VDAI (Lithuania) - 3R-1040

From GDPRhub
VDAI - 3R-1040
Authority: VDAI (Lithuania)
Jurisdiction: Lithuania
Relevant Law: Article 4(7) GDPR
Article 5(1)(a) GDPR
Article 6(1) GDPR
Article 9(2) GDPR
Article 32(4) GDPR
Type: Investigation
Outcome: Violation Found
Started: 17.12.2024
Decided: 05.06.2026
Published:
Fine: 1,153 EUR
Parties: n/a
National Case Number/Name: 3R-1040
European Case Law Identifier: n/a
Appeal: Unknown
Original Language(s): Lithuanian
Original Source: VDAI (in LT)
Initial Contributor: ap

The DPA fined a doctor €1,153 for unlawfully accessing the data of over 1,200 patients of a medical centre the doctor worked for. Acting as a controller, the doctor invited the patients to a new medical institution they planned to move to.

English Summary

Facts

Šakiai Primary Health Care Center (the medical centre) is a medical centre. In 2024, the medical centre reported a data breach to the DPA. The DPA later initiated an ex-officio investigation, and found that the data breach affected approximately 1,200 data subjects. In 2025, the DPA initiated an investigation regarding one of the doctors working at the centre (the controller), as it suspected that they had unlawfully processed the personal data of their patients in relation to the data breach.

The controller claimed that they accessed data subjects’ data in order to inform them that they would no longer be working at the centre, as there were no procedures in place to inform data subjects of such changes. In addition, they stated that they only made a list of the data subjects and did not access their medical files. Finally, the controller stated that they only contacted the data subjects by email. During its investigations, the DPA found that the controller had accessed the system several times, and had also contacted data subjects through SMS.

Holding

The DPA first clarified that the doctor was a controller. According to EDPB Guidelines[1], employees that have access to personal data are generally not considered controllers or processors. Instead, they would be considered as acting under the authority of a controller or processor (Article 29 GDPR). However, in exceptional cases an employee can be considered a controller if they process personal data for their own purposes. The DPA found that the controller accessed the data for personal reasons, as they had invited data subjects to continue to visit them. The DPA considered that the medical centre had fulfilled its obligations under Article 32(4) GDPR to implement appropriate organisational and technical measures. The DPA also noted that the doctor did not contact the data subjects under instructions of their employer.

The DPA found a violation of Articles 5(1)(a), 6(1) and 9(2) GDPR, as the controller did not have a legal basis to process the data subjects’ personal data. The DPA stated that the controller could not rely on any legal basis under Article 6(1) GDPR, or any of the exceptions to process sensitive personal data under Article 9(2) GDPR. Finally, the DPA stated that the data subjects’ right to be informed about healthcare professionals under national law did not include the right to know that the healthcare professional will be working in a different institution.

The DPA fined the controller €1,153. The DPA considered the number of affected data subjects and the fact that health data was processed as aggravating factors.

Comment

Share your comments here!

Further Resources

Share blogs or news articles here!

English Machine Translation of the Decision

The decision below is a machine translation of the Lithuanian original. Please refer to the Lithuanian original for more details.

Extract of an electronic document
STATE DATA PROTECTION INSPECTORATE
DECISION
June 5, 2026 No. 3R-1040 (2.13-1.E)
Vilnius
The State Data Protection Inspectorate (hereinafter referred to as the Inspectorate) having examined the case regarding the imposition of an administrative fine on Reda Naujokaitienė in the written procedure,
determines:
1. Circumstances for initiating the inspection by the Inspectorate
On 2024-11-06, the Inspectorate received a notification from the Public Institution Šakiai Primary Personal Health Care Centre (hereinafter referred to as the Institution) about a personal data security breach (Inspection reg. No. 1R-7139 (2.23 K))
(hereinafter referred to as the Notification) and the Director of the State Data Protection Inspectorate by order No. of December 17, 2024 1T-105 (1.12 E) on its own initiative initiated an investigation into the Institution regarding a possible violation of the provisions of the GDPR1.
The Inspectorate, having conducted an investigation into the Institution on its own initiative, taking into account the Notification and the information submitted to the Inspectorate regarding the loss of confidentiality of 1,231 personal data subjects of the Institution and the circumstances established during the investigation conducted by the Inspectorate that doctor Reda Naujokaitienė may have unlawfully processed the personal data of the Institution's patients, decided by order No. 1T-62 (1.12 E) of the Director of the State Data Protection Inspectorate of 7 August 2025 to initiate an investigation into a possible violation of the provisions of the GDPR.
2. Explanations received during the inspection
The inspected person, in his response to the Inspection on 18 November 2025 (Inspection reg. No. 1R-8008 (2.13 Mr)), indicated that he knew that from 08 November 2024 he would no longer work at the Institution, and that there was no procedure in place to inform patients about the healthcare specialist providing healthcare services and their change, therefore, in accordance with Article 5(2) of the PTŽSAĮ2, which establishes that a patient has the right to receive information about the healthcare specialist providing healthcare services to him (name, surname, position) and information about his professional qualifications, and subparagraph 23.3 of the Rules3, he logged in once to the information system "Foxus" (hereinafter referred to as the System) on the day before the incapacity for work or the first day of incapacity for work, in order to generate a list of patients and see how many patients in the Institution were assigned to him. They did not review individual patient cards and did not store any data, but only generated a general list of assigned patients. No other connections to
1 Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation) (hereinafter referred to as the GDPR).
2 Law of the Republic of Lithuania on Patients' Rights and Compensation for Damage to Health (hereinafter referred to as the Law on Patients' Rights and Compensation for Damage to Health).
3 Personal Data Processing Rules No. 1, approved by Order No. V-62 of the Director of the Public Institution Šakiai Primary Personal Health Care Centre of 1 July 2024 (hereinafter referred to as the Rules).
2
There were and could not be any other connections during the system period from 2024-10-23 to 2024-10-27. The System was connected and a general list of patients was generated exclusively for the purpose of ensuring patients' rights and communicating with the patient. When connecting to the System, she used her personally assigned login name and password. She had not received a ban from her employer on connecting to the System during non-working or sick leave, if there is a legitimate basis for this. She wrote to patients exclusively via e-mail addresses and the purpose of these letters was related to the implementation of the patient's right to information. She did not send SMS messages to patients. 3. Inspectorate assessment The processing of personal data is regulated by the GDPR and the Data Protection Act4. According to these legal acts, the processing of personal data is considered lawful only if it complies with the principles related to the processing of personal data set out in Article 5 of the GDPR and is based on at least one condition for the lawful processing of personal data provided for in Article 6 of the GDPR, and in Articles 6 and 9 of the GDPR, when special categories of personal data are processed. Article 4(2) of the GDPR provides that data processing means any operation or set of operations which is performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination with other data, restriction, erasure or destruction. According to Article 4(7) of the GDPR, data controller means the natural or legal person, public authority, agency or other body which, alone or jointly with others, determines the purposes and means of data processing; where the purposes and means of such data processing are determined by European Union or Member State law, the data controller or the specific criteria for his appointment may be determined by European Union or Member State law. The main characteristic of the data controller is autonomy in deciding on the purposes and means of data processing. The European Data Protection Board Guidelines No. 07/2020 of 07/07/2020 on the concepts of “controller” and “processor” under the GDPR (hereinafter referred to as the Guidelines) state in paragraph 21 that “controller” is a practical concept and is based not on a formal aspect but on an analysis of specific facts. In this regard, in order to determine the controller, it is necessary to assess the specific data processing operations and understand who determines them, as well as to answer the questions: “why are these data processed?” and “who decided that the data would be processed for a particular purpose?” (Paragraph 20 of the Guidelines). Paragraph 25 of the Guidelines notes that if data management is not carried out in accordance with the provisions of legal acts, the attribution of a country to the controller must be determined based on an assessment of the actual circumstances of data processing. Point 26 of the Guidelines states that “the need for an assessment of the factual circumstances also means that the role of the data controller does not depend on the nature of the entity processing the data, but on its specific activities in the specific circumstances”. As stated in point 17 of the Guidelines, there are no restrictions on the type of entity that can act as a data controller. It can be an organisation, but it can also be an individual or a group of individuals. However, the main responsibility for the processing of data and the obligations under data processing legislation usually lie with the legal person and not with a specific person working within that legal person. Point 19 of the Guidelines also states that “it can be assumed in principle that any processing of personal data carried out by employees in the context of the activities of the organisation is controlled by the organisation”. However, the same paragraph of the Guidelines notes that “in exceptional circumstances, it may happen that an employee decides to use personal data for his own purposes and thus unlawfully exceeds the powers granted to him”. Only in such cases is it important that the legal entity applies appropriate organizational and technical security measures, “including training and informing employees, in order to ensure compliance with the GDPR”. Taking into account the above, it can be concluded that an employee of a legal entity may be considered a data controller and in exceptional cases may be subject to the liability established by the GDPR. Based on the information and evidence provided by the Institution, it was established that the Person Under Review viewed 1,231 patient cards in the System during his period of incapacity for work from 2024-10-23 to 2024-10-27. Although the Person Under Inspection claims that he had logged into the System only once, in order to generate a list of patients and see how many patients were assigned to him in the Institution and that there were no other logins, these statements of the Person Under Inspection are refuted by the System report submitted by the Institution, which shows that the System was logged into more than once at different times, at different intervals from 2024-10-23 to 2024-10-27 (usually in the evenings), to different patient cards, i.e. it was not a one-time login and the report was generated only during it. The Person Under Inspection stated that in the case under consideration he logged into the System because he knew that he would no longer work at the Institution, and that there was no procedure for informing patients about the healthcare professional providing healthcare services and his change, referring to Article 5(2) of the Act on the Provision of Healthcare Services. E-mail The Inspected Person also bases the sending of emails to patients exclusively on the implementation of the patient's right to information. From the explanation of the Inspected Person submitted by the Institution on 2024-11-07, it can be seen that the Inspected Person provided the Institution with an extract of the email he sent to the patient, which shows that he informed the patient that he would no longer work at the institution "Good day, I would like to inform you that from 11-08 I will no longer work at the Šakiai Polyclinic. Thank you for the opportunity to be your family doctor - it was an honor for me! I invite you to continue our friendship at the Zaleckienė outpatient clinic from 11-18."5.
Article 5, Part 2 of the PTŽSAĮ establishes that the patient has the right to receive information about the healthcare specialist providing healthcare services to him (name, surname, position) and information about his professional qualifications.
The Inspectorate notes that the Inspected Person, via the above-mentioned email, informed the patient by letter that he would no longer work at the institution, therefore the claims of the Inspected Person that he processed patient data in the System (generated a report) and used this data because he wanted to inform them (patients) in accordance with Article 5, Part 2 of the PTŽSAĮ are unfounded, since the aforementioned provision establishes that the patient has the right to receive information about the specialist providing the services, and not about the fact that the specialist will work in another institution. Also, during the inspection, the Inspected Person did not provide any evidence that the Institution instructed him (the Inspected Person) to inform the patients of the Institution about the termination of the employment relationship; on the contrary, from the information provided by the Institution and the notification of the personal data security breach, it is clear that the Inspected Person used the patients' data for purposes unrelated to the performance of his functions.
It was also established during the inspection that the Inspected Person used the personal data of the patients
by sending them e-mails and an SMS message. The Inspected
person admitted that he wrote to the patients using e-mail addresses, but indicated that he did not send SMS messages, however, the Inspectorate critically assesses these statements of the Inspected Person, since after assessing the content of the e-mails sent by the Inspected Person (see paragraph 3 of page 3 of this decision) and the SMS message received by the patient6, it can be seen that it is essentially the same, they
have the same writing style, the same date writing format is used, therefore the Inspectorate concludes
that both the e-mail and the SMS message were written by the same person (in the case under consideration, the Inspected Person).
Taking into account the above, the Inspectorate concludes that the Inspected Person, who at that time worked as a doctor in the Institution and had access rights to the System, in order to achieve his (not the Institution's) set goals (including informing patients that he would be working in another medical institution and inviting them to continue to visit him (the Inspected Person)), connected to the System from 2024-10-23 to 2024-10-27 and reviewed the cards of 1,231 patients in the System, which undoubtedly contain 5 Uncorrected language.
6 "Good day. I would like to inform you that from 11.08. I will no longer work at the polyclinic. Thank you for the opportunity to be your family doctor. I invite you to continue our friendship from 11.18. at the Zaleckienė outpatient clinic. Sincerely, R. Naujokaitienė". Uncorrected language.
4
patients' health data, and sent e-mails and SMS messages to the patients using their contacts.
It should be noted that the Inspectorate, having conducted an inspection of the Institution, by decision No. 3R-644 (2.13-1.E) of 2025-06-02
established that the Inspected Person could not perform work functions and access the patients' personal data, including those contained in the System's patient cards, during his incapacity for work, and when connected to the System, he acted not in accordance with the Institution's instructions and violated the requirements of the Rules. Also, by this
decision, the Inspectorate established that the Institution had implemented basic technical measures,
established in the Rules access of employees to personal data, that the data may be processed only for the purpose of performing work functions,
the Inspected Person was familiarized with these Rules, i.e.
The Institution took the necessary steps to ensure that the Inspected Person, who has access to the personal data, did not process them, except in cases where the Institution gives instructions to process them, and properly implemented the requirements of Article 32(4) of the GDPR. Based on the above, the Inspectorate decides that the Inspected Person, by making a decision to process the personal data of patients in violation of the established requirements7, acted as an independent data controller. When deciding to recognize the Inspected Person as an independent data controller, the Inspectorate takes into account the fact that the personal data of as many as 1,231 patients were checked in the System and this was done in order to achieve the goals set by the Inspected Person related to his profession and professional activities (to inform patients that he will work in another medical institution and to invite them to continue to visit him (the Inspected Person)). The person being checked bases the processing of patient data (checking in the System and using it when sending emails) on Article 5(2) of the Personal Data Protection Act, however, as indicated above, the data processing carried out cannot be based on the aforementioned provision of the Personal Data Protection Act. The person being checked did not indicate any other provisions of Article 6(1) and Article 9(2) of the GDPR on the basis of which the patient data (checked in the System and used when sending emails and SMS messages from 23-10-2024 to 27-10-2024) were processed. Based on the above, the Inspectorate decides that in the case under consideration, the Inspected Person
did not prove that the personal data of patients were processed (verified in the System and used when sending
e-mails and SMS messages) in the presence of at least one condition for lawful personal data processing,
enforced in Article 6(1) of the GDPR, and the exception to the prohibition on processing special categories of data,
enforced in Article 9(2) of the GDPR, thus the data were processed unlawfully and the Inspected Person
violated the principle of lawfulness established in Article 5(1)(a) of the GDPR, Article 6(1) of the GDPR and
Article 9(2) of the GDPR.
Having assessed the identified violations of the Inspected Person, the Inspectorate decided to initiate the procedure for imposing an administrative
fine by letter No.
2R-2409 (2.14 E) of 28 April 2026 (hereinafter – the Proposal to impose an administrative fine).
Pursuant to Article 34(1) of the ADTAĮ, the Inspectorate, in its Proposal to impose an administrative fine, requested the inspected person to submit: 1) its explanations regarding the circumstances set out in the Proposal to impose an administrative fine, except for what had already been submitted to the Inspectorate during the inspection, and to provide information relevant to the imposition of an administrative fine (Article 83(2) of the GDPR); 2) its opinion on the procedure for examining the case. 4. Written explanations received after the proposal to impose a fine The person complained about submitted his explanations to the Inspectorate on 15 May 2026 (Inspection Reg. No. 1R-3912 (2.14 K)), in which he indicated essentially analogous information to that provided during the inspection, i.e. that she connected to the System in order to generate a list of patients and see how many patients she has
7 Paragraph 57 of the Rules establishes that only those persons who need it for the purpose of performing direct work functions have the right to access the data of data subjects in the Institution.
5
was assigned to the Institution, did not review individual patient cards, that she did not send SMS messages to the patient,
the message was sent from a phone number other than his/hers. Additionally, she indicated that during the inspection
it was not established whether the System was connected from the same IP address in the period from 2024-10-23 to 2024-10-27, and if this circumstance is not established, it must be assessed that the System was connected to
once. The inspected person noted that if his actions are to be assessed as a violation, it is obvious that it was committed unintentionally, due to ignorance and lack of clear procedures in the Institution, the data subjects did not suffer or suffer any damage as a result of the actions taken, no personal data processing violations had been established in relation to him (the inspected person) before. The inspected person also indicated that he agrees that the case would be examined in a written procedure. 5. Assessment of the explanations received from the inspected person after the Proposal to impose an administrative fine The Inspectorate, having examined the explanations provided by the inspected person, notes that the inspected person essentially indicated in them analogous information that was submitted to the Inspectorate or established by the Inspectorate during the inspection and on which the Inspectorate has already expressed its opinion above in this decision. It should be additionally noted that in the case under consideration, it is irrelevant whether the System was accessed from the same or different IP addresses during the period from 2024-10-23 to 2024-10-27, since it was undoubtedly established that the connection was made from the account of the Person Under Inspection. During the inspection, no data was established that other persons had accessed the System on behalf of the Person Under Inspection, or that the Person Under Inspection had lost or disclosed his or her login details to other persons. 6. Reasons for the decision to impose/not impose an administrative penalty Pursuant to Article 83(1) of the GDPR, the supervisory authority shall ensure that the administrative fines imposed in accordance with this Article of the GDPR for the infringements referred to in paragraphs 4, 5 and 6 of this Regulation are effective, proportionate and dissuasive in each specific case. According to Article 83(2) of the GDPR, administrative fines shall be imposed in addition to or instead of the measures referred to in Article 58(2)(a) to (h) and (j) of the GDPR, taking into account the circumstances of each case. When deciding whether to impose an administrative fine and when determining the amount of the administrative fine, due account shall be taken in each individual case of the following: (a) the nature, gravity and duration of the infringement, taking into account the nature, scope or purpose of the processing concerned, as well as the number of data subjects affected and the extent of the damage suffered by them; (b) whether the infringement was committed intentionally or negligently; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the extent of the liability of the controller or processor, taking into account the technical and organisational measures implemented by them in accordance with Articles 25 and 32; (e) any significant previous breaches by that controller or processor; (f) the degree of cooperation with the supervisory authority to remedy the breach and mitigate its potential adverse effects; (g) the categories of personal data affected by the breach; (h) the manner in which the supervisory authority became aware of the breach, in particular whether the controller or processor notified the breach (and if so, to what extent); (i) where the controller or processor concerned has previously been subject to measures referred to in Article 58(2) in respect of the same matter, whether those measures have been complied with; (j) whether the approved codes of conduct pursuant to Article 40 or the approved certification mechanisms pursuant to Article 42 are complied with; (k) other aggravating or mitigating factors relating to the circumstances of the particular case, such as the financial benefit gained or the loss avoided, directly or indirectly as a result of the breach.
According to recital 129 of the GDPR, the enforcement measure imposed by the supervisory authority should
be appropriate, necessary and proportionate to ensure compliance with the GDPR, taking into account the circumstances of each
6 case, it should respect the right of each person to be heard before a specific measure which would adversely affect him or her is taken, and it should be applied in a way that does not entail unnecessary costs and disproportionate inconvenience for the persons concerned.

Recital 129 of the GDPR states that, in order to ensure consistent monitoring of the application of this Regulation and its enforcement throughout the European Union, supervisory authorities in each Member State should carry out the same tasks and exercise the same effective powers, including investigative powers, powers to take corrective action and impose sanctions, as well as authorisation and advisory powers, in particular in cases where complaints are received from natural persons, and, without prejudice to the powers of criminal prosecution authorities under Member State law, to bring infringements of this Regulation to the attention of judicial authorities and/or to be a party to legal proceedings. The powers of supervisory authorities should be exercised in accordance with appropriate procedural safeguards laid down in Union and Member State law, impartially, fairly and within a reasonable time. In particular, any measure should be appropriate, necessary and proportionate to ensure compliance with this Regulation, taking into account the circumstances of each individual case, respect the right of every person to be heard before any specific measure which would adversely affect them is taken, and be applied in such a way as to avoid unnecessary costs and undue inconvenience to the persons concerned.
In order to ensure a consistent approach to the imposition of administrative fines, the European Data Protection Board (hereinafter referred to as the EDPB) has adopted Guidelines on the calculation of administrative fines8, which state that the administrative fines imposed should be proportionate to the nature, gravity and consequences of the infringement. The Guidelines state that each case must be assessed individually and that Article 83(2) of the GDPR is the starting point for such an individual assessment. These Guidelines provide an interpretation of the assessment criteria set out in Article 83(2) of the GDPR, which is the basis for this Decision below. In addition, the aforementioned guidelines establish a methodology for calculating fines and note that when imposing fines, the following three elements must be taken into account: the classification of the infringements by nature, the seriousness of the infringement and the turnover of the undertaking, and also indicate that data protection authorities must also take into account aggravating or mitigating circumstances, which may increase or decrease the fine and for which the EDPB provides a consistent explanation. When assessing the information collected during the inspection and provided in this decision, when deciding whether to impose an administrative fine on the Inspected Person and when deciding on the amount of the administrative fine, the Inspectorate shall take into account the following aspects set out in Article 83(2) of the GDPR. i) Article 83(2)(a) GDPR – nature, gravity and duration of the infringement
Infringements relating to unlawful data processing
(infringements of Article 5(1)(a) (principle of lawfulness), Article 6(1) and Article 9(2) GDPR) established in relation to the person being checked, which by their nature fall into the category of more serious infringements (Article 83(5)(a) GDPR).
The Guidelines state that the gravity of the infringement is assessed in accordance with the specific circumstances and this includes, among other things, the nature of the processing, as well as the scope, the purpose of the processing, the number of data subjects affected (actually and potentially)
and the extent of the damage.
In the case under consideration, infringements were established, namely the unlawful processing of patient data
(inspection in the System and use by sending e-mails and SMS messages), i.e. the unlawful processing of health data, which is subject to stricter security requirements. In the Inspectorate's assessment, this circumstance makes the infringement more serious.
When assessing the number of data subjects affected, the Inspectorate notes that the EDPB has indicated that the larger the number of data subjects affected, the more importance the supervisory authority may attach to this factor.
8 European Data Protection Board 2023-05-24 Guidelines No. 04/2022 on the calculation of administrative fines under the GDPR (hereinafter referred to as the Guidelines on the calculation of administrative fines).
7
The inspection established that a large number of data subjects (1,231) were affected by the actions of the Inspected Person, therefore, the Inspectorate, when assessing the seriousness of the infringement, attaches more importance to the factor related to the number of data subjects affected.
When assessing the damage, it should be noted that the damage caused by the unlawful processing of personal data does not necessarily have to be material. Recital 75 of the GDPR explains that risks of varying likelihood and severity to the rights and freedoms of natural persons may arise from such processing, where data subjects may lose the opportunity to exercise their rights and freedoms and are prevented from controlling their personal data. The Guidelines on the calculation of administrative fines note that it is necessary to pay attention not only to the damage suffered (according to Recital 75 of the GDPR, the amount of damage suffered means bodily injury, material or non-material damage), but also to the likely damage. The aforementioned Guidelines indicate that damage is assessed only to the extent that is functionally necessary in order to correctly assess the seriousness of the violation and not to duplicate the activities of judicial authorities tasked with determining different forms of individual damage9. According to the Inspectorate, the unlawful processing of personal data has made it more difficult for data subjects (patients) to control their personal data. The Inspectorate assesses the amount of damage suffered as average (i.e. non-material damage).
When assessing the duration of the violations, the Inspectorate notes that the Inspected Person unlawfully processed patient data (checked it in the System and used it to send e-mails and SMS messages) during the period from
2024-10-23 to 2024-10-28, i.e. 6 days. The duration of the violation should be assessed as relatively short.
Taking into account the above, the Inspectorate considers the actions of the Inspected Person to be an aggravating factor in accordance with Article 83(2)(a) of the GDPR.
(ii) Article 83(2)(b) GDPR – whether the infringement was committed intentionally or negligently The Guidelines on the calculation of administrative fines state that, in terms of the elements of an infringement, “intentional” includes both knowledge and deliberate action, while “negligent” means that there was no intention to commit an infringement, although the controller and/or processor breached a legal duty of care. The aforementioned Guidelines state that the intentional or negligent nature of the infringement (Article 83(2)(b) GDPR) should be assessed in the light of objective elements of conduct established in the assessment of the factual circumstances of the case. In the light of the circumstances of the case, the supervisory authority may also give weight to the degree of negligence. In the best case, negligence could be considered neutral. The Inspectorate, assessing the circumstances established during the inspection and the nature of the violations, states that the actions of the Inspected Person in checking patient data in the System, sending e-mails and SMS messages were carried out consciously, in pursuit of specific goals set by the Inspected Person, and were not accidental and should be assessed as intentional. Taking into account the above, the Inspectorate considers the actions of the Inspected Person to be an aggravating factor in accordance with Article 83(2)(b) of the GDPR. iii) Article 83(2)(c) of the GDPR – actions taken to mitigate the damage suffered by data subjects The Guidelines on the calculation of administrative fines state that appropriate measures intended to mitigate the damage suffered by data subjects must be assessed primarily taking into account the element of timeliness, i.e. the time at which the data controller or processor implements them, and their effectiveness. The EDPB emphasises that measures implemented spontaneously before the supervisory authority started an investigation and the controller or processor became aware of it are more likely to be considered as mitigating circumstances than those implemented after that point.
9 Paragraph 53(a)(v) of the Guidelines on the method of setting administrative fines.
8
During the inspection, it was not established that the Inspected Person, having learned about the infringement, took actions to mitigate the damage suffered, however, it should be noted that during the inspection, the Inspected Person indicated that he did not store patient data or transfer it to anyone, therefore it can be concluded that there was no objective need to take additional damage mitigation actions.
Taking into account the above, the Inspectorate considers the actions of the Inspected Person to be a neutral factor under Article 83(2)(c) of the GDPR.
(iv) Article 83(2)(d) GDPR – Extent of liability taking into account the technical and organisational measures implemented by the controller in accordance with Articles 25 and 32 GDPR Articles 25 and 32 GDPR regulate the obligation of the controller to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk when processing personal data. The Guidelines on the calculation of administrative fines note that, given the increased level of accountability under the GDPR, the degree of liability of the controller or processor is likely to be considered as an aggravating or neutral factor and only in exceptional circumstances where the controller or processor goes beyond their obligations under Articles 25 and 32 GDPR will this be considered as a mitigating factor. Considering that no organizational and/or technical data security measures implemented (or not implemented) by the Inspected Person had any impact on the processing of personal data (verification of patient data in the System, sending e-mails and SMS messages), the Inspectorate considers the extent of the liability of the Inspected Person within the scope of Article 83(2)(d) of the GDPR to be a neutral factor. v) Article 83(2)(e) of the GDPR – previous violations of the complained person This criterion is intended to assess the reputation of the entity that committed the violation. The Guidelines on the Calculation of Administrative Fines indicate that the presence of previous violations may be considered an aggravating circumstance when calculating the fine. The importance of this factor must be determined taking into account the nature and frequency of previous violations. The aforementioned Guidelines also note that the presence of previous violations may be considered an aggravating factor when calculating the administrative fine. The nature and frequency of previous infringements are taken into account. However, it is emphasized that the absence of previous infringements could not be considered a mitigating factor, since compliance with the GDPR is the norm and the fact that there are no previous infringements could be assessed as neutral. The Inspectorate has no information that the Inspected Person has previously violated the provisions of the GDPR, therefore it considers the factor set out in Article 83(2)(e) of the GDPR to be neutral. vi) Article 83(2)(f) of the GDPR – cooperation with the Inspectorate in order to remedy the infringement and reduce its potential negative impact Article 83(2)(f) of the GDPR provides that cooperation with the supervisory authority may be “due regard” when deciding whether to impose an administrative fine and when setting the amount of the fine. The Guidelines on the calculation of administrative fines state that, pursuant to Article 31 of the GDPR, the controller and the processor have a joint obligation to cooperate and that insufficient cooperation may lead to a fine under Article 83(4)(a) of the GDPR. Therefore, it should be assumed that the normal obligation to cooperate is mandatory and should therefore be considered a neutral (rather than mitigating) circumstance. The person inspected provided the Inspectorate with the requested information, both during the inspection and after the decision to initiate the administrative fine procedure. However, both the GDPR and the ADTAĮ establish an obligation (duty) for the controller to comply with the requirements of the supervisory authority, therefore timely responses to the Inspectorate's questions or instructions to provide information are not considered a mitigating factor.
9
The Inspectorate, having assessed the above, does not consider the mandatory cooperation of the Inspected Person with the Inspectorate, regulated by legal acts, as either a mitigating or aggravating factor, i.e. it considers it a neutral factor.
vii) Article 83(2)(g) GDPR – categories of personal data affected by the infringement
The Guidelines on the calculation of fines note that the GDPR clearly specifies the types of data that require special protection and therefore a more stringent response in the imposition of fines. This concerns at least the types of data specified in Articles 9 and 10 of the GDPR and data outside the scope of these Articles, which cause direct harm or distress to the data subject of the distribution (such as, for example,
location data, data of private conversations, national identification numbers
or financial data, such as transaction overviews or credit card numbers). In general, the more such categories of data or the more sensitive the data, the more importance the supervisory authority may attach to this factor. In addition, it is important to determine the amount of data relating to each data subject, taking into account that the increase in the amount of data of each data subject increases the infringement of the right to privacy and the protection of personal data. Given that during the inspection it was established that the Inspected Person checked patient data in the System in which health data is processed, i.e. patients' health data were processed, the actions of the Inspected Person are considered an aggravating factor pursuant to Article 83(2)(g) of the GDPR. viii) Article 83(2)(h) of the GDPR – Learning about the infringement by the Inspectorate The supervisory authority may learn about the infringement through an investigation, through complaints, through the media, anonymous reports or through a report by the data controller. The Guidelines on the calculation of administrative fines state that when the supervisory authority has learned of the infringement following a complaint or after an inspection, this factor should be considered neutral. In the case under consideration, the infringement was established after an inspection, therefore this factor is considered neutral. ix) Article 83(2)(i) of the GDPR – application of the measures referred to in Article 58(2) of the GDPR to the person complained of Article 83(2)(i) of the GDPR is related to the circumstance of assessing whether the data controller has complied with the measures referred to in Article 58(2) of the GDPR if these measures have previously been applied to the data controller for the same matter. Given that no corrective measures have been applied to the Person Inspected before, the Inspectorate does not assess the factor referred to in Article 83(2)(i) of the GDPR. x) Article 83(2)(j) of the GDPR – codes of conduct or certification mechanisms applied to the person complained about
Given that certification mechanisms were not applied to the Person Inspected, this
factor is not assessed.
xi) Article 83(2)(k) of the GDPR – other mitigating or aggravating factors
The Inspectorate has not identified any other mitigating or aggravating factors.
Taking into account the arguments of the Inspectorate set out above, the Inspectorate decides to impose an administrative fine on the Person Inspected.
7. Determination of the amount of the administrative fine
10
In the case under consideration, it should be noted that, taking into account that the fine is imposed on a natural person, it will be determined based on the minimum monthly wage (hereinafter referred to as the MMA), while assessing the mitigating and aggravating factors affecting the determination of the amount of the fine. By Resolution No. 16 of the Government of the Republic of Lithuania of 16 October 2025 of the Government of the Republic of Lithuania 700 “On the minimum wage applicable in 2026” approved the minimum wage for 2026 – EUR 1,153.
Having assessed the violations of the Inspected Person (the principle of legality established in Article 5(a) of the GDPR, Article 6(1) of the GDPR, Article 9(2) of the GDPR), the Inspectorate determined that they fall under the categories of violations established in Article 83(5) of the GDPR. Three aggravating factors and five neutral factors were identified in relation to the Inspected Person. No mitigating factors were identified.
Taking into account the fact that out of the eight factors applied to the Inspected Person in Article 83(2) of the GDPR, three factors were identified as aggravating factors for the Inspected Person’s liability, and no mitigating factors were identified, the Inspectorate decides that the fine of EUR 1,153 is to be considered effective, proportionate and dissuasive.
The Inspectorate, having taken into account the provisions of this decision and in accordance with Article 58(2)(i), Article 83(1) and (2), Article 83(5)(a), and Article 34(10) of the GDPR,
decides:
1. To impose a fine of EUR 1,153 (one thousand one hundred and fifty-three euros) on Reda Naujokaitiene for the violations of Article 5(1)(a),
Article 6(1) and
Article 9(2) of the GDPR established in this decision.
2. To inform the Inspected Person about the decision.
This decision may be appealed to the Regional Administrative Court (address: Žygimantų g. 2,
Vilnius) within one month from the date of its delivery, in accordance with the procedure established by the Law on Administrative Procedure.
In accordance with Article 35(1) of the Act on the Prevention of Corruption, the fine imposed shall be paid to the budget revenue collection account10 (contribution code 6803, recipient of funds State Tax Inspectorate under the Ministry of Finance of the Republic of Lithuania, legal entity code 188659752) no later than within three months from the date of acceptance of the fine.

Director Dijana Šinkūnienė

10 No. LT787290000000130151 (AB “Citadele” bankas); No. LT744010051001324763 and No. LT122140030002680220

(Luminor Bank AS Lithuanian branch); No. LT057044060007887175 (AB SEB bankas); No. LT327180000000141038 (AB Šiaulių bankas); No. LT247300010112394300 (AB Swedbank); LT427230000000120025 (UAB Medicinos bankas).
  1. Guidelines 07/2020 on the concepts of controller and processor in the GDPR (7 July 2021), Version 2.1, margins 17 and 19. https://www.edpb.europa.eu/system/files/2023-10/EDPB_guidelines_202007_controllerprocessor_final_en.pdf