Lithuania Data Removal Guide (2026)
Lithuanian residents may exercise GDPR rights to access, correct, erase, restrict, or object to processing where the legal conditions apply. Public registers, legal-entity records, source rules, and international providers can have separate scope and exceptions.
Research status: sources last checked 2026-09-07.
This page is educational orientation, not legal advice. The legal fields below are a research snapshot; eligibility, exemptions, deadlines, penalty rules and broker routes can change. Verify the current statute and regulator guidance before relying on a right or filing a complaint.
At a glance
- Governing law
- EU GDPR
- Response deadline
- GDPR rights requests: within 1 month; a 2-month extension may apply for complexity or request volume with notice
- Regulator
- State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija - VDAI)
- Private right of action
- Potential: GDPR Article 82 compensation and other judicial remedies where the claim and applicable conditions are satisfied
EU General Data Protection Regulation (GDPR) + Republic of Lithuania Law on Legal Protection of Personal Data
The GDPR applies in Lithuania alongside the Republic of Lithuania Law on Legal Protection of Personal Data. It provides rights of access, rectification, erasure, restriction, objection, and portability subject to legal bases, identification, exceptions, and scope. A controller generally must respond within one month and may extend by two months for complex or numerous requests if it gives notice within the first month; VDAI is the supervisory complaint route.
Read the full EU GDPRexplainer →Scope, penalties, private right of action, enforcement history.
What rights do Lithuania residents have?
- →Right of access (Subject Access Request, Article 15)
- →Right to erasure / right to be forgotten where Article 17 conditions apply (and subject to exceptions)
- →Right to object: direct-marketing processing must stop when you object; other objections are conditional (Article 21)
- →Right to restriction of processing (Article 18)
- →Right to lodge a complaint with the State Data Protection Inspectorate (VDAI)
Who holds your data in Lithuania?
A Lithuania request may involve official or public registers, professional directories, B2B and contact providers, credit or risk databases, or international data services. Whether a listing can be changed depends on the controller, legal basis, whether it concerns a natural person or a legal entity, public-register and source rules, and the provider's role; no category is universally removable.
Public-record sources brokers scrape
- State Enterprise Centre of Registers (Registrų centras) and other official/public registers: source-specific disclosure and correction rules
- Business directories and professional profiles: provider-specific privacy routes
- B2B/contact, credit/risk, and international data providers: controller and legal-basis routes
How to remove your data in Lithuania
- 1Identify each controller and exact listing; distinguish a natural-person record from a legal-entity or public-register entry and keep the source record separate.
- 2Send a written GDPR rights request to the current privacy contact or data protection officer, explaining the right sought and providing only proportionate identity information if needed.
- 3Request Article 17 erasure only where its conditions apply; legal-retention, public-interest, freedom-of-expression, and other exceptions may limit the result.
- 4Use the current provider or official-register/source-custodian route separately; a provider request does not necessarily amend an underlying register or public source.
- 5If the controller does not respond within the applicable period or the response is unsatisfactory, preserve the correspondence and use VDAI's current complaint route. VDAI asks people to contact the controller first, and a complaint does not guarantee removal.
Generate requests in under 60 seconds
Generate requests for 1,034 US/global broker workflows for $9
What if a company ignores your request?
Consider the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija - VDAI) information or complaint route above if the controller does not respond or the response is unsatisfactory. This guide records the following penalty orientation: Up to €20M or 4% of worldwide annual turnover, whichever is higher, for specified GDPR infringements. The private-action note is: Potential: GDPR Article 82 compensation and other judicial remedies where the claim and applicable conditions are satisfied. Neither field is an individual award or a promise of enforcement.
Open the State Data Protection Inspectorate (Valstybinė duomenų apsaugos inspekcija - VDAI) information or complaint route ↗FAQ: Lithuania data removal
Is there an affordable option for data broker removal in Lithuania?+
OfflistMe can help prepare user-reviewed request drafts for the provider routes in scope. The user chooses what to send from their own email client; OfflistMe does not decide whether a request is legally available or guarantee a controller's GDPR response.
Does the GDPR apply to data brokers operating outside of Lithuania?+
Potentially. Article 3(2) can apply to a provider outside the EU when processing is connected to offering goods or services to people in the EU or monitoring their behaviour. The controller, activity, evidence, and Article 3(2) conditions must be assessed rather than assumed from geography alone.