Articles on data protection from DAT.lt. Our older articles are available in Lithuanian on the Lithuanian blog page.
Health data at work: what an employer may know
An employer may process an employee's health data only where an exception in Article 9(2) GDPR applies. In employment this is most often a duty or right under employment or workplace safety law (Article 9(2)(b) GDPR). Health is assessed not by the employer but by a health care institution, whose con
Read more: Health data at work: what an employer may knowCookies and consent banners: what the ERĮ and the GDPR require
Storing information on a visitor's device, or reading it from there, is allowed only with their consent, after they have been given clear and comprehensive information, including about the purposes (Article 73(4) ERĮ, the Lithuanian Law on Electronic Communications). The law has only two exceptions:
Read more: Cookies and consent banners: what the ERĮ and the GDPR requireErasure requests: when you must erase and when you may refuse
You must erase personal data when a person asks and at least one of the grounds in Article 17(1) GDPR applies, most commonly: the data is no longer needed for its purpose, the person has withdrawn consent and there is no other basis, the person objects and your grounds do not override, or the proces
Read more: Erasure requests: when you must erase and when you may refuseWhistleblowing channels and personal data: what the law requires
An internal channel for reporting breaches is personal data processing from the first report: it holds data on the reporter, on the person reported on and on witnesses. The Law on the Protection of Whistleblowers (PAĮ) requires confidentiality for both the reporter and the persons concerned (Article
Read more: Whistleblowing channels and personal data: what the law requiresAI tools and personal data at work: what the law allows and the risks
When an employee puts a client's or a colleague's data into an artificial intelligence (AI) tool, the organisation is responsible. It is the controller, because it determines the purposes and means of the processing (Article 4(7) GDPR). So an AI tool needs the same as any other processing: a clear p
Read more: AI tools and personal data at work: what the law allows and the risksWhen an employee leaves: mailbox, files, accounts and their data
When an employee leaves, the work mailbox, files and accounts stay with the employer, but the data in them does not become free to use. The employer may keep what it needs to continue the work and to meet legal obligations. At the same time it must revoke the former employee's access, must not read
Read more: When an employee leaves: mailbox, files, accounts and their dataBiometric data at work: fingerprints and face recognition
A fingerprint or face scanner that recognises an employee at a door, a time clock or a computer processes biometric data (Article 4(14) GDPR). When the purpose is to uniquely identify a person, this is special category data, which may not be processed unless one of the exceptions in Article 9(2) GDP
Read more: Biometric data at work: fingerprints and face recognitionJoint controllers: what the arrangement must cover and who is liable
When two organisations jointly determine the purposes and means of processing, they are joint controllers and must set out, in an arrangement between them, who is responsible for which GDPR obligation (Article 26(1) GDPR). People must be able to see the essence of that arrangement (Article 26(2) GDP
Read more: Joint controllers: what the arrangement must cover and who is liablePersonal code and ID copies: what you may ask a customer for
A customer's personal code (asmens kodas, the Lithuanian national identification number) may be processed only where one of the legal bases in Article 6 GDPR applies (Article 3(1) ADTAĮ, the Lithuanian Law on Legal Protection of Personal Data). The personal code may not be made public (Article 3(2)
Read more: Personal code and ID copies: what you may ask a customer forRequests for CCTV footage: who must get what
Requests for CCTV footage usually come from three different kinds of people, and a different rule applies to each. The person filmed has the right to a copy of their own data (Article 15(3) GDPR) within one month at the latest (Article 12(3) GDPR), but the data of other people in the frame must be p
Read more: Requests for CCTV footage: who must get whatConsent under the GDPR: when you need it and when it is invalid
You need consent when the data is not needed to perform a contract or to meet a legal obligation, and no other basis fits, or when the law requires consent directly, for example for advertising by email to individuals (Article 81(1) ERĮ). Your own customers whose email address you obtained when sell
Read more: Consent under the GDPR: when you need it and when it is invalidSubject access requests: the deadline and the answer
A request for access to personal data must be answered without undue delay, and within one month of receipt at the latest (Article 12(3) GDPR). The answer has three parts: confirmation of whether the person's data is processed, a copy of it, and information about the processing (Article 15(1) and Ar
Read more: Subject access requests: the deadline and the answerA client’s GDPR questionnaire to a supplier: what you must answer
If you process personal data for a client, you must make available to it all information necessary to demonstrate that you meet your obligations under Article 28 GDPR and allow for audits and inspections – this is a mandatory term of the data processing agreement (Article 28(3)(h) GDPR). So you must
Read more: A client’s GDPR questionnaire to a supplier: what you must answerData processing agreement: when required and the risk without one
Whenever a service provider processes personal data on your behalf, that processing must be governed by a data processing agreement, unless another legal act under Union or Member State law already governs it (Article 28(3) GDPR). It must be in writing, but electronic form is enough (Article 28(9) G
Read more: Data processing agreement: when required and the risk without oneSharing data with a partner: controller, processor or joint controller
Before you pass personal data to another company, you need to establish what that company will be in relation to the data. If it processes the data on your behalf and on your instructions, it is a processor. If it uses the data for its own purposes, it is a separate controller. If you decide the pur
Read more: Sharing data with a partner: controller, processor or joint controllerEmployee monitoring: cameras, GPS, call recording and e-mail
An employer may monitor employees, but not without limits. Monitoring needs a specific purpose, a legal basis and must be proportionate. Employees must be informed in advance, against signature or in another way that proves they were informed, with all the information listed in Article 13(1) and (2)
Read more: Employee monitoring: cameras, GPS, call recording and e-mailInforming employees about data processing: what to say and when
An employer must tell an employee who processes their data, for what purposes and on what legal bases, to whom it is passed, how long it is kept and what rights the employee has. This is done when the data is obtained (Article 13(1) GDPR), usually already at hiring. The information must be concise,
Read more: Informing employees about data processing: what to say and whenEmployee photos on the website and social media
In practice, an employee's photo can safely be published on the company website, on social media or in advertising only with the employee's consent. This follows not only from the GDPR. The Civil Code separately provides that a person's photo may be displayed and printed only with their consent (Art
Read more: Employee photos on the website and social mediaGDPR security measures: what Article 32 actually requires
The GDPR sets no mandatory list of security measures. It requires the controller and the processor to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk (Article 32(1) GDPR). What is appropriate depends on the risk: what data, how much o
Read more: GDPR security measures: what Article 32 actually requiresA letter or inquiry from VDAI: what it means and what to do
A letter from the State Data Protection Inspectorate (VDAI) may be an inquiry, a reminder, a notice of an investigation or a decision. An inquiry is not a decision that you have committed an infringement. But if the letter asks for information or documents, you must answer: persons must comply with
Read more: A letter or inquiry from VDAI: what it means and what to doDirect marketing by email and SMS: when consent is needed
You may send advertising by email or SMS to a natural person only with their prior consent. There is one exception for your own customers. If you obtained an email address when selling goods or a service to a customer who is a natural person, you may offer them your own similar goods or services, pr
Read more: Direct marketing by email and SMS: when consent is neededLegitimate interest: when it is enough and when it is not
Legitimate interest is enough when three conditions are met: you have a specific, legitimate interest, the processing is genuinely necessary for it, and the person's interests and rights do not override it (Article 6(1)(f) GDPR). The EDPB advises making the assessment before processing starts and wr
Read more: Legitimate interest: when it is enough and when it is notPrivacy policy: is it mandatory and when must it be updated?
The law does not require a document called a "privacy policy". It requires something else: you must inform people when you collect their data. Article 13(1) GDPR says the information is given at the time the data are obtained, and Article 12(1) GDPR says it must be concise, transparent, intelligible
Read more: Privacy policy: is it mandatory and when must it be updated?Candidate CVs and ID copies: what an employer may keep
The CVs of unsuccessful candidates must be deleted once the selection is over and the new employee has been chosen. You may keep them longer for future vacancies only if the candidate has consented, and only for the period stated in the consent. For a short, justified period you may keep only what i
Read more: Candidate CVs and ID copies: what an employer may keepGDPR scope: companies, public bodies, associations, foreign firms
The GDPR applies to everyone who processes personal data: a company, a sole trader, an association, a community body, a public institution and a state authority. The size of the company, its turnover and the number of employees do not decide whether it applies. Our answer to this question is always
Read more: GDPR scope: companies, public bodies, associations, foreign firmsPersonal data breach: when to notify VDAI and the people affected
Every personal data breach must be recorded in your breach log. The State Data Protection Inspectorate (VDAI) is notified without undue delay and, where feasible, not later than 72 hours after you become aware of the breach, unless the breach is unlikely to result in a risk to people's rights and fr
Read more: Personal data breach: when to notify VDAI and the people affectedTransferring personal data outside the EEA: when SCCs are needed
Personal data, including employee data, can be transferred outside the European Economic Area (EEA). But only under the conditions of Chapter V of the GDPR (Article 44 GDPR). The order is always the same. First, check whether the European Commission has adopted an adequacy decision for the recipient
Read more: Transferring personal data outside the EEA: when SCCs are neededData protection coordinator vs data protection officer
A data protection coordinator is an internal role in your organisation, not a GDPR concept. The word does not appear in the Regulation, and the Regulation gives a coordinator no tasks. A coordinator does what you assign: keeps the records, receives people's requests, maintains the breach log, remind
Read more: Data protection coordinator vs data protection officerPersonal data published without consent: what to do and what to demand
If another person or an organisation has publicly posted your name, photo or other data, for example in an open social-media group, you have several routes. You can demand that the data be erased, report the post to the platform, lodge a complaint with the State Data Protection Inspectorate (VDAI) a
Read more: Personal data published without consent: what to do and what to demandChildren’s photos on the school website and Facebook: when both parents must consent and how to withdraw consent
When a school may publish children's photos, what happens if one parent objects, and how to withdraw consent and have published photos removed.
Read more: Children’s photos on the school website and Facebook: when both parents must consent and how to withdraw consentI have filed a complaint with the State Data Protection Inspectorate — how long until I get an answer?
How long the State Data Protection Inspectorate has to deal with a complaint, when it refuses to examine one, and what a complaint cannot resolve.
Read more: I have filed a complaint with the State Data Protection Inspectorate — how long until I get an answer?Data protection impact assessment: what it consists of, how long it takes and how much work it needs from you
A DPIA usually takes up to three weeks, and most of the work is a questionnaire that one or several employees can fill in.
Read more: Data protection impact assessment: what it consists of, how long it takes and how much work it needs from youWhere the video surveillance sign must go: the building entrance is not enough
One sign at the main entrance is not enough: people must see the notice before entering each monitored room, and employees must sign.
Read more: Where the video surveillance sign must go: the building entrance is not enoughWhat fines a state or municipal institution really faces for a GDPR breach
The "up to EUR 20 million" headline does not apply to Lithuanian state and municipal institutions: the law sets much lower limits.
Read more: What fines a state or municipal institution really faces for a GDPR breachHow long to keep personal data when the law sets no retention period
For most data the law sets no retention period: the organisation sets it itself under Article 5 GDPR and must be able to explain why.
Read more: How long to keep personal data when the law sets no retention periodWhat an external data protection officer service costs and what the price includes
The DPO service is paid as a fixed monthly fee set by the flow of questions, not headcount; the initial audit is paid separately.
Read more: What an external data protection officer service costs and what the price includesCameras in apartment buildings and yards: who may view the recordings and who may not
Recordings may be viewed only by whoever is responsible for them, and only as far as a specific purpose requires.
Read more: Cameras in apartment buildings and yards: who may view the recordings and who may notWhat a GDPR document package contains and why we prepare it only after an audit
GDPR compliance documents come in external and internal sets, and we prepare them only after an audit shows which obligations actually apply.
Read more: What a GDPR document package contains and why we prepare it only after an auditWhy an employee’s consent to data processing is almost never valid
An employee depends on the employer, so consent is rarely free under the GDPR; legal obligation, contract or legitimate interest usually fit instead.
Read more: Why an employee’s consent to data processing is almost never validDoes our organisation need a data protection officer — and what happens when we appoint one of our own
Most private companies are not required to appoint a DPO under Article 37(1) GDPR, and appointing an unprepared employee often gives no protection.
Read more: Does our organisation need a data protection officer — and what happens when we appoint one of our own