Under Article 30 of the LFPRC, the prohibition on working with children applies irrespective of whether the conviction has become spent or has been expunged.
The host organisation must check the validity of the lawful work with children code periodically, but at least once per calendar year.
Persons working with children in church communities are being checked in this inspection for compliance with the statutory preventive measure: possession of a valid lawful work with children code (QR code). The inspection is based on Article 30 of the Law on the Fundamentals of Protection of the Rights of the Child (LFPRC), under which persons convicted of sexual offences or other intentional serious and very serious crimes are prohibited from working or engaging in activities involving children, irrespective of whether the conviction has become spent. The precise legal question being assessed by the State Child Rights Protection and Adoption Service (the Service) is whether persons working with children in churches have a generated, valid QR code, and whether the host organisations checked it in accordance with Article 30(1) of the LFPRC and the inspection procedure approved by the order “On the Approval of the Description of the Procedure for Inspection of the Implementation of the Provisions of Article 30 of the LFPRC and Prevention of Violations.”
Under Article 30 of the LFPRC, the prohibition applies to persons found guilty by a final conviction of criminal offences against a person’s freedom of sexual self-determination and inviolability, exploitation of a child for pornography, possession of pornographic material depicting a child, and other offences, even where the conviction has become spent or has been expunged. Under Article 30(1) of the LFPRC, as amended by the 2024 amending law, the host organisation or legal entity engaging a person to provide services must check the validity of the code periodically, but at least once per calendar year; if the person’s code has not been generated, the employer applies for its issuance, or the person does so personally if engaged in individual activity. The Service’s competence to carry out such an inspection follows from Article 50 of the LFPRC, which entrusts it with defending and ensuring children’s rights within municipal territories. Separately, it should be assessed that the inspection is taking place in parallel with two criminal cases: that of T. Švedavičius, involving 34 counts related to the sexual abuse of children, possession of pornographic material, and involving children in alcohol consumption, and that of R. Peciunas, concerning possession of pornographic material. Both cases have already been referred to court, and R. Peciunas’s case is being heard on the merits before the Vilnius Regional Court. Until a conviction becomes final, the prohibition under Article 30 cannot yet be applied to these priests as a sanction; the assumptions of innocence applicable in criminal proceedings remain in force in respect of them, and the inspection concerns only the factual issue of possession of the code. The absence of identified violations in relation to some QR codes, as stated by the Service’s Director I. Skuodienė in early September, means that no legal obstacle is created to those persons continuing their activities.
If, upon summarising the inspection in October, it is established that any person prohibited under Article 30(1) of the LFPRC is working with children without a code or with an invalid code, the host organisation must terminate that person’s activities involving children, and the violation may give rise to liability under the Code of Administrative Offences, as provided in Article 29(4) of the LFPRC in respect of violations of children’s rights not connected with a criminal offence. If, during the inspection, the Service receives substantiated information about a criminal offence being committed or possibly having been committed against a child, it must, under Article 35(1) of the LFPRC, immediately inform the police and take action under Article 36(5) of the LFPRC. For church communities, the most important practical point is to prove that they have checked the codes periodically, because the organisation’s duty to check validity at least once per year is an independent legal requirement.
The regulation concerning the lawful work with children code (QR code) was initiated by legislators with a view to protecting children from sexual violence and ensuring that persons who have direct and regular contact with children have no convictions for serious, very serious, or sexual offences. However, the drafting of the amendments was also prompted by numerous complaints about this procedure: critics described it as excessive and disproportionate, because the prohibition also applies to persons whose convictions have become spent, who committed offences not against children, who were released from liability or reconciled with the victim, and because no account is taken of the nature of the offence. Disagreements arose between the initiators and critics as to the scope of the measure: some proposed narrowing the list of offences that bar a person from working with children, while others proposed expanding it. At the same time, technical issues were being addressed, such as which law should set the deadline for employers to carry out the initial check.
The procedural position of priests accused of sexual offences against minors is determined under Chapter XXI of the Criminal Code currently in force. For pending cases, the decisive issue is which version of the law applies to each individual episode. The internal investigation initiated by the Bishops’ Conference does not alter legal liability: criminal prosecution remains the monopoly of the State, namely the prosecution service and the courts, while the Church’s investigation may only supplement it with information. The relevant legal question is what penalties and ancillary consequences the accused may face for the sexual abuse of children, and by what legal standard the court will assess episodes committed before 1 May 2003.
Prosecutors and the court will have to distinguish between the relevant periods:
Where the accused is found guilty of offences against a person’s freedom of sexual self-determination under Articles 149, 150 and 151¹ of the Criminal Code, or of exploiting children for pornography, the court may impose not only principal penalties but also additional measures under Article 72 of the Criminal Code: compulsory, uncompensated confiscation of property obtained through or used in the commission of the offence. In case law, including the Supreme Court ruling of 6 November 2007 in case No. 2K-514/2007, this is treated as mandatory where the law so provides.
Under Article 16 of the Law on the Legal Protection of Personal Data, video surveillance is permitted only where other means are insufficient or inappropriate and the interests of the data subject do not override it.
If the established requirements are breached, an administrative offence report may be drawn up under Article 83 of the Code of Administrative Offences, with fines for individuals ranging from EUR 150 to EUR 580, and, in the event of a repeated breach, from EUR 550 to EUR 1,200.
A neighbour dispute over video cameras ended with the owner who filmed the neighbour’s property losing the case and now being required to pay EUR 420 in litigation costs, while the SDPI’s instructions to adjust the camera and destroy the recordings remain in force. In case No. eA-413-789/2026 (ruling of 1 July 2026), the Supreme Administrative Court of Lithuania confirmed that ownership of a land plot does not in itself confer the right to monitor other persons: the lawfulness of video surveillance is determined not by land ownership, but by the requirements governing the legal protection of personal data.
This means that the owner must prove that filming is necessary and proportionate. Article 18(1) requires a written document specifying the purpose and scope of surveillance, the retention period, access conditions, and the procedure for erasure of data. Upon receiving the data subject’s complaint, the SDPI, pursuant to Article 31 of the Law on the Legal Protection of Personal Data, found the complaint well-founded and imposed measures: it ordered the camera to be adjusted, the servitude area to be masked, and the recordings to be destroyed. By its judgment of 19 November 2024, the Regional Administrative Court, and subsequently the SAC in appellate proceedings, held that the applicant’s lawful interests, as the camera owner, did not in this case override the interests or fundamental rights of the data subject. In case eA-413-789/2026, the panel of judges stated that the third interested party, S. Č., must initiate separate proceedings if seeking compensation for non-pecuniary damage. Litigation costs of EUR 420 for preparation of the response were awarded under Article 144(1)(1) of the Law on Administrative Proceedings.
The practical consequences for the camera owner are as follows:
The neighbour, as the data subject, may bring a separate claim for compensation for non-pecuniary damage.
Article 13(2)(4) of the Law on the Management of Radioactive Waste of the Republic of Lithuania reflects the same principle from the Lithuanian perspective: when selecting a site, neighbouring states must be informed if there is a likelihood that the facility will have an adverse impact on them, and general data must be provided at their request.
Article 15 of the Law on Environmental Protection of the Republic of Lithuania prohibits the adoption of decisions that would predetermine or limit the choice of alternatives before an environmental impact assessment has been carried out.
The report on the potentially planned Belarusian radioactive waste disposal and storage facility (RWDF) in the Astravyets District is currently being assessed under Belarusian procedures; however, if the facility is located near the Lithuanian border, Lithuania has a legal instrument, namely the transboundary impact assessment mechanism under the Espoo Convention, to require that the impact on its territory be assessed and taken into account before a decision is adopted. The precise legal issue is whether the environmental impact assessment (EIA) report being prepared by Belarus complies with the requirements for transboundary assessment, particularly as regards the analysis of alternatives and the description of impacts on a neighbouring state, and what comments Lithuania may lawfully submit. This issue will be determined under the Espoo Convention, to which Lithuania is a ratifying party ([12]), and under Article 129 of the Law on Environmental Protection of the Republic of Lithuania, which obliges Lithuania to cooperate with other states on environmental protection matters and to pursue regional ecological security.
The Espoo Convention requires a state planning an activity likely to have a significant transboundary impact to notify a potentially affected party and allow it to participate in the assessment procedure. I. Suchij notes that Belarus has not withdrawn from this Convention; therefore, Lithuania, as a party potentially affected by the activity, has the right not only to submit comments but also to influence the decisions adopted. Lithuania’s Ministries of Energy and Environment have already prepared their comments on the Belarusian project, which is consistent with the obligations of a party to the Convention. Lithuania’s practice in relation to the Astravyets Nuclear Power Plant demonstrates that this route is effective: in 2017, by Resolution No. 413 ([15]), the Government declared the Astravyets NPP unsafe and submitted its assessment to the Seimas, and Lithuania succeeded in having the Astravyets NPP issue included on the EU-Belarus agenda ([13]). The 14 non-compliances with Belarusian legislation identified by experts, including a merely formal analysis of alternatives and an undescribed impact of radionuclides, are precisely the arguments on which Lithuania may rely when requesting an additional assessment. Article 3(1) of the same law provides that, in managing waste, environmental protection must be ensured both within the territory of Lithuania and beyond it; this constitutes the normative basis for comments defending Lithuania’s interests.
In practical terms, the key point for Lithuania is that the decision on the site has not yet been adopted, which means that comments may have a real influence on the choice of location. If Belarus selects the Astravyets District, Lithuania may demand a full transboundary assessment under the Espoo Convention and, as with the Astravyets NPP, raise the issue in international fora, including meetings of the parties to the Nuclear Safety, Espoo and Aarhus Conventions, the EU and the IAEA ([11], [13]). If Belarus refuses to properly assess the transboundary impact, Lithuania may rely on Article 129 of the Law on Environmental Protection in pursuing regional ecological security and international support. The experts’ demand that the documents be withdrawn and that the impact be assessed across all stages of the waste life cycle, comparing the project with alternatives, is a viable course of action, since Article 15 of the Law on Environmental Protection prohibits the prior limitation of the choice of alternatives before an assessment is carried out.
Under paragraphs 1 and 4, liability arises only upon a complaint by the victim or at the request of a prosecutor, while under paragraphs 2 and 3 (cases involving high and very high value), imprisonment may reach six and eight years, respectively.
Where the value does not exceed three basic amounts of penalties and fines, Article 108 of the Code of Administrative Offences applies to the conduct, carrying a fine of EUR 90 to EUR 400.
In cases of social engineering, companies that lose data or money through deception fall not within the sphere of data security but within criminal law: the conduct should be assessed under Article 182 of the Criminal Code (fraud) and Article 198 of the Criminal Code (unlawful interception and use of electronic data). The precise legal question is which provision applies to conduct where fraudsters, posing as representatives of institutions or business partners, deceptively obtain confidential data or a proprietary right, and what threshold of liability applies where the loss is minor. The answer depends on two factors: the value of the property obtained and the nature of the data.
If the value of property obtained by deception does not exceed three basic amounts of penalties and fines, the conduct is governed not by the Criminal Code but by Article 108 of the Code of Administrative Offences, carrying a fine of EUR 90 to EUR 400. Where the value is higher, Article 182 of the Criminal Code applies: under paragraphs 1 and 4, liability arises only upon a complaint by the victim or at the request of a prosecutor, while under paragraphs 2 and 3 the custodial sentence may reach six and eight years, respectively; Article 182(6) of the Criminal Code also permits liability of a legal person. If the fraudsters not only deceive but also unlawfully intercept non-public electronic data, Article 198 of the Criminal Code applies, carrying up to four years’ imprisonment, or up to six years where the data are of major significance to state governance, the economy, or the financial system. Access to an information system in breach of security measures is classified under Article 198-1 of the Criminal Code, while unlawful possession of passwords or codes intended for access to a system is classified under Article 198-2 of the Criminal Code, carrying up to four years’ imprisonment. Leaked data subsequently handled or disposed of may also constitute an offence under Article 189 of the Criminal Code, namely acquisition of property obtained by criminal means. In investigating an incident, Article 98 of the Code of Criminal Procedure gives the company the right, on its own initiative, to submit logs, emails, and documents to investigators as evidence, while Article 93 of the Code of Criminal Procedure provides that such items are retained until the judgment becomes final.
For the affected company, three practical points are important:
Follow-up point: once a company identifies a leak, the practical step is to file a report of a criminal offence for the purposes of a pre-trial investigation.
Regulation was initiated by the Ministry of Justice (Department of Administrative and Criminal Justice) in order to transpose into national law the provisions of EU Directive 2013/40/EU on attacks against information systems. The objective was to clarify the constituent elements of offences against the security of electronic data and information systems, and to increase liability where substantial damage is caused, offences are committed against multiple systems, or another person’s personal data are used. The principal rationale was the need to fully align the Criminal Code with the requirements of the Directive.
Under Article 9 of Regulation (EU) 2024/1689, providers of high-risk AI systems must establish a risk-management system covering the entire lifecycle of the system, irrespective of international consensus.
In its judgment of 9 July 2026 in case No I1-3333-484/2026, the Regional Administrative Court examined a claim for EUR 100 in compensation for non-pecuniary damage for each day connected with access to an AI program.
The disagreement between the United States and China at the UN meeting over the level at which AI rules should be adopted means that a unified international AI regulatory framework is unlikely to emerge in the near term, and that companies and states will operate within different legal frameworks. In this situation, the most practically important legal question is this: which rules will govern the assessment of AI system use in states that are not dependent on international consensus, and whether EU and Lithuanian domestic law already creates a binding regulatory basis irrespective of the outcome of the dispute at UN level. The principal rules under which this issue will be resolved are Article 1 of Regulation (EU) 2024/1689 (the Artificial Intelligence Act), which lays down harmonised rules for the placing on the market and use of AI systems in the Union, Article 6, which defines high-risk AI systems, and the AI use rules approved by Lithuanian ministries. The US position that AI regulation should remain at national level essentially corresponds to what the EU has already done internally: it has created binding, rather than voluntary, regulation whose application does not depend on an international agreement.
Article 1(2) of Regulation (EU) 2024/1689 provides that the Regulation covers: harmonised rules for the placing on the market of AI systems, prohibitions of certain AI-related practices, requirements for high-risk AI systems, transparency rules, rules for general-purpose AI models, and market surveillance rules. This means that the EU has chosen precisely the direction defended by China at the UN meeting: a centralised, binding system of standards, but only within its own territory. Providers and deployers of high-risk AI systems are subject to specific obligations under the following provisions:
The most realistic scenario for further developments is the growth of several parallel regulatory tracks: voluntary international commitments at UN level and binding regional legislation. In practical terms, this is most important for providers and deployers of AI systems operating in the EU market: they must comply with the requirements of Articles 9, 15 and 22 irrespective of whether the UN agrees on global standards. For Lithuanian state institutions, the key point is that ministerial rules already require employees to assume responsibility for the accuracy of AI-generated content and to ensure traceability; accordingly, errors in the use of AI in administrative decisions may become grounds for litigation. Monitoring point: in practice, attention should be paid to implementation at EU level: the commencement of the activities of the European Artificial Intelligence Board established under Article 65 and the practice of national supervisory authorities in applying the requirements for high-risk AI systems.
Under Article 6(2) of the Law on Assemblies, the organisers were required to submit written notice no later than four working days before the assembly.
Where several organisers plan assemblies at the same place and at the same time, the mayor, under Article 7(5), coordinates another possible assembly location or time with the other organisers.
On 3 October, several assemblies expressing opposing positions will take place simultaneously in central Vilnius: the National Alliance protest in Vincas Kudirka Square and countervailing actions in Lukiškės Square and on the other side of Gediminas Avenue. Accordingly, the legal situation will be governed by the procedural and security provisions of the Law on Assemblies of the Republic of Lithuania. The issue for the organisers and the municipality is whether the procedure for coordinating notices and selecting assembly locations complied with statutory requirements, in particular the priority rule laid down in Article 7(5) and the list of mandatory particulars to be included in a notice under Article 6(3). The decision will be made by applying Articles 6, 7, 9 and 12 of the Law on Assemblies, while the risk of conflict situations will be assessed in light of the provisions on the purpose of Article 2(8), concerning the protection of public order and the rights of other persons. V. Sinica’s draft law XVP-1166 on the automatic expulsion of convicted foreign nationals remained at the draft-law stage: the Legal Department and the Government did not support it, and therefore the applicable legal position on this issue is determined by the legislation currently in force.
According to the municipality, the National Alliance notice was received on 21 September, which satisfies the requirement. Under Article 6(3), the notice must also specify the organiser’s name, surname and declared place of residence or, where the organiser is a legal person, those details in respect of its representative. Four aspects of assessment follow:
The following scenarios are practically significant: