The authority must tell you about the progress or the outcome of your complaint no later than 3 months after receiving it — this is set by Article 30(1) of the Law on the Legal Protection of Personal Data (ADTAĮ). The complaint itself must be examined and answered within 4 months (Article 30(2) ADTAĮ). If the matter is complex, this time limit is extended, but by no more than 2 months, and the overall time limit may not exceed 6 months. You must be told about the extension.
Those are all the time limits that apply. The right to lodge a complaint with a supervisory authority comes from Article 77 GDPR, and the procedure for examining complaints in Lithuania is set by the Law on the Legal Protection of Personal Data.
What happens in the first few days
Before a complaint is examined on the merits, there is one more stage that hardly anyone mentions.
Article 27(1) ADTAĮ sets out the grounds on which the authority refuses to examine a complaint, and you must be told about such a refusal within 5 working days at the latest. The law lists more grounds than these; the most common are:
- the complaint does not meet the content requirements, or the required documents have not been submitted;
- investigating the circumstances does not fall within the authority’s competence;
- the same matter has already been examined by the authority;
- the same matter has been examined, or is being examined, by a court;
- the same matter is being examined by the supervisory authority of another Member State.
The practical takeaway: if you have heard nothing within a week, your complaint has most likely been accepted for examination. If you received a letter within a few days, it is almost always one of the grounds set out in Article 27 ADTAĮ, not a decision on the merits. Most often it means that a document is missing or that the matter is not one for this authority — and both can be put right.
Why two similar complaints are handled differently
People ask this often, and it deserves an honest answer.
Article 23 ADTAĮ allows the authority to choose how it examines complaints. In making that choice it takes into account, among other things, its annual priorities, possible systemic infringements, the number of data subjects affected and the scale of the consequences of the infringement.
This means that one person’s complaint about a single photo and a data leak that affected hundreds of people are not handled in the same way, even though both are legitimate complaints. The law does not hide this or call it an exception — it is a choice of examination method that the law provides for.
So the answer to the question “why did my neighbour get a reply within a month, while mine is now in its third” is not “something has gone wrong” but, most often, a difference in scope.
The decision is published
Both sides should know about this part.
Article 14¹(1) ADTAĮ provides that the authority’s decisions are published on its website within 5 working days. Under Article 14¹(2) ADTAĮ, they stay published for 10 years.
There is an important exception: where no infringement is found, the controller’s identity is not disclosed. This means that, for the organisation the complaint was made against, publicity only arises once an infringement is confirmed.
For many public bodies and companies, a decision that stays publicly available for ten years is a more serious consequence than the order to fix something itself.
Why we ourselves often suggest going to the authority
When someone writes to us about their own personal situation — a neighbour’s camera, a former employer, a shop that will not delete their data — our most common answer is to refer them to the State Data Protection Inspectorate (VDAI).
We answer this way not because we do not want the work. In many cases it is both the fastest route and a free one. A complaint to the authority costs nothing, it does not need to be prepared with a lawyer, and the authority has powers that a private individual does not have: it can require explanations from the controller and give it a binding order.
Bringing in a lawyer at this stage usually adds cost but not results. It becomes worthwhile later — when there is a decision that needs to be appealed, or when a claim for damages is brought at the same time.
What a complaint will not do
A second common situation goes like this. Someone contacts us because a company is demanding a debt from them, and they want to complain about it as a data protection infringement.
A dispute about the debt itself is not a data protection matter. It is a civil dispute, and the supervisory authority will not resolve it — it has no power to decide whether the debt exists or whether its amount is correct. Such a complaint will fall under the competence ground in Article 27(1) ADTAĮ.
The data protection question here can only be a narrower one: whether a particular recipient had a lawful basis to receive your data, whether you were properly informed, and whether the data are accurate. Whether the debt exists is decided elsewhere.
The same distinction applies to employment disputes, disputes between neighbours over plot boundaries and disputes with a service provider over a bill. Data protection is only the part of the dispute that concerns the processing of data.
How to start
If you are not sure whether your situation is a data protection matter at all, write us one paragraph about what happened. We will reply free of charge and tell you where to turn — often that will be the authority directly, and if so, that is exactly what we will tell you.
You can check whether your organisation needs a record of processing activities with the Privacio tool, built by Linden (in Lithuanian).
Email: info@linden.lt
More about this service: GDPR audit, compliance documents and advice.