Skip to content
これは参考訳です。英語版が正式かつ法的拘束力を持つ公式バージョンです。 英語版を表示
EUMEDIUM coverage

Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy: AI Compliance Requirements

Lithuania's Valstybinė duomenų apsaugos inspekcija (VDAI) supervises GDPR compliance. Lithuania adopted its AI Strategy in 2019 and has invested heavily in a tech startup ecosystem (Vilnius is the fastest-growing startup hub in the Baltics). Lithuania's National Cybersecurity Centre (NKSC) has published AI security guidelines. Key sectors: fintech (Revolut EU HQ in Vilnius), legal tech, logistics AI.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

May 25, 2018

Enforcement Begins

August 2, 2026

Maximum Penalty

€20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover

What Your Business Must Do

3 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

GDPR AI Compliance — VDAI Supervision

Critical

VDAI actively monitors AI data processing. Lithuania hosts major fintech operations (Revolut, Western Union EU processing). AI systems in financial services, credit scoring, and fraud detection processing Lithuanian resident data require DPIA, lawful basis documentation, and automated decision-making rights implementation (GDPR Art. 22).

GDPR Art. 22 (automated decisions); Art. 35 (DPIA)

EU AI Act — Fintech AI High-Risk Obligations

High Priority

Lithuanian-regulated fintechs using AI for credit decisions, transaction fraud detection, AML/KYC screening, or customer risk scoring face EU AI Act Annex III high-risk classification. Conformity assessment, technical documentation, and human oversight required. Lithuanian Bank (Lietuvos bankas) has issued supplementary AI governance guidance for supervised entities. NOTE: the "Digital Omnibus" amendment (Regulation (EU) 2026/1744, in force 2026-07-27) deferred stand-alone high-risk (Annex III) conformity obligations from 2026-08-02 to 2027-12-02.

Deadline: December 2, 2027

EU AI Act Art. 6, Annex III (high-risk classification); Art. 16 (provider obligations); Art. 43 (conformity assessment); Art. 26 (deployer obligations)

NKSC AI Cybersecurity Guidelines

Medium Priority

Lithuania's National Cybersecurity Centre (NKSC) has published AI security guidelines covering adversarial attacks, model poisoning, and AI supply chain risks. Relevant to any AI system classified as critical infrastructure or handling sensitive personal data. Implement AI-specific security controls: input validation, output monitoring, model versioning, and incident response plans.

NKSC (National Cybersecurity Centre) AI security guidelines

Who Does This Apply To?

Applies to: any organisation established in Lithuania, and any organisation outside Lithuania processing the personal data of Lithuanian residents through AI systems — GDPR applies with extraterritorial reach (Art. 3), obligations attaching to the processing activity rather than company size, with no general small-business exemption. Because Lithuania hosts major fintech operations, AI in credit scoring, transaction fraud detection and AML/KYC is a priority. As an EU member state, Lithuania is fully subject to the EU AI Act: such fintech AI faces Annex III high-risk classification requiring conformity assessment, technical documentation and human oversight. The Valstybinė duomenų apsaugos inspekcija (VDAI) treats AI-driven account restrictions as Article 22 automated decisions with significant effects — requiring a real-time human-escalation path, customer notification, and review of AI-triggered restrictions. The National Cybersecurity Centre (NKSC) AI security guidelines (adversarial attacks, model poisoning, AI supply-chain risk) apply to critical or sensitive-data AI. Penalties reach €20M / 4% of global turnover under GDPR and €35M / 7% under the EU AI Act.

Recent Regulatory Guidance

guidance2024-04

VDAI AI and Fintech — Lithuanian Bank AI Governance Guidance (2024)

VDAI and Lietuvos bankas issued joint guidance for Lithuanian fintech AI: (1) AI-driven account restrictions require real-time human escalation path; (2) AML/KYC AI decisions must include customer notification and review mechanism; (3) NKSC AI security guidelines apply to AI systems handling financial data; (4) Cross-border AI data transfers for model training require SCCs + TIA.

Frequently Asked Questions

Does Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy apply to my business?

Lithuania's Valstybinė duomenų apsaugos inspekcija (VDAI) supervises GDPR compliance. Lithuania adopted its AI Strategy in 2019 and has invested heavily in a tech startup ecosystem (Vilnius is the fastest-growing startup hub in the Baltics).… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy is: €20,000,000 or 4% of global turnover (GDPR); EU AI Act: €35M or 7% global turnover. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Lithuania — GDPR + EU AI Act + Lithuanian AI Strategy?

The 3 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://vdai.lrv.lt/en

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan