WAYS. Article 32(3): no administrative fine may be imposed more than two years after the infringement was carried out. Good news for a company that self-reports late; bad news for a complainant with an old grievance.
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Articles 3, 6, 7, 32(3) and 33
vdai.lrv.lt
“It is prohibited to publish the personal identification number. It is prohibited to process personal identification number for purposes of direct marketing.”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — the state data centre requirement by importance grade, and the ministerial order on data centres in European Union, European Economic Area and NATO states
eimin.lrv.lt
Link checked 18 August 2026
- Official sourceZurnalistu etikos inspektoriaus tarnybaZurnalistu etikos inspektoriaus tarnyba — the second supervisory authority, for journalistic and artistic processing
zeit.lt
Link checked 18 August 2026
What is changing soon in Lithuania?
Two dated changes matter in the next twelve months, and both are European. From 12 January 2027 every cloud provider must let customers move their data out for free — no exit fees at all. Around the same period, the technical security requirements of Lithuania's cyber law start biting for organisations registered in April 2025, roughly two years after registration. The bigger Lithuanian risk is not a new law at all: the government can change where state data must live by resolution, without going to parliament and without consulting anyone.
DATED AND COMING: - 12 January 2027: the European Data Act requires all cloud switching charges and data egress fees to be zero. Applies in Lithuania directly. - Roughly 17 April 2026 onwards, and 17 April 2027: under the Lithuanian Cybersecurity Law, an entity has 12 months from registration to meet the general cybersecurity requirements and 24 months to meet the technical requirements. The National Cyber Security Centre had to identify and register entities by 17 April 2025, so the technical requirements bite for the first cohort around 17 April 2027. This is why the law is recorded as partly in force, not fully in force. - 1 January 2026: amendments to the Law on the Management of State Information Resources (Law No. XV-565, adopted 20 November 2025, published 28 November 2025) took effect, touching 17 articles including Article 45 on where resources are held. Secondary rules under it are still settling. DORMANT SWITCHES — powers already held that can change the picture without notice: - The Government can, by resolution, set a different legal regime for the state information resources of a named institution under Articles 45(3) and 45(4) of the Law on the Management of State Information Resources. That is a per-institution carve-out or carve-in decided by cabinet. - The list of state data centres is itself a Government resolution (No. 349). Adding or removing a data centre changes who can legally host state systems, overnight. - The technical and organisational requirements for data centres in European Union, European Economic Area and NATO states are a Minister of the Economy and Innovation order (No. 4-249). A minister can tighten them by signature. - The importance grading of any state information system can be revised. Moving a system from 'medium' to 'important' moves it behind the wall with no legislative step at all. EUROPEAN ITEMS TO WATCH, none of them settled: - The European Union–United States Data Privacy Framework remains valid, but the Latombe appeal is pending before the Court of Justice and on 31 July 2026 the European Data Protection Board formally asked the Commission to examine the decision's validity. - The Digital Omnibus proposal of 19 November 2025 is not adopted and has no legal effect. It would, among other things, extend breach notification from 72 to 96 hours. - The European cloud certification scheme is still not adopted, so national schemes and national procurement rules like Lithuania's continue to govern. - Artificial Intelligence Act transparency obligations started on 2 August 2026.
Sources
- Official sourceNacionalinis kibernetinio saugumo centrasKibernetinio saugumo istatymas FAQ — 12-month and 24-month compliance windows from registration, registration deadline 17 April 2025
nksc.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos Seimas (Parliament of Lithuania), Register of Legal ActsLaw No. XV-565 amending the Law on the Management of State Information Resources No. XI-1807, Articles 4, 6, 10, 11, 12, 17, 23-29, 34, 43, 45 and 46 — adopted 20 November 2025, in force 1 January 2026
e-seimas.lrs.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — the Government resolution and ministerial order that can be changed without parliament
eimin.lrv.lt
“isskyrus atvejus, numatytus VIIVI 45 straipsnio 3 ir 4 dalyse, kai Vyriausybe nutarimu konkrecios institucijos valdomiems VII nustato kita teisini rezima”
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapter VI — zero switching charges from 12 January 2027
eur-lex.europa.eu
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
3 rules here
Layer 2
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
6 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules3 rules
Europos Parlamento ir Tarybos reglamentas (ES) 2016/679 (Bendrasis duomenu apsaugos reglamentas)
Directly binding regulation · Regulation (EU) 2016/679
The European baseline that governs almost all personal data in Lithuania. It does not require data to stay in Europe; it sets the conditions under which data may leave. Lithuania lowered the children's consent age to 14.
Enforced by European Data Protection Board
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims
What it makes you do
- Get consent
- Document a legitimate interest
- Tell people what you do
- Keep records of processing
- Let people see their data
- Let people correct their data
- Let people delete their data
- Let people take their data elsewhere
- Let people object
- Limit automated decisions
- Secure the data
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Assess high-risk projects
- Written vendor contract
- Appoint a local representativeRequired where there is no establishment in the European Union.
- Put a transfer safeguard in placePlus a documented transfer impact assessment after the Schrems II judgment.
- Do not hand data to foreign authorities on demandA third-country authority's order is not by itself a lawful basis to disclose (EDPB Guidelines 02/2024).
- Delete data after a period
- Get a parent's consent for children — applies at: 14 in Lithuania — Lithuania took the lowest age the Regulation permits, two years below the default of 16
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnover or €20,000,000, whichever is higher — about $22 millionBasic principles, individual rights, unlawful international transfers, defying a regulator order
- Percentage of global turnover: 2% of worldwide group turnover or €10,000,000, whichever is higher — about $11 millionController and processor obligations
- Order to stopThe regulator can order processing to stop or suspend flows to a third country
- Claims by individualsIndividuals can claim compensation
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2016/679 (General Data Protection Regulation), Articles 3, 8, 27, 44-49 and 83
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the Commission's own list of countries found to provide adequate protection
commission.europa.eu
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLegislation — the Lithuanian supervisory authority's own list of national data protection laws sitting on top of the Regulation
vdai.lrv.lt
Link checked 18 August 2026
Reglamentas (ES) 2018/1807 del laisvo ne asmens duomenu judejimo Europos Sajungoje pagrindu
Directly binding regulation · Regulation (EU) 2018/1807
Lithuania is forbidden from forcing non-personal data to be stored on its territory, except where public security genuinely requires it. This is the rule Lithuania's state data centre requirement has to justify itself against.
Transfer model: No restriction · Accepted routes: Nothing required
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2018/1807 on a framework for the free flow of non-personal data in the European Union, Article 4
eur-lex.europa.eu
Link checked 18 August 2026
Reglamentas (ES) 2023/2854 del suderintu saziningos prieigos prie duomenu ir ju naudojimo taisykliu (Duomenu aktas)
Directly binding regulation · Regulation (EU) 2023/2854 (Data Act)
The European Data Act has applied since 12 September 2025 and gives customers a right to switch cloud providers. Its hardest deadline is 12 January 2027, when all switching charges and data export fees must fall to zero.
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Make switching cloud provider possible — from 12 January 2027All cloud switching charges and data egress fees must be zero from 12 January 2027.
- Do not hand data to foreign authorities on demandChapter VII restricts third-country government access to non-personal data held in the European Union.
Sources
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2023/2854 (Data Act), Chapters VI and VII
eur-lex.europa.eu
Link checked 18 August 2026
National rules4 rules
Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas
Act of parliament · Law No. I-1374, as restated in 2018 (Law on Legal Protection of Personal Data)
Lithuania's own data protection law sits on top of the European rules and adds no storage-location requirement. What it does add is a lower children's consent age of 14, a flat ban on publishing a person's national identification number, a cap on fines for public bodies, and a two-year limit on imposing any fine.
Enforced by State Data Protection Inspectorate
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Government sign-off needed
What it makes you do
- Get a parent's consent for children — applies at: A child older than 14 can consent for themselves to information society services (Article 6)
- Put a transfer safeguard in placeArticle 15: written permission from the State Data Protection Inspectorate is needed only for transfers relying on Article 46(3) of the Regulation — bespoke contractual clauses or administrative arrangements. Decision within 20 working days, extendable once by 10 working days.
- Tell people what you doArticle 5: employees must be informed before video, audio or behaviour, location and movement monitoring at work.
What it costs if you get it wrong
- Fixed maximum fine: €30,000 (or 0.5% of the current year's budget, whichever is lower) for a public institution breaching Article 83(4)(a)-(c); €60,000 (or 1%) for the more serious class — about $65 thousandInfringement by a Lithuanian state or municipal institution — Article 33
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw of the Republic of Lithuania on Legal Protection of Personal Data — Articles 3, 5, 6, 7, 15, 32 and 33 (English translation published by the supervisory authority)
vdai.lrv.lt
“When information society services are directly offered to a child, the processing of the child's personal data is legal if consent is given by a child older than 14 years of age in accordance with Article 6 (1) (a) of Regulation (EU) 2016/679.”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos Seimas, Register of Legal ActsI-1374 Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas — the official register entry for the law
e-seimas.lrs.lt
Link checked 18 August 2026
- Official sourceValstybine duomenu apsaugos inspekcijaLegislation — the supervisory authority's own list of the national laws in force
vdai.lrv.lt
Link checked 18 August 2026
Lietuvos Respublikos asmens duomenu teisines apsaugos istatymas, 3 straipsnis (asmens kodas)
Act of parliament · Law on Legal Protection of Personal Data, Article 3
The Lithuanian national identification number gets its own rule. You may process it where you have a lawful basis, but you may never publish it and you may never use it for marketing. There is no consent workaround.
Enforced by State Data Protection Inspectorate
What it makes you do
- Secure the dataPublishing a Lithuanian personal identification number is prohibited outright. Using it for direct marketing is prohibited outright. Neither prohibition can be cured by consent.
What it costs if you get it wrong
- Percentage of global turnover: Enforced through the European ceilings — up to 4% of worldwide group turnover or €20,000,000 — about $22 millionUnlawful processing of the personal identification number
Sources
- Official sourceValstybine duomenu apsaugos inspekcijaLaw on Legal Protection of Personal Data, Article 3 — peculiarities of processing of the personal identification number
vdai.lrv.lt
“It is prohibited to publish the personal identification number. It is prohibited to process personal identification number for purposes of direct marketing.”
Link checked 18 August 2026
Lietuvos Respublikos kibernetinio saugumo istatymas
Act of parliament · Law on Cybersecurity, implementing Directive (EU) 2022/2555 (NIS 2)
Lithuania's cyber law has been in force since 18 October 2024 but its teeth arrive late. Registered organisations get twelve months to meet the general requirements and twenty-four months for the technical ones, so the hard deadline for the first cohort is around 17 April 2027. It imposes no storage-location rule.
Enforced by National Cyber Security Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursMajor cyber incident: report to the National Cyber Security Centre immediately and no later than 24 hours.
- Report cyber incidents — within 72 hoursDetailed assessment within 72 hours; other incidents within 72 hours; final report within one month of registration.
- Register or notifyThe National Cyber Security Centre identified and registered in-scope entities by 17 April 2025.
- Secure the data — from 17 April 2026General cybersecurity requirements apply 12 months after registration.
- Hold a security certificate — from 17 April 2027Technical cybersecurity requirements apply 24 months after registration. This is the date the law really bites.
What it costs if you get it wrong
- Percentage of global turnover: Up to €10,000,000 or 2% of worldwide annual turnover, whichever is lower — about $11 millionFailure to meet cybersecurity requirements
Sources
- Official sourceLietuvos Respublikos krasto apsaugos ministerijaKibernetinio saugumo istatymas — entry into force 18 October 2024, 12 and 24 month compliance windows, penalties
kam.lt
Link checked 18 August 2026
- Official sourceNacionalinis kibernetinio saugumo centrasKibernetinio saugumo istatymas — frequently asked questions from the national cyber authority
nksc.lt
Link checked 18 August 2026
Bendruju ir sritiniu dokumentu saugojimo terminu rodykles
Government rules · General and sector-specific document retention indexes approved by the Chief Archivist of Lithuania
Lithuania sets minimum keep-it periods through retention tables issued by the Chief Archivist, not through one line in a statute. There is a general table and nineteen industry tables, and the industry table wins where they disagree.
Enforced by Office of the Chief Archivist of Lithuania
What it makes you do
- Keep data for a minimum periodRetention floors are set by a general index plus 19 sector-specific indexes (courts, health care, customs, police, notaries and others). Where a sector index differs from the general index for the same function, the sector index governs.
Sources
- Official sourceLietuvos vyriausiojo archyvaro tarnybaDokumentu saugojimo terminu rodykles — the Chief Archivist's retention indexes
archyvai.lrv.lt
Link checked 18 August 2026
Industry rules6 rules
Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas, 45 straipsnis
Act of parliament · Law No. XI-1807 on the Management of State Information Resources, Article 45, as amended by Law No. XV-565; Government resolution No. 349 (list of state data centres); Minister of the Economy and Innovation order No. 4-249 (requirements for data centres in European Union, European Economic Area and NATO states) · Government
If a Lithuanian public body's computer system is graded critical or important, its data must be held in a state-run data centre inside Lithuania. Cabinet can carve out a named institution by resolution, but no commercial cloud region qualifies by default.
Transfer model: Not allowed · Accepted routes: Government sign-off needed
What it makes you do
- Keep the data in the countryState information resources graded critical ('ypatingos svarbos') or important ('svarbus') must be held in state data centres, unless the Government by resolution sets a different regime for a named institution under Articles 45(3) and 45(4).
- Hold a security certificateOrder No. 4-249 sets technical and organisational requirements for data centres located in European Union, European Economic Area and NATO states.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — the ministry's own statement of the hosting rule by importance grade, citing Article 45 of the law, Government resolution No. 349 and order No. 4-249
eimin.lrv.lt
“Ypatingos svarbos ir svarbius VII privaloma laikyti valstybiniuose duomenu centruose”
Link checked 18 August 2026
- Official sourceLietuvos Respublikos Seimas, Register of Legal ActsLaw No. XV-565 amending the Law on the Management of State Information Resources — amends Article 45, adopted 20 November 2025, in force 1 January 2026
e-seimas.lrs.lt
Link checked 18 August 2026
- Official sourceTeises aktu registras (Register of Legal Acts)XI-1807 Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — consolidated version effective from 1 January 2026
e-tar.lt
Link checked 18 August 2026
Lietuvos Respublikos valstybes informaciniu istekliu valdymo istatymas — vidutines ir mazos svarbos istekliai
Act of parliament · Law No. XI-1807 on the Management of State Information Resources, as explained by the responsible ministry · Government
For the less critical half of Lithuanian government systems you may use a private or foreign data centre, but you must still keep a copy in a Lithuanian state data centre. This is a mirror rule, not a ban.
Transfer model: Allowlist · Accepted routes: Certification scheme
What it makes you do
- Keep the data in the countryMedium and low importance state information resources may be held in foreign or private data centres, but copies must be kept in state data centres.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaValstybes informaciniu istekliu valdymo kryptys — hosting rule for medium and low importance state information resources
eimin.lrv.lt
“Vidutines svarbos ir mazos svarbos VII gali buti laikomi tiek valstybiniuose duomenu centruose, tiek uzsienio ar privaciuose duomenu centruose. Jeigu sie istekliai laikomi uzsienio ar privaciuose duomenu centruose, tuomet ju kopijas privaloma laikyti valstybiniuose duomenu centruose.”
Link checked 18 August 2026
Skaitmenine ambasada — Vyriausybes nutarimas ir Valstybes informaciniu istekliu valdymo istatymo pakeitimai
Directly binding regulation · Government decree of 12 July 2022, together with May 2022 amendments to the Law on the Management of State Information Resources · Government
Lithuania runs a 'digital embassy'. Copies of the most critical state data must be kept outside Lithuania on purpose, so government can keep running in a crisis. Data is graded into four criticality levels to decide what goes where.
What it makes you do
- Keep the data in the countryThe opposite of a normal localisation rule. Copies of the most critical state data must be stored OUTSIDE the territory of Lithuania so the state can keep functioning if its own territory is compromised.
Sources
- Official sourceLietuvos Respublikos ekonomikos ir inovaciju ministerijaDigital Embassy launches to improve security of state data in emergencies
eimin.lrv.lt
“some of the data will be stored in public data centres, but copies will be compulsorily stored outside the territory of Lithuania”
Link checked 18 August 2026
Elektronines sveikatos paslaugu ir bendradarbiavimo infrastrukturos informacine sistema (ESPBI IS)
Directly binding regulation · Regulations of the state e-health information system; controller the Ministry of Health, principal processor the state enterprise Centre of Registers · Health and social care
Lithuania has no separate rule saying health data must stay in the country. But nearly all health records pass through the state e-health system, which is a state information resource — so the government data centre rule is what actually governs where they sit. Records are kept for life plus three years, then archived for 75 years.
What it makes you do
- Keep data for a minimum periodPatient data is kept in the live system for the patient's lifetime plus three years, then transferred to archive for 75 years, then deleted or passed to the state archives.
- Secure the data
Sources
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija / VI Registru centrasE. sveikatos portalas — data security notice: controller, processor and retention periods for the state e-health system
esveikata.lt
Link checked 18 August 2026
- Official sourceLietuvos Respublikos sveikatos apsaugos ministerija (Ministry of Health)Elektronines sveikatos paslaugu ir bendradarbiavimo infrastrukturos informacine sistema (ESPBI IS) — the ministry's own page on the state e-health system
sam.lrv.lt
Link checked 18 August 2026
Lietuvos banko pozicijos ir gaires finansu rinkos dalyviams
Regulator guideline · Bank of Lithuania positions and guidelines catalogue; Regulation (EU) 2022/2554 (digital operational resilience) applies directly since 17 January 2025 · Finance
No rule found requiring banks, payment firms, insurers or investment firms in Lithuania to keep data in the country, checked 18 August 2026. European digital resilience rules make you disclose and control where processing happens; they do not make you keep it local.
Enforced by Bank of Lithuania
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Written vendor contractEuropean digital operational resilience rules require the contract with an information and communication technology supplier to state where data is processed and stored, with audit rights and an exit plan. That is disclosure, not localisation.
- Report cyber incidentsMajor technology incidents must be reported to the Bank of Lithuania on the European digital resilience timetable.
Sources
- Official sourceLietuvos bankasLietuvos banko pozicijos ir gaires — the central bank's own catalogue of 239 positions and guidelines for supervised firms; no cloud or storage-location instrument found
lb.lt
Link checked 18 August 2026
- Official sourceEUR-Lex, Publications Office of the European UnionRegulation (EU) 2022/2554 on digital operational resilience for the financial sector (DORA), Articles 28-30
eur-lex.europa.eu
Link checked 18 August 2026
Nuotolinio losimo irenginiams keliami reikalavimai
Government rules · Requirements for remote gambling devices, approved by the Gaming Control Authority · Online gaming
Lithuania's gambling regulator sets detailed technical rules for remote gambling systems, including keeping logs, gaming records and live-table video for at least 90 days. We found no requirement that the servers themselves sit in Lithuania.
Enforced by Gaming Control Authority
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep logs — 3 monthsAt least 90 calendar days for authenticity check results, authorised change logs and gaming records; 90 days for time-stamped video of live table games.
Sources
- Official sourceLosimu prieziuros tarnyba prie Lietuvos Respublikos finansu ministerijosRequirements for remote gambling devices — Articles 7, 12, 13 and 56
lpt.lrv.lt
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact wording of Article 45 of the Law on the Management of State Information Resources, which is the source of the state data centre requirement.
The parliament's own portal and the Register of Legal Acts serve only metadata and a table of contents to automated fetching; the article text is behind a download. We relied on the Ministry of the Economy and Innovation's own published summary, which quotes the rule and cites Article 45(3) and 45(4). Government backlink exists, but it is a ministry explainer rather than the statute text.
The contents of Government resolution No. 349 (the list of state data centres) and Minister of the Economy and Innovation order No. 4-249 (technical requirements for data centres in European Union, European Economic Area and NATO states).
Both are cited by the ministry but neither was fetched. We do not know which data centres are on the list, or whether any commercial provider qualifies.
The legal basis, host country and exact scope of Lithuania's 'digital embassy'.
The ministry's English news page confirms that copies must be stored outside Lithuania and dates the Government decree to 12 July 2022, but the Lithuanian-language announcement returned a 404 and we did not read the decree itself. We do not know which country hosts the copies.
Whether Lithuania imposes a retention obligation on telecoms traffic and location data for law enforcement, for how long, and whether it survives European court rulings.
The Law on Electronic Communications has a consolidated version dated 1 July 2026, but neither the regulator's site nor the legal act register returned article text to automated fetching, and the web search budget ran out before an alternative route could be tried. This is the most likely place for a rule in the 'disapplied' state, and it is unresolved.
Whether Lithuania has any mapping, geospatial or aerial imagery deposit or localisation requirement.
Not checked in this run. Neighbouring jurisdictions in this dataset do have such rules, so its absence here should not be read as a finding.
The commonly repeated claim that Lithuanian accounting records must be kept for ten years.
We could not open the Chief Archivist's general retention index or the Law on Financial Accounting from a government source, so we did not assert a number. Only the retention index landing page was verified.
Whether the state e-health system is graded as a critical or important state information resource.
It is plainly a state information resource controlled by the Ministry of Health, but we did not find the grading decision, so we could not confirm that the strictest state data centre rule applies to it.
Whether the Lithuanian Law on Gambling itself (as opposed to the regulator's technical requirements) contains a server or equipment location rule.
The Register of Legal Acts returned only metadata for the Law on Gambling. The regulator's own technical requirements document contains no location rule, which is suggestive but not conclusive.
Whether the Inspector of Journalist Ethics has issued data protection decisions recently, and how many.
Its site is live and publishing guidance in 2026, but we did not locate a decisions register. Its operational rating as a data protection regulator rests on its own site rather than on a decision count.
Whether the Bank of Lithuania has any cloud or outsourcing instrument affecting storage location.
We read the first page of a 239-document catalogue of positions and guidelines and found none, but we did not read all 239 entries. Treat the 'no localisation in finance' finding as a negative check, not a proof.
The precise commencement dates for the general and technical cybersecurity requirements under the Cybersecurity Law.
The rule is 12 and 24 months from registration, and registration had to be completed by 17 April 2025. We inferred the April 2026 and April 2027 dates from those two facts rather than reading a commencement provision.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 60 days. Next check due 17 October 2026.
Compare with
- Lithuania versus Argentina
- Lithuania versus Armenia
- Lithuania versus Australia
- Lithuania versus Austria
- Lithuania versus Azerbaijan
- Lithuania versus Brazil
- Lithuania versus Bulgaria
- Lithuania versus Cambodia
- Lithuania versus Canada
- Lithuania versus China
- Lithuania versus Croatia
- Lithuania versus Cyprus
- Lithuania versus Estonia
- Lithuania versus France
- Lithuania versus Georgia
- Lithuania versus Germany
- Lithuania versus Greece
- Lithuania versus Hong Kong SAR
- Lithuania versus Hungary
- Lithuania versus Iceland
- Lithuania versus India
- Lithuania versus Indonesia
- Lithuania versus Ireland
- Lithuania versus Israel
- Lithuania versus Italy
- Lithuania versus Japan
- Lithuania versus Latvia
- Lithuania versus Luxembourg
- Lithuania versus Malta
- Lithuania versus Mexico
- Lithuania versus Mongolia
- Lithuania versus Nepal
- Lithuania versus Netherlands
- Lithuania versus Poland
- Lithuania versus Russia
- Lithuania versus Saudi Arabia
- Lithuania versus Serbia
- Lithuania versus Singapore
- Lithuania versus Slovakia
- Lithuania versus Slovenia
- Lithuania versus South Korea
- Lithuania versus Spain
- Lithuania versus Sri Lanka
- Lithuania versus Sweden
- Lithuania versus Switzerland
- Lithuania versus Taiwan
- Lithuania versus Thailand
- Lithuania versus Turkey
- Lithuania versus Ukraine
- Lithuania versus United Arab Emirates
- Lithuania versus United Kingdom
- Lithuania versus United States
- Lithuania versus Uzbekistan