Enforcement · Lithuanian Data Protection Authority (VDAI) EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.
Company: Insufficient fulfilment of data subjects rights
How it connects
Related across sources
Case Law GC and Others v CNIL Guidance Guidelines 9/2022 on personal data breach notification under GDPR Guidance EDPB Annual Report 2021 Guidance Guidelines 10/2020 on restrictions under Article 23 GDPR Guidance Guidelines 4/2019 on Article 25 Data Protection by Design and by Default Version 2.0 Adopted on 20 October 2020 Guidance Guidelines 5/2019 on the criteria of the Right to be Forgotten in the search engines cases under the GDPR (part 1)
Full text
The Lithuanian DPA has fined a company EUR 8, 000. The controller failed ot properly fulfil the data subject's right to access their personal data processed by the company. The controller partially provided information about the processing of the data subject's personal data, but the data subject was not given the opportunity to verify the legal basis (or bases) for the processing of their personal data, the specific data being processed, the purposes of processing, the retention period, etc.
Industry: Health Care
Original document at the source vdai.lrv.lt