Understand your legal situation — with grounds.
Ask in plain language. We answer from Lithuanian statutes and case law — not from memory. No sign-up, free.
Harder examples — click
[ESMĖ] As of 2 August 2026, the threshold for AI use shifts from technical deployment to demonstrable organisational control. For a Lithuanian company, the question will not be whether it developed the AI system itself, but whether its use affects informing individuals, data protection, consumer rights or supervised systems. News fact: as of 2 August 2026, a new phase of the AI Act applies, including transparency obligations under the referenced Article 50 of the AI Act. The assessment based on the sources provided relies on Article 39 GDPR, Article 58 GDPR, Article 99 GDPR, Article 40 of the Law on Consumer Rights Protection, Article 51 of the Law on Consumer Rights Protection, and, sectorally, Article 21 of the Law on Markets in Financial Instruments and Article 12 of the Law on Cyber Security. [VERTINIMAS] If an AI chatbot, emotion analysis or content imitating a real person involves the processing of personal data, data protection governance obligations arise within the organisation under Article 39 GDPR. The data protection officer must not only advise, but also monitor compliance, staff awareness, training, audits and cooperate with the supervisory authority. - Article 39(1)(a) GDPR: the obligation to inform the controller, processor and employees of their obligations. - Article 39(1)(b) GDPR: the obligation to monitor compliance, policies, allocation of responsibilities, training and audits. - Article 39(1)(d)–(e) GDPR: the obligation to cooperate and act as a contact point for the supervisory authority. In practice, a breach of AI transparency may also become a consumer rights issue if a business does not disclose material information to the consumer about the interaction or content. In such a case, Article 51 of the Law on Consumer Rights Protection allows competent authorities to collect documents, data and information, while protecting commercial, professional and banking secrets. The authority may also carry out on-site inspections when exercising the powers under Regulation (EU) 2017/2394. Regime — Amount or deadline Article 99 GDPR — applicable from 25 May 2018 Article 40 of the Law on Consumer Rights Protection — fine from EUR 500 to EUR 5,000 Article 40 of the Law on Consumer Rights Protection — fine from EUR 250 to EUR 2,500 High-risk AI phase referred to in the news item — from 2 December 2027 The level of sanctions in the sources provided is not directly linked to the AI Act, but specific ranges are indicated for consumer protection infringements. Article 40 of the Law on Consumer Rights Protection allows a warning to be issued where the infringement does not cause material harm to the protected interests of consumers. In the financial sector, AI or algorithmic solutions must be assessed more strictly because Article 21 of the Law on Markets in Financial Instruments requires effective systems, risk controls, business continuity, testing and supervision. An investment firm engaged in algorithmic trading must notify the supervisory authority of that activity and of the trading venue. If an AI tool is used in a trading system, the compliance issue is not limited to notifying the consumer; it moves to the level of resilience, prevention of erroneous orders and prevention of market disruption. For cyber security entities, the issue of internal processes is likewise not a formality. Article 12 of the Law on Cyber Security requires managers of critical information infrastructure to have incident plans, conduct annual testing of measures and submit the results to the National Cyber Security Centre. An AI tool integrated into such infrastructure must be managed through the regime for incidents, testing and technical measures. The sharpest formulation of this situation is as follows: from 2 August 2026, unlabelled AI content becomes, for a company, not a marketing error but a compliance gap that must be substantiated with documentation. The sources provided contain no case law; therefore, no precedent rule applies to this analysis. [PASEKMĖS] In practical terms, the most important first scenario for businesses is self-monitoring before supervisory action. The company must link the description of its AI use with documents on data protection, consumer information, cyber security and sectoral risk management. - inventory AI systems and their purpose; - determine whether personal data are processed; - assign responsibilities and training procedures under Article 39 GDPR; - prepare a consumer-facing information mechanism; - retain evidence that the transparency obligation has been implemented. The second scenario is an institutional inspection, where documents, data or information are requested under Article 51 of the Law on Consumer Rights Protection. In such a case, the business may request protection of commercial, professional or banking secrets, but must clearly identify the information to be protected. The third scenario is relevant to regulated sectors: investment firms, cyber security entities and electronic identification service providers. Their AI solutions will be assessed not only by reference to transparency, but also by reference to system resilience, the functions of supervisory authorities and business continuity obligations. Procedurally, companies can next be expected to update their internal AI inventories, information notices and responsibility allocation documents by 2 August 2026, and, for high-risk AI systems, to prepare documentation before 2 December 2027. [CITATA] - from 2 August 2026, unlabelled AI content becomes, for a company, not a marketing error but a compliance gap that must be substantiated with documentation. - For a Lithuanian company, the question will not be whether it developed the AI system itself, but whether its use affects informing individuals, data protection, consumer rights or supervised systems.
[ESMĖ] The Lithuanian question is not simply “whether AI content must be labelled”, but who in Lithuania will have clear competence to supervise this obligation. It must be assessed under Regulation (EU) 2024/1689, referred to in the source concerning the implementing law, as well as under Article 4(2), Article 58(4) and (5), and Article 65(1) GDPR, and national framework documents. The news point is this: from Sunday, AI content created for professional purposes will have to be labelled, while existing systems must be aligned by 2 December. The axis of Lithuanian lawmaking is now not the label itself, but the allocation of competences: the source states that a separate draft law is being prepared on the competence of the institutions implementing Regulation (EU) 2024/1689, and on the rights and obligations of relevant entities. Question — Legal reference point visible in the source Who will supervise AI rules in Lithuania — A separate draft law on the implementation of Regulation (EU) 2024/1689 When the institutional framework must be established — Q4 2026 under item 1.1.19 of the Government plan When existing systems must be aligned — By 2 December, according to the deadline stated in the news item [VERTINIMAS] - For professional entities, the practical obligation under the regime described in the news item is not merely a technical label, but a disclosure intelligible to the user. - If chatbots are used, the user must be clearly informed that they are interacting with an AI system. - If an AI-generated image or text is disseminated for professional purposes, the content must be labelled. - Public-interest information text must be labelled where it was created by AI and not reviewed by a human. This obligation becomes particularly strict where AI content is presented as realistic text, image, audio, or video. A professional disseminator that conceals the AI origin is exposed not because of the method of creation, but because of the failure to disclose it to the user. If AI content involves the use of personal data, Article 4(2) GDPR becomes relevant: processing includes collection, recording, storage, adaptation, alteration, disclosure, and dissemination. In such a case, the creation, modification, and publication of AI content may be assessed through the chain of data-processing operations. Article 12(8) GDPR further indicates that standardised icons may be used to present information in a clear and machine-readable manner. Institutional competence in Lithuania is still being structured at national level. The source concerning draft law No XVP-925 expressly states that the Ministry of the Economy and Innovation is preparing a separate draft law on the competence of institutions implementing Regulation (EU) 2024/1689 and on the rights and obligations of relevant entities. The same source criticises declaratory regulation that does not establish specific rights and obligations of public administration entities. - In 2026, the State Digital Solutions Agency is envisaged as a centre for methodological and expert assistance to public administration entities. - In Q4 2026, item 1.1.19 of the Government plan provides for the creation of an institutional framework for implementing the AI Act. - In the same direction, an AI regulatory sandbox is envisaged for development and practical application. From a data protection perspective, action by the supervisory authority cannot be arbitrary: Article 58(4) GDPR requires safeguards, effective judicial remedy, and due process. Article 58(5) GDPR allows the supervisory authority to bring matters before the courts or participate in proceedings concerning enforcement of the Regulation. In cross-border disputes, Article 65(1) GDPR gives the European Data Protection Board the power to adopt a binding decision to ensure correct and consistent application. [PASEKMĖS] First scenario: major platforms implement labelling in advance and reduce sanctions risk through standardised labelling tools. Second scenario: professional content disseminators wait for the national competence framework, but must still align existing systems by 2 December in accordance with the deadline stated in the news item. Third scenario: the dispute shifts into the data protection sphere if the creation or dissemination of AI content involves data relating to identifiable persons. In practice, this matters for platforms, media organisations, advertising agencies, public administration entities, and AI service providers. They need to distinguish personal AI use from professional content dissemination, because the exception stated in the news item applies to personal needs. For public-interest texts, the risk is greatest where AI-prepared text is published without human review and without clear labelling. Procedurally, the nearest point to monitor is the national implementing draft law on the competence of institutions under Regulation (EU) 2024/1689. Under item 1.1.19 of the Government plan, the institutional framework and AI regulatory sandbox should be expected in Q4 2026, while the alignment deadline for existing systems under the news item is 2 December. [CITATA] - A professional disseminator that conceals the AI origin is exposed not because of the method of creation, but because of the failure to disclose it to the user. - The Lithuanian question is not simply “whether AI content must be labelled”, but who in Lithuania will have clear competence to supervise this obligation.
[ESMĖ] The legal axis of fintech and credit bureau integration is not technology, but the permissible purpose of data use and its limits. Where data are used both for loan pricing and default scenarios, the assessment rests on Article 22 of the Law on Legal Protection of Personal Data, Article 8 of the Law on Consumer Credit, and Article 15 of the Law on Credit Relating to Immovable Property. The news item falls within a single regulatory question: when a financial institution may obtain, combine and continuously use credit data. Under Article 22(1) of the Law on Legal Protection of Personal Data, this is permitted for the purposes of assessing a person’s solvency and financial risk and managing indebtedness, provided that the data subject gives consent. [VERTINIMAS] Article 8(1) of the Law on Consumer Credit establishes not a right, but an obligation to assess creditworthiness before entering into a contract. The creditor must rely on sufficient information concerning the consumer and carry out checks in registers and information systems, or substantiate the information by other evidence. - before the contract, the specific financial obligation is assessed; - before any significant increase in the total amount of credit, the information is updated; - under Article 8(5) of the Law on Consumer Credit, the consumer must provide the requested information necessary for the solvency assessment; - under Article 8(3) of the Law on Consumer Credit, personal data are processed in accordance with the procedure established by the Law on Legal Protection of Personal Data. The expansion of data use is lawful only to the extent that it remains tied to solvency, financial risk or indebtedness management. A fintech risk model becomes unlawful not because of automation, but because the purpose expands beyond the limits of Article 22(1) of the Law on Legal Protection of Personal Data. A separate logic applies at the debt administration stage. Under Article 21(1) of the Law on Legal Protection of Personal Data, debtors’ data, including the personal identification number, may be processed and disclosed to third parties having a legitimate interest for the purposes of assessing solvency and managing indebtedness. - the controller must remind the debtor in writing of the failure to perform obligations; - under Article 21(3) of the Law on Legal Protection of Personal Data, 30 calendar days must elapse; - during that period, the debt must remain unpaid or the payment deadline must not have been deferred; - the data subject must not have reasonably disputed the debt; - under Article 21(4), special categories of personal data may not be processed. Question — Applicable limit Transfer of debtor data — 30 calendar days after written reminder LTV for immovable property credit — not more than 85 percent DSTI — not more than 40 percent Stress-test DSTI at 5 percent interest — not more than 50 percent Maximum loan maturity — 30 years Joint debtor files are not an unrestricted data warehouse. Under Article 21(2) of the Law on Legal Protection of Personal Data, their processor must notify the State Data Protection Inspectorate, which is required to carry out a prior check. In the case of immovable property credit, data monitoring is expressly written into the law. Article 15(1) of the Law on Credit Relating to Immovable Property permits the provision of data not only for creditworthiness assessment, but also for monitoring the performance of obligations during the term of the agreement. The competence of the Bank of Lithuania arises from several of the sources cited. Under Article 23(1) of the Law on Consumer Credit, consumer credit providers must submit to the supervisory authority, at least once a year, information on the scale and cost of credit and overdue payments. The case law of the Supreme Administrative Court of Lithuania, published in Bulletin No. 31 of the administrative law practice of that court, emphasises the normative function of responsible lending rules. This means that creditworthiness assessment rules are not an internal convenience document, but criteria that must be followed when assessing a consumer credit recipient. [PASEKMĖS] In practical terms, for the client this means a faster decision, but a narrower tolerance for error in the event of late payment. A better history may affect the price and limit, but a late instalment may move more quickly into indebtedness management mode. For a fintech company, three procedural safeguards become paramount. They determine whether the credit bureau integration can be justified before the supervisory authority. - obtain consent where data are obtained under Article 22(1) of the Law on Legal Protection of Personal Data; - before granting credit, carry out a creditworthiness assessment under Article 8(1) of the Law on Consumer Credit; - before transferring debtor data, observe the 30-calendar-day procedure under Article 21(3) of the Law on Legal Protection of Personal Data. For credit bureaus and processors of joint files, what matters most is not the volume of data, but the lawful purpose and the prior check. Without this link, the automation of debt management may lose its legal basis even before the substance of the algorithms is assessed. The next procedurally most significant point will be the specific moment of data transfer: after the written reminder, 30 calendar days must be allowed to elapse, and only then should it be decided whether to transfer the debtor’s data to a joint file or to a third party having a legitimate interest. [CITATA] - A fintech risk model becomes unlawful not because of automation, but because the purpose expands beyond the limits of Article 22(1) of the Law on Legal Protection of Personal Data. - Joint debtor files are not an unrestricted data warehouse.
Not an “opinion from memory”, but an answer you can verify.
Official sources
Every answer is grounded in consolidated Lithuanian legal acts.
Case law
How the courts actually interpret the rule — not just the letter of the statute.
In-force version
The current consolidated version of the act, with effective dates.
Transparent
We show where each statement comes from. This is information with sources — not individual legal advice.
How it works
Ask a question
Describe your situation in plain language.
We search the sources
The system searches the statutes and case law.
Get an answer
With references to specific sources you can check.
Only the official Lithuanian legal base.
Answers are generated only from consolidated Lithuanian legal acts and case law.